bundle.yaml 1.9 MB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488248924902491249224932494249524962497249824992500250125022503250425052506250725082509251025112512251325142515251625172518251925202521252225232524252525262527252825292530253125322533253425352536253725382539254025412542254325442545254625472548254925502551255225532554255525562557255825592560256125622563256425652566256725682569257025712572257325742575257625772578257925802581258225832584258525862587258825892590259125922593259425952596259725982599260026012602260326042605260626072608260926102611261226132614261526162617261826192620262126222623262426252626262726282629263026312632263326342635263626372638263926402641264226432644264526462647264826492650265126522653265426552656265726582659266026612662266326642665266626672668266926702671267226732674267526762677267826792680268126822683268426852686268726882689269026912692269326942695269626972698269927002701270227032704270527062707270827092710271127122713271427152716271727182719272027212722272327242725272627272728272927302731273227332734273527362737273827392740274127422743274427452746274727482749275027512752275327542755275627572758275927602761276227632764276527662767276827692770277127722773277427752776277727782779278027812782278327842785278627872788278927902791279227932794279527962797279827992800280128022803280428052806280728082809281028112812281328142815281628172818281928202821282228232824282528262827282828292830283128322833283428352836283728382839284028412842284328442845284628472848284928502851285228532854285528562857285828592860286128622863286428652866286728682869287028712872287328742875287628772878287928802881288228832884288528862887288828892890289128922893289428952896289728982899290029012902290329042905290629072908290929102911291229132914291529162917291829192920292129222923292429252926292729282929293029312932293329342935293629372938293929402941294229432944294529462947294829492950295129522953295429552956295729582959296029612962296329642965296629672968296929702971297229732974297529762977297829792980298129822983298429852986298729882989299029912992299329942995299629972998299930003001300230033004300530063007300830093010301130123013301430153016301730183019302030213022302330243025302630273028302930303031303230333034303530363037303830393040304130423043304430453046304730483049305030513052305330543055305630573058305930603061306230633064306530663067306830693070307130723073307430753076307730783079308030813082308330843085308630873088308930903091309230933094309530963097309830993100310131023103310431053106310731083109311031113112311331143115311631173118311931203121312231233124312531263127312831293130313131323133313431353136313731383139314031413142314331443145314631473148314931503151315231533154315531563157315831593160316131623163316431653166316731683169317031713172317331743175317631773178317931803181318231833184318531863187318831893190319131923193319431953196319731983199320032013202320332043205320632073208320932103211321232133214321532163217321832193220322132223223322432253226322732283229323032313232323332343235323632373238323932403241324232433244324532463247324832493250325132523253325432553256325732583259326032613262326332643265326632673268326932703271327232733274327532763277327832793280328132823283328432853286328732883289329032913292329332943295329632973298329933003301330233033304330533063307330833093310331133123313331433153316331733183319332033213322332333243325332633273328332933303331333233333334333533363337333833393340334133423343334433453346334733483349335033513352335333543355335633573358335933603361336233633364336533663367336833693370337133723373337433753376337733783379338033813382338333843385338633873388338933903391339233933394339533963397339833993400340134023403340434053406340734083409341034113412341334143415341634173418341934203421342234233424342534263427342834293430343134323433343434353436343734383439344034413442344334443445344634473448344934503451345234533454345534563457345834593460346134623463346434653466346734683469347034713472347334743475347634773478347934803481348234833484348534863487348834893490349134923493349434953496349734983499350035013502350335043505350635073508350935103511351235133514351535163517351835193520352135223523352435253526352735283529353035313532353335343535353635373538353935403541354235433544354535463547354835493550355135523553355435553556355735583559356035613562356335643565356635673568356935703571357235733574357535763577357835793580358135823583358435853586358735883589359035913592359335943595359635973598359936003601360236033604360536063607360836093610361136123613361436153616361736183619362036213622362336243625362636273628362936303631363236333634363536363637363836393640364136423643364436453646364736483649365036513652365336543655365636573658365936603661366236633664366536663667366836693670367136723673367436753676367736783679368036813682368336843685368636873688368936903691369236933694369536963697369836993700370137023703370437053706370737083709371037113712371337143715371637173718371937203721372237233724372537263727372837293730373137323733373437353736373737383739374037413742374337443745374637473748374937503751375237533754375537563757375837593760376137623763376437653766376737683769377037713772377337743775377637773778377937803781378237833784378537863787378837893790379137923793379437953796379737983799380038013802380338043805380638073808380938103811381238133814381538163817381838193820382138223823382438253826382738283829383038313832383338343835383638373838383938403841384238433844384538463847384838493850385138523853385438553856385738583859386038613862386338643865386638673868386938703871387238733874387538763877387838793880388138823883388438853886388738883889389038913892389338943895389638973898389939003901390239033904390539063907390839093910391139123913391439153916391739183919392039213922392339243925392639273928392939303931393239333934393539363937393839393940394139423943394439453946394739483949395039513952395339543955395639573958395939603961396239633964396539663967396839693970397139723973397439753976397739783979398039813982398339843985398639873988398939903991399239933994399539963997399839994000400140024003400440054006400740084009401040114012401340144015401640174018401940204021402240234024402540264027402840294030403140324033403440354036403740384039404040414042404340444045404640474048404940504051405240534054405540564057405840594060406140624063406440654066406740684069407040714072407340744075407640774078407940804081408240834084408540864087408840894090409140924093409440954096409740984099410041014102410341044105410641074108410941104111411241134114411541164117411841194120412141224123412441254126412741284129413041314132413341344135413641374138413941404141414241434144414541464147414841494150415141524153415441554156415741584159416041614162416341644165416641674168416941704171417241734174417541764177417841794180418141824183418441854186418741884189419041914192419341944195419641974198419942004201420242034204420542064207420842094210421142124213421442154216421742184219422042214222422342244225422642274228422942304231423242334234423542364237423842394240424142424243424442454246424742484249425042514252425342544255425642574258425942604261426242634264426542664267426842694270427142724273427442754276427742784279428042814282428342844285428642874288428942904291429242934294429542964297429842994300430143024303430443054306430743084309431043114312431343144315431643174318431943204321432243234324432543264327432843294330433143324333433443354336433743384339434043414342434343444345434643474348434943504351435243534354435543564357435843594360436143624363436443654366436743684369437043714372437343744375437643774378437943804381438243834384438543864387438843894390439143924393439443954396439743984399440044014402440344044405440644074408440944104411441244134414441544164417441844194420442144224423442444254426442744284429443044314432443344344435443644374438443944404441444244434444444544464447444844494450445144524453445444554456445744584459446044614462446344644465446644674468446944704471447244734474447544764477447844794480448144824483448444854486448744884489449044914492449344944495449644974498449945004501450245034504450545064507450845094510451145124513451445154516451745184519452045214522452345244525452645274528452945304531453245334534453545364537453845394540454145424543454445454546454745484549455045514552455345544555455645574558455945604561456245634564456545664567456845694570457145724573457445754576457745784579458045814582458345844585458645874588458945904591459245934594459545964597459845994600460146024603460446054606460746084609461046114612461346144615461646174618461946204621462246234624462546264627462846294630463146324633463446354636463746384639464046414642464346444645464646474648464946504651465246534654465546564657465846594660466146624663466446654666466746684669467046714672467346744675467646774678467946804681468246834684468546864687468846894690469146924693469446954696469746984699470047014702470347044705470647074708470947104711471247134714471547164717471847194720472147224723472447254726472747284729473047314732473347344735473647374738473947404741474247434744474547464747474847494750475147524753475447554756475747584759476047614762476347644765476647674768476947704771477247734774477547764777477847794780478147824783478447854786478747884789479047914792479347944795479647974798479948004801480248034804480548064807480848094810481148124813481448154816481748184819482048214822482348244825482648274828482948304831483248334834483548364837483848394840484148424843484448454846484748484849485048514852485348544855485648574858485948604861486248634864486548664867486848694870487148724873487448754876487748784879488048814882488348844885488648874888488948904891489248934894489548964897489848994900490149024903490449054906490749084909491049114912491349144915491649174918491949204921492249234924492549264927492849294930493149324933493449354936493749384939494049414942494349444945494649474948494949504951495249534954495549564957495849594960496149624963496449654966496749684969497049714972497349744975497649774978497949804981498249834984498549864987498849894990499149924993499449954996499749984999500050015002500350045005500650075008500950105011501250135014501550165017501850195020502150225023502450255026502750285029503050315032503350345035503650375038503950405041504250435044504550465047504850495050505150525053505450555056505750585059506050615062506350645065506650675068506950705071507250735074507550765077507850795080508150825083508450855086508750885089509050915092509350945095509650975098509951005101510251035104510551065107510851095110511151125113511451155116511751185119512051215122512351245125512651275128512951305131513251335134513551365137513851395140514151425143514451455146514751485149515051515152515351545155515651575158515951605161516251635164516551665167516851695170517151725173517451755176517751785179518051815182518351845185518651875188518951905191519251935194519551965197519851995200520152025203520452055206520752085209521052115212521352145215521652175218521952205221522252235224522552265227522852295230523152325233523452355236523752385239524052415242524352445245524652475248524952505251525252535254525552565257525852595260526152625263526452655266526752685269527052715272527352745275527652775278527952805281528252835284528552865287528852895290529152925293529452955296529752985299530053015302530353045305530653075308530953105311531253135314531553165317531853195320532153225323532453255326532753285329533053315332533353345335533653375338533953405341534253435344534553465347534853495350535153525353535453555356535753585359536053615362536353645365536653675368536953705371537253735374537553765377537853795380538153825383538453855386538753885389539053915392539353945395539653975398539954005401540254035404540554065407540854095410541154125413541454155416541754185419542054215422542354245425542654275428542954305431543254335434543554365437543854395440544154425443544454455446544754485449545054515452545354545455545654575458545954605461546254635464546554665467546854695470547154725473547454755476547754785479548054815482548354845485548654875488548954905491549254935494549554965497549854995500550155025503550455055506550755085509551055115512551355145515551655175518551955205521552255235524552555265527552855295530553155325533553455355536553755385539554055415542554355445545554655475548554955505551555255535554555555565557555855595560556155625563556455655566556755685569557055715572557355745575557655775578557955805581558255835584558555865587558855895590559155925593559455955596559755985599560056015602560356045605560656075608560956105611561256135614561556165617561856195620562156225623562456255626562756285629563056315632563356345635563656375638563956405641564256435644564556465647564856495650565156525653565456555656565756585659566056615662566356645665566656675668566956705671567256735674567556765677567856795680568156825683568456855686568756885689569056915692569356945695569656975698569957005701570257035704570557065707570857095710571157125713571457155716571757185719572057215722572357245725572657275728572957305731573257335734573557365737573857395740574157425743574457455746574757485749575057515752575357545755575657575758575957605761576257635764576557665767576857695770577157725773577457755776577757785779578057815782578357845785578657875788578957905791579257935794579557965797579857995800580158025803580458055806580758085809581058115812581358145815581658175818581958205821582258235824582558265827582858295830583158325833583458355836583758385839584058415842584358445845584658475848584958505851585258535854585558565857585858595860586158625863586458655866586758685869587058715872587358745875587658775878587958805881588258835884588558865887588858895890589158925893589458955896589758985899590059015902590359045905590659075908590959105911591259135914591559165917591859195920592159225923592459255926592759285929593059315932593359345935593659375938593959405941594259435944594559465947594859495950595159525953595459555956595759585959596059615962596359645965596659675968596959705971597259735974597559765977597859795980598159825983598459855986598759885989599059915992599359945995599659975998599960006001600260036004600560066007600860096010601160126013601460156016601760186019602060216022602360246025602660276028602960306031603260336034603560366037603860396040604160426043604460456046604760486049605060516052605360546055605660576058605960606061606260636064606560666067606860696070607160726073607460756076607760786079608060816082608360846085608660876088608960906091609260936094609560966097609860996100610161026103610461056106610761086109611061116112611361146115611661176118611961206121612261236124612561266127612861296130613161326133613461356136613761386139614061416142614361446145614661476148614961506151615261536154615561566157615861596160616161626163616461656166616761686169617061716172617361746175617661776178617961806181618261836184618561866187618861896190619161926193619461956196619761986199620062016202620362046205620662076208620962106211621262136214621562166217621862196220622162226223622462256226622762286229623062316232623362346235623662376238623962406241624262436244624562466247624862496250625162526253625462556256625762586259626062616262626362646265626662676268626962706271627262736274627562766277627862796280628162826283628462856286628762886289629062916292629362946295629662976298629963006301630263036304630563066307630863096310631163126313631463156316631763186319632063216322632363246325632663276328632963306331633263336334633563366337633863396340634163426343634463456346634763486349635063516352635363546355635663576358635963606361636263636364636563666367636863696370637163726373637463756376637763786379638063816382638363846385638663876388638963906391639263936394639563966397639863996400640164026403640464056406640764086409641064116412641364146415641664176418641964206421642264236424642564266427642864296430643164326433643464356436643764386439644064416442644364446445644664476448644964506451645264536454645564566457645864596460646164626463646464656466646764686469647064716472647364746475647664776478647964806481648264836484648564866487648864896490649164926493649464956496649764986499650065016502650365046505650665076508650965106511651265136514651565166517651865196520652165226523652465256526652765286529653065316532653365346535653665376538653965406541654265436544654565466547654865496550655165526553655465556556655765586559656065616562656365646565656665676568656965706571657265736574657565766577657865796580658165826583658465856586658765886589659065916592659365946595659665976598659966006601660266036604660566066607660866096610661166126613661466156616661766186619662066216622662366246625662666276628662966306631663266336634663566366637663866396640664166426643664466456646664766486649665066516652665366546655665666576658665966606661666266636664666566666667666866696670667166726673667466756676667766786679668066816682668366846685668666876688668966906691669266936694669566966697669866996700670167026703670467056706670767086709671067116712671367146715671667176718671967206721672267236724672567266727672867296730673167326733673467356736673767386739674067416742674367446745674667476748674967506751675267536754675567566757675867596760676167626763676467656766676767686769677067716772677367746775677667776778677967806781678267836784678567866787678867896790679167926793679467956796679767986799680068016802680368046805680668076808680968106811681268136814681568166817681868196820682168226823682468256826682768286829683068316832683368346835683668376838683968406841684268436844684568466847684868496850685168526853685468556856685768586859686068616862686368646865686668676868686968706871687268736874687568766877687868796880688168826883688468856886688768886889689068916892689368946895689668976898689969006901690269036904690569066907690869096910691169126913691469156916691769186919692069216922692369246925692669276928692969306931693269336934693569366937693869396940694169426943694469456946694769486949695069516952695369546955695669576958695969606961696269636964696569666967696869696970697169726973697469756976697769786979698069816982698369846985698669876988698969906991699269936994699569966997699869997000700170027003700470057006700770087009701070117012701370147015701670177018701970207021702270237024702570267027702870297030703170327033703470357036703770387039704070417042704370447045704670477048704970507051705270537054705570567057705870597060706170627063706470657066706770687069707070717072707370747075707670777078707970807081708270837084708570867087708870897090709170927093709470957096709770987099710071017102710371047105710671077108710971107111711271137114711571167117711871197120712171227123712471257126712771287129713071317132713371347135713671377138713971407141714271437144714571467147714871497150715171527153715471557156715771587159716071617162716371647165716671677168716971707171717271737174717571767177717871797180718171827183718471857186718771887189719071917192719371947195719671977198719972007201720272037204720572067207720872097210721172127213721472157216721772187219722072217222722372247225722672277228722972307231723272337234723572367237723872397240724172427243724472457246724772487249725072517252725372547255725672577258725972607261726272637264726572667267726872697270727172727273727472757276727772787279728072817282728372847285728672877288728972907291729272937294729572967297729872997300730173027303730473057306730773087309731073117312731373147315731673177318731973207321732273237324732573267327732873297330733173327333733473357336733773387339734073417342734373447345734673477348734973507351735273537354735573567357735873597360736173627363736473657366736773687369737073717372737373747375737673777378737973807381738273837384738573867387738873897390739173927393739473957396739773987399740074017402740374047405740674077408740974107411741274137414741574167417741874197420742174227423742474257426742774287429743074317432743374347435743674377438743974407441744274437444744574467447744874497450745174527453745474557456745774587459746074617462746374647465746674677468746974707471747274737474747574767477747874797480748174827483748474857486748774887489749074917492749374947495749674977498749975007501750275037504750575067507750875097510751175127513751475157516751775187519752075217522752375247525752675277528752975307531753275337534753575367537753875397540754175427543754475457546754775487549755075517552755375547555755675577558755975607561756275637564756575667567756875697570757175727573757475757576757775787579758075817582758375847585758675877588758975907591759275937594759575967597759875997600760176027603760476057606760776087609761076117612761376147615761676177618761976207621762276237624762576267627762876297630763176327633763476357636763776387639764076417642764376447645764676477648764976507651765276537654765576567657765876597660766176627663766476657666766776687669767076717672767376747675767676777678767976807681768276837684768576867687768876897690769176927693769476957696769776987699770077017702770377047705770677077708770977107711771277137714771577167717771877197720772177227723772477257726772777287729773077317732773377347735773677377738773977407741774277437744774577467747774877497750775177527753775477557756775777587759776077617762776377647765776677677768776977707771777277737774777577767777777877797780778177827783778477857786778777887789779077917792779377947795779677977798779978007801780278037804780578067807780878097810781178127813781478157816781778187819782078217822782378247825782678277828782978307831783278337834783578367837783878397840784178427843784478457846784778487849785078517852785378547855785678577858785978607861786278637864786578667867786878697870787178727873787478757876787778787879788078817882788378847885788678877888788978907891789278937894789578967897789878997900790179027903790479057906790779087909791079117912791379147915791679177918791979207921792279237924792579267927792879297930793179327933793479357936793779387939794079417942794379447945794679477948794979507951795279537954795579567957795879597960796179627963796479657966796779687969797079717972797379747975797679777978797979807981798279837984798579867987798879897990799179927993799479957996799779987999800080018002800380048005800680078008800980108011801280138014801580168017801880198020802180228023802480258026802780288029803080318032803380348035803680378038803980408041804280438044804580468047804880498050805180528053805480558056805780588059806080618062806380648065806680678068806980708071807280738074807580768077807880798080808180828083808480858086808780888089809080918092809380948095809680978098809981008101810281038104810581068107810881098110811181128113811481158116811781188119812081218122812381248125812681278128812981308131813281338134813581368137813881398140814181428143814481458146814781488149815081518152815381548155815681578158815981608161816281638164816581668167816881698170817181728173817481758176817781788179818081818182818381848185818681878188818981908191819281938194819581968197819881998200820182028203820482058206820782088209821082118212821382148215821682178218821982208221822282238224822582268227822882298230823182328233823482358236823782388239824082418242824382448245824682478248824982508251825282538254825582568257825882598260826182628263826482658266826782688269827082718272827382748275827682778278827982808281828282838284828582868287828882898290829182928293829482958296829782988299830083018302830383048305830683078308830983108311831283138314831583168317831883198320832183228323832483258326832783288329833083318332833383348335833683378338833983408341834283438344834583468347834883498350835183528353835483558356835783588359836083618362836383648365836683678368836983708371837283738374837583768377837883798380838183828383838483858386838783888389839083918392839383948395839683978398839984008401840284038404840584068407840884098410841184128413841484158416841784188419842084218422842384248425842684278428842984308431843284338434843584368437843884398440844184428443844484458446844784488449845084518452845384548455845684578458845984608461846284638464846584668467846884698470847184728473847484758476847784788479848084818482848384848485848684878488848984908491849284938494849584968497849884998500850185028503850485058506850785088509851085118512851385148515851685178518851985208521852285238524852585268527852885298530853185328533853485358536853785388539854085418542854385448545854685478548854985508551855285538554855585568557855885598560856185628563856485658566856785688569857085718572857385748575857685778578857985808581858285838584858585868587858885898590859185928593859485958596859785988599860086018602860386048605860686078608860986108611861286138614861586168617861886198620862186228623862486258626862786288629863086318632863386348635863686378638863986408641864286438644864586468647864886498650865186528653865486558656865786588659866086618662866386648665866686678668866986708671867286738674867586768677867886798680868186828683868486858686868786888689869086918692869386948695869686978698869987008701870287038704870587068707870887098710871187128713871487158716871787188719872087218722872387248725872687278728872987308731873287338734873587368737873887398740874187428743874487458746874787488749875087518752875387548755875687578758875987608761876287638764876587668767876887698770877187728773877487758776877787788779878087818782878387848785878687878788878987908791879287938794879587968797879887998800880188028803880488058806880788088809881088118812881388148815881688178818881988208821882288238824882588268827882888298830883188328833883488358836883788388839884088418842884388448845884688478848884988508851885288538854885588568857885888598860886188628863886488658866886788688869887088718872887388748875887688778878887988808881888288838884888588868887888888898890889188928893889488958896889788988899890089018902890389048905890689078908890989108911891289138914891589168917891889198920892189228923892489258926892789288929893089318932893389348935893689378938893989408941894289438944894589468947894889498950895189528953895489558956895789588959896089618962896389648965896689678968896989708971897289738974897589768977897889798980898189828983898489858986898789888989899089918992899389948995899689978998899990009001900290039004900590069007900890099010901190129013901490159016901790189019902090219022902390249025902690279028902990309031903290339034903590369037903890399040904190429043904490459046904790489049905090519052905390549055905690579058905990609061906290639064906590669067906890699070907190729073907490759076907790789079908090819082908390849085908690879088908990909091909290939094909590969097909890999100910191029103910491059106910791089109911091119112911391149115911691179118911991209121912291239124912591269127912891299130913191329133913491359136913791389139914091419142914391449145914691479148914991509151915291539154915591569157915891599160916191629163916491659166916791689169917091719172917391749175917691779178917991809181918291839184918591869187918891899190919191929193919491959196919791989199920092019202920392049205920692079208920992109211921292139214921592169217921892199220922192229223922492259226922792289229923092319232923392349235923692379238923992409241924292439244924592469247924892499250925192529253925492559256925792589259926092619262926392649265926692679268926992709271927292739274927592769277927892799280928192829283928492859286928792889289929092919292929392949295929692979298929993009301930293039304930593069307930893099310931193129313931493159316931793189319932093219322932393249325932693279328932993309331933293339334933593369337933893399340934193429343934493459346934793489349935093519352935393549355935693579358935993609361936293639364936593669367936893699370937193729373937493759376937793789379938093819382938393849385938693879388938993909391939293939394939593969397939893999400940194029403940494059406940794089409941094119412941394149415941694179418941994209421942294239424942594269427942894299430943194329433943494359436943794389439944094419442944394449445944694479448944994509451945294539454945594569457945894599460946194629463946494659466946794689469947094719472947394749475947694779478947994809481948294839484948594869487948894899490949194929493949494959496949794989499950095019502950395049505950695079508950995109511951295139514951595169517951895199520952195229523952495259526952795289529953095319532953395349535953695379538953995409541954295439544954595469547954895499550955195529553955495559556955795589559956095619562956395649565956695679568956995709571957295739574957595769577957895799580958195829583958495859586958795889589959095919592959395949595959695979598959996009601960296039604960596069607960896099610961196129613961496159616961796189619962096219622962396249625962696279628962996309631963296339634963596369637963896399640964196429643964496459646964796489649965096519652965396549655965696579658965996609661966296639664966596669667966896699670967196729673967496759676967796789679968096819682968396849685968696879688968996909691969296939694969596969697969896999700970197029703970497059706970797089709971097119712971397149715971697179718971997209721972297239724972597269727972897299730973197329733973497359736973797389739974097419742974397449745974697479748974997509751975297539754975597569757975897599760976197629763976497659766976797689769977097719772977397749775977697779778977997809781978297839784978597869787978897899790979197929793979497959796979797989799980098019802980398049805980698079808980998109811981298139814981598169817981898199820982198229823982498259826982798289829983098319832983398349835983698379838983998409841984298439844984598469847984898499850985198529853985498559856985798589859986098619862986398649865986698679868986998709871987298739874987598769877987898799880988198829883988498859886988798889889989098919892989398949895989698979898989999009901990299039904990599069907990899099910991199129913991499159916991799189919992099219922992399249925992699279928992999309931993299339934993599369937993899399940994199429943994499459946994799489949995099519952995399549955995699579958995999609961996299639964996599669967996899699970997199729973997499759976997799789979998099819982998399849985998699879988998999909991999299939994999599969997999899991000010001100021000310004100051000610007100081000910010100111001210013100141001510016100171001810019100201002110022100231002410025100261002710028100291003010031100321003310034100351003610037100381003910040100411004210043100441004510046100471004810049100501005110052100531005410055100561005710058100591006010061100621006310064100651006610067100681006910070100711007210073100741007510076100771007810079100801008110082100831008410085100861008710088100891009010091100921009310094100951009610097100981009910100101011010210103101041010510106101071010810109101101011110112101131011410115101161011710118101191012010121101221012310124101251012610127101281012910130101311013210133101341013510136101371013810139101401014110142101431014410145101461014710148101491015010151101521015310154101551015610157101581015910160101611016210163101641016510166101671016810169101701017110172101731017410175101761017710178101791018010181101821018310184101851018610187101881018910190101911019210193101941019510196101971019810199102001020110202102031020410205102061020710208102091021010211102121021310214102151021610217102181021910220102211022210223102241022510226102271022810229102301023110232102331023410235102361023710238102391024010241102421024310244102451024610247102481024910250102511025210253102541025510256102571025810259102601026110262102631026410265102661026710268102691027010271102721027310274102751027610277102781027910280102811028210283102841028510286102871028810289102901029110292102931029410295102961029710298102991030010301103021030310304103051030610307103081030910310103111031210313103141031510316103171031810319103201032110322103231032410325103261032710328103291033010331103321033310334103351033610337103381033910340103411034210343103441034510346103471034810349103501035110352103531035410355103561035710358103591036010361103621036310364103651036610367103681036910370103711037210373103741037510376103771037810379103801038110382103831038410385103861038710388103891039010391103921039310394103951039610397103981039910400104011040210403104041040510406104071040810409104101041110412104131041410415104161041710418104191042010421104221042310424104251042610427104281042910430104311043210433104341043510436104371043810439104401044110442104431044410445104461044710448104491045010451104521045310454104551045610457104581045910460104611046210463104641046510466104671046810469104701047110472104731047410475104761047710478104791048010481104821048310484104851048610487104881048910490104911049210493104941049510496104971049810499105001050110502105031050410505105061050710508105091051010511105121051310514105151051610517105181051910520105211052210523105241052510526105271052810529105301053110532105331053410535105361053710538105391054010541105421054310544105451054610547105481054910550105511055210553105541055510556105571055810559105601056110562105631056410565105661056710568105691057010571105721057310574105751057610577105781057910580105811058210583105841058510586105871058810589105901059110592105931059410595105961059710598105991060010601106021060310604106051060610607106081060910610106111061210613106141061510616106171061810619106201062110622106231062410625106261062710628106291063010631106321063310634106351063610637106381063910640106411064210643106441064510646106471064810649106501065110652106531065410655106561065710658106591066010661106621066310664106651066610667106681066910670106711067210673106741067510676106771067810679106801068110682106831068410685106861068710688106891069010691106921069310694106951069610697106981069910700107011070210703107041070510706107071070810709107101071110712107131071410715107161071710718107191072010721107221072310724107251072610727107281072910730107311073210733107341073510736107371073810739107401074110742107431074410745107461074710748107491075010751107521075310754107551075610757107581075910760107611076210763107641076510766107671076810769107701077110772107731077410775107761077710778107791078010781107821078310784107851078610787107881078910790107911079210793107941079510796107971079810799108001080110802108031080410805108061080710808108091081010811108121081310814108151081610817108181081910820108211082210823108241082510826108271082810829108301083110832108331083410835108361083710838108391084010841108421084310844108451084610847108481084910850108511085210853108541085510856108571085810859108601086110862108631086410865108661086710868108691087010871108721087310874108751087610877108781087910880108811088210883108841088510886108871088810889108901089110892108931089410895108961089710898108991090010901109021090310904109051090610907109081090910910109111091210913109141091510916109171091810919109201092110922109231092410925109261092710928109291093010931109321093310934109351093610937109381093910940109411094210943109441094510946109471094810949109501095110952109531095410955109561095710958109591096010961109621096310964109651096610967109681096910970109711097210973109741097510976109771097810979109801098110982109831098410985109861098710988109891099010991109921099310994109951099610997109981099911000110011100211003110041100511006110071100811009110101101111012110131101411015110161101711018110191102011021110221102311024110251102611027110281102911030110311103211033110341103511036110371103811039110401104111042110431104411045110461104711048110491105011051110521105311054110551105611057110581105911060110611106211063110641106511066110671106811069110701107111072110731107411075110761107711078110791108011081110821108311084110851108611087110881108911090110911109211093110941109511096110971109811099111001110111102111031110411105111061110711108111091111011111111121111311114111151111611117111181111911120111211112211123111241112511126111271112811129111301113111132111331113411135111361113711138111391114011141111421114311144111451114611147111481114911150111511115211153111541115511156111571115811159111601116111162111631116411165111661116711168111691117011171111721117311174111751117611177111781117911180111811118211183111841118511186111871118811189111901119111192111931119411195111961119711198111991120011201112021120311204112051120611207112081120911210112111121211213112141121511216112171121811219112201122111222112231122411225112261122711228112291123011231112321123311234112351123611237112381123911240112411124211243112441124511246112471124811249112501125111252112531125411255112561125711258112591126011261112621126311264112651126611267112681126911270112711127211273112741127511276112771127811279112801128111282112831128411285112861128711288112891129011291112921129311294112951129611297112981129911300113011130211303113041130511306113071130811309113101131111312113131131411315113161131711318113191132011321113221132311324113251132611327113281132911330113311133211333113341133511336113371133811339113401134111342113431134411345113461134711348113491135011351113521135311354113551135611357113581135911360113611136211363113641136511366113671136811369113701137111372113731137411375113761137711378113791138011381113821138311384113851138611387113881138911390113911139211393113941139511396113971139811399114001140111402114031140411405114061140711408114091141011411114121141311414114151141611417114181141911420114211142211423114241142511426114271142811429114301143111432114331143411435114361143711438114391144011441114421144311444114451144611447114481144911450114511145211453114541145511456114571145811459114601146111462114631146411465114661146711468114691147011471114721147311474114751147611477114781147911480114811148211483114841148511486114871148811489114901149111492114931149411495114961149711498114991150011501115021150311504115051150611507115081150911510115111151211513115141151511516115171151811519115201152111522115231152411525115261152711528115291153011531115321153311534115351153611537115381153911540115411154211543115441154511546115471154811549115501155111552115531155411555115561155711558115591156011561115621156311564115651156611567115681156911570115711157211573115741157511576115771157811579115801158111582115831158411585115861158711588115891159011591115921159311594115951159611597115981159911600116011160211603116041160511606116071160811609116101161111612116131161411615116161161711618116191162011621116221162311624116251162611627116281162911630116311163211633116341163511636116371163811639116401164111642116431164411645116461164711648116491165011651116521165311654116551165611657116581165911660116611166211663116641166511666116671166811669116701167111672116731167411675116761167711678116791168011681116821168311684116851168611687116881168911690116911169211693116941169511696116971169811699117001170111702117031170411705117061170711708117091171011711117121171311714117151171611717117181171911720117211172211723117241172511726117271172811729117301173111732117331173411735117361173711738117391174011741117421174311744117451174611747117481174911750117511175211753117541175511756117571175811759117601176111762117631176411765117661176711768117691177011771117721177311774117751177611777117781177911780117811178211783117841178511786117871178811789117901179111792117931179411795117961179711798117991180011801118021180311804118051180611807118081180911810118111181211813118141181511816118171181811819118201182111822118231182411825118261182711828118291183011831118321183311834118351183611837118381183911840118411184211843118441184511846118471184811849118501185111852118531185411855118561185711858118591186011861118621186311864118651186611867118681186911870118711187211873118741187511876118771187811879118801188111882118831188411885118861188711888118891189011891118921189311894118951189611897118981189911900119011190211903119041190511906119071190811909119101191111912119131191411915119161191711918119191192011921119221192311924119251192611927119281192911930119311193211933119341193511936119371193811939119401194111942119431194411945119461194711948119491195011951119521195311954119551195611957119581195911960119611196211963119641196511966119671196811969119701197111972119731197411975119761197711978119791198011981119821198311984119851198611987119881198911990119911199211993119941199511996119971199811999120001200112002120031200412005120061200712008120091201012011120121201312014120151201612017120181201912020120211202212023120241202512026120271202812029120301203112032120331203412035120361203712038120391204012041120421204312044120451204612047120481204912050120511205212053120541205512056120571205812059120601206112062120631206412065120661206712068120691207012071120721207312074120751207612077120781207912080120811208212083120841208512086120871208812089120901209112092120931209412095120961209712098120991210012101121021210312104121051210612107121081210912110121111211212113121141211512116121171211812119121201212112122121231212412125121261212712128121291213012131121321213312134121351213612137121381213912140121411214212143121441214512146121471214812149121501215112152121531215412155121561215712158121591216012161121621216312164121651216612167121681216912170121711217212173121741217512176121771217812179121801218112182121831218412185121861218712188121891219012191121921219312194121951219612197121981219912200122011220212203122041220512206122071220812209122101221112212122131221412215122161221712218122191222012221122221222312224122251222612227122281222912230122311223212233122341223512236122371223812239122401224112242122431224412245122461224712248122491225012251122521225312254122551225612257122581225912260122611226212263122641226512266122671226812269122701227112272122731227412275122761227712278122791228012281122821228312284122851228612287122881228912290122911229212293122941229512296122971229812299123001230112302123031230412305123061230712308123091231012311123121231312314123151231612317123181231912320123211232212323123241232512326123271232812329123301233112332123331233412335123361233712338123391234012341123421234312344123451234612347123481234912350123511235212353123541235512356123571235812359123601236112362123631236412365123661236712368123691237012371123721237312374123751237612377123781237912380123811238212383123841238512386123871238812389123901239112392123931239412395123961239712398123991240012401124021240312404124051240612407124081240912410124111241212413124141241512416124171241812419124201242112422124231242412425124261242712428124291243012431124321243312434124351243612437124381243912440124411244212443124441244512446124471244812449124501245112452124531245412455124561245712458124591246012461124621246312464124651246612467124681246912470124711247212473124741247512476124771247812479124801248112482124831248412485124861248712488124891249012491124921249312494124951249612497124981249912500125011250212503125041250512506125071250812509125101251112512125131251412515125161251712518125191252012521125221252312524125251252612527125281252912530125311253212533125341253512536125371253812539125401254112542125431254412545125461254712548125491255012551125521255312554125551255612557125581255912560125611256212563125641256512566125671256812569125701257112572125731257412575125761257712578125791258012581125821258312584125851258612587125881258912590125911259212593125941259512596125971259812599126001260112602126031260412605126061260712608126091261012611126121261312614126151261612617126181261912620126211262212623126241262512626126271262812629126301263112632126331263412635126361263712638126391264012641126421264312644126451264612647126481264912650126511265212653126541265512656126571265812659126601266112662126631266412665126661266712668126691267012671126721267312674126751267612677126781267912680126811268212683126841268512686126871268812689126901269112692126931269412695126961269712698126991270012701127021270312704127051270612707127081270912710127111271212713127141271512716127171271812719127201272112722127231272412725127261272712728127291273012731127321273312734127351273612737127381273912740127411274212743127441274512746127471274812749127501275112752127531275412755127561275712758127591276012761127621276312764127651276612767127681276912770127711277212773127741277512776127771277812779127801278112782127831278412785127861278712788127891279012791127921279312794127951279612797127981279912800128011280212803128041280512806128071280812809128101281112812128131281412815128161281712818128191282012821128221282312824128251282612827128281282912830128311283212833128341283512836128371283812839128401284112842128431284412845128461284712848128491285012851128521285312854128551285612857128581285912860128611286212863128641286512866128671286812869128701287112872128731287412875128761287712878128791288012881128821288312884128851288612887128881288912890128911289212893128941289512896128971289812899129001290112902129031290412905129061290712908129091291012911129121291312914129151291612917129181291912920129211292212923129241292512926129271292812929129301293112932129331293412935129361293712938129391294012941129421294312944129451294612947129481294912950129511295212953129541295512956129571295812959129601296112962129631296412965129661296712968129691297012971129721297312974129751297612977129781297912980129811298212983129841298512986129871298812989129901299112992129931299412995129961299712998129991300013001130021300313004130051300613007130081300913010130111301213013130141301513016130171301813019130201302113022130231302413025130261302713028130291303013031130321303313034130351303613037130381303913040130411304213043130441304513046130471304813049130501305113052130531305413055130561305713058130591306013061130621306313064130651306613067130681306913070130711307213073130741307513076130771307813079130801308113082130831308413085130861308713088130891309013091130921309313094130951309613097130981309913100131011310213103131041310513106131071310813109131101311113112131131311413115131161311713118131191312013121131221312313124131251312613127131281312913130131311313213133131341313513136131371313813139131401314113142131431314413145131461314713148131491315013151131521315313154131551315613157131581315913160131611316213163131641316513166131671316813169131701317113172131731317413175131761317713178131791318013181131821318313184131851318613187131881318913190131911319213193131941319513196131971319813199132001320113202132031320413205132061320713208132091321013211132121321313214132151321613217132181321913220132211322213223132241322513226132271322813229132301323113232132331323413235132361323713238132391324013241132421324313244132451324613247132481324913250132511325213253132541325513256132571325813259132601326113262132631326413265132661326713268132691327013271132721327313274132751327613277132781327913280132811328213283132841328513286132871328813289132901329113292132931329413295132961329713298132991330013301133021330313304133051330613307133081330913310133111331213313133141331513316133171331813319133201332113322133231332413325133261332713328133291333013331133321333313334133351333613337133381333913340133411334213343133441334513346133471334813349133501335113352133531335413355133561335713358133591336013361133621336313364133651336613367133681336913370133711337213373133741337513376133771337813379133801338113382133831338413385133861338713388133891339013391133921339313394133951339613397133981339913400134011340213403134041340513406134071340813409134101341113412134131341413415134161341713418134191342013421134221342313424134251342613427134281342913430134311343213433134341343513436134371343813439134401344113442134431344413445134461344713448134491345013451134521345313454134551345613457134581345913460134611346213463134641346513466134671346813469134701347113472134731347413475134761347713478134791348013481134821348313484134851348613487134881348913490134911349213493134941349513496134971349813499135001350113502135031350413505135061350713508135091351013511135121351313514135151351613517135181351913520135211352213523135241352513526135271352813529135301353113532135331353413535135361353713538135391354013541135421354313544135451354613547135481354913550135511355213553135541355513556135571355813559135601356113562135631356413565135661356713568135691357013571135721357313574135751357613577135781357913580135811358213583135841358513586135871358813589135901359113592135931359413595135961359713598135991360013601136021360313604136051360613607136081360913610136111361213613136141361513616136171361813619136201362113622136231362413625136261362713628136291363013631136321363313634136351363613637136381363913640136411364213643136441364513646136471364813649136501365113652136531365413655136561365713658136591366013661136621366313664136651366613667136681366913670136711367213673136741367513676136771367813679136801368113682136831368413685136861368713688136891369013691136921369313694136951369613697136981369913700137011370213703137041370513706137071370813709137101371113712137131371413715137161371713718137191372013721137221372313724137251372613727137281372913730137311373213733137341373513736137371373813739137401374113742137431374413745137461374713748137491375013751137521375313754137551375613757137581375913760137611376213763137641376513766137671376813769137701377113772137731377413775137761377713778137791378013781137821378313784137851378613787137881378913790137911379213793137941379513796137971379813799138001380113802138031380413805138061380713808138091381013811138121381313814138151381613817138181381913820138211382213823138241382513826138271382813829138301383113832138331383413835138361383713838138391384013841138421384313844138451384613847138481384913850138511385213853138541385513856138571385813859138601386113862138631386413865138661386713868138691387013871138721387313874138751387613877138781387913880138811388213883138841388513886138871388813889138901389113892138931389413895138961389713898138991390013901139021390313904139051390613907139081390913910139111391213913139141391513916139171391813919139201392113922139231392413925139261392713928139291393013931139321393313934139351393613937139381393913940139411394213943139441394513946139471394813949139501395113952139531395413955139561395713958139591396013961139621396313964139651396613967139681396913970139711397213973139741397513976139771397813979139801398113982139831398413985139861398713988139891399013991139921399313994139951399613997139981399914000140011400214003140041400514006140071400814009140101401114012140131401414015140161401714018140191402014021140221402314024140251402614027140281402914030140311403214033140341403514036140371403814039140401404114042140431404414045140461404714048140491405014051140521405314054140551405614057140581405914060140611406214063140641406514066140671406814069140701407114072140731407414075140761407714078140791408014081140821408314084140851408614087140881408914090140911409214093140941409514096140971409814099141001410114102141031410414105141061410714108141091411014111141121411314114141151411614117141181411914120141211412214123141241412514126141271412814129141301413114132141331413414135141361413714138141391414014141141421414314144141451414614147141481414914150141511415214153141541415514156141571415814159141601416114162141631416414165141661416714168141691417014171141721417314174141751417614177141781417914180141811418214183141841418514186141871418814189141901419114192141931419414195141961419714198141991420014201142021420314204142051420614207142081420914210142111421214213142141421514216142171421814219142201422114222142231422414225142261422714228142291423014231142321423314234142351423614237142381423914240142411424214243142441424514246142471424814249142501425114252142531425414255142561425714258142591426014261142621426314264142651426614267142681426914270142711427214273142741427514276142771427814279142801428114282142831428414285142861428714288142891429014291142921429314294142951429614297142981429914300143011430214303143041430514306143071430814309143101431114312143131431414315143161431714318143191432014321143221432314324143251432614327143281432914330143311433214333143341433514336143371433814339143401434114342143431434414345143461434714348143491435014351143521435314354143551435614357143581435914360143611436214363143641436514366143671436814369143701437114372143731437414375143761437714378143791438014381143821438314384143851438614387143881438914390143911439214393143941439514396143971439814399144001440114402144031440414405144061440714408144091441014411144121441314414144151441614417144181441914420144211442214423144241442514426144271442814429144301443114432144331443414435144361443714438144391444014441144421444314444144451444614447144481444914450144511445214453144541445514456144571445814459144601446114462144631446414465144661446714468144691447014471144721447314474144751447614477144781447914480144811448214483144841448514486144871448814489144901449114492144931449414495144961449714498144991450014501145021450314504145051450614507145081450914510145111451214513145141451514516145171451814519145201452114522145231452414525145261452714528145291453014531145321453314534145351453614537145381453914540145411454214543145441454514546145471454814549145501455114552145531455414555145561455714558145591456014561145621456314564145651456614567145681456914570145711457214573145741457514576145771457814579145801458114582145831458414585145861458714588145891459014591145921459314594145951459614597145981459914600146011460214603146041460514606146071460814609146101461114612146131461414615146161461714618146191462014621146221462314624146251462614627146281462914630146311463214633146341463514636146371463814639146401464114642146431464414645146461464714648146491465014651146521465314654146551465614657146581465914660146611466214663146641466514666146671466814669146701467114672146731467414675146761467714678146791468014681146821468314684146851468614687146881468914690146911469214693146941469514696146971469814699147001470114702147031470414705147061470714708147091471014711147121471314714147151471614717147181471914720147211472214723147241472514726147271472814729147301473114732147331473414735147361473714738147391474014741147421474314744147451474614747147481474914750147511475214753147541475514756147571475814759147601476114762147631476414765147661476714768147691477014771147721477314774147751477614777147781477914780147811478214783147841478514786147871478814789147901479114792147931479414795147961479714798147991480014801148021480314804148051480614807148081480914810148111481214813148141481514816148171481814819148201482114822148231482414825148261482714828148291483014831148321483314834148351483614837148381483914840148411484214843148441484514846148471484814849148501485114852148531485414855148561485714858148591486014861148621486314864148651486614867148681486914870148711487214873148741487514876148771487814879148801488114882148831488414885148861488714888148891489014891148921489314894148951489614897148981489914900149011490214903149041490514906149071490814909149101491114912149131491414915149161491714918149191492014921149221492314924149251492614927149281492914930149311493214933149341493514936149371493814939149401494114942149431494414945149461494714948149491495014951149521495314954149551495614957149581495914960149611496214963149641496514966149671496814969149701497114972149731497414975149761497714978149791498014981149821498314984149851498614987149881498914990149911499214993149941499514996149971499814999150001500115002150031500415005150061500715008150091501015011150121501315014150151501615017150181501915020150211502215023150241502515026150271502815029150301503115032150331503415035150361503715038150391504015041150421504315044150451504615047150481504915050150511505215053150541505515056150571505815059150601506115062150631506415065150661506715068150691507015071150721507315074150751507615077150781507915080150811508215083150841508515086150871508815089150901509115092150931509415095150961509715098150991510015101151021510315104151051510615107151081510915110151111511215113151141511515116151171511815119151201512115122151231512415125151261512715128151291513015131151321513315134151351513615137151381513915140151411514215143151441514515146151471514815149151501515115152151531515415155151561515715158151591516015161151621516315164151651516615167151681516915170151711517215173151741517515176151771517815179151801518115182151831518415185151861518715188151891519015191151921519315194151951519615197151981519915200152011520215203152041520515206152071520815209152101521115212152131521415215152161521715218152191522015221152221522315224152251522615227152281522915230152311523215233152341523515236152371523815239152401524115242152431524415245152461524715248152491525015251152521525315254152551525615257152581525915260152611526215263152641526515266152671526815269152701527115272152731527415275152761527715278152791528015281152821528315284152851528615287152881528915290152911529215293152941529515296152971529815299153001530115302153031530415305153061530715308153091531015311153121531315314153151531615317153181531915320153211532215323153241532515326153271532815329153301533115332153331533415335153361533715338153391534015341153421534315344153451534615347153481534915350153511535215353153541535515356153571535815359153601536115362153631536415365153661536715368153691537015371153721537315374153751537615377153781537915380153811538215383153841538515386153871538815389153901539115392153931539415395153961539715398153991540015401154021540315404154051540615407154081540915410154111541215413154141541515416154171541815419154201542115422154231542415425154261542715428154291543015431154321543315434154351543615437154381543915440154411544215443154441544515446154471544815449154501545115452154531545415455154561545715458154591546015461154621546315464154651546615467154681546915470154711547215473154741547515476154771547815479154801548115482154831548415485154861548715488154891549015491154921549315494154951549615497154981549915500155011550215503155041550515506155071550815509155101551115512155131551415515155161551715518155191552015521155221552315524155251552615527155281552915530155311553215533155341553515536155371553815539155401554115542155431554415545155461554715548155491555015551155521555315554155551555615557155581555915560155611556215563155641556515566155671556815569155701557115572155731557415575155761557715578155791558015581155821558315584155851558615587155881558915590155911559215593155941559515596155971559815599156001560115602156031560415605156061560715608156091561015611156121561315614156151561615617156181561915620156211562215623156241562515626156271562815629156301563115632156331563415635156361563715638156391564015641156421564315644156451564615647156481564915650156511565215653156541565515656156571565815659156601566115662156631566415665156661566715668156691567015671156721567315674156751567615677156781567915680156811568215683156841568515686156871568815689156901569115692156931569415695156961569715698156991570015701157021570315704157051570615707157081570915710157111571215713157141571515716157171571815719157201572115722157231572415725157261572715728157291573015731157321573315734157351573615737157381573915740157411574215743157441574515746157471574815749157501575115752157531575415755157561575715758157591576015761157621576315764157651576615767157681576915770157711577215773157741577515776157771577815779157801578115782157831578415785157861578715788157891579015791157921579315794157951579615797157981579915800158011580215803158041580515806158071580815809158101581115812158131581415815158161581715818158191582015821158221582315824158251582615827158281582915830158311583215833158341583515836158371583815839158401584115842158431584415845158461584715848158491585015851158521585315854158551585615857158581585915860158611586215863158641586515866158671586815869158701587115872158731587415875158761587715878158791588015881158821588315884158851588615887158881588915890158911589215893158941589515896158971589815899159001590115902159031590415905159061590715908159091591015911159121591315914159151591615917159181591915920159211592215923159241592515926159271592815929159301593115932159331593415935159361593715938159391594015941159421594315944159451594615947159481594915950159511595215953159541595515956159571595815959159601596115962159631596415965159661596715968159691597015971159721597315974159751597615977159781597915980159811598215983159841598515986159871598815989159901599115992159931599415995159961599715998159991600016001160021600316004160051600616007160081600916010160111601216013160141601516016160171601816019160201602116022160231602416025160261602716028160291603016031160321603316034160351603616037160381603916040160411604216043160441604516046160471604816049160501605116052160531605416055160561605716058160591606016061160621606316064160651606616067160681606916070160711607216073160741607516076160771607816079160801608116082160831608416085160861608716088160891609016091160921609316094160951609616097160981609916100161011610216103161041610516106161071610816109161101611116112161131611416115161161611716118161191612016121161221612316124161251612616127161281612916130161311613216133161341613516136161371613816139161401614116142161431614416145161461614716148161491615016151161521615316154161551615616157161581615916160161611616216163161641616516166161671616816169161701617116172161731617416175161761617716178161791618016181161821618316184161851618616187161881618916190161911619216193161941619516196161971619816199162001620116202162031620416205162061620716208162091621016211162121621316214162151621616217162181621916220162211622216223162241622516226162271622816229162301623116232162331623416235162361623716238162391624016241162421624316244162451624616247162481624916250162511625216253162541625516256162571625816259162601626116262162631626416265162661626716268162691627016271162721627316274162751627616277162781627916280162811628216283162841628516286162871628816289162901629116292162931629416295162961629716298162991630016301163021630316304163051630616307163081630916310163111631216313163141631516316163171631816319163201632116322163231632416325163261632716328163291633016331163321633316334163351633616337163381633916340163411634216343163441634516346163471634816349163501635116352163531635416355163561635716358163591636016361163621636316364163651636616367163681636916370163711637216373163741637516376163771637816379163801638116382163831638416385163861638716388163891639016391163921639316394163951639616397163981639916400164011640216403164041640516406164071640816409164101641116412164131641416415164161641716418164191642016421164221642316424164251642616427164281642916430164311643216433164341643516436164371643816439164401644116442164431644416445164461644716448164491645016451164521645316454164551645616457164581645916460164611646216463164641646516466164671646816469164701647116472164731647416475164761647716478164791648016481164821648316484164851648616487164881648916490164911649216493164941649516496164971649816499165001650116502165031650416505165061650716508165091651016511165121651316514165151651616517165181651916520165211652216523165241652516526165271652816529165301653116532165331653416535165361653716538165391654016541165421654316544165451654616547165481654916550165511655216553165541655516556165571655816559165601656116562165631656416565165661656716568165691657016571165721657316574165751657616577165781657916580165811658216583165841658516586165871658816589165901659116592165931659416595165961659716598165991660016601166021660316604166051660616607166081660916610166111661216613166141661516616166171661816619166201662116622166231662416625166261662716628166291663016631166321663316634166351663616637166381663916640166411664216643166441664516646166471664816649166501665116652166531665416655166561665716658166591666016661166621666316664166651666616667166681666916670166711667216673166741667516676166771667816679166801668116682166831668416685166861668716688166891669016691166921669316694166951669616697166981669916700167011670216703167041670516706167071670816709167101671116712167131671416715167161671716718167191672016721167221672316724167251672616727167281672916730167311673216733167341673516736167371673816739167401674116742167431674416745167461674716748167491675016751167521675316754167551675616757167581675916760167611676216763167641676516766167671676816769167701677116772167731677416775167761677716778167791678016781167821678316784167851678616787167881678916790167911679216793167941679516796167971679816799168001680116802168031680416805168061680716808168091681016811168121681316814168151681616817168181681916820168211682216823168241682516826168271682816829168301683116832168331683416835168361683716838168391684016841168421684316844168451684616847168481684916850168511685216853168541685516856168571685816859168601686116862168631686416865168661686716868168691687016871168721687316874168751687616877168781687916880168811688216883168841688516886168871688816889168901689116892168931689416895168961689716898168991690016901169021690316904169051690616907169081690916910169111691216913169141691516916169171691816919169201692116922169231692416925169261692716928169291693016931169321693316934169351693616937169381693916940169411694216943169441694516946169471694816949169501695116952169531695416955169561695716958169591696016961169621696316964169651696616967169681696916970169711697216973169741697516976169771697816979169801698116982169831698416985169861698716988169891699016991169921699316994169951699616997169981699917000170011700217003170041700517006170071700817009170101701117012170131701417015170161701717018170191702017021170221702317024170251702617027170281702917030170311703217033170341703517036170371703817039170401704117042170431704417045170461704717048170491705017051170521705317054170551705617057170581705917060170611706217063170641706517066170671706817069170701707117072170731707417075170761707717078170791708017081170821708317084170851708617087170881708917090170911709217093170941709517096170971709817099171001710117102171031710417105171061710717108171091711017111171121711317114171151711617117171181711917120171211712217123171241712517126171271712817129171301713117132171331713417135171361713717138171391714017141171421714317144171451714617147171481714917150171511715217153171541715517156171571715817159171601716117162171631716417165171661716717168171691717017171171721717317174171751717617177171781717917180171811718217183171841718517186171871718817189171901719117192171931719417195171961719717198171991720017201172021720317204172051720617207172081720917210172111721217213172141721517216172171721817219172201722117222172231722417225172261722717228172291723017231172321723317234172351723617237172381723917240172411724217243172441724517246172471724817249172501725117252172531725417255172561725717258172591726017261172621726317264172651726617267172681726917270172711727217273172741727517276172771727817279172801728117282172831728417285172861728717288172891729017291172921729317294172951729617297172981729917300173011730217303173041730517306173071730817309173101731117312173131731417315173161731717318173191732017321173221732317324173251732617327173281732917330173311733217333173341733517336173371733817339173401734117342173431734417345173461734717348173491735017351173521735317354173551735617357173581735917360173611736217363173641736517366173671736817369173701737117372173731737417375173761737717378173791738017381173821738317384173851738617387173881738917390173911739217393173941739517396173971739817399174001740117402174031740417405174061740717408174091741017411174121741317414174151741617417174181741917420174211742217423174241742517426174271742817429174301743117432174331743417435174361743717438174391744017441174421744317444174451744617447174481744917450174511745217453174541745517456174571745817459174601746117462174631746417465174661746717468174691747017471174721747317474174751747617477174781747917480174811748217483174841748517486174871748817489174901749117492174931749417495174961749717498174991750017501175021750317504175051750617507175081750917510175111751217513175141751517516175171751817519175201752117522175231752417525175261752717528175291753017531175321753317534175351753617537175381753917540175411754217543175441754517546175471754817549175501755117552175531755417555175561755717558175591756017561175621756317564175651756617567175681756917570175711757217573175741757517576175771757817579175801758117582175831758417585175861758717588175891759017591175921759317594175951759617597175981759917600176011760217603176041760517606176071760817609176101761117612176131761417615176161761717618176191762017621176221762317624176251762617627176281762917630176311763217633176341763517636176371763817639176401764117642176431764417645176461764717648176491765017651176521765317654176551765617657176581765917660176611766217663176641766517666176671766817669176701767117672176731767417675176761767717678176791768017681176821768317684176851768617687176881768917690176911769217693176941769517696176971769817699177001770117702177031770417705177061770717708177091771017711177121771317714177151771617717177181771917720177211772217723177241772517726177271772817729177301773117732177331773417735177361773717738177391774017741177421774317744177451774617747177481774917750177511775217753177541775517756177571775817759177601776117762177631776417765177661776717768177691777017771177721777317774177751777617777177781777917780177811778217783177841778517786177871778817789177901779117792177931779417795177961779717798177991780017801178021780317804178051780617807178081780917810178111781217813178141781517816178171781817819178201782117822178231782417825178261782717828178291783017831178321783317834178351783617837178381783917840178411784217843178441784517846178471784817849178501785117852178531785417855178561785717858178591786017861178621786317864178651786617867178681786917870178711787217873178741787517876178771787817879178801788117882178831788417885178861788717888178891789017891178921789317894178951789617897178981789917900179011790217903179041790517906179071790817909179101791117912179131791417915179161791717918179191792017921179221792317924179251792617927179281792917930179311793217933179341793517936179371793817939179401794117942179431794417945179461794717948179491795017951179521795317954179551795617957179581795917960179611796217963179641796517966179671796817969179701797117972179731797417975179761797717978179791798017981179821798317984179851798617987179881798917990179911799217993179941799517996179971799817999180001800118002180031800418005180061800718008180091801018011180121801318014180151801618017180181801918020180211802218023180241802518026180271802818029180301803118032180331803418035180361803718038180391804018041180421804318044180451804618047180481804918050180511805218053180541805518056180571805818059180601806118062180631806418065180661806718068180691807018071180721807318074180751807618077180781807918080180811808218083180841808518086180871808818089180901809118092180931809418095180961809718098180991810018101181021810318104181051810618107181081810918110181111811218113181141811518116181171811818119181201812118122181231812418125181261812718128181291813018131181321813318134181351813618137181381813918140181411814218143181441814518146181471814818149181501815118152181531815418155181561815718158181591816018161181621816318164181651816618167181681816918170181711817218173181741817518176181771817818179181801818118182181831818418185181861818718188181891819018191181921819318194181951819618197181981819918200182011820218203182041820518206182071820818209182101821118212182131821418215182161821718218182191822018221182221822318224182251822618227182281822918230182311823218233182341823518236182371823818239182401824118242182431824418245182461824718248182491825018251182521825318254182551825618257182581825918260182611826218263182641826518266182671826818269182701827118272182731827418275182761827718278182791828018281182821828318284182851828618287182881828918290182911829218293182941829518296182971829818299183001830118302183031830418305183061830718308183091831018311183121831318314183151831618317183181831918320183211832218323183241832518326183271832818329183301833118332183331833418335183361833718338183391834018341183421834318344183451834618347183481834918350183511835218353183541835518356183571835818359183601836118362183631836418365183661836718368183691837018371183721837318374183751837618377183781837918380183811838218383183841838518386183871838818389183901839118392183931839418395183961839718398183991840018401184021840318404184051840618407184081840918410184111841218413184141841518416184171841818419184201842118422184231842418425184261842718428184291843018431184321843318434184351843618437184381843918440184411844218443184441844518446184471844818449184501845118452184531845418455184561845718458184591846018461184621846318464184651846618467184681846918470184711847218473184741847518476184771847818479184801848118482184831848418485184861848718488184891849018491184921849318494184951849618497184981849918500185011850218503185041850518506185071850818509185101851118512185131851418515185161851718518185191852018521185221852318524185251852618527185281852918530185311853218533185341853518536185371853818539185401854118542185431854418545185461854718548185491855018551185521855318554185551855618557185581855918560185611856218563185641856518566185671856818569185701857118572185731857418575185761857718578185791858018581185821858318584185851858618587185881858918590185911859218593185941859518596185971859818599186001860118602186031860418605186061860718608186091861018611186121861318614186151861618617186181861918620186211862218623186241862518626186271862818629186301863118632186331863418635186361863718638186391864018641186421864318644186451864618647186481864918650186511865218653186541865518656186571865818659186601866118662186631866418665186661866718668186691867018671186721867318674186751867618677186781867918680186811868218683186841868518686186871868818689186901869118692186931869418695186961869718698186991870018701187021870318704187051870618707187081870918710187111871218713187141871518716187171871818719187201872118722187231872418725187261872718728187291873018731187321873318734187351873618737187381873918740187411874218743187441874518746187471874818749187501875118752187531875418755187561875718758187591876018761187621876318764187651876618767187681876918770187711877218773187741877518776187771877818779187801878118782187831878418785187861878718788187891879018791187921879318794187951879618797187981879918800188011880218803188041880518806188071880818809188101881118812188131881418815188161881718818188191882018821188221882318824188251882618827188281882918830188311883218833188341883518836188371883818839188401884118842188431884418845188461884718848188491885018851188521885318854188551885618857188581885918860188611886218863188641886518866188671886818869188701887118872188731887418875188761887718878188791888018881188821888318884188851888618887188881888918890188911889218893188941889518896188971889818899189001890118902189031890418905189061890718908189091891018911189121891318914189151891618917189181891918920189211892218923189241892518926189271892818929189301893118932189331893418935189361893718938189391894018941189421894318944189451894618947189481894918950189511895218953189541895518956189571895818959189601896118962189631896418965189661896718968189691897018971189721897318974189751897618977189781897918980189811898218983189841898518986189871898818989189901899118992189931899418995189961899718998189991900019001190021900319004190051900619007190081900919010190111901219013190141901519016190171901819019190201902119022190231902419025190261902719028190291903019031190321903319034190351903619037190381903919040190411904219043190441904519046190471904819049190501905119052190531905419055190561905719058190591906019061190621906319064190651906619067190681906919070190711907219073190741907519076190771907819079190801908119082190831908419085190861908719088190891909019091190921909319094190951909619097190981909919100191011910219103191041910519106191071910819109191101911119112191131911419115191161911719118191191912019121191221912319124191251912619127191281912919130191311913219133191341913519136191371913819139191401914119142191431914419145191461914719148191491915019151191521915319154191551915619157191581915919160191611916219163191641916519166191671916819169191701917119172191731917419175191761917719178191791918019181191821918319184191851918619187191881918919190191911919219193191941919519196191971919819199192001920119202192031920419205192061920719208192091921019211192121921319214192151921619217192181921919220192211922219223192241922519226192271922819229192301923119232192331923419235192361923719238192391924019241192421924319244192451924619247192481924919250192511925219253192541925519256192571925819259192601926119262192631926419265192661926719268192691927019271192721927319274192751927619277192781927919280192811928219283192841928519286192871928819289192901929119292192931929419295192961929719298192991930019301193021930319304193051930619307193081930919310193111931219313193141931519316193171931819319193201932119322193231932419325193261932719328193291933019331193321933319334193351933619337193381933919340193411934219343193441934519346193471934819349193501935119352193531935419355193561935719358193591936019361193621936319364193651936619367193681936919370193711937219373193741937519376193771937819379193801938119382193831938419385193861938719388193891939019391193921939319394193951939619397193981939919400194011940219403194041940519406194071940819409194101941119412194131941419415194161941719418194191942019421194221942319424194251942619427194281942919430194311943219433194341943519436194371943819439194401944119442194431944419445194461944719448194491945019451194521945319454194551945619457194581945919460194611946219463194641946519466194671946819469194701947119472194731947419475194761947719478194791948019481194821948319484194851948619487194881948919490194911949219493194941949519496194971949819499195001950119502195031950419505195061950719508195091951019511195121951319514195151951619517195181951919520195211952219523195241952519526195271952819529195301953119532195331953419535195361953719538195391954019541195421954319544195451954619547195481954919550195511955219553195541955519556195571955819559195601956119562195631956419565195661956719568195691957019571195721957319574195751957619577195781957919580195811958219583195841958519586195871958819589195901959119592195931959419595195961959719598195991960019601196021960319604196051960619607196081960919610196111961219613196141961519616196171961819619196201962119622196231962419625196261962719628196291963019631196321963319634196351963619637196381963919640196411964219643196441964519646196471964819649196501965119652196531965419655196561965719658196591966019661196621966319664196651966619667196681966919670196711967219673196741967519676196771967819679196801968119682196831968419685196861968719688196891969019691196921969319694196951969619697196981969919700197011970219703197041970519706197071970819709197101971119712197131971419715197161971719718197191972019721197221972319724197251972619727197281972919730197311973219733197341973519736197371973819739197401974119742197431974419745197461974719748197491975019751197521975319754197551975619757197581975919760197611976219763197641976519766197671976819769197701977119772197731977419775197761977719778197791978019781197821978319784197851978619787197881978919790197911979219793197941979519796197971979819799198001980119802198031980419805198061980719808198091981019811198121981319814198151981619817198181981919820198211982219823198241982519826198271982819829198301983119832198331983419835198361983719838198391984019841198421984319844198451984619847198481984919850198511985219853198541985519856198571985819859198601986119862198631986419865198661986719868198691987019871198721987319874198751987619877198781987919880198811988219883198841988519886198871988819889198901989119892198931989419895198961989719898198991990019901199021990319904199051990619907199081990919910199111991219913199141991519916199171991819919199201992119922199231992419925199261992719928199291993019931199321993319934199351993619937199381993919940199411994219943199441994519946199471994819949199501995119952199531995419955199561995719958199591996019961199621996319964199651996619967199681996919970199711997219973199741997519976199771997819979199801998119982199831998419985199861998719988199891999019991199921999319994199951999619997199981999920000200012000220003200042000520006200072000820009200102001120012200132001420015200162001720018200192002020021200222002320024200252002620027200282002920030200312003220033200342003520036200372003820039200402004120042200432004420045200462004720048200492005020051200522005320054200552005620057200582005920060200612006220063200642006520066200672006820069200702007120072200732007420075200762007720078200792008020081200822008320084200852008620087200882008920090200912009220093200942009520096200972009820099201002010120102201032010420105201062010720108201092011020111201122011320114201152011620117201182011920120201212012220123201242012520126201272012820129201302013120132201332013420135201362013720138201392014020141201422014320144201452014620147201482014920150201512015220153201542015520156201572015820159201602016120162201632016420165201662016720168201692017020171201722017320174201752017620177201782017920180201812018220183201842018520186201872018820189201902019120192201932019420195201962019720198201992020020201202022020320204202052020620207202082020920210202112021220213202142021520216202172021820219202202022120222202232022420225202262022720228202292023020231202322023320234202352023620237202382023920240202412024220243202442024520246202472024820249202502025120252202532025420255202562025720258202592026020261202622026320264202652026620267202682026920270202712027220273202742027520276202772027820279202802028120282202832028420285202862028720288202892029020291202922029320294202952029620297202982029920300203012030220303203042030520306203072030820309203102031120312203132031420315203162031720318203192032020321203222032320324203252032620327203282032920330203312033220333203342033520336203372033820339203402034120342203432034420345203462034720348203492035020351203522035320354203552035620357203582035920360203612036220363203642036520366203672036820369203702037120372203732037420375203762037720378203792038020381203822038320384203852038620387203882038920390203912039220393203942039520396203972039820399204002040120402204032040420405204062040720408204092041020411204122041320414204152041620417204182041920420204212042220423204242042520426204272042820429204302043120432204332043420435204362043720438204392044020441204422044320444204452044620447204482044920450204512045220453204542045520456204572045820459204602046120462204632046420465204662046720468204692047020471204722047320474204752047620477204782047920480204812048220483204842048520486204872048820489204902049120492204932049420495204962049720498204992050020501205022050320504205052050620507205082050920510205112051220513205142051520516205172051820519205202052120522205232052420525205262052720528205292053020531205322053320534205352053620537205382053920540205412054220543205442054520546205472054820549205502055120552205532055420555205562055720558205592056020561205622056320564205652056620567205682056920570205712057220573205742057520576205772057820579205802058120582205832058420585205862058720588205892059020591205922059320594205952059620597205982059920600206012060220603206042060520606206072060820609206102061120612206132061420615206162061720618206192062020621206222062320624206252062620627206282062920630206312063220633206342063520636206372063820639206402064120642206432064420645206462064720648206492065020651206522065320654206552065620657206582065920660206612066220663206642066520666206672066820669206702067120672206732067420675206762067720678206792068020681206822068320684206852068620687206882068920690206912069220693206942069520696206972069820699207002070120702207032070420705207062070720708207092071020711207122071320714207152071620717207182071920720207212072220723207242072520726207272072820729207302073120732207332073420735207362073720738207392074020741207422074320744207452074620747207482074920750207512075220753207542075520756207572075820759207602076120762207632076420765207662076720768207692077020771207722077320774207752077620777207782077920780207812078220783207842078520786207872078820789207902079120792207932079420795207962079720798207992080020801208022080320804208052080620807208082080920810208112081220813208142081520816208172081820819208202082120822208232082420825208262082720828208292083020831208322083320834208352083620837208382083920840208412084220843208442084520846208472084820849208502085120852208532085420855208562085720858208592086020861208622086320864208652086620867208682086920870208712087220873208742087520876208772087820879208802088120882208832088420885208862088720888208892089020891208922089320894208952089620897208982089920900209012090220903209042090520906209072090820909209102091120912209132091420915209162091720918209192092020921209222092320924209252092620927209282092920930209312093220933209342093520936209372093820939209402094120942209432094420945209462094720948209492095020951209522095320954209552095620957209582095920960209612096220963209642096520966209672096820969209702097120972209732097420975209762097720978209792098020981209822098320984209852098620987209882098920990209912099220993209942099520996209972099820999210002100121002210032100421005210062100721008210092101021011210122101321014210152101621017210182101921020210212102221023210242102521026210272102821029210302103121032210332103421035210362103721038210392104021041210422104321044210452104621047210482104921050210512105221053210542105521056210572105821059210602106121062210632106421065210662106721068210692107021071210722107321074210752107621077210782107921080210812108221083210842108521086210872108821089210902109121092210932109421095210962109721098210992110021101211022110321104211052110621107211082110921110211112111221113211142111521116211172111821119211202112121122211232112421125211262112721128211292113021131211322113321134211352113621137211382113921140211412114221143211442114521146211472114821149211502115121152211532115421155211562115721158211592116021161211622116321164211652116621167211682116921170211712117221173211742117521176211772117821179211802118121182211832118421185211862118721188211892119021191211922119321194211952119621197211982119921200212012120221203212042120521206212072120821209212102121121212212132121421215212162121721218212192122021221212222122321224212252122621227212282122921230212312123221233212342123521236212372123821239212402124121242212432124421245212462124721248212492125021251212522125321254212552125621257212582125921260212612126221263212642126521266212672126821269212702127121272212732127421275212762127721278212792128021281212822128321284212852128621287212882128921290212912129221293212942129521296212972129821299213002130121302213032130421305213062130721308213092131021311213122131321314213152131621317213182131921320213212132221323213242132521326213272132821329213302133121332213332133421335213362133721338213392134021341213422134321344213452134621347213482134921350213512135221353213542135521356213572135821359213602136121362213632136421365213662136721368213692137021371213722137321374213752137621377213782137921380213812138221383213842138521386213872138821389213902139121392213932139421395213962139721398213992140021401214022140321404214052140621407214082140921410214112141221413214142141521416214172141821419214202142121422214232142421425214262142721428214292143021431214322143321434214352143621437214382143921440214412144221443214442144521446214472144821449214502145121452214532145421455214562145721458214592146021461214622146321464214652146621467214682146921470214712147221473214742147521476214772147821479214802148121482214832148421485214862148721488214892149021491214922149321494214952149621497214982149921500215012150221503215042150521506215072150821509215102151121512215132151421515215162151721518215192152021521215222152321524215252152621527215282152921530215312153221533215342153521536215372153821539215402154121542215432154421545215462154721548215492155021551215522155321554215552155621557215582155921560215612156221563215642156521566215672156821569215702157121572215732157421575215762157721578215792158021581215822158321584215852158621587215882158921590215912159221593215942159521596215972159821599216002160121602216032160421605216062160721608216092161021611216122161321614216152161621617216182161921620216212162221623216242162521626216272162821629216302163121632216332163421635216362163721638216392164021641216422164321644216452164621647216482164921650216512165221653216542165521656216572165821659216602166121662216632166421665216662166721668216692167021671216722167321674216752167621677216782167921680216812168221683216842168521686216872168821689216902169121692216932169421695216962169721698216992170021701217022170321704217052170621707217082170921710217112171221713217142171521716217172171821719217202172121722217232172421725217262172721728217292173021731217322173321734217352173621737217382173921740217412174221743217442174521746217472174821749217502175121752217532175421755217562175721758217592176021761217622176321764217652176621767217682176921770217712177221773217742177521776217772177821779217802178121782217832178421785217862178721788217892179021791217922179321794217952179621797217982179921800218012180221803218042180521806218072180821809218102181121812218132181421815218162181721818218192182021821218222182321824218252182621827218282182921830218312183221833218342183521836218372183821839218402184121842218432184421845218462184721848218492185021851218522185321854218552185621857218582185921860218612186221863218642186521866218672186821869218702187121872218732187421875218762187721878218792188021881218822188321884218852188621887218882188921890218912189221893218942189521896218972189821899219002190121902219032190421905219062190721908219092191021911219122191321914219152191621917219182191921920219212192221923219242192521926219272192821929219302193121932219332193421935219362193721938219392194021941219422194321944219452194621947219482194921950219512195221953219542195521956219572195821959219602196121962219632196421965219662196721968219692197021971219722197321974219752197621977219782197921980219812198221983219842198521986219872198821989219902199121992219932199421995219962199721998219992200022001220022200322004220052200622007220082200922010220112201222013220142201522016220172201822019220202202122022220232202422025220262202722028220292203022031220322203322034220352203622037220382203922040220412204222043220442204522046220472204822049220502205122052220532205422055220562205722058220592206022061220622206322064220652206622067220682206922070220712207222073220742207522076220772207822079220802208122082220832208422085220862208722088220892209022091220922209322094220952209622097220982209922100221012210222103221042210522106221072210822109221102211122112221132211422115221162211722118221192212022121221222212322124221252212622127221282212922130221312213222133221342213522136221372213822139221402214122142221432214422145221462214722148221492215022151221522215322154221552215622157221582215922160221612216222163221642216522166221672216822169221702217122172221732217422175221762217722178221792218022181221822218322184221852218622187221882218922190221912219222193221942219522196221972219822199222002220122202222032220422205222062220722208222092221022211222122221322214222152221622217222182221922220222212222222223222242222522226222272222822229222302223122232222332223422235222362223722238222392224022241222422224322244222452224622247222482224922250222512225222253222542225522256222572225822259222602226122262222632226422265222662226722268222692227022271222722227322274222752227622277222782227922280222812228222283222842228522286222872228822289222902229122292222932229422295222962229722298222992230022301223022230322304223052230622307223082230922310223112231222313223142231522316223172231822319223202232122322223232232422325223262232722328223292233022331223322233322334223352233622337223382233922340223412234222343223442234522346223472234822349223502235122352223532235422355223562235722358223592236022361223622236322364223652236622367223682236922370223712237222373223742237522376223772237822379223802238122382223832238422385223862238722388223892239022391223922239322394223952239622397223982239922400224012240222403224042240522406224072240822409224102241122412224132241422415224162241722418224192242022421224222242322424224252242622427224282242922430224312243222433224342243522436224372243822439224402244122442224432244422445224462244722448224492245022451224522245322454224552245622457224582245922460224612246222463224642246522466224672246822469224702247122472224732247422475224762247722478224792248022481224822248322484224852248622487224882248922490224912249222493224942249522496224972249822499225002250122502225032250422505225062250722508225092251022511225122251322514225152251622517225182251922520225212252222523225242252522526225272252822529225302253122532225332253422535225362253722538225392254022541225422254322544225452254622547225482254922550225512255222553225542255522556225572255822559225602256122562225632256422565225662256722568225692257022571225722257322574225752257622577225782257922580225812258222583225842258522586225872258822589225902259122592225932259422595225962259722598225992260022601226022260322604226052260622607226082260922610226112261222613226142261522616226172261822619226202262122622226232262422625226262262722628226292263022631226322263322634226352263622637226382263922640226412264222643226442264522646226472264822649226502265122652226532265422655226562265722658226592266022661226622266322664226652266622667226682266922670226712267222673226742267522676226772267822679226802268122682226832268422685226862268722688226892269022691226922269322694226952269622697226982269922700227012270222703227042270522706227072270822709227102271122712227132271422715227162271722718227192272022721227222272322724227252272622727227282272922730227312273222733227342273522736227372273822739227402274122742227432274422745227462274722748227492275022751227522275322754227552275622757227582275922760227612276222763227642276522766227672276822769227702277122772227732277422775227762277722778227792278022781227822278322784227852278622787227882278922790227912279222793227942279522796227972279822799228002280122802228032280422805228062280722808228092281022811228122281322814228152281622817228182281922820228212282222823228242282522826228272282822829228302283122832228332283422835228362283722838228392284022841228422284322844228452284622847228482284922850228512285222853228542285522856228572285822859228602286122862228632286422865228662286722868228692287022871228722287322874228752287622877228782287922880228812288222883228842288522886228872288822889228902289122892228932289422895228962289722898228992290022901229022290322904229052290622907229082290922910229112291222913229142291522916229172291822919229202292122922229232292422925229262292722928229292293022931229322293322934229352293622937229382293922940229412294222943229442294522946229472294822949229502295122952229532295422955229562295722958229592296022961229622296322964229652296622967229682296922970229712297222973229742297522976229772297822979229802298122982229832298422985229862298722988229892299022991229922299322994229952299622997229982299923000230012300223003230042300523006230072300823009230102301123012230132301423015230162301723018230192302023021230222302323024230252302623027230282302923030230312303223033230342303523036230372303823039230402304123042230432304423045230462304723048230492305023051230522305323054230552305623057230582305923060230612306223063230642306523066230672306823069230702307123072230732307423075230762307723078230792308023081230822308323084230852308623087230882308923090230912309223093230942309523096230972309823099231002310123102231032310423105231062310723108231092311023111231122311323114231152311623117231182311923120231212312223123231242312523126231272312823129231302313123132231332313423135231362313723138231392314023141231422314323144231452314623147231482314923150231512315223153231542315523156231572315823159231602316123162231632316423165231662316723168231692317023171231722317323174231752317623177231782317923180231812318223183231842318523186231872318823189231902319123192231932319423195231962319723198231992320023201232022320323204232052320623207232082320923210232112321223213232142321523216232172321823219232202322123222232232322423225232262322723228232292323023231232322323323234232352323623237232382323923240232412324223243232442324523246232472324823249232502325123252232532325423255232562325723258232592326023261232622326323264232652326623267232682326923270232712327223273232742327523276232772327823279232802328123282232832328423285232862328723288232892329023291232922329323294232952329623297232982329923300233012330223303233042330523306233072330823309233102331123312233132331423315233162331723318233192332023321233222332323324233252332623327233282332923330233312333223333233342333523336233372333823339233402334123342233432334423345233462334723348233492335023351233522335323354233552335623357233582335923360233612336223363233642336523366233672336823369233702337123372233732337423375233762337723378233792338023381233822338323384233852338623387233882338923390233912339223393233942339523396233972339823399234002340123402234032340423405234062340723408234092341023411234122341323414234152341623417234182341923420234212342223423234242342523426234272342823429234302343123432234332343423435234362343723438234392344023441234422344323444234452344623447234482344923450234512345223453234542345523456234572345823459234602346123462234632346423465234662346723468234692347023471234722347323474234752347623477234782347923480234812348223483234842348523486234872348823489234902349123492234932349423495234962349723498234992350023501235022350323504235052350623507235082350923510235112351223513235142351523516235172351823519235202352123522235232352423525235262352723528235292353023531235322353323534235352353623537235382353923540235412354223543235442354523546235472354823549235502355123552235532355423555235562355723558235592356023561235622356323564235652356623567235682356923570235712357223573235742357523576235772357823579235802358123582235832358423585235862358723588235892359023591235922359323594235952359623597235982359923600236012360223603236042360523606236072360823609236102361123612236132361423615236162361723618236192362023621236222362323624236252362623627236282362923630236312363223633236342363523636236372363823639236402364123642236432364423645236462364723648236492365023651236522365323654236552365623657236582365923660236612366223663236642366523666236672366823669236702367123672236732367423675236762367723678236792368023681236822368323684236852368623687236882368923690236912369223693236942369523696236972369823699237002370123702237032370423705237062370723708237092371023711237122371323714237152371623717237182371923720237212372223723237242372523726237272372823729237302373123732237332373423735237362373723738237392374023741237422374323744237452374623747237482374923750237512375223753237542375523756237572375823759237602376123762237632376423765237662376723768237692377023771237722377323774237752377623777237782377923780237812378223783237842378523786237872378823789237902379123792237932379423795237962379723798237992380023801238022380323804238052380623807238082380923810238112381223813238142381523816238172381823819238202382123822238232382423825238262382723828238292383023831238322383323834238352383623837238382383923840238412384223843238442384523846238472384823849238502385123852238532385423855238562385723858238592386023861238622386323864238652386623867238682386923870238712387223873238742387523876238772387823879238802388123882238832388423885238862388723888238892389023891238922389323894238952389623897238982389923900239012390223903239042390523906239072390823909239102391123912239132391423915239162391723918239192392023921239222392323924239252392623927239282392923930239312393223933239342393523936239372393823939239402394123942239432394423945239462394723948239492395023951239522395323954239552395623957239582395923960239612396223963239642396523966239672396823969239702397123972239732397423975239762397723978239792398023981239822398323984239852398623987239882398923990239912399223993239942399523996239972399823999240002400124002240032400424005240062400724008240092401024011240122401324014240152401624017240182401924020240212402224023240242402524026240272402824029240302403124032240332403424035240362403724038240392404024041240422404324044240452404624047240482404924050240512405224053240542405524056240572405824059240602406124062240632406424065240662406724068240692407024071240722407324074240752407624077240782407924080240812408224083240842408524086240872408824089240902409124092240932409424095240962409724098240992410024101241022410324104241052410624107241082410924110241112411224113241142411524116241172411824119241202412124122241232412424125241262412724128241292413024131241322413324134241352413624137241382413924140241412414224143241442414524146241472414824149241502415124152241532415424155241562415724158241592416024161241622416324164241652416624167241682416924170241712417224173241742417524176241772417824179241802418124182241832418424185241862418724188241892419024191241922419324194241952419624197241982419924200242012420224203242042420524206242072420824209242102421124212242132421424215242162421724218242192422024221242222422324224242252422624227242282422924230242312423224233242342423524236242372423824239242402424124242242432424424245242462424724248242492425024251242522425324254242552425624257242582425924260242612426224263242642426524266242672426824269242702427124272242732427424275242762427724278242792428024281242822428324284242852428624287242882428924290242912429224293242942429524296242972429824299243002430124302243032430424305243062430724308243092431024311243122431324314243152431624317243182431924320243212432224323243242432524326243272432824329243302433124332243332433424335243362433724338243392434024341243422434324344243452434624347243482434924350243512435224353243542435524356243572435824359243602436124362243632436424365243662436724368243692437024371243722437324374243752437624377243782437924380243812438224383243842438524386243872438824389243902439124392243932439424395243962439724398243992440024401244022440324404244052440624407244082440924410244112441224413244142441524416244172441824419244202442124422244232442424425244262442724428244292443024431244322443324434244352443624437244382443924440244412444224443244442444524446244472444824449244502445124452244532445424455244562445724458244592446024461244622446324464244652446624467244682446924470244712447224473244742447524476244772447824479244802448124482244832448424485244862448724488244892449024491244922449324494244952449624497244982449924500245012450224503245042450524506245072450824509245102451124512245132451424515245162451724518245192452024521245222452324524245252452624527245282452924530245312453224533245342453524536245372453824539245402454124542245432454424545245462454724548245492455024551245522455324554245552455624557245582455924560245612456224563245642456524566245672456824569245702457124572245732457424575245762457724578245792458024581245822458324584245852458624587245882458924590245912459224593245942459524596245972459824599246002460124602246032460424605246062460724608246092461024611246122461324614246152461624617246182461924620246212462224623246242462524626246272462824629246302463124632246332463424635246362463724638246392464024641246422464324644246452464624647246482464924650246512465224653246542465524656246572465824659246602466124662246632466424665246662466724668246692467024671246722467324674246752467624677246782467924680246812468224683246842468524686246872468824689246902469124692246932469424695246962469724698246992470024701247022470324704247052470624707247082470924710247112471224713247142471524716247172471824719247202472124722247232472424725247262472724728247292473024731247322473324734247352473624737247382473924740247412474224743247442474524746247472474824749247502475124752247532475424755247562475724758247592476024761247622476324764247652476624767247682476924770247712477224773247742477524776247772477824779247802478124782247832478424785247862478724788247892479024791247922479324794247952479624797247982479924800248012480224803248042480524806248072480824809248102481124812248132481424815248162481724818248192482024821248222482324824248252482624827248282482924830248312483224833248342483524836248372483824839248402484124842248432484424845248462484724848248492485024851248522485324854248552485624857248582485924860248612486224863248642486524866248672486824869248702487124872248732487424875248762487724878248792488024881248822488324884248852488624887248882488924890248912489224893248942489524896248972489824899249002490124902249032490424905249062490724908249092491024911249122491324914249152491624917249182491924920249212492224923249242492524926249272492824929249302493124932249332493424935249362493724938249392494024941249422494324944249452494624947249482494924950249512495224953249542495524956249572495824959249602496124962249632496424965249662496724968249692497024971249722497324974249752497624977249782497924980249812498224983249842498524986249872498824989249902499124992249932499424995249962499724998249992500025001250022500325004250052500625007250082500925010250112501225013250142501525016250172501825019250202502125022250232502425025250262502725028250292503025031250322503325034250352503625037250382503925040250412504225043250442504525046250472504825049250502505125052250532505425055250562505725058250592506025061250622506325064250652506625067250682506925070250712507225073250742507525076250772507825079250802508125082250832508425085250862508725088250892509025091250922509325094250952509625097250982509925100251012510225103251042510525106251072510825109251102511125112251132511425115251162511725118251192512025121251222512325124251252512625127251282512925130251312513225133251342513525136251372513825139251402514125142251432514425145251462514725148251492515025151251522515325154251552515625157251582515925160251612516225163251642516525166251672516825169251702517125172251732517425175251762517725178251792518025181251822518325184251852518625187251882518925190251912519225193251942519525196251972519825199252002520125202252032520425205252062520725208252092521025211252122521325214252152521625217252182521925220252212522225223252242522525226252272522825229252302523125232252332523425235252362523725238252392524025241252422524325244252452524625247252482524925250252512525225253252542525525256252572525825259252602526125262252632526425265252662526725268252692527025271252722527325274252752527625277252782527925280252812528225283252842528525286252872528825289252902529125292252932529425295252962529725298252992530025301253022530325304253052530625307253082530925310253112531225313253142531525316253172531825319253202532125322253232532425325253262532725328253292533025331253322533325334253352533625337253382533925340253412534225343253442534525346253472534825349253502535125352253532535425355253562535725358253592536025361253622536325364253652536625367253682536925370253712537225373253742537525376253772537825379253802538125382253832538425385253862538725388253892539025391253922539325394253952539625397253982539925400254012540225403254042540525406254072540825409254102541125412254132541425415254162541725418254192542025421254222542325424254252542625427254282542925430254312543225433254342543525436254372543825439254402544125442254432544425445254462544725448254492545025451254522545325454254552545625457254582545925460254612546225463254642546525466254672546825469254702547125472254732547425475254762547725478254792548025481254822548325484254852548625487254882548925490254912549225493254942549525496254972549825499255002550125502255032550425505255062550725508255092551025511255122551325514255152551625517255182551925520255212552225523255242552525526255272552825529255302553125532255332553425535255362553725538255392554025541255422554325544255452554625547255482554925550255512555225553255542555525556255572555825559255602556125562255632556425565255662556725568255692557025571255722557325574255752557625577255782557925580255812558225583255842558525586255872558825589255902559125592255932559425595255962559725598255992560025601256022560325604256052560625607256082560925610256112561225613256142561525616256172561825619256202562125622256232562425625256262562725628256292563025631256322563325634256352563625637256382563925640256412564225643256442564525646256472564825649256502565125652256532565425655256562565725658256592566025661256622566325664256652566625667256682566925670256712567225673256742567525676256772567825679256802568125682256832568425685256862568725688256892569025691256922569325694256952569625697256982569925700257012570225703257042570525706257072570825709257102571125712257132571425715257162571725718257192572025721257222572325724257252572625727257282572925730257312573225733257342573525736257372573825739257402574125742257432574425745257462574725748257492575025751257522575325754257552575625757257582575925760257612576225763257642576525766257672576825769257702577125772257732577425775257762577725778257792578025781257822578325784257852578625787257882578925790257912579225793257942579525796257972579825799258002580125802258032580425805258062580725808258092581025811258122581325814258152581625817258182581925820258212582225823258242582525826258272582825829258302583125832258332583425835258362583725838258392584025841258422584325844258452584625847258482584925850258512585225853258542585525856258572585825859258602586125862258632586425865258662586725868258692587025871258722587325874258752587625877258782587925880258812588225883258842588525886258872588825889258902589125892258932589425895258962589725898258992590025901259022590325904259052590625907259082590925910259112591225913259142591525916259172591825919259202592125922259232592425925259262592725928259292593025931259322593325934259352593625937259382593925940259412594225943259442594525946259472594825949259502595125952259532595425955259562595725958259592596025961259622596325964259652596625967259682596925970259712597225973259742597525976259772597825979259802598125982259832598425985259862598725988259892599025991259922599325994259952599625997259982599926000260012600226003260042600526006260072600826009260102601126012260132601426015260162601726018260192602026021260222602326024260252602626027260282602926030260312603226033260342603526036260372603826039260402604126042260432604426045260462604726048260492605026051260522605326054260552605626057260582605926060260612606226063260642606526066260672606826069260702607126072260732607426075260762607726078260792608026081260822608326084260852608626087260882608926090260912609226093260942609526096260972609826099261002610126102261032610426105261062610726108261092611026111261122611326114261152611626117261182611926120261212612226123261242612526126261272612826129261302613126132261332613426135261362613726138261392614026141261422614326144261452614626147261482614926150261512615226153261542615526156261572615826159261602616126162261632616426165261662616726168261692617026171261722617326174261752617626177261782617926180261812618226183261842618526186261872618826189261902619126192261932619426195261962619726198261992620026201262022620326204262052620626207262082620926210262112621226213262142621526216262172621826219262202622126222262232622426225262262622726228262292623026231262322623326234262352623626237262382623926240262412624226243262442624526246262472624826249262502625126252262532625426255262562625726258262592626026261262622626326264262652626626267262682626926270262712627226273262742627526276262772627826279262802628126282262832628426285262862628726288262892629026291262922629326294262952629626297262982629926300263012630226303263042630526306263072630826309263102631126312263132631426315263162631726318263192632026321263222632326324263252632626327263282632926330263312633226333263342633526336263372633826339263402634126342263432634426345263462634726348263492635026351263522635326354263552635626357263582635926360263612636226363263642636526366263672636826369263702637126372263732637426375263762637726378263792638026381263822638326384263852638626387263882638926390263912639226393263942639526396263972639826399264002640126402264032640426405264062640726408264092641026411264122641326414264152641626417264182641926420264212642226423264242642526426264272642826429264302643126432264332643426435264362643726438264392644026441264422644326444264452644626447264482644926450264512645226453264542645526456264572645826459264602646126462264632646426465264662646726468264692647026471264722647326474264752647626477264782647926480264812648226483264842648526486264872648826489264902649126492264932649426495264962649726498264992650026501265022650326504265052650626507265082650926510265112651226513265142651526516265172651826519265202652126522265232652426525265262652726528265292653026531265322653326534265352653626537265382653926540265412654226543265442654526546265472654826549265502655126552265532655426555265562655726558265592656026561265622656326564265652656626567265682656926570265712657226573265742657526576265772657826579265802658126582265832658426585265862658726588265892659026591265922659326594265952659626597265982659926600266012660226603266042660526606266072660826609266102661126612266132661426615266162661726618266192662026621266222662326624266252662626627266282662926630266312663226633266342663526636266372663826639266402664126642266432664426645266462664726648266492665026651266522665326654266552665626657266582665926660266612666226663266642666526666266672666826669266702667126672266732667426675266762667726678266792668026681266822668326684266852668626687266882668926690266912669226693266942669526696266972669826699267002670126702267032670426705267062670726708267092671026711267122671326714267152671626717267182671926720267212672226723267242672526726267272672826729267302673126732267332673426735267362673726738267392674026741267422674326744267452674626747267482674926750267512675226753267542675526756267572675826759267602676126762267632676426765267662676726768267692677026771267722677326774267752677626777267782677926780267812678226783267842678526786267872678826789267902679126792267932679426795267962679726798267992680026801268022680326804268052680626807268082680926810268112681226813268142681526816268172681826819268202682126822268232682426825268262682726828268292683026831268322683326834268352683626837268382683926840268412684226843268442684526846268472684826849268502685126852268532685426855268562685726858268592686026861268622686326864268652686626867268682686926870268712687226873268742687526876268772687826879268802688126882268832688426885268862688726888268892689026891268922689326894268952689626897268982689926900269012690226903269042690526906269072690826909269102691126912269132691426915269162691726918269192692026921269222692326924269252692626927269282692926930269312693226933269342693526936269372693826939269402694126942269432694426945269462694726948269492695026951269522695326954269552695626957269582695926960269612696226963269642696526966269672696826969269702697126972269732697426975269762697726978269792698026981269822698326984269852698626987269882698926990269912699226993269942699526996269972699826999270002700127002270032700427005270062700727008270092701027011270122701327014270152701627017270182701927020270212702227023270242702527026270272702827029270302703127032270332703427035270362703727038270392704027041270422704327044270452704627047270482704927050270512705227053270542705527056270572705827059270602706127062270632706427065270662706727068270692707027071270722707327074270752707627077270782707927080270812708227083270842708527086270872708827089270902709127092270932709427095270962709727098270992710027101271022710327104271052710627107271082710927110271112711227113271142711527116271172711827119271202712127122271232712427125271262712727128271292713027131271322713327134271352713627137271382713927140271412714227143271442714527146271472714827149271502715127152271532715427155271562715727158271592716027161271622716327164271652716627167271682716927170271712717227173271742717527176271772717827179271802718127182271832718427185271862718727188271892719027191271922719327194271952719627197271982719927200272012720227203272042720527206272072720827209272102721127212272132721427215272162721727218272192722027221272222722327224272252722627227272282722927230272312723227233272342723527236272372723827239272402724127242272432724427245272462724727248272492725027251272522725327254272552725627257272582725927260272612726227263272642726527266272672726827269272702727127272272732727427275272762727727278272792728027281272822728327284272852728627287272882728927290272912729227293272942729527296272972729827299273002730127302273032730427305273062730727308273092731027311273122731327314273152731627317273182731927320273212732227323273242732527326273272732827329273302733127332273332733427335273362733727338273392734027341273422734327344273452734627347273482734927350273512735227353273542735527356273572735827359273602736127362273632736427365273662736727368273692737027371273722737327374273752737627377273782737927380273812738227383273842738527386273872738827389273902739127392273932739427395273962739727398273992740027401274022740327404274052740627407274082740927410274112741227413274142741527416274172741827419274202742127422274232742427425274262742727428274292743027431274322743327434274352743627437274382743927440274412744227443274442744527446274472744827449274502745127452274532745427455274562745727458274592746027461274622746327464274652746627467274682746927470274712747227473274742747527476274772747827479274802748127482274832748427485274862748727488274892749027491274922749327494274952749627497274982749927500275012750227503275042750527506275072750827509275102751127512275132751427515275162751727518275192752027521275222752327524275252752627527275282752927530275312753227533275342753527536275372753827539275402754127542275432754427545275462754727548275492755027551275522755327554275552755627557275582755927560275612756227563275642756527566275672756827569275702757127572275732757427575275762757727578275792758027581275822758327584275852758627587275882758927590275912759227593275942759527596275972759827599276002760127602276032760427605276062760727608276092761027611276122761327614276152761627617276182761927620276212762227623276242762527626276272762827629276302763127632276332763427635276362763727638276392764027641276422764327644276452764627647276482764927650276512765227653276542765527656276572765827659276602766127662276632766427665276662766727668276692767027671276722767327674276752767627677276782767927680276812768227683276842768527686276872768827689276902769127692276932769427695276962769727698276992770027701277022770327704277052770627707277082770927710277112771227713277142771527716277172771827719277202772127722277232772427725277262772727728277292773027731277322773327734277352773627737277382773927740277412774227743277442774527746277472774827749277502775127752277532775427755277562775727758277592776027761277622776327764277652776627767277682776927770277712777227773277742777527776277772777827779277802778127782277832778427785277862778727788277892779027791277922779327794277952779627797277982779927800278012780227803278042780527806278072780827809278102781127812278132781427815278162781727818278192782027821278222782327824278252782627827278282782927830278312783227833278342783527836278372783827839278402784127842278432784427845278462784727848278492785027851278522785327854278552785627857278582785927860278612786227863278642786527866278672786827869278702787127872278732787427875278762787727878278792788027881278822788327884278852788627887278882788927890278912789227893278942789527896278972789827899279002790127902279032790427905279062790727908279092791027911279122791327914279152791627917279182791927920279212792227923279242792527926279272792827929279302793127932279332793427935279362793727938279392794027941279422794327944279452794627947279482794927950279512795227953279542795527956279572795827959279602796127962279632796427965279662796727968279692797027971279722797327974279752797627977279782797927980279812798227983279842798527986279872798827989279902799127992279932799427995279962799727998279992800028001280022800328004280052800628007280082800928010280112801228013280142801528016280172801828019280202802128022280232802428025280262802728028280292803028031280322803328034280352803628037280382803928040280412804228043280442804528046280472804828049280502805128052280532805428055280562805728058280592806028061280622806328064280652806628067280682806928070280712807228073280742807528076280772807828079280802808128082280832808428085280862808728088280892809028091280922809328094280952809628097280982809928100281012810228103281042810528106281072810828109281102811128112281132811428115281162811728118281192812028121281222812328124281252812628127281282812928130281312813228133281342813528136281372813828139281402814128142281432814428145281462814728148281492815028151281522815328154281552815628157281582815928160281612816228163281642816528166281672816828169281702817128172281732817428175281762817728178281792818028181281822818328184281852818628187281882818928190281912819228193281942819528196281972819828199282002820128202282032820428205282062820728208282092821028211282122821328214282152821628217282182821928220282212822228223282242822528226282272822828229282302823128232282332823428235282362823728238282392824028241282422824328244282452824628247282482824928250282512825228253282542825528256282572825828259282602826128262282632826428265282662826728268282692827028271282722827328274282752827628277282782827928280282812828228283282842828528286282872828828289282902829128292282932829428295282962829728298282992830028301283022830328304283052830628307283082830928310283112831228313283142831528316283172831828319283202832128322283232832428325283262832728328283292833028331283322833328334283352833628337283382833928340283412834228343283442834528346283472834828349283502835128352283532835428355283562835728358283592836028361283622836328364283652836628367283682836928370283712837228373283742837528376283772837828379283802838128382283832838428385283862838728388283892839028391283922839328394283952839628397283982839928400284012840228403284042840528406284072840828409284102841128412284132841428415284162841728418284192842028421284222842328424284252842628427284282842928430284312843228433284342843528436284372843828439284402844128442284432844428445284462844728448284492845028451284522845328454284552845628457284582845928460284612846228463284642846528466284672846828469284702847128472284732847428475284762847728478284792848028481284822848328484284852848628487284882848928490284912849228493284942849528496284972849828499285002850128502285032850428505285062850728508285092851028511285122851328514285152851628517285182851928520285212852228523285242852528526285272852828529285302853128532285332853428535285362853728538285392854028541285422854328544285452854628547285482854928550285512855228553285542855528556285572855828559285602856128562285632856428565285662856728568285692857028571285722857328574285752857628577285782857928580285812858228583285842858528586285872858828589285902859128592285932859428595285962859728598285992860028601286022860328604286052860628607286082860928610286112861228613286142861528616286172861828619286202862128622286232862428625286262862728628286292863028631286322863328634286352863628637286382863928640286412864228643286442864528646286472864828649286502865128652286532865428655286562865728658286592866028661286622866328664286652866628667286682866928670286712867228673286742867528676286772867828679286802868128682286832868428685286862868728688286892869028691286922869328694286952869628697286982869928700287012870228703287042870528706287072870828709287102871128712287132871428715287162871728718287192872028721287222872328724287252872628727287282872928730287312873228733287342873528736287372873828739287402874128742287432874428745287462874728748287492875028751287522875328754287552875628757287582875928760287612876228763287642876528766287672876828769287702877128772287732877428775287762877728778287792878028781287822878328784287852878628787287882878928790287912879228793287942879528796287972879828799288002880128802288032880428805288062880728808288092881028811288122881328814288152881628817288182881928820288212882228823288242882528826288272882828829288302883128832288332883428835288362883728838288392884028841288422884328844288452884628847288482884928850288512885228853288542885528856288572885828859288602886128862288632886428865288662886728868288692887028871288722887328874288752887628877288782887928880288812888228883288842888528886288872888828889288902889128892288932889428895288962889728898288992890028901289022890328904289052890628907289082890928910289112891228913289142891528916289172891828919289202892128922289232892428925289262892728928289292893028931289322893328934289352893628937289382893928940289412894228943289442894528946289472894828949289502895128952289532895428955289562895728958289592896028961289622896328964289652896628967289682896928970289712897228973289742897528976289772897828979289802898128982289832898428985289862898728988289892899028991289922899328994289952899628997289982899929000290012900229003290042900529006290072900829009290102901129012290132901429015290162901729018290192902029021290222902329024290252902629027290282902929030290312903229033290342903529036290372903829039290402904129042290432904429045290462904729048290492905029051290522905329054290552905629057290582905929060290612906229063290642906529066290672906829069290702907129072290732907429075290762907729078290792908029081290822908329084290852908629087290882908929090290912909229093290942909529096290972909829099291002910129102291032910429105291062910729108291092911029111291122911329114291152911629117291182911929120291212912229123291242912529126291272912829129291302913129132291332913429135291362913729138291392914029141291422914329144291452914629147291482914929150291512915229153291542915529156291572915829159291602916129162291632916429165291662916729168291692917029171291722917329174291752917629177291782917929180291812918229183291842918529186291872918829189291902919129192291932919429195291962919729198291992920029201292022920329204292052920629207292082920929210292112921229213292142921529216292172921829219292202922129222292232922429225292262922729228292292923029231292322923329234292352923629237292382923929240292412924229243292442924529246292472924829249292502925129252292532925429255292562925729258292592926029261292622926329264292652926629267292682926929270292712927229273292742927529276292772927829279292802928129282292832928429285292862928729288292892929029291292922929329294292952929629297292982929929300293012930229303293042930529306293072930829309293102931129312293132931429315293162931729318293192932029321293222932329324293252932629327293282932929330293312933229333293342933529336293372933829339293402934129342293432934429345293462934729348293492935029351293522935329354293552935629357293582935929360293612936229363293642936529366293672936829369293702937129372293732937429375293762937729378293792938029381293822938329384293852938629387293882938929390293912939229393293942939529396293972939829399294002940129402294032940429405294062940729408294092941029411294122941329414294152941629417294182941929420294212942229423294242942529426294272942829429294302943129432294332943429435294362943729438294392944029441294422944329444294452944629447294482944929450294512945229453294542945529456294572945829459294602946129462294632946429465294662946729468294692947029471294722947329474294752947629477294782947929480294812948229483294842948529486294872948829489294902949129492294932949429495294962949729498294992950029501295022950329504295052950629507295082950929510295112951229513295142951529516295172951829519295202952129522295232952429525295262952729528295292953029531295322953329534295352953629537295382953929540295412954229543295442954529546295472954829549295502955129552295532955429555295562955729558295592956029561295622956329564295652956629567295682956929570295712957229573295742957529576295772957829579295802958129582295832958429585295862958729588295892959029591295922959329594295952959629597295982959929600296012960229603296042960529606296072960829609296102961129612296132961429615296162961729618296192962029621296222962329624296252962629627296282962929630296312963229633296342963529636296372963829639296402964129642296432964429645296462964729648296492965029651296522965329654296552965629657296582965929660296612966229663296642966529666296672966829669296702967129672296732967429675296762967729678296792968029681296822968329684296852968629687296882968929690296912969229693296942969529696296972969829699297002970129702297032970429705297062970729708297092971029711297122971329714297152971629717297182971929720297212972229723297242972529726297272972829729297302973129732297332973429735297362973729738297392974029741297422974329744297452974629747297482974929750297512975229753297542975529756297572975829759297602976129762297632976429765297662976729768297692977029771297722977329774297752977629777297782977929780297812978229783297842978529786297872978829789297902979129792297932979429795297962979729798297992980029801298022980329804298052980629807298082980929810298112981229813298142981529816298172981829819298202982129822298232982429825298262982729828298292983029831298322983329834298352983629837298382983929840298412984229843298442984529846298472984829849298502985129852298532985429855298562985729858298592986029861298622986329864298652986629867298682986929870298712987229873298742987529876298772987829879298802988129882298832988429885298862988729888298892989029891298922989329894298952989629897298982989929900299012990229903299042990529906299072990829909299102991129912299132991429915299162991729918299192992029921299222992329924299252992629927299282992929930299312993229933299342993529936299372993829939299402994129942299432994429945299462994729948299492995029951299522995329954299552995629957299582995929960299612996229963299642996529966299672996829969299702997129972299732997429975299762997729978299792998029981299822998329984299852998629987299882998929990299912999229993299942999529996299972999829999300003000130002300033000430005300063000730008300093001030011300123001330014300153001630017300183001930020300213002230023300243002530026300273002830029300303003130032300333003430035300363003730038300393004030041300423004330044300453004630047300483004930050300513005230053300543005530056300573005830059300603006130062300633006430065300663006730068300693007030071300723007330074300753007630077300783007930080300813008230083300843008530086300873008830089300903009130092300933009430095300963009730098300993010030101301023010330104301053010630107301083010930110301113011230113301143011530116301173011830119301203012130122301233012430125301263012730128301293013030131301323013330134301353013630137301383013930140301413014230143301443014530146301473014830149301503015130152301533015430155301563015730158301593016030161301623016330164301653016630167301683016930170301713017230173301743017530176301773017830179301803018130182301833018430185301863018730188301893019030191301923019330194301953019630197301983019930200302013020230203302043020530206302073020830209302103021130212302133021430215302163021730218302193022030221302223022330224302253022630227302283022930230302313023230233302343023530236302373023830239302403024130242302433024430245302463024730248302493025030251302523025330254302553025630257302583025930260302613026230263302643026530266302673026830269302703027130272302733027430275302763027730278302793028030281302823028330284302853028630287302883028930290302913029230293302943029530296302973029830299303003030130302303033030430305303063030730308303093031030311303123031330314303153031630317303183031930320303213032230323303243032530326303273032830329303303033130332303333033430335303363033730338303393034030341303423034330344303453034630347303483034930350303513035230353303543035530356303573035830359303603036130362303633036430365303663036730368303693037030371303723037330374303753037630377303783037930380303813038230383303843038530386303873038830389303903039130392303933039430395303963039730398303993040030401304023040330404304053040630407304083040930410304113041230413304143041530416304173041830419304203042130422304233042430425304263042730428304293043030431304323043330434304353043630437304383043930440304413044230443304443044530446304473044830449304503045130452304533045430455304563045730458304593046030461304623046330464304653046630467304683046930470304713047230473304743047530476304773047830479304803048130482304833048430485304863048730488304893049030491304923049330494304953049630497304983049930500305013050230503305043050530506305073050830509305103051130512305133051430515305163051730518305193052030521305223052330524305253052630527305283052930530305313053230533305343053530536305373053830539305403054130542305433054430545305463054730548305493055030551305523055330554305553055630557305583055930560305613056230563305643056530566305673056830569305703057130572305733057430575305763057730578305793058030581305823058330584305853058630587305883058930590305913059230593305943059530596305973059830599306003060130602306033060430605306063060730608306093061030611306123061330614306153061630617306183061930620306213062230623306243062530626306273062830629306303063130632306333063430635306363063730638306393064030641306423064330644306453064630647306483064930650306513065230653306543065530656306573065830659306603066130662306633066430665306663066730668306693067030671306723067330674306753067630677306783067930680306813068230683306843068530686306873068830689306903069130692306933069430695306963069730698306993070030701307023070330704307053070630707307083070930710307113071230713307143071530716307173071830719307203072130722307233072430725307263072730728307293073030731307323073330734307353073630737307383073930740307413074230743307443074530746307473074830749307503075130752307533075430755307563075730758307593076030761307623076330764307653076630767307683076930770307713077230773307743077530776307773077830779307803078130782307833078430785307863078730788307893079030791307923079330794307953079630797307983079930800308013080230803308043080530806308073080830809308103081130812308133081430815308163081730818308193082030821308223082330824308253082630827308283082930830308313083230833308343083530836308373083830839308403084130842308433084430845308463084730848308493085030851308523085330854308553085630857308583085930860308613086230863308643086530866308673086830869308703087130872308733087430875308763087730878308793088030881308823088330884308853088630887308883088930890308913089230893308943089530896308973089830899309003090130902309033090430905309063090730908309093091030911309123091330914309153091630917309183091930920309213092230923309243092530926309273092830929309303093130932309333093430935309363093730938309393094030941309423094330944309453094630947309483094930950309513095230953309543095530956309573095830959309603096130962309633096430965309663096730968309693097030971309723097330974309753097630977309783097930980309813098230983309843098530986309873098830989309903099130992309933099430995309963099730998309993100031001310023100331004310053100631007310083100931010310113101231013310143101531016310173101831019310203102131022310233102431025310263102731028310293103031031310323103331034310353103631037310383103931040310413104231043310443104531046310473104831049310503105131052310533105431055310563105731058310593106031061310623106331064310653106631067310683106931070310713107231073310743107531076310773107831079310803108131082310833108431085310863108731088310893109031091310923109331094310953109631097310983109931100311013110231103311043110531106311073110831109311103111131112311133111431115311163111731118311193112031121311223112331124311253112631127311283112931130311313113231133311343113531136311373113831139311403114131142311433114431145311463114731148311493115031151311523115331154311553115631157311583115931160311613116231163311643116531166311673116831169311703117131172311733117431175311763117731178311793118031181311823118331184311853118631187311883118931190311913119231193311943119531196311973119831199312003120131202312033120431205312063120731208312093121031211312123121331214312153121631217312183121931220312213122231223312243122531226312273122831229312303123131232312333123431235312363123731238312393124031241312423124331244312453124631247312483124931250312513125231253312543125531256312573125831259312603126131262312633126431265312663126731268312693127031271312723127331274312753127631277312783127931280312813128231283312843128531286312873128831289312903129131292312933129431295312963129731298312993130031301313023130331304313053130631307313083130931310313113131231313313143131531316313173131831319313203132131322313233132431325313263132731328313293133031331313323133331334313353133631337313383133931340313413134231343313443134531346313473134831349313503135131352313533135431355313563135731358313593136031361313623136331364313653136631367313683136931370313713137231373313743137531376313773137831379313803138131382313833138431385313863138731388313893139031391313923139331394313953139631397313983139931400314013140231403314043140531406314073140831409314103141131412314133141431415314163141731418314193142031421314223142331424314253142631427314283142931430314313143231433314343143531436314373143831439314403144131442314433144431445314463144731448314493145031451314523145331454314553145631457314583145931460314613146231463314643146531466314673146831469314703147131472314733147431475314763147731478314793148031481314823148331484314853148631487314883148931490314913149231493314943149531496314973149831499315003150131502315033150431505315063150731508315093151031511315123151331514315153151631517315183151931520315213152231523315243152531526315273152831529315303153131532315333153431535315363153731538315393154031541315423154331544315453154631547315483154931550315513155231553315543155531556315573155831559315603156131562315633156431565315663156731568315693157031571315723157331574315753157631577315783157931580315813158231583315843158531586315873158831589315903159131592315933159431595315963159731598315993160031601316023160331604316053160631607316083160931610316113161231613316143161531616316173161831619316203162131622316233162431625316263162731628316293163031631316323163331634316353163631637316383163931640316413164231643316443164531646316473164831649316503165131652316533165431655316563165731658316593166031661316623166331664316653166631667316683166931670316713167231673316743167531676316773167831679316803168131682316833168431685316863168731688316893169031691316923169331694316953169631697316983169931700317013170231703317043170531706317073170831709317103171131712317133171431715317163171731718317193172031721317223172331724317253172631727317283172931730317313173231733317343173531736317373173831739317403174131742317433174431745317463174731748317493175031751317523175331754317553175631757317583175931760317613176231763317643176531766317673176831769317703177131772317733177431775317763177731778317793178031781317823178331784317853178631787317883178931790317913179231793317943179531796317973179831799318003180131802318033180431805318063180731808318093181031811318123181331814318153181631817318183181931820318213182231823318243182531826318273182831829318303183131832318333183431835318363183731838318393184031841318423184331844318453184631847318483184931850318513185231853318543185531856318573185831859318603186131862318633186431865318663186731868318693187031871318723187331874318753187631877318783187931880318813188231883318843188531886318873188831889318903189131892318933189431895318963189731898318993190031901319023190331904319053190631907319083190931910319113191231913319143191531916319173191831919319203192131922319233192431925319263192731928319293193031931319323193331934319353193631937319383193931940319413194231943319443194531946319473194831949319503195131952319533195431955319563195731958319593196031961319623196331964319653196631967319683196931970319713197231973319743197531976319773197831979319803198131982319833198431985319863198731988319893199031991319923199331994319953199631997319983199932000320013200232003320043200532006320073200832009320103201132012320133201432015320163201732018320193202032021320223202332024320253202632027320283202932030320313203232033320343203532036320373203832039320403204132042320433204432045320463204732048320493205032051320523205332054320553205632057320583205932060320613206232063320643206532066320673206832069320703207132072320733207432075320763207732078320793208032081320823208332084320853208632087320883208932090320913209232093320943209532096320973209832099321003210132102321033210432105321063210732108321093211032111321123211332114321153211632117321183211932120321213212232123321243212532126321273212832129321303213132132321333213432135321363213732138321393214032141321423214332144321453214632147321483214932150321513215232153321543215532156321573215832159321603216132162321633216432165321663216732168321693217032171321723217332174321753217632177321783217932180321813218232183321843218532186321873218832189321903219132192321933219432195321963219732198321993220032201322023220332204322053220632207322083220932210322113221232213322143221532216322173221832219322203222132222322233222432225322263222732228322293223032231322323223332234322353223632237322383223932240322413224232243322443224532246322473224832249322503225132252322533225432255322563225732258322593226032261322623226332264322653226632267322683226932270322713227232273322743227532276322773227832279322803228132282322833228432285322863228732288322893229032291322923229332294322953229632297322983229932300323013230232303323043230532306323073230832309323103231132312323133231432315323163231732318323193232032321323223232332324323253232632327323283232932330323313233232333323343233532336323373233832339323403234132342323433234432345323463234732348323493235032351323523235332354323553235632357323583235932360323613236232363323643236532366323673236832369323703237132372323733237432375323763237732378323793238032381323823238332384323853238632387323883238932390323913239232393323943239532396323973239832399324003240132402324033240432405324063240732408324093241032411324123241332414324153241632417324183241932420324213242232423324243242532426324273242832429324303243132432324333243432435324363243732438324393244032441324423244332444324453244632447324483244932450324513245232453324543245532456324573245832459324603246132462324633246432465324663246732468324693247032471324723247332474324753247632477324783247932480324813248232483324843248532486324873248832489324903249132492324933249432495324963249732498324993250032501325023250332504325053250632507325083250932510325113251232513325143251532516325173251832519325203252132522325233252432525325263252732528325293253032531325323253332534325353253632537325383253932540325413254232543325443254532546325473254832549325503255132552325533255432555325563255732558325593256032561325623256332564325653256632567325683256932570325713257232573325743257532576325773257832579325803258132582325833258432585325863258732588325893259032591325923259332594325953259632597325983259932600326013260232603326043260532606326073260832609326103261132612326133261432615326163261732618326193262032621326223262332624326253262632627326283262932630326313263232633326343263532636326373263832639326403264132642326433264432645326463264732648326493265032651326523265332654326553265632657326583265932660326613266232663326643266532666326673266832669326703267132672326733267432675326763267732678326793268032681326823268332684326853268632687326883268932690326913269232693326943269532696326973269832699327003270132702327033270432705327063270732708327093271032711327123271332714327153271632717327183271932720327213272232723327243272532726327273272832729327303273132732327333273432735327363273732738327393274032741327423274332744327453274632747327483274932750327513275232753327543275532756327573275832759327603276132762327633276432765327663276732768327693277032771327723277332774327753277632777327783277932780327813278232783327843278532786327873278832789327903279132792327933279432795327963279732798327993280032801328023280332804328053280632807328083280932810328113281232813328143281532816328173281832819328203282132822328233282432825328263282732828328293283032831328323283332834328353283632837328383283932840328413284232843328443284532846328473284832849328503285132852328533285432855328563285732858328593286032861328623286332864328653286632867328683286932870328713287232873328743287532876328773287832879328803288132882328833288432885328863288732888328893289032891328923289332894328953289632897328983289932900329013290232903329043290532906329073290832909329103291132912329133291432915329163291732918329193292032921
  1. apiVersion: apiextensions.k8s.io/v1
  2. kind: CustomResourceDefinition
  3. metadata:
  4. annotations:
  5. controller-gen.kubebuilder.io/version: v0.19.0
  6. labels:
  7. external-secrets.io/component: controller
  8. name: clusterexternalsecrets.external-secrets.io
  9. spec:
  10. group: external-secrets.io
  11. names:
  12. categories:
  13. - external-secrets
  14. kind: ClusterExternalSecret
  15. listKind: ClusterExternalSecretList
  16. plural: clusterexternalsecrets
  17. shortNames:
  18. - ces
  19. singular: clusterexternalsecret
  20. scope: Cluster
  21. versions:
  22. - additionalPrinterColumns:
  23. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  24. name: Store
  25. type: string
  26. - jsonPath: .spec.refreshTime
  27. name: Refresh Interval
  28. type: string
  29. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  30. name: Ready
  31. type: string
  32. name: v1
  33. schema:
  34. openAPIV3Schema:
  35. description: ClusterExternalSecret is the Schema for the clusterexternalsecrets API.
  36. properties:
  37. apiVersion:
  38. description: |-
  39. APIVersion defines the versioned schema of this representation of an object.
  40. Servers should convert recognized schemas to the latest internal value, and
  41. may reject unrecognized values.
  42. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  43. type: string
  44. kind:
  45. description: |-
  46. Kind is a string value representing the REST resource this object represents.
  47. Servers may infer this from the endpoint the client submits requests to.
  48. Cannot be updated.
  49. In CamelCase.
  50. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  51. type: string
  52. metadata:
  53. type: object
  54. spec:
  55. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  56. properties:
  57. externalSecretMetadata:
  58. description: The metadata of the external secrets to be created
  59. properties:
  60. annotations:
  61. additionalProperties:
  62. type: string
  63. type: object
  64. labels:
  65. additionalProperties:
  66. type: string
  67. type: object
  68. type: object
  69. externalSecretName:
  70. description: |-
  71. The name of the external secrets to be created.
  72. Defaults to the name of the ClusterExternalSecret
  73. maxLength: 253
  74. minLength: 1
  75. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  76. type: string
  77. externalSecretSpec:
  78. description: The spec for the ExternalSecrets to be created
  79. properties:
  80. data:
  81. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  82. items:
  83. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  84. properties:
  85. remoteRef:
  86. description: |-
  87. RemoteRef points to the remote secret and defines
  88. which secret (version/property/..) to fetch.
  89. properties:
  90. conversionStrategy:
  91. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  92. enum:
  93. - Default
  94. - Unicode
  95. type: string
  96. decodingStrategy:
  97. description: Used to define a decoding Strategy. Defaults to None when omitted.
  98. enum:
  99. - Auto
  100. - Base64
  101. - Base64URL
  102. - None
  103. type: string
  104. key:
  105. description: Key is the key used in the Provider, mandatory
  106. type: string
  107. metadataPolicy:
  108. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  109. enum:
  110. - None
  111. - Fetch
  112. type: string
  113. nullBytePolicy:
  114. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  115. enum:
  116. - Ignore
  117. - Fail
  118. type: string
  119. property:
  120. description: Used to select a specific property of the Provider value (if a map), if supported
  121. type: string
  122. version:
  123. description: Used to select a specific version of the Provider value, if supported
  124. type: string
  125. required:
  126. - key
  127. type: object
  128. secretKey:
  129. description: The key in the Kubernetes Secret to store the value.
  130. maxLength: 253
  131. minLength: 1
  132. pattern: ^[-._a-zA-Z0-9]+$
  133. type: string
  134. sourceRef:
  135. description: |-
  136. SourceRef allows you to override the source
  137. from which the value will be pulled.
  138. maxProperties: 1
  139. minProperties: 1
  140. properties:
  141. generatorRef:
  142. description: |-
  143. GeneratorRef points to a generator custom resource.
  144. Deprecated: The generatorRef is not implemented in .data[].
  145. this will be removed with v1.
  146. properties:
  147. apiVersion:
  148. default: generators.external-secrets.io/v1alpha1
  149. description: Specify the apiVersion of the generator resource
  150. type: string
  151. kind:
  152. description: Specify the Kind of the generator resource
  153. enum:
  154. - ACRAccessToken
  155. - BeyondtrustWorkloadCredentialsDynamicSecret
  156. - ClusterGenerator
  157. - CloudsmithAccessToken
  158. - ECRAuthorizationToken
  159. - Fake
  160. - GCRAccessToken
  161. - GithubAccessToken
  162. - GitlabDeployToken
  163. - QuayAccessToken
  164. - Password
  165. - SSHKey
  166. - STSSessionToken
  167. - UUID
  168. - VaultDynamicSecret
  169. - Webhook
  170. - Grafana
  171. - MFA
  172. type: string
  173. name:
  174. description: Specify the name of the generator resource
  175. maxLength: 253
  176. minLength: 1
  177. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  178. type: string
  179. required:
  180. - kind
  181. - name
  182. type: object
  183. storeRef:
  184. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  185. properties:
  186. kind:
  187. description: |-
  188. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  189. Defaults to `SecretStore`
  190. enum:
  191. - SecretStore
  192. - ClusterSecretStore
  193. type: string
  194. name:
  195. description: Name of the SecretStore resource
  196. maxLength: 253
  197. minLength: 1
  198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  199. type: string
  200. type: object
  201. type: object
  202. required:
  203. - remoteRef
  204. - secretKey
  205. type: object
  206. type: array
  207. dataFrom:
  208. description: |-
  209. DataFrom is used to fetch all properties from a specific Provider data
  210. If multiple entries are specified, the Secret keys are merged in the specified order
  211. items:
  212. description: |-
  213. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  214. when using DataFrom to fetch multiple values from a Provider.
  215. properties:
  216. extract:
  217. description: |-
  218. Used to extract multiple key/value pairs from one secret
  219. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  220. properties:
  221. conversionStrategy:
  222. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  223. enum:
  224. - Default
  225. - Unicode
  226. type: string
  227. decodingStrategy:
  228. description: Used to define a decoding Strategy. Defaults to None when omitted.
  229. enum:
  230. - Auto
  231. - Base64
  232. - Base64URL
  233. - None
  234. type: string
  235. key:
  236. description: Key is the key used in the Provider, mandatory
  237. type: string
  238. metadataPolicy:
  239. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  240. enum:
  241. - None
  242. - Fetch
  243. type: string
  244. nullBytePolicy:
  245. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  246. enum:
  247. - Ignore
  248. - Fail
  249. type: string
  250. property:
  251. description: Used to select a specific property of the Provider value (if a map), if supported
  252. type: string
  253. version:
  254. description: Used to select a specific version of the Provider value, if supported
  255. type: string
  256. required:
  257. - key
  258. type: object
  259. find:
  260. description: |-
  261. Used to find secrets based on tags or regular expressions
  262. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  263. properties:
  264. conversionStrategy:
  265. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  266. enum:
  267. - Default
  268. - Unicode
  269. type: string
  270. decodingStrategy:
  271. description: Used to define a decoding Strategy. Defaults to None when omitted.
  272. enum:
  273. - Auto
  274. - Base64
  275. - Base64URL
  276. - None
  277. type: string
  278. name:
  279. description: Finds secrets based on the name.
  280. properties:
  281. regexp:
  282. description: Finds secrets base
  283. type: string
  284. type: object
  285. nullBytePolicy:
  286. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  287. enum:
  288. - Ignore
  289. - Fail
  290. type: string
  291. path:
  292. description: A root path to start the find operations.
  293. type: string
  294. tags:
  295. additionalProperties:
  296. type: string
  297. description: Find secrets based on tags.
  298. type: object
  299. type: object
  300. rewrite:
  301. description: |-
  302. Used to rewrite secret Keys after getting them from the secret Provider
  303. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  304. items:
  305. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  306. maxProperties: 1
  307. minProperties: 1
  308. properties:
  309. merge:
  310. description: |-
  311. Used to merge key/values in one single Secret
  312. The resulting key will contain all values from the specified secrets
  313. properties:
  314. conflictPolicy:
  315. default: Error
  316. description: Used to define the policy to use in conflict resolution.
  317. enum:
  318. - Ignore
  319. - Error
  320. type: string
  321. into:
  322. default: ""
  323. description: |-
  324. Used to define the target key of the merge operation.
  325. Required if strategy is JSON. Ignored otherwise.
  326. type: string
  327. priority:
  328. description: Used to define key priority in conflict resolution.
  329. items:
  330. type: string
  331. type: array
  332. priorityPolicy:
  333. default: Strict
  334. description: Used to define the policy when a key in the priority list does not exist in the input.
  335. enum:
  336. - IgnoreNotFound
  337. - Strict
  338. type: string
  339. strategy:
  340. default: Extract
  341. description: Used to define the strategy to use in the merge operation.
  342. enum:
  343. - Extract
  344. - JSON
  345. type: string
  346. type: object
  347. regexp:
  348. description: |-
  349. Used to rewrite with regular expressions.
  350. The resulting key will be the output of a regexp.ReplaceAll operation.
  351. properties:
  352. source:
  353. description: Used to define the regular expression of a re.Compiler.
  354. type: string
  355. target:
  356. description: Used to define the target pattern of a ReplaceAll operation.
  357. type: string
  358. required:
  359. - source
  360. - target
  361. type: object
  362. transform:
  363. description: |-
  364. Used to apply string transformation on the secrets.
  365. The resulting key will be the output of the template applied by the operation.
  366. properties:
  367. template:
  368. description: |-
  369. Used to define the template to apply on the secret name.
  370. `.value ` will specify the secret name in the template.
  371. type: string
  372. required:
  373. - template
  374. type: object
  375. type: object
  376. type: array
  377. sourceRef:
  378. description: |-
  379. SourceRef points to a store or generator
  380. which contains secret values ready to use.
  381. Use this in combination with Extract or Find pull values out of
  382. a specific SecretStore.
  383. When sourceRef points to a generator Extract or Find is not supported.
  384. The generator returns a static map of values
  385. maxProperties: 1
  386. minProperties: 1
  387. properties:
  388. generatorRef:
  389. description: GeneratorRef points to a generator custom resource.
  390. properties:
  391. apiVersion:
  392. default: generators.external-secrets.io/v1alpha1
  393. description: Specify the apiVersion of the generator resource
  394. type: string
  395. kind:
  396. description: Specify the Kind of the generator resource
  397. enum:
  398. - ACRAccessToken
  399. - BeyondtrustWorkloadCredentialsDynamicSecret
  400. - ClusterGenerator
  401. - CloudsmithAccessToken
  402. - ECRAuthorizationToken
  403. - Fake
  404. - GCRAccessToken
  405. - GithubAccessToken
  406. - GitlabDeployToken
  407. - QuayAccessToken
  408. - Password
  409. - SSHKey
  410. - STSSessionToken
  411. - UUID
  412. - VaultDynamicSecret
  413. - Webhook
  414. - Grafana
  415. - MFA
  416. type: string
  417. name:
  418. description: Specify the name of the generator resource
  419. maxLength: 253
  420. minLength: 1
  421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  422. type: string
  423. required:
  424. - kind
  425. - name
  426. type: object
  427. storeRef:
  428. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  429. properties:
  430. kind:
  431. description: |-
  432. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  433. Defaults to `SecretStore`
  434. enum:
  435. - SecretStore
  436. - ClusterSecretStore
  437. type: string
  438. name:
  439. description: Name of the SecretStore resource
  440. maxLength: 253
  441. minLength: 1
  442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  443. type: string
  444. type: object
  445. type: object
  446. type: object
  447. type: array
  448. refreshInterval:
  449. default: 1h0m0s
  450. description: |-
  451. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  452. specified as Golang Duration strings.
  453. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  454. Example values: "1h0m0s", "2h30m0s", "10m0s"
  455. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  456. type: string
  457. refreshPolicy:
  458. description: |-
  459. RefreshPolicy determines how the ExternalSecret should be refreshed:
  460. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  461. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  462. No periodic updates occur if refreshInterval is 0.
  463. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  464. enum:
  465. - CreatedOnce
  466. - Periodic
  467. - OnChange
  468. type: string
  469. secretStoreRef:
  470. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  471. properties:
  472. kind:
  473. description: |-
  474. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  475. Defaults to `SecretStore`
  476. enum:
  477. - SecretStore
  478. - ClusterSecretStore
  479. type: string
  480. name:
  481. description: Name of the SecretStore resource
  482. maxLength: 253
  483. minLength: 1
  484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  485. type: string
  486. type: object
  487. syncWindows:
  488. description: |-
  489. SyncWindows optionally restricts when periodic refreshes may occur.
  490. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  491. properties:
  492. kind:
  493. description: |-
  494. Kind applies to every window in the list.
  495. "allow" -- syncs are permitted only while at least one window is active;
  496. all other times are blocked.
  497. "deny" -- syncs are blocked while any window is active;
  498. all other times are permitted.
  499. enum:
  500. - allow
  501. - deny
  502. type: string
  503. windows:
  504. description: Windows is the list of schedule+duration pairs.
  505. items:
  506. description: |-
  507. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  508. within a SyncWindows block.
  509. properties:
  510. duration:
  511. description: |-
  512. Duration specifies how long the window stays open after each Schedule
  513. firing. Example: "8h".
  514. type: string
  515. schedule:
  516. description: |-
  517. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  518. named shorthand such as @daily or @every 1h. It marks the start time of
  519. each window occurrence.
  520. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  521. minLength: 1
  522. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  523. type: string
  524. required:
  525. - duration
  526. - schedule
  527. type: object
  528. minItems: 1
  529. type: array
  530. required:
  531. - kind
  532. - windows
  533. type: object
  534. target:
  535. default:
  536. creationPolicy: Owner
  537. deletionPolicy: Retain
  538. description: |-
  539. ExternalSecretTarget defines the Kubernetes Secret to be created,
  540. there can be only one target per ExternalSecret.
  541. properties:
  542. creationPolicy:
  543. default: Owner
  544. description: |-
  545. CreationPolicy defines rules on how to create the resulting Secret.
  546. Defaults to "Owner"
  547. enum:
  548. - Owner
  549. - Orphan
  550. - Merge
  551. - None
  552. - CreateOrMerge
  553. type: string
  554. deletionPolicy:
  555. default: Retain
  556. description: |-
  557. DeletionPolicy defines rules on how to delete the resulting Secret.
  558. Defaults to "Retain"
  559. enum:
  560. - Delete
  561. - Merge
  562. - Retain
  563. type: string
  564. immutable:
  565. description: Immutable defines if the final secret will be immutable
  566. type: boolean
  567. manifest:
  568. description: |-
  569. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  570. When specified, ExternalSecret will create the resource type defined here
  571. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  572. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  573. properties:
  574. apiVersion:
  575. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  576. minLength: 1
  577. type: string
  578. kind:
  579. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  580. minLength: 1
  581. type: string
  582. required:
  583. - apiVersion
  584. - kind
  585. type: object
  586. name:
  587. description: |-
  588. The name of the Secret resource to be managed.
  589. Defaults to the .metadata.name of the ExternalSecret resource
  590. maxLength: 253
  591. minLength: 1
  592. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  593. type: string
  594. template:
  595. description: Template defines a blueprint for the created Secret resource.
  596. properties:
  597. data:
  598. additionalProperties:
  599. type: string
  600. type: object
  601. engineVersion:
  602. default: v2
  603. description: |-
  604. EngineVersion specifies the template engine version
  605. that should be used to compile/execute the
  606. template specified in .data and .templateFrom[].
  607. enum:
  608. - v2
  609. type: string
  610. mergePolicy:
  611. default: Replace
  612. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  613. enum:
  614. - Replace
  615. - Merge
  616. type: string
  617. metadata:
  618. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  619. properties:
  620. annotations:
  621. additionalProperties:
  622. type: string
  623. type: object
  624. finalizers:
  625. items:
  626. type: string
  627. type: array
  628. labels:
  629. additionalProperties:
  630. type: string
  631. type: object
  632. type: object
  633. templateFrom:
  634. items:
  635. description: |-
  636. TemplateFrom specifies a source for templates.
  637. Each item in the list can either reference a ConfigMap or a Secret resource.
  638. properties:
  639. configMap:
  640. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  641. properties:
  642. items:
  643. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  644. items:
  645. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  646. properties:
  647. key:
  648. description: A key in the ConfigMap/Secret
  649. maxLength: 253
  650. minLength: 1
  651. pattern: ^[-._a-zA-Z0-9]+$
  652. type: string
  653. templateAs:
  654. default: Values
  655. description: TemplateScope specifies how the template keys should be interpreted.
  656. enum:
  657. - Values
  658. - KeysAndValues
  659. type: string
  660. required:
  661. - key
  662. type: object
  663. type: array
  664. name:
  665. description: The name of the ConfigMap/Secret resource
  666. maxLength: 253
  667. minLength: 1
  668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  669. type: string
  670. required:
  671. - items
  672. - name
  673. type: object
  674. literal:
  675. type: string
  676. secret:
  677. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  678. properties:
  679. items:
  680. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  681. items:
  682. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  683. properties:
  684. key:
  685. description: A key in the ConfigMap/Secret
  686. maxLength: 253
  687. minLength: 1
  688. pattern: ^[-._a-zA-Z0-9]+$
  689. type: string
  690. templateAs:
  691. default: Values
  692. description: TemplateScope specifies how the template keys should be interpreted.
  693. enum:
  694. - Values
  695. - KeysAndValues
  696. type: string
  697. required:
  698. - key
  699. type: object
  700. type: array
  701. name:
  702. description: The name of the ConfigMap/Secret resource
  703. maxLength: 253
  704. minLength: 1
  705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  706. type: string
  707. required:
  708. - items
  709. - name
  710. type: object
  711. target:
  712. default: Data
  713. description: |-
  714. Target specifies where to place the template result.
  715. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  716. any other value is rejected because it would allow writes to privileged Secret fields.
  717. For custom resources (when spec.target.manifest is set), this supports
  718. nested paths like "spec.database.config" or "data".
  719. type: string
  720. valuesDecodingStrategy:
  721. description: |-
  722. Used to define a decoding Strategy for the rendered template values.
  723. Defaults to None when omitted.
  724. enum:
  725. - Auto
  726. - Base64
  727. - Base64URL
  728. - None
  729. type: string
  730. type: object
  731. type: array
  732. type:
  733. type: string
  734. type: object
  735. type: object
  736. type: object
  737. namespaceSelector:
  738. description: |-
  739. The labels to select by to find the Namespaces to create the ExternalSecrets in.
  740. Deprecated: Use NamespaceSelectors instead.
  741. properties:
  742. matchExpressions:
  743. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  744. items:
  745. description: |-
  746. A label selector requirement is a selector that contains values, a key, and an operator that
  747. relates the key and values.
  748. properties:
  749. key:
  750. description: key is the label key that the selector applies to.
  751. type: string
  752. operator:
  753. description: |-
  754. operator represents a key's relationship to a set of values.
  755. Valid operators are In, NotIn, Exists and DoesNotExist.
  756. type: string
  757. values:
  758. description: |-
  759. values is an array of string values. If the operator is In or NotIn,
  760. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  761. the values array must be empty. This array is replaced during a strategic
  762. merge patch.
  763. items:
  764. type: string
  765. type: array
  766. x-kubernetes-list-type: atomic
  767. required:
  768. - key
  769. - operator
  770. type: object
  771. type: array
  772. x-kubernetes-list-type: atomic
  773. matchLabels:
  774. additionalProperties:
  775. type: string
  776. description: |-
  777. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  778. map is equivalent to an element of matchExpressions, whose key field is "key", the
  779. operator is "In", and the values array contains only "value". The requirements are ANDed.
  780. type: object
  781. type: object
  782. x-kubernetes-map-type: atomic
  783. namespaceSelectors:
  784. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  785. items:
  786. description: |-
  787. A label selector is a label query over a set of resources. The result of matchLabels and
  788. matchExpressions are ANDed. An empty label selector matches all objects. A null
  789. label selector matches no objects.
  790. properties:
  791. matchExpressions:
  792. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  793. items:
  794. description: |-
  795. A label selector requirement is a selector that contains values, a key, and an operator that
  796. relates the key and values.
  797. properties:
  798. key:
  799. description: key is the label key that the selector applies to.
  800. type: string
  801. operator:
  802. description: |-
  803. operator represents a key's relationship to a set of values.
  804. Valid operators are In, NotIn, Exists and DoesNotExist.
  805. type: string
  806. values:
  807. description: |-
  808. values is an array of string values. If the operator is In or NotIn,
  809. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  810. the values array must be empty. This array is replaced during a strategic
  811. merge patch.
  812. items:
  813. type: string
  814. type: array
  815. x-kubernetes-list-type: atomic
  816. required:
  817. - key
  818. - operator
  819. type: object
  820. type: array
  821. x-kubernetes-list-type: atomic
  822. matchLabels:
  823. additionalProperties:
  824. type: string
  825. description: |-
  826. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  827. map is equivalent to an element of matchExpressions, whose key field is "key", the
  828. operator is "In", and the values array contains only "value". The requirements are ANDed.
  829. type: object
  830. type: object
  831. x-kubernetes-map-type: atomic
  832. type: array
  833. namespaces:
  834. description: |-
  835. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  836. Deprecated: Use NamespaceSelectors instead.
  837. items:
  838. maxLength: 63
  839. minLength: 1
  840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  841. type: string
  842. type: array
  843. refreshTime:
  844. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  845. type: string
  846. required:
  847. - externalSecretSpec
  848. type: object
  849. status:
  850. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  851. properties:
  852. conditions:
  853. items:
  854. description: ClusterExternalSecretStatusCondition defines the observed state of a ClusterExternalSecret resource.
  855. properties:
  856. message:
  857. type: string
  858. status:
  859. type: string
  860. type:
  861. description: ClusterExternalSecretConditionType defines a value type for ClusterExternalSecret conditions.
  862. type: string
  863. required:
  864. - status
  865. - type
  866. type: object
  867. type: array
  868. externalSecretName:
  869. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  870. type: string
  871. failedNamespaces:
  872. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  873. items:
  874. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  875. properties:
  876. namespace:
  877. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  878. type: string
  879. reason:
  880. description: Reason is why the ExternalSecret failed to apply to the namespace
  881. type: string
  882. required:
  883. - namespace
  884. type: object
  885. type: array
  886. provisionedNamespaces:
  887. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  888. items:
  889. type: string
  890. type: array
  891. type: object
  892. type: object
  893. served: true
  894. storage: true
  895. subresources:
  896. status: {}
  897. - additionalPrinterColumns:
  898. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  899. name: Store
  900. type: string
  901. - jsonPath: .spec.refreshTime
  902. name: Refresh Interval
  903. type: string
  904. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  905. name: Ready
  906. type: string
  907. deprecated: true
  908. name: v1beta1
  909. schema:
  910. openAPIV3Schema:
  911. description: ClusterExternalSecret is the schema for the clusterexternalsecrets API.
  912. properties:
  913. apiVersion:
  914. description: |-
  915. APIVersion defines the versioned schema of this representation of an object.
  916. Servers should convert recognized schemas to the latest internal value, and
  917. may reject unrecognized values.
  918. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  919. type: string
  920. kind:
  921. description: |-
  922. Kind is a string value representing the REST resource this object represents.
  923. Servers may infer this from the endpoint the client submits requests to.
  924. Cannot be updated.
  925. In CamelCase.
  926. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  927. type: string
  928. metadata:
  929. type: object
  930. spec:
  931. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  932. properties:
  933. externalSecretMetadata:
  934. description: The metadata of the external secrets to be created
  935. properties:
  936. annotations:
  937. additionalProperties:
  938. type: string
  939. type: object
  940. labels:
  941. additionalProperties:
  942. type: string
  943. type: object
  944. type: object
  945. externalSecretName:
  946. description: |-
  947. The name of the external secrets to be created.
  948. Defaults to the name of the ClusterExternalSecret
  949. maxLength: 253
  950. minLength: 1
  951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  952. type: string
  953. externalSecretSpec:
  954. description: The spec for the ExternalSecrets to be created
  955. properties:
  956. data:
  957. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  958. items:
  959. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  960. properties:
  961. remoteRef:
  962. description: |-
  963. RemoteRef points to the remote secret and defines
  964. which secret (version/property/..) to fetch.
  965. properties:
  966. conversionStrategy:
  967. default: Default
  968. description: Used to define a conversion Strategy
  969. enum:
  970. - Default
  971. - Unicode
  972. type: string
  973. decodingStrategy:
  974. default: None
  975. description: Used to define a decoding Strategy
  976. enum:
  977. - Auto
  978. - Base64
  979. - Base64URL
  980. - None
  981. type: string
  982. key:
  983. description: Key is the key used in the Provider, mandatory
  984. type: string
  985. metadataPolicy:
  986. default: None
  987. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  988. enum:
  989. - None
  990. - Fetch
  991. type: string
  992. property:
  993. description: Used to select a specific property of the Provider value (if a map), if supported
  994. type: string
  995. version:
  996. description: Used to select a specific version of the Provider value, if supported
  997. type: string
  998. required:
  999. - key
  1000. type: object
  1001. secretKey:
  1002. description: The key in the Kubernetes Secret to store the value.
  1003. maxLength: 253
  1004. minLength: 1
  1005. pattern: ^[-._a-zA-Z0-9]+$
  1006. type: string
  1007. sourceRef:
  1008. description: |-
  1009. SourceRef allows you to override the source
  1010. from which the value will be pulled.
  1011. maxProperties: 1
  1012. minProperties: 1
  1013. properties:
  1014. generatorRef:
  1015. description: |-
  1016. GeneratorRef points to a generator custom resource.
  1017. Deprecated: The generatorRef is not implemented in .data[].
  1018. this will be removed with v1.
  1019. properties:
  1020. apiVersion:
  1021. default: generators.external-secrets.io/v1alpha1
  1022. description: Specify the apiVersion of the generator resource
  1023. type: string
  1024. kind:
  1025. description: Specify the Kind of the generator resource
  1026. enum:
  1027. - ACRAccessToken
  1028. - ClusterGenerator
  1029. - ECRAuthorizationToken
  1030. - Fake
  1031. - GCRAccessToken
  1032. - GithubAccessToken
  1033. - QuayAccessToken
  1034. - Password
  1035. - SSHKey
  1036. - STSSessionToken
  1037. - UUID
  1038. - VaultDynamicSecret
  1039. - Webhook
  1040. - Grafana
  1041. type: string
  1042. name:
  1043. description: Specify the name of the generator resource
  1044. maxLength: 253
  1045. minLength: 1
  1046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1047. type: string
  1048. required:
  1049. - kind
  1050. - name
  1051. type: object
  1052. storeRef:
  1053. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1054. properties:
  1055. kind:
  1056. description: |-
  1057. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1058. Defaults to `SecretStore`
  1059. enum:
  1060. - SecretStore
  1061. - ClusterSecretStore
  1062. type: string
  1063. name:
  1064. description: Name of the SecretStore resource
  1065. maxLength: 253
  1066. minLength: 1
  1067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1068. type: string
  1069. type: object
  1070. type: object
  1071. required:
  1072. - remoteRef
  1073. - secretKey
  1074. type: object
  1075. type: array
  1076. dataFrom:
  1077. description: |-
  1078. DataFrom is used to fetch all properties from a specific Provider data
  1079. If multiple entries are specified, the Secret keys are merged in the specified order
  1080. items:
  1081. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  1082. properties:
  1083. extract:
  1084. description: |-
  1085. Used to extract multiple key/value pairs from one secret
  1086. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1087. properties:
  1088. conversionStrategy:
  1089. default: Default
  1090. description: Used to define a conversion Strategy
  1091. enum:
  1092. - Default
  1093. - Unicode
  1094. type: string
  1095. decodingStrategy:
  1096. default: None
  1097. description: Used to define a decoding Strategy
  1098. enum:
  1099. - Auto
  1100. - Base64
  1101. - Base64URL
  1102. - None
  1103. type: string
  1104. key:
  1105. description: Key is the key used in the Provider, mandatory
  1106. type: string
  1107. metadataPolicy:
  1108. default: None
  1109. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  1110. enum:
  1111. - None
  1112. - Fetch
  1113. type: string
  1114. property:
  1115. description: Used to select a specific property of the Provider value (if a map), if supported
  1116. type: string
  1117. version:
  1118. description: Used to select a specific version of the Provider value, if supported
  1119. type: string
  1120. required:
  1121. - key
  1122. type: object
  1123. find:
  1124. description: |-
  1125. Used to find secrets based on tags or regular expressions
  1126. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1127. properties:
  1128. conversionStrategy:
  1129. default: Default
  1130. description: Used to define a conversion Strategy
  1131. enum:
  1132. - Default
  1133. - Unicode
  1134. type: string
  1135. decodingStrategy:
  1136. default: None
  1137. description: Used to define a decoding Strategy
  1138. enum:
  1139. - Auto
  1140. - Base64
  1141. - Base64URL
  1142. - None
  1143. type: string
  1144. name:
  1145. description: Finds secrets based on the name.
  1146. properties:
  1147. regexp:
  1148. description: Finds secrets base
  1149. type: string
  1150. type: object
  1151. path:
  1152. description: A root path to start the find operations.
  1153. type: string
  1154. tags:
  1155. additionalProperties:
  1156. type: string
  1157. description: Find secrets based on tags.
  1158. type: object
  1159. type: object
  1160. rewrite:
  1161. description: |-
  1162. Used to rewrite secret Keys after getting them from the secret Provider
  1163. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  1164. items:
  1165. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  1166. maxProperties: 1
  1167. minProperties: 1
  1168. properties:
  1169. regexp:
  1170. description: |-
  1171. Used to rewrite with regular expressions.
  1172. The resulting key will be the output of a regexp.ReplaceAll operation.
  1173. properties:
  1174. source:
  1175. description: Used to define the regular expression of a re.Compiler.
  1176. type: string
  1177. target:
  1178. description: Used to define the target pattern of a ReplaceAll operation.
  1179. type: string
  1180. required:
  1181. - source
  1182. - target
  1183. type: object
  1184. transform:
  1185. description: |-
  1186. Used to apply string transformation on the secrets.
  1187. The resulting key will be the output of the template applied by the operation.
  1188. properties:
  1189. template:
  1190. description: |-
  1191. Used to define the template to apply on the secret name.
  1192. `.value ` will specify the secret name in the template.
  1193. type: string
  1194. required:
  1195. - template
  1196. type: object
  1197. type: object
  1198. type: array
  1199. sourceRef:
  1200. description: |-
  1201. SourceRef points to a store or generator
  1202. which contains secret values ready to use.
  1203. Use this in combination with Extract or Find pull values out of
  1204. a specific SecretStore.
  1205. When sourceRef points to a generator Extract or Find is not supported.
  1206. The generator returns a static map of values
  1207. maxProperties: 1
  1208. minProperties: 1
  1209. properties:
  1210. generatorRef:
  1211. description: GeneratorRef points to a generator custom resource.
  1212. properties:
  1213. apiVersion:
  1214. default: generators.external-secrets.io/v1alpha1
  1215. description: Specify the apiVersion of the generator resource
  1216. type: string
  1217. kind:
  1218. description: Specify the Kind of the generator resource
  1219. enum:
  1220. - ACRAccessToken
  1221. - ClusterGenerator
  1222. - ECRAuthorizationToken
  1223. - Fake
  1224. - GCRAccessToken
  1225. - GithubAccessToken
  1226. - QuayAccessToken
  1227. - Password
  1228. - SSHKey
  1229. - STSSessionToken
  1230. - UUID
  1231. - VaultDynamicSecret
  1232. - Webhook
  1233. - Grafana
  1234. type: string
  1235. name:
  1236. description: Specify the name of the generator resource
  1237. maxLength: 253
  1238. minLength: 1
  1239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1240. type: string
  1241. required:
  1242. - kind
  1243. - name
  1244. type: object
  1245. storeRef:
  1246. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1247. properties:
  1248. kind:
  1249. description: |-
  1250. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1251. Defaults to `SecretStore`
  1252. enum:
  1253. - SecretStore
  1254. - ClusterSecretStore
  1255. type: string
  1256. name:
  1257. description: Name of the SecretStore resource
  1258. maxLength: 253
  1259. minLength: 1
  1260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1261. type: string
  1262. type: object
  1263. type: object
  1264. type: object
  1265. type: array
  1266. refreshInterval:
  1267. default: 1h0m0s
  1268. description: |-
  1269. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  1270. specified as Golang Duration strings.
  1271. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  1272. Example values: "1h0m0s", "2h30m0s", "10m0s"
  1273. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  1274. type: string
  1275. refreshPolicy:
  1276. description: |-
  1277. RefreshPolicy determines how the ExternalSecret should be refreshed:
  1278. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  1279. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  1280. No periodic updates occur if refreshInterval is 0.
  1281. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  1282. enum:
  1283. - CreatedOnce
  1284. - Periodic
  1285. - OnChange
  1286. type: string
  1287. secretStoreRef:
  1288. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1289. properties:
  1290. kind:
  1291. description: |-
  1292. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1293. Defaults to `SecretStore`
  1294. enum:
  1295. - SecretStore
  1296. - ClusterSecretStore
  1297. type: string
  1298. name:
  1299. description: Name of the SecretStore resource
  1300. maxLength: 253
  1301. minLength: 1
  1302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1303. type: string
  1304. type: object
  1305. target:
  1306. default:
  1307. creationPolicy: Owner
  1308. deletionPolicy: Retain
  1309. description: |-
  1310. ExternalSecretTarget defines the Kubernetes Secret to be created
  1311. There can be only one target per ExternalSecret.
  1312. properties:
  1313. creationPolicy:
  1314. default: Owner
  1315. description: |-
  1316. CreationPolicy defines rules on how to create the resulting Secret.
  1317. Defaults to "Owner"
  1318. enum:
  1319. - Owner
  1320. - Orphan
  1321. - Merge
  1322. - None
  1323. type: string
  1324. deletionPolicy:
  1325. default: Retain
  1326. description: |-
  1327. DeletionPolicy defines rules on how to delete the resulting Secret.
  1328. Defaults to "Retain"
  1329. enum:
  1330. - Delete
  1331. - Merge
  1332. - Retain
  1333. type: string
  1334. immutable:
  1335. description: Immutable defines if the final secret will be immutable
  1336. type: boolean
  1337. name:
  1338. description: |-
  1339. The name of the Secret resource to be managed.
  1340. Defaults to the .metadata.name of the ExternalSecret resource
  1341. maxLength: 253
  1342. minLength: 1
  1343. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1344. type: string
  1345. template:
  1346. description: Template defines a blueprint for the created Secret resource.
  1347. properties:
  1348. data:
  1349. additionalProperties:
  1350. type: string
  1351. type: object
  1352. engineVersion:
  1353. default: v2
  1354. description: |-
  1355. EngineVersion specifies the template engine version
  1356. that should be used to compile/execute the
  1357. template specified in .data and .templateFrom[].
  1358. enum:
  1359. - v2
  1360. type: string
  1361. mergePolicy:
  1362. default: Replace
  1363. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  1364. enum:
  1365. - Replace
  1366. - Merge
  1367. type: string
  1368. metadata:
  1369. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  1370. properties:
  1371. annotations:
  1372. additionalProperties:
  1373. type: string
  1374. type: object
  1375. labels:
  1376. additionalProperties:
  1377. type: string
  1378. type: object
  1379. type: object
  1380. templateFrom:
  1381. items:
  1382. description: TemplateFrom defines a source for template data.
  1383. properties:
  1384. configMap:
  1385. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1386. properties:
  1387. items:
  1388. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1389. items:
  1390. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1391. properties:
  1392. key:
  1393. description: A key in the ConfigMap/Secret
  1394. maxLength: 253
  1395. minLength: 1
  1396. pattern: ^[-._a-zA-Z0-9]+$
  1397. type: string
  1398. templateAs:
  1399. default: Values
  1400. description: TemplateScope defines the scope of the template when processing template data.
  1401. enum:
  1402. - Values
  1403. - KeysAndValues
  1404. type: string
  1405. required:
  1406. - key
  1407. type: object
  1408. type: array
  1409. name:
  1410. description: The name of the ConfigMap/Secret resource
  1411. maxLength: 253
  1412. minLength: 1
  1413. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1414. type: string
  1415. required:
  1416. - items
  1417. - name
  1418. type: object
  1419. literal:
  1420. type: string
  1421. secret:
  1422. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1423. properties:
  1424. items:
  1425. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1426. items:
  1427. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1428. properties:
  1429. key:
  1430. description: A key in the ConfigMap/Secret
  1431. maxLength: 253
  1432. minLength: 1
  1433. pattern: ^[-._a-zA-Z0-9]+$
  1434. type: string
  1435. templateAs:
  1436. default: Values
  1437. description: TemplateScope defines the scope of the template when processing template data.
  1438. enum:
  1439. - Values
  1440. - KeysAndValues
  1441. type: string
  1442. required:
  1443. - key
  1444. type: object
  1445. type: array
  1446. name:
  1447. description: The name of the ConfigMap/Secret resource
  1448. maxLength: 253
  1449. minLength: 1
  1450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1451. type: string
  1452. required:
  1453. - items
  1454. - name
  1455. type: object
  1456. target:
  1457. default: Data
  1458. description: TemplateTarget defines the target field where the template result will be stored.
  1459. enum:
  1460. - Data
  1461. - Annotations
  1462. - Labels
  1463. type: string
  1464. type: object
  1465. type: array
  1466. type:
  1467. type: string
  1468. type: object
  1469. type: object
  1470. type: object
  1471. namespaceSelector:
  1472. description: The labels to select by to find the Namespaces to create the ExternalSecrets in
  1473. properties:
  1474. matchExpressions:
  1475. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1476. items:
  1477. description: |-
  1478. A label selector requirement is a selector that contains values, a key, and an operator that
  1479. relates the key and values.
  1480. properties:
  1481. key:
  1482. description: key is the label key that the selector applies to.
  1483. type: string
  1484. operator:
  1485. description: |-
  1486. operator represents a key's relationship to a set of values.
  1487. Valid operators are In, NotIn, Exists and DoesNotExist.
  1488. type: string
  1489. values:
  1490. description: |-
  1491. values is an array of string values. If the operator is In or NotIn,
  1492. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1493. the values array must be empty. This array is replaced during a strategic
  1494. merge patch.
  1495. items:
  1496. type: string
  1497. type: array
  1498. x-kubernetes-list-type: atomic
  1499. required:
  1500. - key
  1501. - operator
  1502. type: object
  1503. type: array
  1504. x-kubernetes-list-type: atomic
  1505. matchLabels:
  1506. additionalProperties:
  1507. type: string
  1508. description: |-
  1509. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1510. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1511. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1512. type: object
  1513. type: object
  1514. x-kubernetes-map-type: atomic
  1515. namespaceSelectors:
  1516. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1517. items:
  1518. description: |-
  1519. A label selector is a label query over a set of resources. The result of matchLabels and
  1520. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1521. label selector matches no objects.
  1522. properties:
  1523. matchExpressions:
  1524. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1525. items:
  1526. description: |-
  1527. A label selector requirement is a selector that contains values, a key, and an operator that
  1528. relates the key and values.
  1529. properties:
  1530. key:
  1531. description: key is the label key that the selector applies to.
  1532. type: string
  1533. operator:
  1534. description: |-
  1535. operator represents a key's relationship to a set of values.
  1536. Valid operators are In, NotIn, Exists and DoesNotExist.
  1537. type: string
  1538. values:
  1539. description: |-
  1540. values is an array of string values. If the operator is In or NotIn,
  1541. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1542. the values array must be empty. This array is replaced during a strategic
  1543. merge patch.
  1544. items:
  1545. type: string
  1546. type: array
  1547. x-kubernetes-list-type: atomic
  1548. required:
  1549. - key
  1550. - operator
  1551. type: object
  1552. type: array
  1553. x-kubernetes-list-type: atomic
  1554. matchLabels:
  1555. additionalProperties:
  1556. type: string
  1557. description: |-
  1558. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1559. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1560. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1561. type: object
  1562. type: object
  1563. x-kubernetes-map-type: atomic
  1564. type: array
  1565. namespaces:
  1566. description: |-
  1567. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  1568. Deprecated: Use NamespaceSelectors instead.
  1569. items:
  1570. maxLength: 63
  1571. minLength: 1
  1572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1573. type: string
  1574. type: array
  1575. refreshTime:
  1576. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  1577. type: string
  1578. required:
  1579. - externalSecretSpec
  1580. type: object
  1581. status:
  1582. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  1583. properties:
  1584. conditions:
  1585. items:
  1586. description: ClusterExternalSecretStatusCondition indicates the status of the ClusterExternalSecret.
  1587. properties:
  1588. message:
  1589. type: string
  1590. status:
  1591. type: string
  1592. type:
  1593. description: ClusterExternalSecretConditionType indicates the condition of the ClusterExternalSecret.
  1594. type: string
  1595. required:
  1596. - status
  1597. - type
  1598. type: object
  1599. type: array
  1600. externalSecretName:
  1601. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  1602. type: string
  1603. failedNamespaces:
  1604. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  1605. items:
  1606. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  1607. properties:
  1608. namespace:
  1609. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  1610. type: string
  1611. reason:
  1612. description: Reason is why the ExternalSecret failed to apply to the namespace
  1613. type: string
  1614. required:
  1615. - namespace
  1616. type: object
  1617. type: array
  1618. provisionedNamespaces:
  1619. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  1620. items:
  1621. type: string
  1622. type: array
  1623. type: object
  1624. type: object
  1625. served: false
  1626. storage: false
  1627. subresources:
  1628. status: {}
  1629. ---
  1630. apiVersion: apiextensions.k8s.io/v1
  1631. kind: CustomResourceDefinition
  1632. metadata:
  1633. annotations:
  1634. controller-gen.kubebuilder.io/version: v0.19.0
  1635. labels:
  1636. external-secrets.io/component: controller
  1637. name: clusterpushsecrets.external-secrets.io
  1638. spec:
  1639. group: external-secrets.io
  1640. names:
  1641. categories:
  1642. - external-secrets
  1643. kind: ClusterPushSecret
  1644. listKind: ClusterPushSecretList
  1645. plural: clusterpushsecrets
  1646. singular: clusterpushsecret
  1647. scope: Cluster
  1648. versions:
  1649. - additionalPrinterColumns:
  1650. - jsonPath: .metadata.creationTimestamp
  1651. name: AGE
  1652. type: date
  1653. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  1654. name: Status
  1655. type: string
  1656. name: v1alpha1
  1657. schema:
  1658. openAPIV3Schema:
  1659. description: ClusterPushSecret is the Schema for the ClusterPushSecrets API that enables cluster-wide management of pushing Kubernetes secrets to external providers.
  1660. properties:
  1661. apiVersion:
  1662. description: |-
  1663. APIVersion defines the versioned schema of this representation of an object.
  1664. Servers should convert recognized schemas to the latest internal value, and
  1665. may reject unrecognized values.
  1666. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  1667. type: string
  1668. kind:
  1669. description: |-
  1670. Kind is a string value representing the REST resource this object represents.
  1671. Servers may infer this from the endpoint the client submits requests to.
  1672. Cannot be updated.
  1673. In CamelCase.
  1674. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  1675. type: string
  1676. metadata:
  1677. type: object
  1678. spec:
  1679. description: ClusterPushSecretSpec defines the configuration for a ClusterPushSecret resource.
  1680. properties:
  1681. namespaceSelectors:
  1682. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1683. items:
  1684. description: |-
  1685. A label selector is a label query over a set of resources. The result of matchLabels and
  1686. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1687. label selector matches no objects.
  1688. properties:
  1689. matchExpressions:
  1690. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1691. items:
  1692. description: |-
  1693. A label selector requirement is a selector that contains values, a key, and an operator that
  1694. relates the key and values.
  1695. properties:
  1696. key:
  1697. description: key is the label key that the selector applies to.
  1698. type: string
  1699. operator:
  1700. description: |-
  1701. operator represents a key's relationship to a set of values.
  1702. Valid operators are In, NotIn, Exists and DoesNotExist.
  1703. type: string
  1704. values:
  1705. description: |-
  1706. values is an array of string values. If the operator is In or NotIn,
  1707. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1708. the values array must be empty. This array is replaced during a strategic
  1709. merge patch.
  1710. items:
  1711. type: string
  1712. type: array
  1713. x-kubernetes-list-type: atomic
  1714. required:
  1715. - key
  1716. - operator
  1717. type: object
  1718. type: array
  1719. x-kubernetes-list-type: atomic
  1720. matchLabels:
  1721. additionalProperties:
  1722. type: string
  1723. description: |-
  1724. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1725. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1726. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1727. type: object
  1728. type: object
  1729. x-kubernetes-map-type: atomic
  1730. type: array
  1731. pushSecretMetadata:
  1732. description: The metadata of the external secrets to be created
  1733. properties:
  1734. annotations:
  1735. additionalProperties:
  1736. type: string
  1737. type: object
  1738. labels:
  1739. additionalProperties:
  1740. type: string
  1741. type: object
  1742. type: object
  1743. pushSecretName:
  1744. description: |-
  1745. The name of the push secrets to be created.
  1746. Defaults to the name of the ClusterPushSecret
  1747. maxLength: 253
  1748. minLength: 1
  1749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1750. type: string
  1751. pushSecretSpec:
  1752. description: PushSecretSpec defines what to do with the secrets.
  1753. properties:
  1754. data:
  1755. description: Secret Data that should be pushed to providers
  1756. items:
  1757. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  1758. properties:
  1759. conversionStrategy:
  1760. default: None
  1761. description: Used to define a conversion Strategy for the secret keys
  1762. enum:
  1763. - None
  1764. - ReverseUnicode
  1765. type: string
  1766. match:
  1767. description: Match a given Secret Key to be pushed to the provider.
  1768. properties:
  1769. remoteRef:
  1770. description: Remote Refs to push to providers.
  1771. properties:
  1772. property:
  1773. description: Name of the property in the resulting secret
  1774. type: string
  1775. remoteKey:
  1776. description: Name of the resulting provider secret.
  1777. type: string
  1778. required:
  1779. - remoteKey
  1780. type: object
  1781. secretKey:
  1782. description: Secret Key to be pushed
  1783. type: string
  1784. required:
  1785. - remoteRef
  1786. type: object
  1787. metadata:
  1788. description: |-
  1789. Metadata is metadata attached to the secret.
  1790. The structure of metadata is provider specific, please look it up in the provider documentation.
  1791. x-kubernetes-preserve-unknown-fields: true
  1792. required:
  1793. - match
  1794. type: object
  1795. type: array
  1796. dataTo:
  1797. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  1798. items:
  1799. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  1800. properties:
  1801. conversionStrategy:
  1802. default: None
  1803. description: Used to define a conversion Strategy for the secret keys
  1804. enum:
  1805. - None
  1806. - ReverseUnicode
  1807. type: string
  1808. match:
  1809. description: |-
  1810. Match pattern for selecting keys from the source Secret.
  1811. If not specified, all keys are selected.
  1812. properties:
  1813. regexp:
  1814. description: |-
  1815. Regexp matches keys by regular expression.
  1816. If not specified, all keys are matched.
  1817. type: string
  1818. type: object
  1819. metadata:
  1820. description: |-
  1821. Metadata is metadata attached to the secret.
  1822. The structure of metadata is provider specific, please look it up in the provider documentation.
  1823. x-kubernetes-preserve-unknown-fields: true
  1824. remoteKey:
  1825. description: |-
  1826. RemoteKey is the name of the single provider secret that will receive ALL
  1827. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  1828. When set, per-key expansion is skipped and a single push is performed.
  1829. The provider's store prefix (if any) is still prepended to this value.
  1830. When not set, each matched key is pushed as its own individual provider secret.
  1831. type: string
  1832. rewrite:
  1833. description: |-
  1834. Rewrite operations to transform keys before pushing to the provider.
  1835. Operations are applied sequentially.
  1836. items:
  1837. description: PushSecretRewrite defines how to transform secret keys before pushing.
  1838. properties:
  1839. regexp:
  1840. description: Used to rewrite with regular expressions.
  1841. properties:
  1842. source:
  1843. description: Used to define the regular expression of a re.Compiler.
  1844. type: string
  1845. target:
  1846. description: Used to define the target pattern of a ReplaceAll operation.
  1847. type: string
  1848. required:
  1849. - source
  1850. - target
  1851. type: object
  1852. transform:
  1853. description: Used to apply string transformation on the secrets.
  1854. properties:
  1855. template:
  1856. description: |-
  1857. Used to define the template to apply on the secret name.
  1858. `.value ` will specify the secret name in the template.
  1859. type: string
  1860. required:
  1861. - template
  1862. type: object
  1863. type: object
  1864. x-kubernetes-validations:
  1865. - message: exactly one of regexp or transform must be set
  1866. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  1867. type: array
  1868. storeRef:
  1869. description: StoreRef specifies which SecretStore to push to. Required.
  1870. properties:
  1871. kind:
  1872. default: SecretStore
  1873. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1874. enum:
  1875. - SecretStore
  1876. - ClusterSecretStore
  1877. type: string
  1878. labelSelector:
  1879. description: Optionally, sync to secret stores with label selector
  1880. properties:
  1881. matchExpressions:
  1882. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1883. items:
  1884. description: |-
  1885. A label selector requirement is a selector that contains values, a key, and an operator that
  1886. relates the key and values.
  1887. properties:
  1888. key:
  1889. description: key is the label key that the selector applies to.
  1890. type: string
  1891. operator:
  1892. description: |-
  1893. operator represents a key's relationship to a set of values.
  1894. Valid operators are In, NotIn, Exists and DoesNotExist.
  1895. type: string
  1896. values:
  1897. description: |-
  1898. values is an array of string values. If the operator is In or NotIn,
  1899. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1900. the values array must be empty. This array is replaced during a strategic
  1901. merge patch.
  1902. items:
  1903. type: string
  1904. type: array
  1905. x-kubernetes-list-type: atomic
  1906. required:
  1907. - key
  1908. - operator
  1909. type: object
  1910. type: array
  1911. x-kubernetes-list-type: atomic
  1912. matchLabels:
  1913. additionalProperties:
  1914. type: string
  1915. description: |-
  1916. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1917. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1918. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1919. type: object
  1920. type: object
  1921. x-kubernetes-map-type: atomic
  1922. name:
  1923. description: Optionally, sync to the SecretStore of the given name
  1924. maxLength: 253
  1925. minLength: 1
  1926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1927. type: string
  1928. type: object
  1929. type: object
  1930. x-kubernetes-validations:
  1931. - message: storeRef must specify either name or labelSelector
  1932. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  1933. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  1934. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  1935. type: array
  1936. deletionPolicy:
  1937. default: None
  1938. description: Deletion Policy to handle Secrets in the provider.
  1939. enum:
  1940. - Delete
  1941. - None
  1942. type: string
  1943. refreshInterval:
  1944. default: 1h0m0s
  1945. description: The Interval to which External Secrets will try to push a secret definition
  1946. type: string
  1947. secretStoreRefs:
  1948. items:
  1949. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  1950. properties:
  1951. kind:
  1952. default: SecretStore
  1953. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1954. enum:
  1955. - SecretStore
  1956. - ClusterSecretStore
  1957. type: string
  1958. labelSelector:
  1959. description: Optionally, sync to secret stores with label selector
  1960. properties:
  1961. matchExpressions:
  1962. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1963. items:
  1964. description: |-
  1965. A label selector requirement is a selector that contains values, a key, and an operator that
  1966. relates the key and values.
  1967. properties:
  1968. key:
  1969. description: key is the label key that the selector applies to.
  1970. type: string
  1971. operator:
  1972. description: |-
  1973. operator represents a key's relationship to a set of values.
  1974. Valid operators are In, NotIn, Exists and DoesNotExist.
  1975. type: string
  1976. values:
  1977. description: |-
  1978. values is an array of string values. If the operator is In or NotIn,
  1979. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1980. the values array must be empty. This array is replaced during a strategic
  1981. merge patch.
  1982. items:
  1983. type: string
  1984. type: array
  1985. x-kubernetes-list-type: atomic
  1986. required:
  1987. - key
  1988. - operator
  1989. type: object
  1990. type: array
  1991. x-kubernetes-list-type: atomic
  1992. matchLabels:
  1993. additionalProperties:
  1994. type: string
  1995. description: |-
  1996. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1997. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1998. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1999. type: object
  2000. type: object
  2001. x-kubernetes-map-type: atomic
  2002. name:
  2003. description: Optionally, sync to the SecretStore of the given name
  2004. maxLength: 253
  2005. minLength: 1
  2006. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2007. type: string
  2008. type: object
  2009. type: array
  2010. selector:
  2011. description: The Secret Selector (k8s source) for the Push Secret
  2012. maxProperties: 1
  2013. minProperties: 1
  2014. properties:
  2015. generatorRef:
  2016. description: Point to a generator to create a Secret.
  2017. properties:
  2018. apiVersion:
  2019. default: generators.external-secrets.io/v1alpha1
  2020. description: Specify the apiVersion of the generator resource
  2021. type: string
  2022. kind:
  2023. description: Specify the Kind of the generator resource
  2024. enum:
  2025. - ACRAccessToken
  2026. - BeyondtrustWorkloadCredentialsDynamicSecret
  2027. - ClusterGenerator
  2028. - CloudsmithAccessToken
  2029. - ECRAuthorizationToken
  2030. - Fake
  2031. - GCRAccessToken
  2032. - GithubAccessToken
  2033. - GitlabDeployToken
  2034. - QuayAccessToken
  2035. - Password
  2036. - SSHKey
  2037. - STSSessionToken
  2038. - UUID
  2039. - VaultDynamicSecret
  2040. - Webhook
  2041. - Grafana
  2042. - MFA
  2043. type: string
  2044. name:
  2045. description: Specify the name of the generator resource
  2046. maxLength: 253
  2047. minLength: 1
  2048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2049. type: string
  2050. required:
  2051. - kind
  2052. - name
  2053. type: object
  2054. secret:
  2055. description: Select a Secret to Push.
  2056. properties:
  2057. name:
  2058. description: |-
  2059. Name of the Secret.
  2060. The Secret must exist in the same namespace as the PushSecret manifest.
  2061. maxLength: 253
  2062. minLength: 1
  2063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2064. type: string
  2065. selector:
  2066. description: Selector chooses secrets using a labelSelector.
  2067. properties:
  2068. matchExpressions:
  2069. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2070. items:
  2071. description: |-
  2072. A label selector requirement is a selector that contains values, a key, and an operator that
  2073. relates the key and values.
  2074. properties:
  2075. key:
  2076. description: key is the label key that the selector applies to.
  2077. type: string
  2078. operator:
  2079. description: |-
  2080. operator represents a key's relationship to a set of values.
  2081. Valid operators are In, NotIn, Exists and DoesNotExist.
  2082. type: string
  2083. values:
  2084. description: |-
  2085. values is an array of string values. If the operator is In or NotIn,
  2086. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2087. the values array must be empty. This array is replaced during a strategic
  2088. merge patch.
  2089. items:
  2090. type: string
  2091. type: array
  2092. x-kubernetes-list-type: atomic
  2093. required:
  2094. - key
  2095. - operator
  2096. type: object
  2097. type: array
  2098. x-kubernetes-list-type: atomic
  2099. matchLabels:
  2100. additionalProperties:
  2101. type: string
  2102. description: |-
  2103. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2104. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2105. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2106. type: object
  2107. type: object
  2108. x-kubernetes-map-type: atomic
  2109. type: object
  2110. type: object
  2111. template:
  2112. description: Template defines a blueprint for the created Secret resource.
  2113. properties:
  2114. data:
  2115. additionalProperties:
  2116. type: string
  2117. type: object
  2118. engineVersion:
  2119. default: v2
  2120. description: |-
  2121. EngineVersion specifies the template engine version
  2122. that should be used to compile/execute the
  2123. template specified in .data and .templateFrom[].
  2124. enum:
  2125. - v2
  2126. type: string
  2127. mergePolicy:
  2128. default: Replace
  2129. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  2130. enum:
  2131. - Replace
  2132. - Merge
  2133. type: string
  2134. metadata:
  2135. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  2136. properties:
  2137. annotations:
  2138. additionalProperties:
  2139. type: string
  2140. type: object
  2141. finalizers:
  2142. items:
  2143. type: string
  2144. type: array
  2145. labels:
  2146. additionalProperties:
  2147. type: string
  2148. type: object
  2149. type: object
  2150. templateFrom:
  2151. items:
  2152. description: |-
  2153. TemplateFrom specifies a source for templates.
  2154. Each item in the list can either reference a ConfigMap or a Secret resource.
  2155. properties:
  2156. configMap:
  2157. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2158. properties:
  2159. items:
  2160. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2161. items:
  2162. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2163. properties:
  2164. key:
  2165. description: A key in the ConfigMap/Secret
  2166. maxLength: 253
  2167. minLength: 1
  2168. pattern: ^[-._a-zA-Z0-9]+$
  2169. type: string
  2170. templateAs:
  2171. default: Values
  2172. description: TemplateScope specifies how the template keys should be interpreted.
  2173. enum:
  2174. - Values
  2175. - KeysAndValues
  2176. type: string
  2177. required:
  2178. - key
  2179. type: object
  2180. type: array
  2181. name:
  2182. description: The name of the ConfigMap/Secret resource
  2183. maxLength: 253
  2184. minLength: 1
  2185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2186. type: string
  2187. required:
  2188. - items
  2189. - name
  2190. type: object
  2191. literal:
  2192. type: string
  2193. secret:
  2194. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2195. properties:
  2196. items:
  2197. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2198. items:
  2199. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2200. properties:
  2201. key:
  2202. description: A key in the ConfigMap/Secret
  2203. maxLength: 253
  2204. minLength: 1
  2205. pattern: ^[-._a-zA-Z0-9]+$
  2206. type: string
  2207. templateAs:
  2208. default: Values
  2209. description: TemplateScope specifies how the template keys should be interpreted.
  2210. enum:
  2211. - Values
  2212. - KeysAndValues
  2213. type: string
  2214. required:
  2215. - key
  2216. type: object
  2217. type: array
  2218. name:
  2219. description: The name of the ConfigMap/Secret resource
  2220. maxLength: 253
  2221. minLength: 1
  2222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2223. type: string
  2224. required:
  2225. - items
  2226. - name
  2227. type: object
  2228. target:
  2229. default: Data
  2230. description: |-
  2231. Target specifies where to place the template result.
  2232. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  2233. any other value is rejected because it would allow writes to privileged Secret fields.
  2234. For custom resources (when spec.target.manifest is set), this supports
  2235. nested paths like "spec.database.config" or "data".
  2236. type: string
  2237. valuesDecodingStrategy:
  2238. description: |-
  2239. Used to define a decoding Strategy for the rendered template values.
  2240. Defaults to None when omitted.
  2241. enum:
  2242. - Auto
  2243. - Base64
  2244. - Base64URL
  2245. - None
  2246. type: string
  2247. type: object
  2248. type: array
  2249. type:
  2250. type: string
  2251. type: object
  2252. updatePolicy:
  2253. default: Replace
  2254. description: UpdatePolicy to handle Secrets in the provider.
  2255. enum:
  2256. - Replace
  2257. - IfNotExists
  2258. type: string
  2259. required:
  2260. - secretStoreRefs
  2261. - selector
  2262. type: object
  2263. refreshTime:
  2264. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  2265. type: string
  2266. required:
  2267. - pushSecretSpec
  2268. type: object
  2269. status:
  2270. description: ClusterPushSecretStatus contains the status information for the ClusterPushSecret resource.
  2271. properties:
  2272. conditions:
  2273. items:
  2274. description: PushSecretStatusCondition indicates the status of the PushSecret.
  2275. properties:
  2276. lastTransitionTime:
  2277. format: date-time
  2278. type: string
  2279. message:
  2280. type: string
  2281. reason:
  2282. type: string
  2283. status:
  2284. type: string
  2285. type:
  2286. description: PushSecretConditionType indicates the condition of the PushSecret.
  2287. type: string
  2288. required:
  2289. - status
  2290. - type
  2291. type: object
  2292. type: array
  2293. failedNamespaces:
  2294. description: Failed namespaces are the namespaces that failed to apply an PushSecret
  2295. items:
  2296. description: ClusterPushSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  2297. properties:
  2298. namespace:
  2299. description: Namespace is the namespace that failed when trying to apply an PushSecret
  2300. type: string
  2301. reason:
  2302. description: Reason is why the PushSecret failed to apply to the namespace
  2303. type: string
  2304. required:
  2305. - namespace
  2306. type: object
  2307. type: array
  2308. provisionedNamespaces:
  2309. description: ProvisionedNamespaces are the namespaces where the ClusterPushSecret has secrets
  2310. items:
  2311. type: string
  2312. type: array
  2313. pushSecretName:
  2314. type: string
  2315. type: object
  2316. type: object
  2317. served: true
  2318. storage: true
  2319. subresources:
  2320. status: {}
  2321. ---
  2322. apiVersion: apiextensions.k8s.io/v1
  2323. kind: CustomResourceDefinition
  2324. metadata:
  2325. annotations:
  2326. controller-gen.kubebuilder.io/version: v0.19.0
  2327. labels:
  2328. external-secrets.io/component: controller
  2329. name: clustersecretstores.external-secrets.io
  2330. spec:
  2331. group: external-secrets.io
  2332. names:
  2333. categories:
  2334. - external-secrets
  2335. kind: ClusterSecretStore
  2336. listKind: ClusterSecretStoreList
  2337. plural: clustersecretstores
  2338. shortNames:
  2339. - css
  2340. singular: clustersecretstore
  2341. scope: Cluster
  2342. versions:
  2343. - additionalPrinterColumns:
  2344. - jsonPath: .metadata.creationTimestamp
  2345. name: AGE
  2346. type: date
  2347. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  2348. name: Status
  2349. type: string
  2350. - jsonPath: .status.capabilities
  2351. name: Capabilities
  2352. type: string
  2353. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  2354. name: Ready
  2355. type: string
  2356. name: v1
  2357. schema:
  2358. openAPIV3Schema:
  2359. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  2360. properties:
  2361. apiVersion:
  2362. description: |-
  2363. APIVersion defines the versioned schema of this representation of an object.
  2364. Servers should convert recognized schemas to the latest internal value, and
  2365. may reject unrecognized values.
  2366. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  2367. type: string
  2368. kind:
  2369. description: |-
  2370. Kind is a string value representing the REST resource this object represents.
  2371. Servers may infer this from the endpoint the client submits requests to.
  2372. Cannot be updated.
  2373. In CamelCase.
  2374. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  2375. type: string
  2376. metadata:
  2377. type: object
  2378. spec:
  2379. description: SecretStoreSpec defines the desired state of SecretStore.
  2380. properties:
  2381. conditions:
  2382. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  2383. items:
  2384. description: |-
  2385. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  2386. for a ClusterSecretStore instance.
  2387. properties:
  2388. namespaceRegexes:
  2389. description: Choose namespaces by using regex matching
  2390. items:
  2391. type: string
  2392. type: array
  2393. namespaceSelector:
  2394. description: Choose namespace using a labelSelector
  2395. properties:
  2396. matchExpressions:
  2397. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2398. items:
  2399. description: |-
  2400. A label selector requirement is a selector that contains values, a key, and an operator that
  2401. relates the key and values.
  2402. properties:
  2403. key:
  2404. description: key is the label key that the selector applies to.
  2405. type: string
  2406. operator:
  2407. description: |-
  2408. operator represents a key's relationship to a set of values.
  2409. Valid operators are In, NotIn, Exists and DoesNotExist.
  2410. type: string
  2411. values:
  2412. description: |-
  2413. values is an array of string values. If the operator is In or NotIn,
  2414. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2415. the values array must be empty. This array is replaced during a strategic
  2416. merge patch.
  2417. items:
  2418. type: string
  2419. type: array
  2420. x-kubernetes-list-type: atomic
  2421. required:
  2422. - key
  2423. - operator
  2424. type: object
  2425. type: array
  2426. x-kubernetes-list-type: atomic
  2427. matchLabels:
  2428. additionalProperties:
  2429. type: string
  2430. description: |-
  2431. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2432. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2433. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2434. type: object
  2435. type: object
  2436. x-kubernetes-map-type: atomic
  2437. namespaces:
  2438. description: Choose namespaces by name
  2439. items:
  2440. maxLength: 63
  2441. minLength: 1
  2442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2443. type: string
  2444. type: array
  2445. type: object
  2446. type: array
  2447. controller:
  2448. description: |-
  2449. Used to select the correct ESO controller (think: ingress.ingressClassName)
  2450. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  2451. type: string
  2452. provider:
  2453. description: Used to configure the provider. Only one provider may be set
  2454. maxProperties: 1
  2455. minProperties: 1
  2456. properties:
  2457. akeyless:
  2458. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  2459. properties:
  2460. akeylessGWApiURL:
  2461. description: Akeyless GW API Url from which the secrets to be fetched from.
  2462. type: string
  2463. authSecretRef:
  2464. description: Auth configures how the operator authenticates with Akeyless.
  2465. properties:
  2466. kubernetesAuth:
  2467. description: |-
  2468. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  2469. token stored in the named Secret resource.
  2470. properties:
  2471. accessID:
  2472. description: the Akeyless Kubernetes auth-method access-id
  2473. type: string
  2474. k8sConfName:
  2475. description: Kubernetes-auth configuration name in Akeyless-Gateway
  2476. type: string
  2477. secretRef:
  2478. description: |-
  2479. Optional secret field containing a Kubernetes ServiceAccount JWT used
  2480. for authenticating with Akeyless. If a name is specified without a key,
  2481. `token` is the default. If one is not specified, the one bound to
  2482. the controller will be used.
  2483. properties:
  2484. key:
  2485. description: |-
  2486. A key in the referenced Secret.
  2487. Some instances of this field may be defaulted, in others it may be required.
  2488. maxLength: 253
  2489. minLength: 1
  2490. pattern: ^[-._a-zA-Z0-9]+$
  2491. type: string
  2492. name:
  2493. description: The name of the Secret resource being referred to.
  2494. maxLength: 253
  2495. minLength: 1
  2496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2497. type: string
  2498. namespace:
  2499. description: |-
  2500. The namespace of the Secret resource being referred to.
  2501. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2502. maxLength: 63
  2503. minLength: 1
  2504. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2505. type: string
  2506. type: object
  2507. serviceAccountRef:
  2508. description: |-
  2509. Optional service account field containing the name of a kubernetes ServiceAccount.
  2510. If the service account is specified, the service account secret token JWT will be used
  2511. for authenticating with Akeyless. If the service account selector is not supplied,
  2512. the secretRef will be used instead.
  2513. properties:
  2514. audiences:
  2515. description: |-
  2516. Audience specifies the `aud` claim for the service account token
  2517. Some providers automatically extend the audience field based on well-known annotations for workload
  2518. identity (e.g. IRSA or GCP Workload Identity)
  2519. items:
  2520. type: string
  2521. type: array
  2522. name:
  2523. description: The name of the ServiceAccount resource being referred to.
  2524. maxLength: 253
  2525. minLength: 1
  2526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2527. type: string
  2528. namespace:
  2529. description: |-
  2530. Namespace of the resource being referred to.
  2531. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2532. maxLength: 63
  2533. minLength: 1
  2534. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2535. type: string
  2536. required:
  2537. - name
  2538. type: object
  2539. required:
  2540. - accessID
  2541. - k8sConfName
  2542. type: object
  2543. secretRef:
  2544. description: |-
  2545. Reference to a Secret that contains the details
  2546. to authenticate with Akeyless.
  2547. properties:
  2548. accessID:
  2549. description: The SecretAccessID is used for authentication
  2550. properties:
  2551. key:
  2552. description: |-
  2553. A key in the referenced Secret.
  2554. Some instances of this field may be defaulted, in others it may be required.
  2555. maxLength: 253
  2556. minLength: 1
  2557. pattern: ^[-._a-zA-Z0-9]+$
  2558. type: string
  2559. name:
  2560. description: The name of the Secret resource being referred to.
  2561. maxLength: 253
  2562. minLength: 1
  2563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2564. type: string
  2565. namespace:
  2566. description: |-
  2567. The namespace of the Secret resource being referred to.
  2568. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2569. maxLength: 63
  2570. minLength: 1
  2571. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2572. type: string
  2573. type: object
  2574. accessType:
  2575. description: |-
  2576. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2577. In some instances, `key` is a required field.
  2578. properties:
  2579. key:
  2580. description: |-
  2581. A key in the referenced Secret.
  2582. Some instances of this field may be defaulted, in others it may be required.
  2583. maxLength: 253
  2584. minLength: 1
  2585. pattern: ^[-._a-zA-Z0-9]+$
  2586. type: string
  2587. name:
  2588. description: The name of the Secret resource being referred to.
  2589. maxLength: 253
  2590. minLength: 1
  2591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2592. type: string
  2593. namespace:
  2594. description: |-
  2595. The namespace of the Secret resource being referred to.
  2596. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2597. maxLength: 63
  2598. minLength: 1
  2599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2600. type: string
  2601. type: object
  2602. accessTypeParam:
  2603. description: |-
  2604. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2605. In some instances, `key` is a required field.
  2606. properties:
  2607. key:
  2608. description: |-
  2609. A key in the referenced Secret.
  2610. Some instances of this field may be defaulted, in others it may be required.
  2611. maxLength: 253
  2612. minLength: 1
  2613. pattern: ^[-._a-zA-Z0-9]+$
  2614. type: string
  2615. name:
  2616. description: The name of the Secret resource being referred to.
  2617. maxLength: 253
  2618. minLength: 1
  2619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2620. type: string
  2621. namespace:
  2622. description: |-
  2623. The namespace of the Secret resource being referred to.
  2624. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2625. maxLength: 63
  2626. minLength: 1
  2627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2628. type: string
  2629. type: object
  2630. type: object
  2631. serviceAccountRef:
  2632. description: |-
  2633. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  2634. authentication on AKS Workload Identity. The operator obtains a federated
  2635. identity token from this ServiceAccount via the TokenRequest API instead
  2636. of using the ESO controller pod identity. Ignored for other access types.
  2637. properties:
  2638. audiences:
  2639. description: |-
  2640. Audience specifies the `aud` claim for the service account token
  2641. Some providers automatically extend the audience field based on well-known annotations for workload
  2642. identity (e.g. IRSA or GCP Workload Identity)
  2643. items:
  2644. type: string
  2645. type: array
  2646. name:
  2647. description: The name of the ServiceAccount resource being referred to.
  2648. maxLength: 253
  2649. minLength: 1
  2650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2651. type: string
  2652. namespace:
  2653. description: |-
  2654. Namespace of the resource being referred to.
  2655. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2656. maxLength: 63
  2657. minLength: 1
  2658. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2659. type: string
  2660. required:
  2661. - name
  2662. type: object
  2663. type: object
  2664. caBundle:
  2665. description: |-
  2666. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  2667. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  2668. are used to validate the TLS connection.
  2669. format: byte
  2670. type: string
  2671. caProvider:
  2672. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  2673. properties:
  2674. key:
  2675. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  2676. maxLength: 253
  2677. minLength: 1
  2678. pattern: ^[-._a-zA-Z0-9]+$
  2679. type: string
  2680. name:
  2681. description: The name of the object located at the provider type.
  2682. maxLength: 253
  2683. minLength: 1
  2684. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2685. type: string
  2686. namespace:
  2687. description: |-
  2688. The namespace the Provider type is in.
  2689. Can only be defined when used in a ClusterSecretStore.
  2690. maxLength: 63
  2691. minLength: 1
  2692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2693. type: string
  2694. type:
  2695. description: The type of provider to use such as "Secret", or "ConfigMap".
  2696. enum:
  2697. - Secret
  2698. - ConfigMap
  2699. type: string
  2700. required:
  2701. - name
  2702. - type
  2703. type: object
  2704. ignoreCache:
  2705. description: |-
  2706. IgnoreCache bypasses the Gateway cache for secret reads when true.
  2707. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  2708. type: boolean
  2709. required:
  2710. - akeylessGWApiURL
  2711. - authSecretRef
  2712. type: object
  2713. aws:
  2714. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  2715. properties:
  2716. additionalRoles:
  2717. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  2718. items:
  2719. type: string
  2720. type: array
  2721. auth:
  2722. description: |-
  2723. Auth defines the information necessary to authenticate against AWS
  2724. if not set aws sdk will infer credentials from your environment
  2725. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  2726. properties:
  2727. jwt:
  2728. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  2729. properties:
  2730. serviceAccountRef:
  2731. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  2732. properties:
  2733. audiences:
  2734. description: |-
  2735. Audience specifies the `aud` claim for the service account token
  2736. Some providers automatically extend the audience field based on well-known annotations for workload
  2737. identity (e.g. IRSA or GCP Workload Identity)
  2738. items:
  2739. type: string
  2740. type: array
  2741. name:
  2742. description: The name of the ServiceAccount resource being referred to.
  2743. maxLength: 253
  2744. minLength: 1
  2745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2746. type: string
  2747. namespace:
  2748. description: |-
  2749. Namespace of the resource being referred to.
  2750. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2751. maxLength: 63
  2752. minLength: 1
  2753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2754. type: string
  2755. required:
  2756. - name
  2757. type: object
  2758. type: object
  2759. secretRef:
  2760. description: |-
  2761. AWSAuthSecretRef holds secret references for AWS credentials
  2762. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  2763. properties:
  2764. accessKeyIDSecretRef:
  2765. description: The AccessKeyID is used for authentication
  2766. properties:
  2767. key:
  2768. description: |-
  2769. A key in the referenced Secret.
  2770. Some instances of this field may be defaulted, in others it may be required.
  2771. maxLength: 253
  2772. minLength: 1
  2773. pattern: ^[-._a-zA-Z0-9]+$
  2774. type: string
  2775. name:
  2776. description: The name of the Secret resource being referred to.
  2777. maxLength: 253
  2778. minLength: 1
  2779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2780. type: string
  2781. namespace:
  2782. description: |-
  2783. The namespace of the Secret resource being referred to.
  2784. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2785. maxLength: 63
  2786. minLength: 1
  2787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2788. type: string
  2789. type: object
  2790. secretAccessKeySecretRef:
  2791. description: The SecretAccessKey is used for authentication
  2792. properties:
  2793. key:
  2794. description: |-
  2795. A key in the referenced Secret.
  2796. Some instances of this field may be defaulted, in others it may be required.
  2797. maxLength: 253
  2798. minLength: 1
  2799. pattern: ^[-._a-zA-Z0-9]+$
  2800. type: string
  2801. name:
  2802. description: The name of the Secret resource being referred to.
  2803. maxLength: 253
  2804. minLength: 1
  2805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2806. type: string
  2807. namespace:
  2808. description: |-
  2809. The namespace of the Secret resource being referred to.
  2810. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2811. maxLength: 63
  2812. minLength: 1
  2813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2814. type: string
  2815. type: object
  2816. sessionTokenSecretRef:
  2817. description: |-
  2818. The SessionToken used for authentication
  2819. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  2820. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  2821. properties:
  2822. key:
  2823. description: |-
  2824. A key in the referenced Secret.
  2825. Some instances of this field may be defaulted, in others it may be required.
  2826. maxLength: 253
  2827. minLength: 1
  2828. pattern: ^[-._a-zA-Z0-9]+$
  2829. type: string
  2830. name:
  2831. description: The name of the Secret resource being referred to.
  2832. maxLength: 253
  2833. minLength: 1
  2834. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2835. type: string
  2836. namespace:
  2837. description: |-
  2838. The namespace of the Secret resource being referred to.
  2839. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2840. maxLength: 63
  2841. minLength: 1
  2842. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2843. type: string
  2844. type: object
  2845. type: object
  2846. type: object
  2847. customSessionTags:
  2848. additionalProperties:
  2849. type: string
  2850. description: |-
  2851. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  2852. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  2853. type: object
  2854. x-kubernetes-validations:
  2855. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  2856. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  2857. externalID:
  2858. description: AWS External ID set on assumed IAM roles
  2859. type: string
  2860. prefix:
  2861. description: Prefix adds a prefix to all retrieved values.
  2862. type: string
  2863. region:
  2864. description: AWS Region to be used for the provider
  2865. type: string
  2866. role:
  2867. description: Role is a Role ARN which the provider will assume
  2868. type: string
  2869. secretsManager:
  2870. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  2871. properties:
  2872. forceDeleteWithoutRecovery:
  2873. description: |-
  2874. Specifies whether to delete the secret without any recovery window. You
  2875. can't use both this parameter and RecoveryWindowInDays in the same call.
  2876. If you don't use either, then by default Secrets Manager uses a 30 day
  2877. recovery window.
  2878. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  2879. type: boolean
  2880. recoveryWindowInDays:
  2881. description: |-
  2882. The number of days from 7 to 30 that Secrets Manager waits before
  2883. permanently deleting the secret. You can't use both this parameter and
  2884. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  2885. then by default Secrets Manager uses a 30-day recovery window.
  2886. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  2887. format: int64
  2888. type: integer
  2889. type: object
  2890. service:
  2891. description: Service defines which service should be used to fetch the secrets
  2892. enum:
  2893. - SecretsManager
  2894. - ParameterStore
  2895. - CertificateManager
  2896. type: string
  2897. sessionTags:
  2898. description: AWS STS assume role session tags
  2899. items:
  2900. description: |-
  2901. Tag is a key-value pair that can be attached to an AWS resource.
  2902. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  2903. properties:
  2904. key:
  2905. type: string
  2906. value:
  2907. type: string
  2908. required:
  2909. - key
  2910. - value
  2911. type: object
  2912. type: array
  2913. sessionTagsPolicy:
  2914. default: None
  2915. description: |-
  2916. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  2917. None (default): no tags are added.
  2918. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  2919. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  2920. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  2921. enum:
  2922. - None
  2923. - Simple
  2924. - Custom
  2925. type: string
  2926. transitiveTagKeys:
  2927. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  2928. items:
  2929. type: string
  2930. type: array
  2931. required:
  2932. - region
  2933. - service
  2934. type: object
  2935. azurekv:
  2936. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  2937. properties:
  2938. authSecretRef:
  2939. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  2940. properties:
  2941. clientCertificate:
  2942. description: The Azure ClientCertificate of the service principle used for authentication.
  2943. properties:
  2944. key:
  2945. description: |-
  2946. A key in the referenced Secret.
  2947. Some instances of this field may be defaulted, in others it may be required.
  2948. maxLength: 253
  2949. minLength: 1
  2950. pattern: ^[-._a-zA-Z0-9]+$
  2951. type: string
  2952. name:
  2953. description: The name of the Secret resource being referred to.
  2954. maxLength: 253
  2955. minLength: 1
  2956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2957. type: string
  2958. namespace:
  2959. description: |-
  2960. The namespace of the Secret resource being referred to.
  2961. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2962. maxLength: 63
  2963. minLength: 1
  2964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2965. type: string
  2966. type: object
  2967. clientId:
  2968. description: The Azure clientId of the service principle or managed identity used for authentication.
  2969. properties:
  2970. key:
  2971. description: |-
  2972. A key in the referenced Secret.
  2973. Some instances of this field may be defaulted, in others it may be required.
  2974. maxLength: 253
  2975. minLength: 1
  2976. pattern: ^[-._a-zA-Z0-9]+$
  2977. type: string
  2978. name:
  2979. description: The name of the Secret resource being referred to.
  2980. maxLength: 253
  2981. minLength: 1
  2982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2983. type: string
  2984. namespace:
  2985. description: |-
  2986. The namespace of the Secret resource being referred to.
  2987. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2988. maxLength: 63
  2989. minLength: 1
  2990. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2991. type: string
  2992. type: object
  2993. clientSecret:
  2994. description: The Azure ClientSecret of the service principle used for authentication.
  2995. properties:
  2996. key:
  2997. description: |-
  2998. A key in the referenced Secret.
  2999. Some instances of this field may be defaulted, in others it may be required.
  3000. maxLength: 253
  3001. minLength: 1
  3002. pattern: ^[-._a-zA-Z0-9]+$
  3003. type: string
  3004. name:
  3005. description: The name of the Secret resource being referred to.
  3006. maxLength: 253
  3007. minLength: 1
  3008. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3009. type: string
  3010. namespace:
  3011. description: |-
  3012. The namespace of the Secret resource being referred to.
  3013. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3014. maxLength: 63
  3015. minLength: 1
  3016. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3017. type: string
  3018. type: object
  3019. tenantId:
  3020. description: The Azure tenantId of the managed identity used for authentication.
  3021. properties:
  3022. key:
  3023. description: |-
  3024. A key in the referenced Secret.
  3025. Some instances of this field may be defaulted, in others it may be required.
  3026. maxLength: 253
  3027. minLength: 1
  3028. pattern: ^[-._a-zA-Z0-9]+$
  3029. type: string
  3030. name:
  3031. description: The name of the Secret resource being referred to.
  3032. maxLength: 253
  3033. minLength: 1
  3034. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3035. type: string
  3036. namespace:
  3037. description: |-
  3038. The namespace of the Secret resource being referred to.
  3039. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3040. maxLength: 63
  3041. minLength: 1
  3042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3043. type: string
  3044. type: object
  3045. type: object
  3046. authType:
  3047. default: ServicePrincipal
  3048. description: |-
  3049. Auth type defines how to authenticate to the keyvault service.
  3050. Valid values are:
  3051. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  3052. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  3053. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  3054. enum:
  3055. - ServicePrincipal
  3056. - ManagedIdentity
  3057. - WorkloadIdentity
  3058. type: string
  3059. customCloudConfig:
  3060. description: |-
  3061. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  3062. Required when EnvironmentType is AzureStackCloud.
  3063. Optional for other environment types - useful for Azure China when using Workload Identity
  3064. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  3065. standard China Cloud endpoint (login.chinacloudapi.cn).
  3066. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  3067. configuration is not supported with the legacy go-autorest SDK.
  3068. properties:
  3069. activeDirectoryEndpoint:
  3070. description: |-
  3071. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  3072. Required when using custom cloud configuration
  3073. type: string
  3074. keyVaultDNSSuffix:
  3075. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  3076. type: string
  3077. keyVaultEndpoint:
  3078. description: KeyVaultEndpoint is the Key Vault service endpoint
  3079. type: string
  3080. resourceManagerEndpoint:
  3081. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  3082. type: string
  3083. required:
  3084. - activeDirectoryEndpoint
  3085. type: object
  3086. environmentType:
  3087. default: PublicCloud
  3088. description: |-
  3089. EnvironmentType specifies the Azure cloud environment endpoints to use for
  3090. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  3091. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  3092. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  3093. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  3094. enum:
  3095. - PublicCloud
  3096. - USGovernmentCloud
  3097. - ChinaCloud
  3098. - GermanCloud
  3099. - AzureStackCloud
  3100. type: string
  3101. identityId:
  3102. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  3103. type: string
  3104. serviceAccountRef:
  3105. description: |-
  3106. ServiceAccountRef specified the service account
  3107. that should be used when authenticating with WorkloadIdentity.
  3108. properties:
  3109. audiences:
  3110. description: |-
  3111. Audience specifies the `aud` claim for the service account token
  3112. Some providers automatically extend the audience field based on well-known annotations for workload
  3113. identity (e.g. IRSA or GCP Workload Identity)
  3114. items:
  3115. type: string
  3116. type: array
  3117. name:
  3118. description: The name of the ServiceAccount resource being referred to.
  3119. maxLength: 253
  3120. minLength: 1
  3121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3122. type: string
  3123. namespace:
  3124. description: |-
  3125. Namespace of the resource being referred to.
  3126. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3127. maxLength: 63
  3128. minLength: 1
  3129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3130. type: string
  3131. required:
  3132. - name
  3133. type: object
  3134. tenantId:
  3135. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  3136. type: string
  3137. useAzureSDK:
  3138. default: false
  3139. description: |-
  3140. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  3141. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  3142. type: boolean
  3143. vaultUrl:
  3144. description: Vault Url from which the secrets to be fetched from.
  3145. type: string
  3146. required:
  3147. - vaultUrl
  3148. type: object
  3149. barbican:
  3150. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  3151. properties:
  3152. auth:
  3153. description: BarbicanAuth contains the authentication information for Barbican.
  3154. properties:
  3155. password:
  3156. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  3157. properties:
  3158. secretRef:
  3159. description: |-
  3160. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3161. In some instances, `key` is a required field.
  3162. properties:
  3163. key:
  3164. description: |-
  3165. A key in the referenced Secret.
  3166. Some instances of this field may be defaulted, in others it may be required.
  3167. maxLength: 253
  3168. minLength: 1
  3169. pattern: ^[-._a-zA-Z0-9]+$
  3170. type: string
  3171. name:
  3172. description: The name of the Secret resource being referred to.
  3173. maxLength: 253
  3174. minLength: 1
  3175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3176. type: string
  3177. namespace:
  3178. description: |-
  3179. The namespace of the Secret resource being referred to.
  3180. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3181. maxLength: 63
  3182. minLength: 1
  3183. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3184. type: string
  3185. type: object
  3186. required:
  3187. - secretRef
  3188. type: object
  3189. username:
  3190. description: BarbicanProviderUsernameRef defines a reference to a secret containing username for the Barbican provider.
  3191. maxProperties: 1
  3192. minProperties: 1
  3193. properties:
  3194. secretRef:
  3195. description: |-
  3196. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3197. In some instances, `key` is a required field.
  3198. properties:
  3199. key:
  3200. description: |-
  3201. A key in the referenced Secret.
  3202. Some instances of this field may be defaulted, in others it may be required.
  3203. maxLength: 253
  3204. minLength: 1
  3205. pattern: ^[-._a-zA-Z0-9]+$
  3206. type: string
  3207. name:
  3208. description: The name of the Secret resource being referred to.
  3209. maxLength: 253
  3210. minLength: 1
  3211. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3212. type: string
  3213. namespace:
  3214. description: |-
  3215. The namespace of the Secret resource being referred to.
  3216. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3217. maxLength: 63
  3218. minLength: 1
  3219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3220. type: string
  3221. type: object
  3222. value:
  3223. type: string
  3224. type: object
  3225. required:
  3226. - password
  3227. - username
  3228. type: object
  3229. authURL:
  3230. type: string
  3231. domainName:
  3232. type: string
  3233. region:
  3234. type: string
  3235. tenantName:
  3236. type: string
  3237. required:
  3238. - auth
  3239. type: object
  3240. beyondtrust:
  3241. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  3242. properties:
  3243. auth:
  3244. description: Auth configures how the operator authenticates with Beyondtrust.
  3245. properties:
  3246. apiKey:
  3247. description: APIKey If not provided then ClientID/ClientSecret become required.
  3248. properties:
  3249. secretRef:
  3250. description: SecretRef references a key in a secret that will be used as value.
  3251. properties:
  3252. key:
  3253. description: |-
  3254. A key in the referenced Secret.
  3255. Some instances of this field may be defaulted, in others it may be required.
  3256. maxLength: 253
  3257. minLength: 1
  3258. pattern: ^[-._a-zA-Z0-9]+$
  3259. type: string
  3260. name:
  3261. description: The name of the Secret resource being referred to.
  3262. maxLength: 253
  3263. minLength: 1
  3264. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3265. type: string
  3266. namespace:
  3267. description: |-
  3268. The namespace of the Secret resource being referred to.
  3269. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3270. maxLength: 63
  3271. minLength: 1
  3272. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3273. type: string
  3274. type: object
  3275. value:
  3276. description: Value can be specified directly to set a value without using a secret.
  3277. type: string
  3278. type: object
  3279. certificate:
  3280. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  3281. properties:
  3282. secretRef:
  3283. description: SecretRef references a key in a secret that will be used as value.
  3284. properties:
  3285. key:
  3286. description: |-
  3287. A key in the referenced Secret.
  3288. Some instances of this field may be defaulted, in others it may be required.
  3289. maxLength: 253
  3290. minLength: 1
  3291. pattern: ^[-._a-zA-Z0-9]+$
  3292. type: string
  3293. name:
  3294. description: The name of the Secret resource being referred to.
  3295. maxLength: 253
  3296. minLength: 1
  3297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3298. type: string
  3299. namespace:
  3300. description: |-
  3301. The namespace of the Secret resource being referred to.
  3302. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3303. maxLength: 63
  3304. minLength: 1
  3305. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3306. type: string
  3307. type: object
  3308. value:
  3309. description: Value can be specified directly to set a value without using a secret.
  3310. type: string
  3311. type: object
  3312. certificateKey:
  3313. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  3314. properties:
  3315. secretRef:
  3316. description: SecretRef references a key in a secret that will be used as value.
  3317. properties:
  3318. key:
  3319. description: |-
  3320. A key in the referenced Secret.
  3321. Some instances of this field may be defaulted, in others it may be required.
  3322. maxLength: 253
  3323. minLength: 1
  3324. pattern: ^[-._a-zA-Z0-9]+$
  3325. type: string
  3326. name:
  3327. description: The name of the Secret resource being referred to.
  3328. maxLength: 253
  3329. minLength: 1
  3330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3331. type: string
  3332. namespace:
  3333. description: |-
  3334. The namespace of the Secret resource being referred to.
  3335. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3336. maxLength: 63
  3337. minLength: 1
  3338. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3339. type: string
  3340. type: object
  3341. value:
  3342. description: Value can be specified directly to set a value without using a secret.
  3343. type: string
  3344. type: object
  3345. clientId:
  3346. description: ClientID is the API OAuth Client ID.
  3347. properties:
  3348. secretRef:
  3349. description: SecretRef references a key in a secret that will be used as value.
  3350. properties:
  3351. key:
  3352. description: |-
  3353. A key in the referenced Secret.
  3354. Some instances of this field may be defaulted, in others it may be required.
  3355. maxLength: 253
  3356. minLength: 1
  3357. pattern: ^[-._a-zA-Z0-9]+$
  3358. type: string
  3359. name:
  3360. description: The name of the Secret resource being referred to.
  3361. maxLength: 253
  3362. minLength: 1
  3363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3364. type: string
  3365. namespace:
  3366. description: |-
  3367. The namespace of the Secret resource being referred to.
  3368. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3369. maxLength: 63
  3370. minLength: 1
  3371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3372. type: string
  3373. type: object
  3374. value:
  3375. description: Value can be specified directly to set a value without using a secret.
  3376. type: string
  3377. type: object
  3378. clientSecret:
  3379. description: ClientSecret is the API OAuth Client Secret.
  3380. properties:
  3381. secretRef:
  3382. description: SecretRef references a key in a secret that will be used as value.
  3383. properties:
  3384. key:
  3385. description: |-
  3386. A key in the referenced Secret.
  3387. Some instances of this field may be defaulted, in others it may be required.
  3388. maxLength: 253
  3389. minLength: 1
  3390. pattern: ^[-._a-zA-Z0-9]+$
  3391. type: string
  3392. name:
  3393. description: The name of the Secret resource being referred to.
  3394. maxLength: 253
  3395. minLength: 1
  3396. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3397. type: string
  3398. namespace:
  3399. description: |-
  3400. The namespace of the Secret resource being referred to.
  3401. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3402. maxLength: 63
  3403. minLength: 1
  3404. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3405. type: string
  3406. type: object
  3407. value:
  3408. description: Value can be specified directly to set a value without using a secret.
  3409. type: string
  3410. type: object
  3411. type: object
  3412. server:
  3413. description: Auth configures how API server works.
  3414. properties:
  3415. apiUrl:
  3416. type: string
  3417. apiVersion:
  3418. type: string
  3419. clientTimeOutSeconds:
  3420. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  3421. type: integer
  3422. decrypt:
  3423. default: true
  3424. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  3425. type: boolean
  3426. retrievalType:
  3427. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  3428. type: string
  3429. separator:
  3430. description: A character that separates the folder names.
  3431. type: string
  3432. verifyCA:
  3433. type: boolean
  3434. required:
  3435. - apiUrl
  3436. - verifyCA
  3437. type: object
  3438. required:
  3439. - auth
  3440. - server
  3441. type: object
  3442. beyondtrustworkloadcredentials:
  3443. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  3444. properties:
  3445. auth:
  3446. description: |-
  3447. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  3448. Currently supports API key authentication via Kubernetes secret reference.
  3449. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3450. properties:
  3451. apikey:
  3452. description: |-
  3453. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  3454. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  3455. properties:
  3456. token:
  3457. description: |-
  3458. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  3459. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  3460. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  3461. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3462. properties:
  3463. key:
  3464. description: |-
  3465. A key in the referenced Secret.
  3466. Some instances of this field may be defaulted, in others it may be required.
  3467. maxLength: 253
  3468. minLength: 1
  3469. pattern: ^[-._a-zA-Z0-9]+$
  3470. type: string
  3471. name:
  3472. description: The name of the Secret resource being referred to.
  3473. maxLength: 253
  3474. minLength: 1
  3475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3476. type: string
  3477. namespace:
  3478. description: |-
  3479. The namespace of the Secret resource being referred to.
  3480. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3481. maxLength: 63
  3482. minLength: 1
  3483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3484. type: string
  3485. type: object
  3486. required:
  3487. - token
  3488. type: object
  3489. required:
  3490. - apikey
  3491. type: object
  3492. caBundle:
  3493. description: |-
  3494. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3495. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  3496. If not set, the system's trusted root certificates are used.
  3497. format: byte
  3498. type: string
  3499. caProvider:
  3500. description: |-
  3501. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  3502. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3503. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  3504. properties:
  3505. key:
  3506. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3507. maxLength: 253
  3508. minLength: 1
  3509. pattern: ^[-._a-zA-Z0-9]+$
  3510. type: string
  3511. name:
  3512. description: The name of the object located at the provider type.
  3513. maxLength: 253
  3514. minLength: 1
  3515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3516. type: string
  3517. namespace:
  3518. description: |-
  3519. The namespace the Provider type is in.
  3520. Can only be defined when used in a ClusterSecretStore.
  3521. maxLength: 63
  3522. minLength: 1
  3523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3524. type: string
  3525. type:
  3526. description: The type of provider to use such as "Secret", or "ConfigMap".
  3527. enum:
  3528. - Secret
  3529. - ConfigMap
  3530. type: string
  3531. required:
  3532. - name
  3533. - type
  3534. type: object
  3535. folderPath:
  3536. description: |-
  3537. FolderPath specifies the default folder path for secret retrieval.
  3538. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  3539. Example: "production/database" or "dev/api-keys"
  3540. Leave empty to retrieve secrets from the root folder.
  3541. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  3542. type: string
  3543. server:
  3544. description: |-
  3545. Server configures the BeyondTrust Workload Credentials server connection details.
  3546. Includes the API URL and Site ID for your BeyondTrust instance.
  3547. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3548. properties:
  3549. apiUrl:
  3550. description: |-
  3551. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  3552. This should be the full URL to your BeyondTrust instance.
  3553. Example: https://api.beyondtrust.io/siie
  3554. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  3555. type: string
  3556. siteId:
  3557. description: |-
  3558. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  3559. This identifier is unique to your BeyondTrust Workload Credentials instance.
  3560. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  3561. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  3562. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3563. type: string
  3564. required:
  3565. - apiUrl
  3566. - siteId
  3567. type: object
  3568. required:
  3569. - auth
  3570. - server
  3571. type: object
  3572. bitwardensecretsmanager:
  3573. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  3574. properties:
  3575. apiURL:
  3576. type: string
  3577. auth:
  3578. description: |-
  3579. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  3580. Make sure that the token being used has permissions on the given secret.
  3581. properties:
  3582. secretRef:
  3583. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  3584. properties:
  3585. credentials:
  3586. description: AccessToken used for the bitwarden instance.
  3587. properties:
  3588. key:
  3589. description: |-
  3590. A key in the referenced Secret.
  3591. Some instances of this field may be defaulted, in others it may be required.
  3592. maxLength: 253
  3593. minLength: 1
  3594. pattern: ^[-._a-zA-Z0-9]+$
  3595. type: string
  3596. name:
  3597. description: The name of the Secret resource being referred to.
  3598. maxLength: 253
  3599. minLength: 1
  3600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3601. type: string
  3602. namespace:
  3603. description: |-
  3604. The namespace of the Secret resource being referred to.
  3605. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3606. maxLength: 63
  3607. minLength: 1
  3608. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3609. type: string
  3610. type: object
  3611. required:
  3612. - credentials
  3613. type: object
  3614. required:
  3615. - secretRef
  3616. type: object
  3617. bitwardenServerSDKURL:
  3618. type: string
  3619. caBundle:
  3620. description: |-
  3621. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  3622. can be performed.
  3623. type: string
  3624. caProvider:
  3625. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  3626. properties:
  3627. key:
  3628. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3629. maxLength: 253
  3630. minLength: 1
  3631. pattern: ^[-._a-zA-Z0-9]+$
  3632. type: string
  3633. name:
  3634. description: The name of the object located at the provider type.
  3635. maxLength: 253
  3636. minLength: 1
  3637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3638. type: string
  3639. namespace:
  3640. description: |-
  3641. The namespace the Provider type is in.
  3642. Can only be defined when used in a ClusterSecretStore.
  3643. maxLength: 63
  3644. minLength: 1
  3645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3646. type: string
  3647. type:
  3648. description: The type of provider to use such as "Secret", or "ConfigMap".
  3649. enum:
  3650. - Secret
  3651. - ConfigMap
  3652. type: string
  3653. required:
  3654. - name
  3655. - type
  3656. type: object
  3657. identityURL:
  3658. type: string
  3659. organizationID:
  3660. description: OrganizationID determines which organization this secret store manages.
  3661. type: string
  3662. projectID:
  3663. description: ProjectID determines which project this secret store manages.
  3664. type: string
  3665. required:
  3666. - auth
  3667. - organizationID
  3668. - projectID
  3669. type: object
  3670. chef:
  3671. description: Chef configures this store to sync secrets with chef server
  3672. properties:
  3673. auth:
  3674. description: Auth defines the information necessary to authenticate against chef Server
  3675. properties:
  3676. secretRef:
  3677. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  3678. properties:
  3679. privateKeySecretRef:
  3680. description: SecretKey is the Signing Key in PEM format, used for authentication.
  3681. properties:
  3682. key:
  3683. description: |-
  3684. A key in the referenced Secret.
  3685. Some instances of this field may be defaulted, in others it may be required.
  3686. maxLength: 253
  3687. minLength: 1
  3688. pattern: ^[-._a-zA-Z0-9]+$
  3689. type: string
  3690. name:
  3691. description: The name of the Secret resource being referred to.
  3692. maxLength: 253
  3693. minLength: 1
  3694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3695. type: string
  3696. namespace:
  3697. description: |-
  3698. The namespace of the Secret resource being referred to.
  3699. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3700. maxLength: 63
  3701. minLength: 1
  3702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3703. type: string
  3704. type: object
  3705. required:
  3706. - privateKeySecretRef
  3707. type: object
  3708. required:
  3709. - secretRef
  3710. type: object
  3711. serverUrl:
  3712. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  3713. type: string
  3714. username:
  3715. description: UserName should be the user ID on the chef server
  3716. type: string
  3717. required:
  3718. - auth
  3719. - serverUrl
  3720. - username
  3721. type: object
  3722. cloudrusm:
  3723. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  3724. properties:
  3725. auth:
  3726. description: CSMAuth contains a secretRef for credentials.
  3727. properties:
  3728. secretRef:
  3729. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  3730. properties:
  3731. accessKeyIDSecretRef:
  3732. description: The AccessKeyID is used for authentication
  3733. properties:
  3734. key:
  3735. description: |-
  3736. A key in the referenced Secret.
  3737. Some instances of this field may be defaulted, in others it may be required.
  3738. maxLength: 253
  3739. minLength: 1
  3740. pattern: ^[-._a-zA-Z0-9]+$
  3741. type: string
  3742. name:
  3743. description: The name of the Secret resource being referred to.
  3744. maxLength: 253
  3745. minLength: 1
  3746. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3747. type: string
  3748. namespace:
  3749. description: |-
  3750. The namespace of the Secret resource being referred to.
  3751. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3752. maxLength: 63
  3753. minLength: 1
  3754. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3755. type: string
  3756. type: object
  3757. accessKeySecretSecretRef:
  3758. description: The AccessKeySecret is used for authentication
  3759. properties:
  3760. key:
  3761. description: |-
  3762. A key in the referenced Secret.
  3763. Some instances of this field may be defaulted, in others it may be required.
  3764. maxLength: 253
  3765. minLength: 1
  3766. pattern: ^[-._a-zA-Z0-9]+$
  3767. type: string
  3768. name:
  3769. description: The name of the Secret resource being referred to.
  3770. maxLength: 253
  3771. minLength: 1
  3772. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3773. type: string
  3774. namespace:
  3775. description: |-
  3776. The namespace of the Secret resource being referred to.
  3777. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3778. maxLength: 63
  3779. minLength: 1
  3780. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3781. type: string
  3782. type: object
  3783. required:
  3784. - accessKeyIDSecretRef
  3785. - accessKeySecretSecretRef
  3786. type: object
  3787. type: object
  3788. projectID:
  3789. description: ProjectID is the project, which the secrets are stored in.
  3790. type: string
  3791. required:
  3792. - auth
  3793. type: object
  3794. conjur:
  3795. description: Conjur configures this store to sync secrets using conjur provider
  3796. properties:
  3797. auth:
  3798. description: Defines authentication settings for connecting to Conjur.
  3799. maxProperties: 1
  3800. minProperties: 1
  3801. properties:
  3802. apikey:
  3803. description: Authenticates with Conjur using an API key.
  3804. properties:
  3805. account:
  3806. description: Account is the Conjur organization account name.
  3807. type: string
  3808. apiKeyRef:
  3809. description: |-
  3810. A reference to a specific 'key' containing the Conjur API key
  3811. within a Secret resource. In some instances, `key` is a required field.
  3812. properties:
  3813. key:
  3814. description: |-
  3815. A key in the referenced Secret.
  3816. Some instances of this field may be defaulted, in others it may be required.
  3817. maxLength: 253
  3818. minLength: 1
  3819. pattern: ^[-._a-zA-Z0-9]+$
  3820. type: string
  3821. name:
  3822. description: The name of the Secret resource being referred to.
  3823. maxLength: 253
  3824. minLength: 1
  3825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3826. type: string
  3827. namespace:
  3828. description: |-
  3829. The namespace of the Secret resource being referred to.
  3830. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3831. maxLength: 63
  3832. minLength: 1
  3833. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3834. type: string
  3835. type: object
  3836. userRef:
  3837. description: |-
  3838. A reference to a specific 'key' containing the Conjur username
  3839. within a Secret resource. In some instances, `key` is a required field.
  3840. properties:
  3841. key:
  3842. description: |-
  3843. A key in the referenced Secret.
  3844. Some instances of this field may be defaulted, in others it may be required.
  3845. maxLength: 253
  3846. minLength: 1
  3847. pattern: ^[-._a-zA-Z0-9]+$
  3848. type: string
  3849. name:
  3850. description: The name of the Secret resource being referred to.
  3851. maxLength: 253
  3852. minLength: 1
  3853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3854. type: string
  3855. namespace:
  3856. description: |-
  3857. The namespace of the Secret resource being referred to.
  3858. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3859. maxLength: 63
  3860. minLength: 1
  3861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3862. type: string
  3863. type: object
  3864. required:
  3865. - account
  3866. - apiKeyRef
  3867. - userRef
  3868. type: object
  3869. cert:
  3870. description: Cert enables certificate-based authentication using a client certificate and key.
  3871. properties:
  3872. account:
  3873. description: Account is the Conjur organization account name.
  3874. type: string
  3875. clientCertRef:
  3876. description: |-
  3877. ClientCertRef is a reference to a specific 'key' containing the client certificate
  3878. within a Secret resource. The certificate must be PEM-encoded.
  3879. properties:
  3880. key:
  3881. description: |-
  3882. A key in the referenced Secret.
  3883. Some instances of this field may be defaulted, in others it may be required.
  3884. maxLength: 253
  3885. minLength: 1
  3886. pattern: ^[-._a-zA-Z0-9]+$
  3887. type: string
  3888. name:
  3889. description: The name of the Secret resource being referred to.
  3890. maxLength: 253
  3891. minLength: 1
  3892. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3893. type: string
  3894. namespace:
  3895. description: |-
  3896. The namespace of the Secret resource being referred to.
  3897. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3898. maxLength: 63
  3899. minLength: 1
  3900. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3901. type: string
  3902. type: object
  3903. clientKeyRef:
  3904. description: |-
  3905. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  3906. within a Secret resource. The key must be PEM-encoded.
  3907. properties:
  3908. key:
  3909. description: |-
  3910. A key in the referenced Secret.
  3911. Some instances of this field may be defaulted, in others it may be required.
  3912. maxLength: 253
  3913. minLength: 1
  3914. pattern: ^[-._a-zA-Z0-9]+$
  3915. type: string
  3916. name:
  3917. description: The name of the Secret resource being referred to.
  3918. maxLength: 253
  3919. minLength: 1
  3920. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3921. type: string
  3922. namespace:
  3923. description: |-
  3924. The namespace of the Secret resource being referred to.
  3925. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3926. maxLength: 63
  3927. minLength: 1
  3928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3929. type: string
  3930. type: object
  3931. hostId:
  3932. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  3933. type: string
  3934. serviceID:
  3935. description: The conjur authn cert webservice id
  3936. type: string
  3937. required:
  3938. - account
  3939. - clientCertRef
  3940. - clientKeyRef
  3941. - serviceID
  3942. type: object
  3943. jwt:
  3944. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  3945. properties:
  3946. account:
  3947. description: Account is the Conjur organization account name.
  3948. type: string
  3949. hostId:
  3950. description: |-
  3951. Optional HostID for JWT authentication. This may be used depending
  3952. on how the Conjur JWT authenticator policy is configured.
  3953. type: string
  3954. secretRef:
  3955. description: |-
  3956. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  3957. authenticate with Conjur using the JWT authentication method.
  3958. properties:
  3959. key:
  3960. description: |-
  3961. A key in the referenced Secret.
  3962. Some instances of this field may be defaulted, in others it may be required.
  3963. maxLength: 253
  3964. minLength: 1
  3965. pattern: ^[-._a-zA-Z0-9]+$
  3966. type: string
  3967. name:
  3968. description: The name of the Secret resource being referred to.
  3969. maxLength: 253
  3970. minLength: 1
  3971. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3972. type: string
  3973. namespace:
  3974. description: |-
  3975. The namespace of the Secret resource being referred to.
  3976. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3977. maxLength: 63
  3978. minLength: 1
  3979. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3980. type: string
  3981. type: object
  3982. serviceAccountRef:
  3983. description: |-
  3984. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  3985. a token for with the `TokenRequest` API.
  3986. properties:
  3987. audiences:
  3988. description: |-
  3989. Audience specifies the `aud` claim for the service account token
  3990. Some providers automatically extend the audience field based on well-known annotations for workload
  3991. identity (e.g. IRSA or GCP Workload Identity)
  3992. items:
  3993. type: string
  3994. type: array
  3995. name:
  3996. description: The name of the ServiceAccount resource being referred to.
  3997. maxLength: 253
  3998. minLength: 1
  3999. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4000. type: string
  4001. namespace:
  4002. description: |-
  4003. Namespace of the resource being referred to.
  4004. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4005. maxLength: 63
  4006. minLength: 1
  4007. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4008. type: string
  4009. required:
  4010. - name
  4011. type: object
  4012. serviceID:
  4013. description: The conjur authn jwt webservice id
  4014. type: string
  4015. required:
  4016. - account
  4017. - serviceID
  4018. type: object
  4019. type: object
  4020. caBundle:
  4021. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  4022. type: string
  4023. caProvider:
  4024. description: |-
  4025. Used to provide custom certificate authority (CA) certificates
  4026. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  4027. that contains a PEM-encoded certificate.
  4028. properties:
  4029. key:
  4030. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4031. maxLength: 253
  4032. minLength: 1
  4033. pattern: ^[-._a-zA-Z0-9]+$
  4034. type: string
  4035. name:
  4036. description: The name of the object located at the provider type.
  4037. maxLength: 253
  4038. minLength: 1
  4039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4040. type: string
  4041. namespace:
  4042. description: |-
  4043. The namespace the Provider type is in.
  4044. Can only be defined when used in a ClusterSecretStore.
  4045. maxLength: 63
  4046. minLength: 1
  4047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4048. type: string
  4049. type:
  4050. description: The type of provider to use such as "Secret", or "ConfigMap".
  4051. enum:
  4052. - Secret
  4053. - ConfigMap
  4054. type: string
  4055. required:
  4056. - name
  4057. - type
  4058. type: object
  4059. url:
  4060. description: URL is the endpoint of the Conjur instance.
  4061. type: string
  4062. required:
  4063. - auth
  4064. - url
  4065. type: object
  4066. crd:
  4067. description: |-
  4068. CRD configures this store to sync secrets from arbitrary Kubernetes resources,
  4069. including both custom resources (CRDs) and core API resources. Resources are
  4070. selected by API group, version and kind, where group can be "" (empty string)
  4071. for core resources such as ConfigMap. Reading the core v1 Secret is
  4072. intentionally blocked — use the Kubernetes provider for that.
  4073. properties:
  4074. auth:
  4075. description: |-
  4076. Auth configures authentication to the Kubernetes API, same as the
  4077. Kubernetes provider. Required when Server.URL is set (unless using AuthRef).
  4078. maxProperties: 1
  4079. minProperties: 1
  4080. properties:
  4081. cert:
  4082. description: has both clientCert and clientKey as secretKeySelector
  4083. properties:
  4084. clientCert:
  4085. description: |-
  4086. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4087. In some instances, `key` is a required field.
  4088. properties:
  4089. key:
  4090. description: |-
  4091. A key in the referenced Secret.
  4092. Some instances of this field may be defaulted, in others it may be required.
  4093. maxLength: 253
  4094. minLength: 1
  4095. pattern: ^[-._a-zA-Z0-9]+$
  4096. type: string
  4097. name:
  4098. description: The name of the Secret resource being referred to.
  4099. maxLength: 253
  4100. minLength: 1
  4101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4102. type: string
  4103. namespace:
  4104. description: |-
  4105. The namespace of the Secret resource being referred to.
  4106. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4107. maxLength: 63
  4108. minLength: 1
  4109. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4110. type: string
  4111. type: object
  4112. clientKey:
  4113. description: |-
  4114. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4115. In some instances, `key` is a required field.
  4116. properties:
  4117. key:
  4118. description: |-
  4119. A key in the referenced Secret.
  4120. Some instances of this field may be defaulted, in others it may be required.
  4121. maxLength: 253
  4122. minLength: 1
  4123. pattern: ^[-._a-zA-Z0-9]+$
  4124. type: string
  4125. name:
  4126. description: The name of the Secret resource being referred to.
  4127. maxLength: 253
  4128. minLength: 1
  4129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4130. type: string
  4131. namespace:
  4132. description: |-
  4133. The namespace of the Secret resource being referred to.
  4134. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4135. maxLength: 63
  4136. minLength: 1
  4137. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4138. type: string
  4139. type: object
  4140. required:
  4141. - clientCert
  4142. - clientKey
  4143. type: object
  4144. serviceAccount:
  4145. description: points to a service account that should be used for authentication
  4146. properties:
  4147. audiences:
  4148. description: |-
  4149. Audience specifies the `aud` claim for the service account token
  4150. Some providers automatically extend the audience field based on well-known annotations for workload
  4151. identity (e.g. IRSA or GCP Workload Identity)
  4152. items:
  4153. type: string
  4154. type: array
  4155. name:
  4156. description: The name of the ServiceAccount resource being referred to.
  4157. maxLength: 253
  4158. minLength: 1
  4159. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4160. type: string
  4161. namespace:
  4162. description: |-
  4163. Namespace of the resource being referred to.
  4164. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4165. maxLength: 63
  4166. minLength: 1
  4167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4168. type: string
  4169. required:
  4170. - name
  4171. type: object
  4172. token:
  4173. description: use static token to authenticate with
  4174. properties:
  4175. bearerToken:
  4176. description: |-
  4177. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4178. In some instances, `key` is a required field.
  4179. properties:
  4180. key:
  4181. description: |-
  4182. A key in the referenced Secret.
  4183. Some instances of this field may be defaulted, in others it may be required.
  4184. maxLength: 253
  4185. minLength: 1
  4186. pattern: ^[-._a-zA-Z0-9]+$
  4187. type: string
  4188. name:
  4189. description: The name of the Secret resource being referred to.
  4190. maxLength: 253
  4191. minLength: 1
  4192. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4193. type: string
  4194. namespace:
  4195. description: |-
  4196. The namespace of the Secret resource being referred to.
  4197. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4198. maxLength: 63
  4199. minLength: 1
  4200. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4201. type: string
  4202. type: object
  4203. required:
  4204. - bearerToken
  4205. type: object
  4206. type: object
  4207. authRef:
  4208. description: |-
  4209. AuthRef references a Secret containing a kubeconfig. Same semantics as the
  4210. Kubernetes provider.
  4211. properties:
  4212. key:
  4213. description: |-
  4214. A key in the referenced Secret.
  4215. Some instances of this field may be defaulted, in others it may be required.
  4216. maxLength: 253
  4217. minLength: 1
  4218. pattern: ^[-._a-zA-Z0-9]+$
  4219. type: string
  4220. name:
  4221. description: The name of the Secret resource being referred to.
  4222. maxLength: 253
  4223. minLength: 1
  4224. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4225. type: string
  4226. namespace:
  4227. description: |-
  4228. The namespace of the Secret resource being referred to.
  4229. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4230. maxLength: 63
  4231. minLength: 1
  4232. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4233. type: string
  4234. type: object
  4235. resource:
  4236. description: Resource identifies the CRD by its API group, version and kind.
  4237. properties:
  4238. group:
  4239. description: |-
  4240. Group is the API group of the resource. Use "" (empty string) for core
  4241. Kubernetes resources such as ConfigMap; use e.g. "config.example.io"
  4242. for a CRD. The field is required to be present in the manifest — write
  4243. `group: ""` explicitly for core resources so typos fail at admission
  4244. time rather than later at discovery.
  4245. type: string
  4246. kind:
  4247. description: Kind is the Kubernetes resource kind (e.g. "MyCustomResource").
  4248. minLength: 1
  4249. type: string
  4250. version:
  4251. description: Version is the API version of the resource (e.g. "v1alpha1").
  4252. minLength: 1
  4253. type: string
  4254. required:
  4255. - group
  4256. - kind
  4257. - version
  4258. type: object
  4259. server:
  4260. description: |-
  4261. Server configures the Kubernetes API address and TLS trust, same as the
  4262. Kubernetes provider. When omitted, the URL defaults to the in-cluster API.
  4263. properties:
  4264. caBundle:
  4265. description: CABundle is a base64-encoded CA certificate
  4266. format: byte
  4267. type: string
  4268. caProvider:
  4269. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  4270. properties:
  4271. key:
  4272. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4273. maxLength: 253
  4274. minLength: 1
  4275. pattern: ^[-._a-zA-Z0-9]+$
  4276. type: string
  4277. name:
  4278. description: The name of the object located at the provider type.
  4279. maxLength: 253
  4280. minLength: 1
  4281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4282. type: string
  4283. namespace:
  4284. description: |-
  4285. The namespace the Provider type is in.
  4286. Can only be defined when used in a ClusterSecretStore.
  4287. maxLength: 63
  4288. minLength: 1
  4289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4290. type: string
  4291. type:
  4292. description: The type of provider to use such as "Secret", or "ConfigMap".
  4293. enum:
  4294. - Secret
  4295. - ConfigMap
  4296. type: string
  4297. required:
  4298. - name
  4299. - type
  4300. type: object
  4301. url:
  4302. default: kubernetes.default
  4303. description: configures the Kubernetes server Address.
  4304. type: string
  4305. type: object
  4306. whitelist:
  4307. description: |-
  4308. Whitelist optionally restricts which object names and requested properties
  4309. are allowed to be read.
  4310. properties:
  4311. rules:
  4312. description: |-
  4313. Rules is a list of allow rules. If rules are set, at least one rule must
  4314. match for a request to be allowed.
  4315. items:
  4316. description: CRDProviderWhitelistRule defines a single allow rule for CRD reads.
  4317. properties:
  4318. name:
  4319. description: |-
  4320. Name is an optional regular expression matched against the bare object name.
  4321. For both SecretStore and ClusterSecretStore this is always the object name
  4322. without any namespace prefix (e.g. "my-db-spec", not "prod/my-db-spec").
  4323. type: string
  4324. namespace:
  4325. description: |-
  4326. Namespace is an optional regular expression matched against the namespace of
  4327. the object. Applies only when a ClusterSecretStore is used; it is ignored
  4328. for SecretStore (where the namespace is fixed to the store namespace).
  4329. type: string
  4330. properties:
  4331. description: |-
  4332. Properties is an optional list of regular expressions matched against
  4333. requested property keys (for example: "spec.secretValue").
  4334. items:
  4335. type: string
  4336. type: array
  4337. type: object
  4338. type: array
  4339. type: object
  4340. required:
  4341. - resource
  4342. type: object
  4343. x-kubernetes-validations:
  4344. - message: one of auth or authRef is required
  4345. rule: has(self.auth) || has(self.authRef)
  4346. - message: at most one of the fields in [auth authRef] may be set
  4347. rule: '[has(self.auth),has(self.authRef)].filter(x,x==true).size() <= 1'
  4348. delinea:
  4349. description: |-
  4350. Delinea DevOps Secrets Vault
  4351. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  4352. properties:
  4353. clientId:
  4354. description: ClientID is the non-secret part of the credential.
  4355. properties:
  4356. secretRef:
  4357. description: SecretRef references a key in a secret that will be used as value.
  4358. properties:
  4359. key:
  4360. description: |-
  4361. A key in the referenced Secret.
  4362. Some instances of this field may be defaulted, in others it may be required.
  4363. maxLength: 253
  4364. minLength: 1
  4365. pattern: ^[-._a-zA-Z0-9]+$
  4366. type: string
  4367. name:
  4368. description: The name of the Secret resource being referred to.
  4369. maxLength: 253
  4370. minLength: 1
  4371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4372. type: string
  4373. namespace:
  4374. description: |-
  4375. The namespace of the Secret resource being referred to.
  4376. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4377. maxLength: 63
  4378. minLength: 1
  4379. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4380. type: string
  4381. type: object
  4382. value:
  4383. description: Value can be specified directly to set a value without using a secret.
  4384. type: string
  4385. type: object
  4386. clientSecret:
  4387. description: ClientSecret is the secret part of the credential.
  4388. properties:
  4389. secretRef:
  4390. description: SecretRef references a key in a secret that will be used as value.
  4391. properties:
  4392. key:
  4393. description: |-
  4394. A key in the referenced Secret.
  4395. Some instances of this field may be defaulted, in others it may be required.
  4396. maxLength: 253
  4397. minLength: 1
  4398. pattern: ^[-._a-zA-Z0-9]+$
  4399. type: string
  4400. name:
  4401. description: The name of the Secret resource being referred to.
  4402. maxLength: 253
  4403. minLength: 1
  4404. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4405. type: string
  4406. namespace:
  4407. description: |-
  4408. The namespace of the Secret resource being referred to.
  4409. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4410. maxLength: 63
  4411. minLength: 1
  4412. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4413. type: string
  4414. type: object
  4415. value:
  4416. description: Value can be specified directly to set a value without using a secret.
  4417. type: string
  4418. type: object
  4419. tenant:
  4420. description: Tenant is the chosen hostname / site name.
  4421. type: string
  4422. tld:
  4423. description: |-
  4424. TLD is based on the server location that was chosen during provisioning.
  4425. If unset, defaults to "com".
  4426. type: string
  4427. urlTemplate:
  4428. description: |-
  4429. URLTemplate
  4430. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  4431. type: string
  4432. required:
  4433. - clientId
  4434. - clientSecret
  4435. - tenant
  4436. type: object
  4437. doppler:
  4438. description: Doppler configures this store to sync secrets using the Doppler provider
  4439. properties:
  4440. auth:
  4441. description: Auth configures how the Operator authenticates with the Doppler API
  4442. properties:
  4443. oidcConfig:
  4444. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  4445. properties:
  4446. expirationSeconds:
  4447. default: 600
  4448. description: |-
  4449. ExpirationSeconds sets the ServiceAccount token validity duration.
  4450. Defaults to 10 minutes.
  4451. format: int64
  4452. type: integer
  4453. identity:
  4454. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  4455. type: string
  4456. serviceAccountRef:
  4457. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  4458. properties:
  4459. audiences:
  4460. description: |-
  4461. Audience specifies the `aud` claim for the service account token
  4462. Some providers automatically extend the audience field based on well-known annotations for workload
  4463. identity (e.g. IRSA or GCP Workload Identity)
  4464. items:
  4465. type: string
  4466. type: array
  4467. name:
  4468. description: The name of the ServiceAccount resource being referred to.
  4469. maxLength: 253
  4470. minLength: 1
  4471. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4472. type: string
  4473. namespace:
  4474. description: |-
  4475. Namespace of the resource being referred to.
  4476. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4477. maxLength: 63
  4478. minLength: 1
  4479. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4480. type: string
  4481. required:
  4482. - name
  4483. type: object
  4484. required:
  4485. - identity
  4486. - serviceAccountRef
  4487. type: object
  4488. secretRef:
  4489. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  4490. properties:
  4491. dopplerToken:
  4492. description: |-
  4493. The DopplerToken is used for authentication.
  4494. See https://docs.doppler.com/reference/api#authentication for auth token types.
  4495. The Key attribute defaults to dopplerToken if not specified.
  4496. properties:
  4497. key:
  4498. description: |-
  4499. A key in the referenced Secret.
  4500. Some instances of this field may be defaulted, in others it may be required.
  4501. maxLength: 253
  4502. minLength: 1
  4503. pattern: ^[-._a-zA-Z0-9]+$
  4504. type: string
  4505. name:
  4506. description: The name of the Secret resource being referred to.
  4507. maxLength: 253
  4508. minLength: 1
  4509. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4510. type: string
  4511. namespace:
  4512. description: |-
  4513. The namespace of the Secret resource being referred to.
  4514. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4515. maxLength: 63
  4516. minLength: 1
  4517. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4518. type: string
  4519. type: object
  4520. required:
  4521. - dopplerToken
  4522. type: object
  4523. type: object
  4524. x-kubernetes-validations:
  4525. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  4526. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  4527. config:
  4528. description: Doppler config (required if not using a Service Token)
  4529. type: string
  4530. format:
  4531. description: Format enables the downloading of secrets as a file (string)
  4532. enum:
  4533. - json
  4534. - dotnet-json
  4535. - env
  4536. - yaml
  4537. - docker
  4538. type: string
  4539. nameTransformer:
  4540. description: Environment variable compatible name transforms that change secret names to a different format
  4541. enum:
  4542. - upper-camel
  4543. - camel
  4544. - lower-snake
  4545. - tf-var
  4546. - dotnet-env
  4547. - lower-kebab
  4548. type: string
  4549. project:
  4550. description: Doppler project (required if not using a Service Token)
  4551. type: string
  4552. required:
  4553. - auth
  4554. type: object
  4555. dvls:
  4556. description: DVLS configures this store to sync secrets using Devolutions Server provider
  4557. properties:
  4558. auth:
  4559. description: Auth defines the authentication method to use.
  4560. properties:
  4561. secretRef:
  4562. description: SecretRef contains the Application ID and Application Secret for authentication.
  4563. properties:
  4564. appId:
  4565. description: AppID is the reference to the secret containing the Application ID.
  4566. properties:
  4567. key:
  4568. description: |-
  4569. A key in the referenced Secret.
  4570. Some instances of this field may be defaulted, in others it may be required.
  4571. maxLength: 253
  4572. minLength: 1
  4573. pattern: ^[-._a-zA-Z0-9]+$
  4574. type: string
  4575. name:
  4576. description: The name of the Secret resource being referred to.
  4577. maxLength: 253
  4578. minLength: 1
  4579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4580. type: string
  4581. namespace:
  4582. description: |-
  4583. The namespace of the Secret resource being referred to.
  4584. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4585. maxLength: 63
  4586. minLength: 1
  4587. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4588. type: string
  4589. type: object
  4590. appSecret:
  4591. description: AppSecret is the reference to the secret containing the Application Secret.
  4592. properties:
  4593. key:
  4594. description: |-
  4595. A key in the referenced Secret.
  4596. Some instances of this field may be defaulted, in others it may be required.
  4597. maxLength: 253
  4598. minLength: 1
  4599. pattern: ^[-._a-zA-Z0-9]+$
  4600. type: string
  4601. name:
  4602. description: The name of the Secret resource being referred to.
  4603. maxLength: 253
  4604. minLength: 1
  4605. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4606. type: string
  4607. namespace:
  4608. description: |-
  4609. The namespace of the Secret resource being referred to.
  4610. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4611. maxLength: 63
  4612. minLength: 1
  4613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4614. type: string
  4615. type: object
  4616. required:
  4617. - appId
  4618. - appSecret
  4619. type: object
  4620. required:
  4621. - secretRef
  4622. type: object
  4623. insecure:
  4624. description: |-
  4625. Insecure allows connecting to DVLS over plain HTTP.
  4626. This is NOT RECOMMENDED for production use.
  4627. Set to true only if you understand the security implications.
  4628. type: boolean
  4629. serverUrl:
  4630. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  4631. type: string
  4632. vault:
  4633. description: |-
  4634. Vault is the name or UUID of the vault to fetch secrets from.
  4635. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  4636. type: string
  4637. required:
  4638. - auth
  4639. - serverUrl
  4640. type: object
  4641. fake:
  4642. description: Fake configures a store with static key/value pairs
  4643. properties:
  4644. data:
  4645. items:
  4646. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  4647. properties:
  4648. key:
  4649. type: string
  4650. value:
  4651. type: string
  4652. version:
  4653. type: string
  4654. required:
  4655. - key
  4656. - value
  4657. type: object
  4658. type: array
  4659. validationResult:
  4660. description: ValidationResult is defined type for the number of validation results.
  4661. type: integer
  4662. required:
  4663. - data
  4664. type: object
  4665. fortanix:
  4666. description: Fortanix configures this store to sync secrets using the Fortanix provider
  4667. properties:
  4668. apiKey:
  4669. description: APIKey is the API token to access SDKMS Applications.
  4670. properties:
  4671. secretRef:
  4672. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  4673. properties:
  4674. key:
  4675. description: |-
  4676. A key in the referenced Secret.
  4677. Some instances of this field may be defaulted, in others it may be required.
  4678. maxLength: 253
  4679. minLength: 1
  4680. pattern: ^[-._a-zA-Z0-9]+$
  4681. type: string
  4682. name:
  4683. description: The name of the Secret resource being referred to.
  4684. maxLength: 253
  4685. minLength: 1
  4686. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4687. type: string
  4688. namespace:
  4689. description: |-
  4690. The namespace of the Secret resource being referred to.
  4691. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4692. maxLength: 63
  4693. minLength: 1
  4694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4695. type: string
  4696. type: object
  4697. type: object
  4698. apiUrl:
  4699. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  4700. type: string
  4701. type: object
  4702. gcpsm:
  4703. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  4704. properties:
  4705. auth:
  4706. description: Auth defines the information necessary to authenticate against GCP
  4707. properties:
  4708. secretRef:
  4709. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  4710. properties:
  4711. secretAccessKeySecretRef:
  4712. description: The SecretAccessKey is used for authentication
  4713. properties:
  4714. key:
  4715. description: |-
  4716. A key in the referenced Secret.
  4717. Some instances of this field may be defaulted, in others it may be required.
  4718. maxLength: 253
  4719. minLength: 1
  4720. pattern: ^[-._a-zA-Z0-9]+$
  4721. type: string
  4722. name:
  4723. description: The name of the Secret resource being referred to.
  4724. maxLength: 253
  4725. minLength: 1
  4726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4727. type: string
  4728. namespace:
  4729. description: |-
  4730. The namespace of the Secret resource being referred to.
  4731. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4732. maxLength: 63
  4733. minLength: 1
  4734. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4735. type: string
  4736. type: object
  4737. type: object
  4738. workloadIdentity:
  4739. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  4740. properties:
  4741. clusterLocation:
  4742. description: |-
  4743. ClusterLocation is the location of the cluster
  4744. If not specified, it fetches information from the metadata server
  4745. type: string
  4746. clusterName:
  4747. description: |-
  4748. ClusterName is the name of the cluster
  4749. If not specified, it fetches information from the metadata server
  4750. type: string
  4751. clusterProjectID:
  4752. description: |-
  4753. ClusterProjectID is the project ID of the cluster
  4754. If not specified, it fetches information from the metadata server
  4755. type: string
  4756. serviceAccountRef:
  4757. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  4758. properties:
  4759. audiences:
  4760. description: |-
  4761. Audience specifies the `aud` claim for the service account token
  4762. Some providers automatically extend the audience field based on well-known annotations for workload
  4763. identity (e.g. IRSA or GCP Workload Identity)
  4764. items:
  4765. type: string
  4766. type: array
  4767. name:
  4768. description: The name of the ServiceAccount resource being referred to.
  4769. maxLength: 253
  4770. minLength: 1
  4771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4772. type: string
  4773. namespace:
  4774. description: |-
  4775. Namespace of the resource being referred to.
  4776. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4777. maxLength: 63
  4778. minLength: 1
  4779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4780. type: string
  4781. required:
  4782. - name
  4783. type: object
  4784. required:
  4785. - serviceAccountRef
  4786. type: object
  4787. workloadIdentityFederation:
  4788. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  4789. properties:
  4790. audience:
  4791. description: |-
  4792. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  4793. If specified, Audience found in the external account credential config will be overridden with the configured value.
  4794. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  4795. type: string
  4796. awsSecurityCredentials:
  4797. description: |-
  4798. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  4799. when using the AWS metadata server is not an option.
  4800. properties:
  4801. awsCredentialsSecretRef:
  4802. description: |-
  4803. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  4804. Secret should be created with below names for keys
  4805. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  4806. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  4807. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  4808. properties:
  4809. name:
  4810. description: name of the secret.
  4811. maxLength: 253
  4812. minLength: 1
  4813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4814. type: string
  4815. namespace:
  4816. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  4817. maxLength: 63
  4818. minLength: 1
  4819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4820. type: string
  4821. required:
  4822. - name
  4823. type: object
  4824. region:
  4825. description: region is for configuring the AWS region to be used.
  4826. example: ap-south-1
  4827. maxLength: 50
  4828. minLength: 1
  4829. pattern: ^[a-z0-9-]+$
  4830. type: string
  4831. required:
  4832. - awsCredentialsSecretRef
  4833. - region
  4834. type: object
  4835. credConfig:
  4836. description: |-
  4837. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  4838. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  4839. serviceAccountRef must be used by providing operators service account details.
  4840. properties:
  4841. key:
  4842. description: key name holding the external account credential config.
  4843. maxLength: 253
  4844. minLength: 1
  4845. pattern: ^[-._a-zA-Z0-9]+$
  4846. type: string
  4847. name:
  4848. description: name of the configmap.
  4849. maxLength: 253
  4850. minLength: 1
  4851. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4852. type: string
  4853. namespace:
  4854. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  4855. maxLength: 63
  4856. minLength: 1
  4857. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4858. type: string
  4859. required:
  4860. - key
  4861. - name
  4862. type: object
  4863. externalTokenEndpoint:
  4864. description: |-
  4865. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  4866. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  4867. URL is having the expected value.
  4868. type: string
  4869. gcpServiceAccountEmail:
  4870. description: |-
  4871. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  4872. after Workload Identity Federation. Use this to grant access through the service account's
  4873. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  4874. service_account_impersonation_url in the external account JSON from credConfig;
  4875. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  4876. on that ServiceAccount.
  4877. example: my-gsa@my-project.iam.gserviceaccount.com
  4878. minLength: 1
  4879. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  4880. type: string
  4881. serviceAccountRef:
  4882. description: |-
  4883. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  4884. when Kubernetes is configured as provider in workload identity pool.
  4885. properties:
  4886. audiences:
  4887. description: |-
  4888. Audience specifies the `aud` claim for the service account token
  4889. Some providers automatically extend the audience field based on well-known annotations for workload
  4890. identity (e.g. IRSA or GCP Workload Identity)
  4891. items:
  4892. type: string
  4893. type: array
  4894. name:
  4895. description: The name of the ServiceAccount resource being referred to.
  4896. maxLength: 253
  4897. minLength: 1
  4898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4899. type: string
  4900. namespace:
  4901. description: |-
  4902. Namespace of the resource being referred to.
  4903. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4904. maxLength: 63
  4905. minLength: 1
  4906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4907. type: string
  4908. required:
  4909. - name
  4910. type: object
  4911. type: object
  4912. type: object
  4913. location:
  4914. description: Location optionally defines a location for a secret
  4915. type: string
  4916. projectID:
  4917. description: ProjectID project where secret is located
  4918. type: string
  4919. secretVersionSelectionPolicy:
  4920. default: LatestOrFail
  4921. description: |-
  4922. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  4923. when "latest" is disabled or destroyed.
  4924. Possible values are:
  4925. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  4926. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  4927. type: string
  4928. type: object
  4929. github:
  4930. description: |-
  4931. Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  4932. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  4933. properties:
  4934. appID:
  4935. description: appID specifies the Github APP that will be used to authenticate the client
  4936. format: int64
  4937. type: integer
  4938. auth:
  4939. description: auth configures how secret-manager authenticates with a Github instance.
  4940. properties:
  4941. privateKey:
  4942. description: |-
  4943. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4944. In some instances, `key` is a required field.
  4945. properties:
  4946. key:
  4947. description: |-
  4948. A key in the referenced Secret.
  4949. Some instances of this field may be defaulted, in others it may be required.
  4950. maxLength: 253
  4951. minLength: 1
  4952. pattern: ^[-._a-zA-Z0-9]+$
  4953. type: string
  4954. name:
  4955. description: The name of the Secret resource being referred to.
  4956. maxLength: 253
  4957. minLength: 1
  4958. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4959. type: string
  4960. namespace:
  4961. description: |-
  4962. The namespace of the Secret resource being referred to.
  4963. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4964. maxLength: 63
  4965. minLength: 1
  4966. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4967. type: string
  4968. type: object
  4969. required:
  4970. - privateKey
  4971. type: object
  4972. environment:
  4973. description: environment will be used to fetch secrets from a particular environment within a github repository
  4974. type: string
  4975. installationID:
  4976. description: installationID specifies the Github APP installation that will be used to authenticate the client
  4977. format: int64
  4978. type: integer
  4979. orgSecretVisibility:
  4980. description: |-
  4981. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  4982. Valid values are "all" or "private".
  4983. When unset, new secrets are created with visibility "all" and existing secrets preserve
  4984. whatever visibility they already have in GitHub.
  4985. enum:
  4986. - all
  4987. - private
  4988. type: string
  4989. organization:
  4990. description: organization will be used to fetch secrets from the Github organization
  4991. type: string
  4992. repository:
  4993. description: repository will be used to fetch secrets from the Github repository within an organization
  4994. type: string
  4995. uploadURL:
  4996. description: Upload URL for enterprise instances. Default to URL.
  4997. type: string
  4998. url:
  4999. default: https://github.com/
  5000. description: URL configures the Github instance URL. Defaults to https://github.com/.
  5001. type: string
  5002. required:
  5003. - appID
  5004. - auth
  5005. - installationID
  5006. - organization
  5007. type: object
  5008. gitlab:
  5009. description: GitLab configures this store to sync secrets using GitLab Variables provider
  5010. properties:
  5011. auth:
  5012. description: Auth configures how secret-manager authenticates with a GitLab instance.
  5013. properties:
  5014. SecretRef:
  5015. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  5016. properties:
  5017. accessToken:
  5018. description: AccessToken is used for authentication.
  5019. properties:
  5020. key:
  5021. description: |-
  5022. A key in the referenced Secret.
  5023. Some instances of this field may be defaulted, in others it may be required.
  5024. maxLength: 253
  5025. minLength: 1
  5026. pattern: ^[-._a-zA-Z0-9]+$
  5027. type: string
  5028. name:
  5029. description: The name of the Secret resource being referred to.
  5030. maxLength: 253
  5031. minLength: 1
  5032. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5033. type: string
  5034. namespace:
  5035. description: |-
  5036. The namespace of the Secret resource being referred to.
  5037. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5038. maxLength: 63
  5039. minLength: 1
  5040. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5041. type: string
  5042. type: object
  5043. type: object
  5044. required:
  5045. - SecretRef
  5046. type: object
  5047. caBundle:
  5048. description: |-
  5049. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  5050. can be performed.
  5051. format: byte
  5052. type: string
  5053. caProvider:
  5054. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  5055. properties:
  5056. key:
  5057. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5058. maxLength: 253
  5059. minLength: 1
  5060. pattern: ^[-._a-zA-Z0-9]+$
  5061. type: string
  5062. name:
  5063. description: The name of the object located at the provider type.
  5064. maxLength: 253
  5065. minLength: 1
  5066. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5067. type: string
  5068. namespace:
  5069. description: |-
  5070. The namespace the Provider type is in.
  5071. Can only be defined when used in a ClusterSecretStore.
  5072. maxLength: 63
  5073. minLength: 1
  5074. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5075. type: string
  5076. type:
  5077. description: The type of provider to use such as "Secret", or "ConfigMap".
  5078. enum:
  5079. - Secret
  5080. - ConfigMap
  5081. type: string
  5082. required:
  5083. - name
  5084. - type
  5085. type: object
  5086. environment:
  5087. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  5088. type: string
  5089. groupIDs:
  5090. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  5091. items:
  5092. type: string
  5093. type: array
  5094. inheritFromGroups:
  5095. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  5096. type: boolean
  5097. projectID:
  5098. description: ProjectID specifies a project where secrets are located.
  5099. type: string
  5100. url:
  5101. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  5102. type: string
  5103. required:
  5104. - auth
  5105. type: object
  5106. ibm:
  5107. description: IBM configures this store to sync secrets using IBM Cloud provider
  5108. properties:
  5109. auth:
  5110. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  5111. maxProperties: 1
  5112. minProperties: 1
  5113. properties:
  5114. containerAuth:
  5115. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  5116. properties:
  5117. iamEndpoint:
  5118. type: string
  5119. profile:
  5120. description: the IBM Trusted Profile
  5121. type: string
  5122. tokenLocation:
  5123. description: Location the token is mounted on the pod
  5124. type: string
  5125. required:
  5126. - profile
  5127. type: object
  5128. secretRef:
  5129. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  5130. properties:
  5131. iamEndpoint:
  5132. description: The IAM endpoint used to obain a token
  5133. type: string
  5134. secretApiKeySecretRef:
  5135. description: The SecretAccessKey is used for authentication
  5136. properties:
  5137. key:
  5138. description: |-
  5139. A key in the referenced Secret.
  5140. Some instances of this field may be defaulted, in others it may be required.
  5141. maxLength: 253
  5142. minLength: 1
  5143. pattern: ^[-._a-zA-Z0-9]+$
  5144. type: string
  5145. name:
  5146. description: The name of the Secret resource being referred to.
  5147. maxLength: 253
  5148. minLength: 1
  5149. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5150. type: string
  5151. namespace:
  5152. description: |-
  5153. The namespace of the Secret resource being referred to.
  5154. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5155. maxLength: 63
  5156. minLength: 1
  5157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5158. type: string
  5159. type: object
  5160. type: object
  5161. type: object
  5162. serviceUrl:
  5163. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  5164. type: string
  5165. required:
  5166. - auth
  5167. type: object
  5168. infisical:
  5169. description: Infisical configures this store to sync secrets using the Infisical provider
  5170. properties:
  5171. auth:
  5172. description: Auth configures how the Operator authenticates with the Infisical API
  5173. properties:
  5174. awsAuthCredentials:
  5175. description: AwsAuthCredentials represents the credentials for AWS authentication.
  5176. properties:
  5177. identityId:
  5178. description: |-
  5179. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5180. In some instances, `key` is a required field.
  5181. properties:
  5182. key:
  5183. description: |-
  5184. A key in the referenced Secret.
  5185. Some instances of this field may be defaulted, in others it may be required.
  5186. maxLength: 253
  5187. minLength: 1
  5188. pattern: ^[-._a-zA-Z0-9]+$
  5189. type: string
  5190. name:
  5191. description: The name of the Secret resource being referred to.
  5192. maxLength: 253
  5193. minLength: 1
  5194. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5195. type: string
  5196. namespace:
  5197. description: |-
  5198. The namespace of the Secret resource being referred to.
  5199. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5200. maxLength: 63
  5201. minLength: 1
  5202. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5203. type: string
  5204. type: object
  5205. required:
  5206. - identityId
  5207. type: object
  5208. azureAuthCredentials:
  5209. description: AzureAuthCredentials represents the credentials for Azure authentication.
  5210. properties:
  5211. identityId:
  5212. description: |-
  5213. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5214. In some instances, `key` is a required field.
  5215. properties:
  5216. key:
  5217. description: |-
  5218. A key in the referenced Secret.
  5219. Some instances of this field may be defaulted, in others it may be required.
  5220. maxLength: 253
  5221. minLength: 1
  5222. pattern: ^[-._a-zA-Z0-9]+$
  5223. type: string
  5224. name:
  5225. description: The name of the Secret resource being referred to.
  5226. maxLength: 253
  5227. minLength: 1
  5228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5229. type: string
  5230. namespace:
  5231. description: |-
  5232. The namespace of the Secret resource being referred to.
  5233. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5234. maxLength: 63
  5235. minLength: 1
  5236. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5237. type: string
  5238. type: object
  5239. resource:
  5240. description: |-
  5241. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5242. In some instances, `key` is a required field.
  5243. properties:
  5244. key:
  5245. description: |-
  5246. A key in the referenced Secret.
  5247. Some instances of this field may be defaulted, in others it may be required.
  5248. maxLength: 253
  5249. minLength: 1
  5250. pattern: ^[-._a-zA-Z0-9]+$
  5251. type: string
  5252. name:
  5253. description: The name of the Secret resource being referred to.
  5254. maxLength: 253
  5255. minLength: 1
  5256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5257. type: string
  5258. namespace:
  5259. description: |-
  5260. The namespace of the Secret resource being referred to.
  5261. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5262. maxLength: 63
  5263. minLength: 1
  5264. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5265. type: string
  5266. type: object
  5267. required:
  5268. - identityId
  5269. type: object
  5270. gcpIamAuthCredentials:
  5271. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  5272. properties:
  5273. identityId:
  5274. description: |-
  5275. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5276. In some instances, `key` is a required field.
  5277. properties:
  5278. key:
  5279. description: |-
  5280. A key in the referenced Secret.
  5281. Some instances of this field may be defaulted, in others it may be required.
  5282. maxLength: 253
  5283. minLength: 1
  5284. pattern: ^[-._a-zA-Z0-9]+$
  5285. type: string
  5286. name:
  5287. description: The name of the Secret resource being referred to.
  5288. maxLength: 253
  5289. minLength: 1
  5290. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5291. type: string
  5292. namespace:
  5293. description: |-
  5294. The namespace of the Secret resource being referred to.
  5295. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5296. maxLength: 63
  5297. minLength: 1
  5298. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5299. type: string
  5300. type: object
  5301. serviceAccountKeyFilePath:
  5302. description: |-
  5303. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5304. In some instances, `key` is a required field.
  5305. properties:
  5306. key:
  5307. description: |-
  5308. A key in the referenced Secret.
  5309. Some instances of this field may be defaulted, in others it may be required.
  5310. maxLength: 253
  5311. minLength: 1
  5312. pattern: ^[-._a-zA-Z0-9]+$
  5313. type: string
  5314. name:
  5315. description: The name of the Secret resource being referred to.
  5316. maxLength: 253
  5317. minLength: 1
  5318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5319. type: string
  5320. namespace:
  5321. description: |-
  5322. The namespace of the Secret resource being referred to.
  5323. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5324. maxLength: 63
  5325. minLength: 1
  5326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5327. type: string
  5328. type: object
  5329. required:
  5330. - identityId
  5331. - serviceAccountKeyFilePath
  5332. type: object
  5333. gcpIdTokenAuthCredentials:
  5334. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  5335. properties:
  5336. identityId:
  5337. description: |-
  5338. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5339. In some instances, `key` is a required field.
  5340. properties:
  5341. key:
  5342. description: |-
  5343. A key in the referenced Secret.
  5344. Some instances of this field may be defaulted, in others it may be required.
  5345. maxLength: 253
  5346. minLength: 1
  5347. pattern: ^[-._a-zA-Z0-9]+$
  5348. type: string
  5349. name:
  5350. description: The name of the Secret resource being referred to.
  5351. maxLength: 253
  5352. minLength: 1
  5353. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5354. type: string
  5355. namespace:
  5356. description: |-
  5357. The namespace of the Secret resource being referred to.
  5358. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5359. maxLength: 63
  5360. minLength: 1
  5361. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5362. type: string
  5363. type: object
  5364. required:
  5365. - identityId
  5366. type: object
  5367. jwtAuthCredentials:
  5368. description: JwtAuthCredentials represents the credentials for JWT authentication.
  5369. properties:
  5370. identityId:
  5371. description: |-
  5372. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5373. In some instances, `key` is a required field.
  5374. properties:
  5375. key:
  5376. description: |-
  5377. A key in the referenced Secret.
  5378. Some instances of this field may be defaulted, in others it may be required.
  5379. maxLength: 253
  5380. minLength: 1
  5381. pattern: ^[-._a-zA-Z0-9]+$
  5382. type: string
  5383. name:
  5384. description: The name of the Secret resource being referred to.
  5385. maxLength: 253
  5386. minLength: 1
  5387. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5388. type: string
  5389. namespace:
  5390. description: |-
  5391. The namespace of the Secret resource being referred to.
  5392. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5393. maxLength: 63
  5394. minLength: 1
  5395. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5396. type: string
  5397. type: object
  5398. jwt:
  5399. description: |-
  5400. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5401. In some instances, `key` is a required field.
  5402. properties:
  5403. key:
  5404. description: |-
  5405. A key in the referenced Secret.
  5406. Some instances of this field may be defaulted, in others it may be required.
  5407. maxLength: 253
  5408. minLength: 1
  5409. pattern: ^[-._a-zA-Z0-9]+$
  5410. type: string
  5411. name:
  5412. description: The name of the Secret resource being referred to.
  5413. maxLength: 253
  5414. minLength: 1
  5415. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5416. type: string
  5417. namespace:
  5418. description: |-
  5419. The namespace of the Secret resource being referred to.
  5420. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5421. maxLength: 63
  5422. minLength: 1
  5423. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5424. type: string
  5425. type: object
  5426. required:
  5427. - identityId
  5428. - jwt
  5429. type: object
  5430. kubernetesAuthCredentials:
  5431. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  5432. properties:
  5433. identityId:
  5434. description: |-
  5435. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5436. In some instances, `key` is a required field.
  5437. properties:
  5438. key:
  5439. description: |-
  5440. A key in the referenced Secret.
  5441. Some instances of this field may be defaulted, in others it may be required.
  5442. maxLength: 253
  5443. minLength: 1
  5444. pattern: ^[-._a-zA-Z0-9]+$
  5445. type: string
  5446. name:
  5447. description: The name of the Secret resource being referred to.
  5448. maxLength: 253
  5449. minLength: 1
  5450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5451. type: string
  5452. namespace:
  5453. description: |-
  5454. The namespace of the Secret resource being referred to.
  5455. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5456. maxLength: 63
  5457. minLength: 1
  5458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5459. type: string
  5460. type: object
  5461. serviceAccountTokenPath:
  5462. description: |-
  5463. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5464. In some instances, `key` is a required field.
  5465. properties:
  5466. key:
  5467. description: |-
  5468. A key in the referenced Secret.
  5469. Some instances of this field may be defaulted, in others it may be required.
  5470. maxLength: 253
  5471. minLength: 1
  5472. pattern: ^[-._a-zA-Z0-9]+$
  5473. type: string
  5474. name:
  5475. description: The name of the Secret resource being referred to.
  5476. maxLength: 253
  5477. minLength: 1
  5478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5479. type: string
  5480. namespace:
  5481. description: |-
  5482. The namespace of the Secret resource being referred to.
  5483. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5484. maxLength: 63
  5485. minLength: 1
  5486. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5487. type: string
  5488. type: object
  5489. required:
  5490. - identityId
  5491. type: object
  5492. ldapAuthCredentials:
  5493. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  5494. properties:
  5495. identityId:
  5496. description: |-
  5497. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5498. In some instances, `key` is a required field.
  5499. properties:
  5500. key:
  5501. description: |-
  5502. A key in the referenced Secret.
  5503. Some instances of this field may be defaulted, in others it may be required.
  5504. maxLength: 253
  5505. minLength: 1
  5506. pattern: ^[-._a-zA-Z0-9]+$
  5507. type: string
  5508. name:
  5509. description: The name of the Secret resource being referred to.
  5510. maxLength: 253
  5511. minLength: 1
  5512. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5513. type: string
  5514. namespace:
  5515. description: |-
  5516. The namespace of the Secret resource being referred to.
  5517. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5518. maxLength: 63
  5519. minLength: 1
  5520. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5521. type: string
  5522. type: object
  5523. ldapPassword:
  5524. description: |-
  5525. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5526. In some instances, `key` is a required field.
  5527. properties:
  5528. key:
  5529. description: |-
  5530. A key in the referenced Secret.
  5531. Some instances of this field may be defaulted, in others it may be required.
  5532. maxLength: 253
  5533. minLength: 1
  5534. pattern: ^[-._a-zA-Z0-9]+$
  5535. type: string
  5536. name:
  5537. description: The name of the Secret resource being referred to.
  5538. maxLength: 253
  5539. minLength: 1
  5540. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5541. type: string
  5542. namespace:
  5543. description: |-
  5544. The namespace of the Secret resource being referred to.
  5545. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5546. maxLength: 63
  5547. minLength: 1
  5548. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5549. type: string
  5550. type: object
  5551. ldapUsername:
  5552. description: |-
  5553. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5554. In some instances, `key` is a required field.
  5555. properties:
  5556. key:
  5557. description: |-
  5558. A key in the referenced Secret.
  5559. Some instances of this field may be defaulted, in others it may be required.
  5560. maxLength: 253
  5561. minLength: 1
  5562. pattern: ^[-._a-zA-Z0-9]+$
  5563. type: string
  5564. name:
  5565. description: The name of the Secret resource being referred to.
  5566. maxLength: 253
  5567. minLength: 1
  5568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5569. type: string
  5570. namespace:
  5571. description: |-
  5572. The namespace of the Secret resource being referred to.
  5573. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5574. maxLength: 63
  5575. minLength: 1
  5576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5577. type: string
  5578. type: object
  5579. required:
  5580. - identityId
  5581. - ldapPassword
  5582. - ldapUsername
  5583. type: object
  5584. ociAuthCredentials:
  5585. description: OciAuthCredentials represents the credentials for OCI authentication.
  5586. properties:
  5587. fingerprint:
  5588. description: |-
  5589. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5590. In some instances, `key` is a required field.
  5591. properties:
  5592. key:
  5593. description: |-
  5594. A key in the referenced Secret.
  5595. Some instances of this field may be defaulted, in others it may be required.
  5596. maxLength: 253
  5597. minLength: 1
  5598. pattern: ^[-._a-zA-Z0-9]+$
  5599. type: string
  5600. name:
  5601. description: The name of the Secret resource being referred to.
  5602. maxLength: 253
  5603. minLength: 1
  5604. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5605. type: string
  5606. namespace:
  5607. description: |-
  5608. The namespace of the Secret resource being referred to.
  5609. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5610. maxLength: 63
  5611. minLength: 1
  5612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5613. type: string
  5614. type: object
  5615. identityId:
  5616. description: |-
  5617. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5618. In some instances, `key` is a required field.
  5619. properties:
  5620. key:
  5621. description: |-
  5622. A key in the referenced Secret.
  5623. Some instances of this field may be defaulted, in others it may be required.
  5624. maxLength: 253
  5625. minLength: 1
  5626. pattern: ^[-._a-zA-Z0-9]+$
  5627. type: string
  5628. name:
  5629. description: The name of the Secret resource being referred to.
  5630. maxLength: 253
  5631. minLength: 1
  5632. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5633. type: string
  5634. namespace:
  5635. description: |-
  5636. The namespace of the Secret resource being referred to.
  5637. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5638. maxLength: 63
  5639. minLength: 1
  5640. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5641. type: string
  5642. type: object
  5643. privateKey:
  5644. description: |-
  5645. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5646. In some instances, `key` is a required field.
  5647. properties:
  5648. key:
  5649. description: |-
  5650. A key in the referenced Secret.
  5651. Some instances of this field may be defaulted, in others it may be required.
  5652. maxLength: 253
  5653. minLength: 1
  5654. pattern: ^[-._a-zA-Z0-9]+$
  5655. type: string
  5656. name:
  5657. description: The name of the Secret resource being referred to.
  5658. maxLength: 253
  5659. minLength: 1
  5660. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5661. type: string
  5662. namespace:
  5663. description: |-
  5664. The namespace of the Secret resource being referred to.
  5665. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5666. maxLength: 63
  5667. minLength: 1
  5668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5669. type: string
  5670. type: object
  5671. privateKeyPassphrase:
  5672. description: |-
  5673. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5674. In some instances, `key` is a required field.
  5675. properties:
  5676. key:
  5677. description: |-
  5678. A key in the referenced Secret.
  5679. Some instances of this field may be defaulted, in others it may be required.
  5680. maxLength: 253
  5681. minLength: 1
  5682. pattern: ^[-._a-zA-Z0-9]+$
  5683. type: string
  5684. name:
  5685. description: The name of the Secret resource being referred to.
  5686. maxLength: 253
  5687. minLength: 1
  5688. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5689. type: string
  5690. namespace:
  5691. description: |-
  5692. The namespace of the Secret resource being referred to.
  5693. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5694. maxLength: 63
  5695. minLength: 1
  5696. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5697. type: string
  5698. type: object
  5699. region:
  5700. description: |-
  5701. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5702. In some instances, `key` is a required field.
  5703. properties:
  5704. key:
  5705. description: |-
  5706. A key in the referenced Secret.
  5707. Some instances of this field may be defaulted, in others it may be required.
  5708. maxLength: 253
  5709. minLength: 1
  5710. pattern: ^[-._a-zA-Z0-9]+$
  5711. type: string
  5712. name:
  5713. description: The name of the Secret resource being referred to.
  5714. maxLength: 253
  5715. minLength: 1
  5716. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5717. type: string
  5718. namespace:
  5719. description: |-
  5720. The namespace of the Secret resource being referred to.
  5721. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5722. maxLength: 63
  5723. minLength: 1
  5724. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5725. type: string
  5726. type: object
  5727. tenancyId:
  5728. description: |-
  5729. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5730. In some instances, `key` is a required field.
  5731. properties:
  5732. key:
  5733. description: |-
  5734. A key in the referenced Secret.
  5735. Some instances of this field may be defaulted, in others it may be required.
  5736. maxLength: 253
  5737. minLength: 1
  5738. pattern: ^[-._a-zA-Z0-9]+$
  5739. type: string
  5740. name:
  5741. description: The name of the Secret resource being referred to.
  5742. maxLength: 253
  5743. minLength: 1
  5744. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5745. type: string
  5746. namespace:
  5747. description: |-
  5748. The namespace of the Secret resource being referred to.
  5749. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5750. maxLength: 63
  5751. minLength: 1
  5752. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5753. type: string
  5754. type: object
  5755. userId:
  5756. description: |-
  5757. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5758. In some instances, `key` is a required field.
  5759. properties:
  5760. key:
  5761. description: |-
  5762. A key in the referenced Secret.
  5763. Some instances of this field may be defaulted, in others it may be required.
  5764. maxLength: 253
  5765. minLength: 1
  5766. pattern: ^[-._a-zA-Z0-9]+$
  5767. type: string
  5768. name:
  5769. description: The name of the Secret resource being referred to.
  5770. maxLength: 253
  5771. minLength: 1
  5772. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5773. type: string
  5774. namespace:
  5775. description: |-
  5776. The namespace of the Secret resource being referred to.
  5777. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5778. maxLength: 63
  5779. minLength: 1
  5780. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5781. type: string
  5782. type: object
  5783. required:
  5784. - fingerprint
  5785. - identityId
  5786. - privateKey
  5787. - region
  5788. - tenancyId
  5789. - userId
  5790. type: object
  5791. tokenAuthCredentials:
  5792. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  5793. properties:
  5794. accessToken:
  5795. description: |-
  5796. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5797. In some instances, `key` is a required field.
  5798. properties:
  5799. key:
  5800. description: |-
  5801. A key in the referenced Secret.
  5802. Some instances of this field may be defaulted, in others it may be required.
  5803. maxLength: 253
  5804. minLength: 1
  5805. pattern: ^[-._a-zA-Z0-9]+$
  5806. type: string
  5807. name:
  5808. description: The name of the Secret resource being referred to.
  5809. maxLength: 253
  5810. minLength: 1
  5811. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5812. type: string
  5813. namespace:
  5814. description: |-
  5815. The namespace of the Secret resource being referred to.
  5816. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5817. maxLength: 63
  5818. minLength: 1
  5819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5820. type: string
  5821. type: object
  5822. required:
  5823. - accessToken
  5824. type: object
  5825. universalAuthCredentials:
  5826. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  5827. properties:
  5828. clientId:
  5829. description: |-
  5830. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5831. In some instances, `key` is a required field.
  5832. properties:
  5833. key:
  5834. description: |-
  5835. A key in the referenced Secret.
  5836. Some instances of this field may be defaulted, in others it may be required.
  5837. maxLength: 253
  5838. minLength: 1
  5839. pattern: ^[-._a-zA-Z0-9]+$
  5840. type: string
  5841. name:
  5842. description: The name of the Secret resource being referred to.
  5843. maxLength: 253
  5844. minLength: 1
  5845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5846. type: string
  5847. namespace:
  5848. description: |-
  5849. The namespace of the Secret resource being referred to.
  5850. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5851. maxLength: 63
  5852. minLength: 1
  5853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5854. type: string
  5855. type: object
  5856. clientSecret:
  5857. description: |-
  5858. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5859. In some instances, `key` is a required field.
  5860. properties:
  5861. key:
  5862. description: |-
  5863. A key in the referenced Secret.
  5864. Some instances of this field may be defaulted, in others it may be required.
  5865. maxLength: 253
  5866. minLength: 1
  5867. pattern: ^[-._a-zA-Z0-9]+$
  5868. type: string
  5869. name:
  5870. description: The name of the Secret resource being referred to.
  5871. maxLength: 253
  5872. minLength: 1
  5873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5874. type: string
  5875. namespace:
  5876. description: |-
  5877. The namespace of the Secret resource being referred to.
  5878. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5879. maxLength: 63
  5880. minLength: 1
  5881. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5882. type: string
  5883. type: object
  5884. required:
  5885. - clientId
  5886. - clientSecret
  5887. type: object
  5888. type: object
  5889. caBundle:
  5890. description: |-
  5891. CABundle is a PEM-encoded CA certificate bundle used to validate
  5892. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  5893. format: byte
  5894. type: string
  5895. caProvider:
  5896. description: |-
  5897. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  5898. The certificate is used to validate the Infisical server's TLS certificate.
  5899. Mutually exclusive with CABundle.
  5900. properties:
  5901. key:
  5902. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5903. maxLength: 253
  5904. minLength: 1
  5905. pattern: ^[-._a-zA-Z0-9]+$
  5906. type: string
  5907. name:
  5908. description: The name of the object located at the provider type.
  5909. maxLength: 253
  5910. minLength: 1
  5911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5912. type: string
  5913. namespace:
  5914. description: |-
  5915. The namespace the Provider type is in.
  5916. Can only be defined when used in a ClusterSecretStore.
  5917. maxLength: 63
  5918. minLength: 1
  5919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5920. type: string
  5921. type:
  5922. description: The type of provider to use such as "Secret", or "ConfigMap".
  5923. enum:
  5924. - Secret
  5925. - ConfigMap
  5926. type: string
  5927. required:
  5928. - name
  5929. - type
  5930. type: object
  5931. hostAPI:
  5932. default: https://app.infisical.com/api
  5933. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  5934. type: string
  5935. secretsScope:
  5936. description: SecretsScope defines the scope of the secrets within the workspace
  5937. properties:
  5938. environmentSlug:
  5939. description: EnvironmentSlug is the required slug identifier for the environment.
  5940. type: string
  5941. expandSecretReferences:
  5942. default: true
  5943. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  5944. type: boolean
  5945. organizationSlug:
  5946. description: |-
  5947. OrganizationSlug is the optional slug that identifies the organization that will be used
  5948. during authentication. Useful for sub-organization setups
  5949. type: string
  5950. projectSlug:
  5951. description: ProjectSlug is the required slug identifier for the project.
  5952. type: string
  5953. recursive:
  5954. default: false
  5955. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  5956. type: boolean
  5957. secretsPath:
  5958. default: /
  5959. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  5960. type: string
  5961. required:
  5962. - environmentSlug
  5963. - projectSlug
  5964. type: object
  5965. required:
  5966. - auth
  5967. - secretsScope
  5968. type: object
  5969. keepersecurity:
  5970. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  5971. properties:
  5972. authRef:
  5973. description: |-
  5974. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5975. In some instances, `key` is a required field.
  5976. properties:
  5977. key:
  5978. description: |-
  5979. A key in the referenced Secret.
  5980. Some instances of this field may be defaulted, in others it may be required.
  5981. maxLength: 253
  5982. minLength: 1
  5983. pattern: ^[-._a-zA-Z0-9]+$
  5984. type: string
  5985. name:
  5986. description: The name of the Secret resource being referred to.
  5987. maxLength: 253
  5988. minLength: 1
  5989. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5990. type: string
  5991. namespace:
  5992. description: |-
  5993. The namespace of the Secret resource being referred to.
  5994. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5995. maxLength: 63
  5996. minLength: 1
  5997. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5998. type: string
  5999. type: object
  6000. folderID:
  6001. type: string
  6002. getByTitleFallback:
  6003. type: boolean
  6004. required:
  6005. - authRef
  6006. - folderID
  6007. type: object
  6008. kubernetes:
  6009. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  6010. properties:
  6011. auth:
  6012. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  6013. maxProperties: 1
  6014. minProperties: 1
  6015. properties:
  6016. cert:
  6017. description: has both clientCert and clientKey as secretKeySelector
  6018. properties:
  6019. clientCert:
  6020. description: |-
  6021. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6022. In some instances, `key` is a required field.
  6023. properties:
  6024. key:
  6025. description: |-
  6026. A key in the referenced Secret.
  6027. Some instances of this field may be defaulted, in others it may be required.
  6028. maxLength: 253
  6029. minLength: 1
  6030. pattern: ^[-._a-zA-Z0-9]+$
  6031. type: string
  6032. name:
  6033. description: The name of the Secret resource being referred to.
  6034. maxLength: 253
  6035. minLength: 1
  6036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6037. type: string
  6038. namespace:
  6039. description: |-
  6040. The namespace of the Secret resource being referred to.
  6041. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6042. maxLength: 63
  6043. minLength: 1
  6044. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6045. type: string
  6046. type: object
  6047. clientKey:
  6048. description: |-
  6049. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6050. In some instances, `key` is a required field.
  6051. properties:
  6052. key:
  6053. description: |-
  6054. A key in the referenced Secret.
  6055. Some instances of this field may be defaulted, in others it may be required.
  6056. maxLength: 253
  6057. minLength: 1
  6058. pattern: ^[-._a-zA-Z0-9]+$
  6059. type: string
  6060. name:
  6061. description: The name of the Secret resource being referred to.
  6062. maxLength: 253
  6063. minLength: 1
  6064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6065. type: string
  6066. namespace:
  6067. description: |-
  6068. The namespace of the Secret resource being referred to.
  6069. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6070. maxLength: 63
  6071. minLength: 1
  6072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6073. type: string
  6074. type: object
  6075. required:
  6076. - clientCert
  6077. - clientKey
  6078. type: object
  6079. serviceAccount:
  6080. description: points to a service account that should be used for authentication
  6081. properties:
  6082. audiences:
  6083. description: |-
  6084. Audience specifies the `aud` claim for the service account token
  6085. Some providers automatically extend the audience field based on well-known annotations for workload
  6086. identity (e.g. IRSA or GCP Workload Identity)
  6087. items:
  6088. type: string
  6089. type: array
  6090. name:
  6091. description: The name of the ServiceAccount resource being referred to.
  6092. maxLength: 253
  6093. minLength: 1
  6094. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6095. type: string
  6096. namespace:
  6097. description: |-
  6098. Namespace of the resource being referred to.
  6099. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6100. maxLength: 63
  6101. minLength: 1
  6102. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6103. type: string
  6104. required:
  6105. - name
  6106. type: object
  6107. token:
  6108. description: use static token to authenticate with
  6109. properties:
  6110. bearerToken:
  6111. description: |-
  6112. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6113. In some instances, `key` is a required field.
  6114. properties:
  6115. key:
  6116. description: |-
  6117. A key in the referenced Secret.
  6118. Some instances of this field may be defaulted, in others it may be required.
  6119. maxLength: 253
  6120. minLength: 1
  6121. pattern: ^[-._a-zA-Z0-9]+$
  6122. type: string
  6123. name:
  6124. description: The name of the Secret resource being referred to.
  6125. maxLength: 253
  6126. minLength: 1
  6127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6128. type: string
  6129. namespace:
  6130. description: |-
  6131. The namespace of the Secret resource being referred to.
  6132. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6133. maxLength: 63
  6134. minLength: 1
  6135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6136. type: string
  6137. type: object
  6138. required:
  6139. - bearerToken
  6140. type: object
  6141. type: object
  6142. authRef:
  6143. description: A reference to a secret that contains the auth information.
  6144. properties:
  6145. key:
  6146. description: |-
  6147. A key in the referenced Secret.
  6148. Some instances of this field may be defaulted, in others it may be required.
  6149. maxLength: 253
  6150. minLength: 1
  6151. pattern: ^[-._a-zA-Z0-9]+$
  6152. type: string
  6153. name:
  6154. description: The name of the Secret resource being referred to.
  6155. maxLength: 253
  6156. minLength: 1
  6157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6158. type: string
  6159. namespace:
  6160. description: |-
  6161. The namespace of the Secret resource being referred to.
  6162. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6163. maxLength: 63
  6164. minLength: 1
  6165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6166. type: string
  6167. type: object
  6168. remoteNamespace:
  6169. default: default
  6170. description: Remote namespace to fetch the secrets from
  6171. maxLength: 63
  6172. minLength: 1
  6173. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6174. type: string
  6175. server:
  6176. description: configures the Kubernetes server Address.
  6177. properties:
  6178. caBundle:
  6179. description: CABundle is a base64-encoded CA certificate
  6180. format: byte
  6181. type: string
  6182. caProvider:
  6183. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  6184. properties:
  6185. key:
  6186. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6187. maxLength: 253
  6188. minLength: 1
  6189. pattern: ^[-._a-zA-Z0-9]+$
  6190. type: string
  6191. name:
  6192. description: The name of the object located at the provider type.
  6193. maxLength: 253
  6194. minLength: 1
  6195. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6196. type: string
  6197. namespace:
  6198. description: |-
  6199. The namespace the Provider type is in.
  6200. Can only be defined when used in a ClusterSecretStore.
  6201. maxLength: 63
  6202. minLength: 1
  6203. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6204. type: string
  6205. type:
  6206. description: The type of provider to use such as "Secret", or "ConfigMap".
  6207. enum:
  6208. - Secret
  6209. - ConfigMap
  6210. type: string
  6211. required:
  6212. - name
  6213. - type
  6214. type: object
  6215. url:
  6216. default: kubernetes.default
  6217. description: configures the Kubernetes server Address.
  6218. type: string
  6219. type: object
  6220. type: object
  6221. nebiusmysterybox:
  6222. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  6223. properties:
  6224. apiDomain:
  6225. description: NebiusMysterybox API endpoint
  6226. type: string
  6227. auth:
  6228. description: Auth defines parameters to authenticate in MysteryBox
  6229. properties:
  6230. serviceAccountCredsSecretRef:
  6231. description: |-
  6232. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  6233. document with service account credentials used to get an IAM token.
  6234. Expected JSON structure:
  6235. {
  6236. "subject-credentials": {
  6237. "alg": "RS256",
  6238. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  6239. "kid": "<public-key-id>",
  6240. "iss": "<issuer-service-account-id>",
  6241. "sub": "<subject-service-account-id>"
  6242. }
  6243. }
  6244. properties:
  6245. key:
  6246. description: |-
  6247. A key in the referenced Secret.
  6248. Some instances of this field may be defaulted, in others it may be required.
  6249. maxLength: 253
  6250. minLength: 1
  6251. pattern: ^[-._a-zA-Z0-9]+$
  6252. type: string
  6253. name:
  6254. description: The name of the Secret resource being referred to.
  6255. maxLength: 253
  6256. minLength: 1
  6257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6258. type: string
  6259. namespace:
  6260. description: |-
  6261. The namespace of the Secret resource being referred to.
  6262. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6263. maxLength: 63
  6264. minLength: 1
  6265. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6266. type: string
  6267. type: object
  6268. tokenSecretRef:
  6269. description: Token authenticates with Nebius Mysterybox by presenting a token.
  6270. properties:
  6271. key:
  6272. description: |-
  6273. A key in the referenced Secret.
  6274. Some instances of this field may be defaulted, in others it may be required.
  6275. maxLength: 253
  6276. minLength: 1
  6277. pattern: ^[-._a-zA-Z0-9]+$
  6278. type: string
  6279. name:
  6280. description: The name of the Secret resource being referred to.
  6281. maxLength: 253
  6282. minLength: 1
  6283. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6284. type: string
  6285. namespace:
  6286. description: |-
  6287. The namespace of the Secret resource being referred to.
  6288. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6289. maxLength: 63
  6290. minLength: 1
  6291. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6292. type: string
  6293. type: object
  6294. workloadIdentity:
  6295. description: WorkloadIdentity defines configuration for workload identity authentication to Nebius IAM.
  6296. properties:
  6297. iamServiceAccountID:
  6298. description: |-
  6299. IAMServiceAccountID is the Nebius IAM service account identifier that the
  6300. federated Kubernetes service account should impersonate during token exchange.
  6301. example: serviceaccount-e00example
  6302. minLength: 1
  6303. pattern: ^serviceaccount-[a-z][a-z0-9]{2}
  6304. type: string
  6305. serviceAccountRef:
  6306. description: |-
  6307. ServiceAccountRef references a Kubernetes ServiceAccount used to request a
  6308. temporary JWT via the TokenRequest API. The JWT is then exchanged for a
  6309. Nebius IAM token using workload federation.
  6310. properties:
  6311. audiences:
  6312. description: |-
  6313. Audience specifies the `aud` claim for the service account token
  6314. Some providers automatically extend the audience field based on well-known annotations for workload
  6315. identity (e.g. IRSA or GCP Workload Identity)
  6316. items:
  6317. type: string
  6318. type: array
  6319. name:
  6320. description: The name of the ServiceAccount resource being referred to.
  6321. maxLength: 253
  6322. minLength: 1
  6323. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6324. type: string
  6325. namespace:
  6326. description: |-
  6327. Namespace of the resource being referred to.
  6328. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6329. maxLength: 63
  6330. minLength: 1
  6331. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6332. type: string
  6333. required:
  6334. - name
  6335. type: object
  6336. required:
  6337. - iamServiceAccountID
  6338. - serviceAccountRef
  6339. type: object
  6340. type: object
  6341. x-kubernetes-validations:
  6342. - message: exactly one of serviceAccountCredsSecretRef, tokenSecretRef, or workloadIdentity must be set
  6343. rule: '(has(self.serviceAccountCredsSecretRef) && has(self.serviceAccountCredsSecretRef.name) && size(self.serviceAccountCredsSecretRef.name) > 0 ? 1 : 0) + (has(self.tokenSecretRef) && has(self.tokenSecretRef.name) && size(self.tokenSecretRef.name) > 0 ? 1 : 0) + (has(self.workloadIdentity) ? 1 : 0) == 1'
  6344. caProvider:
  6345. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  6346. properties:
  6347. certSecretRef:
  6348. description: |-
  6349. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6350. In some instances, `key` is a required field.
  6351. properties:
  6352. key:
  6353. description: |-
  6354. A key in the referenced Secret.
  6355. Some instances of this field may be defaulted, in others it may be required.
  6356. maxLength: 253
  6357. minLength: 1
  6358. pattern: ^[-._a-zA-Z0-9]+$
  6359. type: string
  6360. name:
  6361. description: The name of the Secret resource being referred to.
  6362. maxLength: 253
  6363. minLength: 1
  6364. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6365. type: string
  6366. namespace:
  6367. description: |-
  6368. The namespace of the Secret resource being referred to.
  6369. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6370. maxLength: 63
  6371. minLength: 1
  6372. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6373. type: string
  6374. type: object
  6375. type: object
  6376. required:
  6377. - apiDomain
  6378. - auth
  6379. type: object
  6380. ngrok:
  6381. description: Ngrok configures this store to sync secrets using the ngrok provider.
  6382. properties:
  6383. apiUrl:
  6384. default: https://api.ngrok.com
  6385. description: APIURL is the URL of the ngrok API.
  6386. type: string
  6387. auth:
  6388. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  6389. maxProperties: 1
  6390. minProperties: 1
  6391. properties:
  6392. apiKey:
  6393. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  6394. properties:
  6395. secretRef:
  6396. description: SecretRef is a reference to a secret containing the ngrok API key.
  6397. properties:
  6398. key:
  6399. description: |-
  6400. A key in the referenced Secret.
  6401. Some instances of this field may be defaulted, in others it may be required.
  6402. maxLength: 253
  6403. minLength: 1
  6404. pattern: ^[-._a-zA-Z0-9]+$
  6405. type: string
  6406. name:
  6407. description: The name of the Secret resource being referred to.
  6408. maxLength: 253
  6409. minLength: 1
  6410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6411. type: string
  6412. namespace:
  6413. description: |-
  6414. The namespace of the Secret resource being referred to.
  6415. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6416. maxLength: 63
  6417. minLength: 1
  6418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6419. type: string
  6420. type: object
  6421. type: object
  6422. type: object
  6423. vault:
  6424. description: Vault configures the ngrok vault to sync secrets with.
  6425. properties:
  6426. name:
  6427. description: Name is the name of the ngrok vault to sync secrets with.
  6428. type: string
  6429. required:
  6430. - name
  6431. type: object
  6432. required:
  6433. - auth
  6434. - vault
  6435. type: object
  6436. onboardbase:
  6437. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  6438. properties:
  6439. apiHost:
  6440. default: https://public.onboardbase.com/api/v1/
  6441. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  6442. type: string
  6443. auth:
  6444. description: Auth configures how the Operator authenticates with the Onboardbase API
  6445. properties:
  6446. apiKeyRef:
  6447. description: |-
  6448. OnboardbaseAPIKey is the APIKey generated by an admin account.
  6449. It is used to recognize and authorize access to a project and environment within onboardbase
  6450. properties:
  6451. key:
  6452. description: |-
  6453. A key in the referenced Secret.
  6454. Some instances of this field may be defaulted, in others it may be required.
  6455. maxLength: 253
  6456. minLength: 1
  6457. pattern: ^[-._a-zA-Z0-9]+$
  6458. type: string
  6459. name:
  6460. description: The name of the Secret resource being referred to.
  6461. maxLength: 253
  6462. minLength: 1
  6463. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6464. type: string
  6465. namespace:
  6466. description: |-
  6467. The namespace of the Secret resource being referred to.
  6468. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6469. maxLength: 63
  6470. minLength: 1
  6471. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6472. type: string
  6473. type: object
  6474. passcodeRef:
  6475. description: OnboardbasePasscode is the passcode attached to the API Key
  6476. properties:
  6477. key:
  6478. description: |-
  6479. A key in the referenced Secret.
  6480. Some instances of this field may be defaulted, in others it may be required.
  6481. maxLength: 253
  6482. minLength: 1
  6483. pattern: ^[-._a-zA-Z0-9]+$
  6484. type: string
  6485. name:
  6486. description: The name of the Secret resource being referred to.
  6487. maxLength: 253
  6488. minLength: 1
  6489. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6490. type: string
  6491. namespace:
  6492. description: |-
  6493. The namespace of the Secret resource being referred to.
  6494. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6495. maxLength: 63
  6496. minLength: 1
  6497. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6498. type: string
  6499. type: object
  6500. required:
  6501. - apiKeyRef
  6502. - passcodeRef
  6503. type: object
  6504. environment:
  6505. default: development
  6506. description: Environment is the name of an environmnent within a project to pull the secrets from
  6507. type: string
  6508. project:
  6509. default: development
  6510. description: Project is an onboardbase project that the secrets should be pulled from
  6511. type: string
  6512. required:
  6513. - apiHost
  6514. - auth
  6515. - environment
  6516. - project
  6517. type: object
  6518. onepassword:
  6519. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  6520. properties:
  6521. auth:
  6522. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  6523. properties:
  6524. secretRef:
  6525. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  6526. properties:
  6527. connectTokenSecretRef:
  6528. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  6529. properties:
  6530. key:
  6531. description: |-
  6532. A key in the referenced Secret.
  6533. Some instances of this field may be defaulted, in others it may be required.
  6534. maxLength: 253
  6535. minLength: 1
  6536. pattern: ^[-._a-zA-Z0-9]+$
  6537. type: string
  6538. name:
  6539. description: The name of the Secret resource being referred to.
  6540. maxLength: 253
  6541. minLength: 1
  6542. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6543. type: string
  6544. namespace:
  6545. description: |-
  6546. The namespace of the Secret resource being referred to.
  6547. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6548. maxLength: 63
  6549. minLength: 1
  6550. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6551. type: string
  6552. type: object
  6553. required:
  6554. - connectTokenSecretRef
  6555. type: object
  6556. required:
  6557. - secretRef
  6558. type: object
  6559. connectHost:
  6560. description: ConnectHost defines the OnePassword Connect Server to connect to
  6561. type: string
  6562. vaults:
  6563. additionalProperties:
  6564. type: integer
  6565. description: Vaults defines which OnePassword vaults to search in which order
  6566. type: object
  6567. required:
  6568. - auth
  6569. - connectHost
  6570. - vaults
  6571. type: object
  6572. onepasswordSDK:
  6573. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  6574. properties:
  6575. auth:
  6576. description: Auth defines the information necessary to authenticate against OnePassword API.
  6577. properties:
  6578. serviceAccountSecretRef:
  6579. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  6580. properties:
  6581. key:
  6582. description: |-
  6583. A key in the referenced Secret.
  6584. Some instances of this field may be defaulted, in others it may be required.
  6585. maxLength: 253
  6586. minLength: 1
  6587. pattern: ^[-._a-zA-Z0-9]+$
  6588. type: string
  6589. name:
  6590. description: The name of the Secret resource being referred to.
  6591. maxLength: 253
  6592. minLength: 1
  6593. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6594. type: string
  6595. namespace:
  6596. description: |-
  6597. The namespace of the Secret resource being referred to.
  6598. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6599. maxLength: 63
  6600. minLength: 1
  6601. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6602. type: string
  6603. type: object
  6604. required:
  6605. - serviceAccountSecretRef
  6606. type: object
  6607. cache:
  6608. description: |-
  6609. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  6610. When enabled, secrets are cached with the specified TTL.
  6611. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  6612. If omitted, caching is disabled (default).
  6613. cache: {} is a valid option to set.
  6614. properties:
  6615. maxSize:
  6616. default: 100
  6617. description: |-
  6618. MaxSize is the maximum number of secrets to cache.
  6619. When the cache is full, least-recently-used entries are evicted.
  6620. minimum: 1
  6621. type: integer
  6622. ttl:
  6623. default: 5m
  6624. description: |-
  6625. TTL is the time-to-live for cached secrets.
  6626. Format: duration string (e.g., "5m", "1h", "30s")
  6627. type: string
  6628. type: object
  6629. environment:
  6630. description: |-
  6631. Environment defines the 1Password Environment ID to read variables from.
  6632. Environments are read-only: PushSecret, DeleteSecret, and SecretExists return an error when set.
  6633. Mutually exclusive with Vault.
  6634. type: string
  6635. integrationInfo:
  6636. description: |-
  6637. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  6638. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  6639. properties:
  6640. name:
  6641. default: 1Password SDK
  6642. description: Name defaults to "1Password SDK".
  6643. type: string
  6644. version:
  6645. default: v1.0.0
  6646. description: Version defaults to "v1.0.0".
  6647. type: string
  6648. type: object
  6649. vault:
  6650. description: |-
  6651. Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  6652. Mutually exclusive with Environment.
  6653. type: string
  6654. required:
  6655. - auth
  6656. type: object
  6657. x-kubernetes-validations:
  6658. - message: at most one of the fields in [vault environment] may be set
  6659. rule: '[has(self.vault),has(self.environment)].filter(x,x==true).size() <= 1'
  6660. openBao:
  6661. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  6662. properties:
  6663. auth:
  6664. description: Auth configures how secret-manager authenticates with the OpenBao server.
  6665. properties:
  6666. appRole:
  6667. description: |-
  6668. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  6669. with the role and secret stored in a Kubernetes Secret resource.
  6670. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  6671. properties:
  6672. path:
  6673. default: approle
  6674. description: |-
  6675. Path where the App Role authentication backend is mounted
  6676. in OpenBao, e.g: "approle"
  6677. type: string
  6678. roleId:
  6679. description: |-
  6680. RoleID configured in the App Role authentication backend when setting
  6681. up the authentication backend in OpenBao.
  6682. minLength: 1
  6683. type: string
  6684. roleRef:
  6685. description: |-
  6686. Reference to a key in a Secret that contains the App Role ID used
  6687. to authenticate with OpenBao.
  6688. The `key` field must be specified and denotes which entry within the Secret
  6689. resource is used as the app role id.
  6690. properties:
  6691. key:
  6692. description: |-
  6693. A key in the referenced Secret.
  6694. Some instances of this field may be defaulted, in others it may be required.
  6695. maxLength: 253
  6696. minLength: 1
  6697. pattern: ^[-._a-zA-Z0-9]+$
  6698. type: string
  6699. name:
  6700. description: The name of the Secret resource being referred to.
  6701. maxLength: 253
  6702. minLength: 1
  6703. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6704. type: string
  6705. namespace:
  6706. description: |-
  6707. The namespace of the Secret resource being referred to.
  6708. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6709. maxLength: 63
  6710. minLength: 1
  6711. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6712. type: string
  6713. type: object
  6714. secretRef:
  6715. description: |-
  6716. Reference to a key in a Secret that contains the App Role secret used
  6717. to authenticate with OpenBao.
  6718. The `key` field must be specified and denotes which entry within the Secret
  6719. resource is used as the app role secret.
  6720. properties:
  6721. key:
  6722. description: |-
  6723. A key in the referenced Secret.
  6724. Some instances of this field may be defaulted, in others it may be required.
  6725. maxLength: 253
  6726. minLength: 1
  6727. pattern: ^[-._a-zA-Z0-9]+$
  6728. type: string
  6729. name:
  6730. description: The name of the Secret resource being referred to.
  6731. maxLength: 253
  6732. minLength: 1
  6733. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6734. type: string
  6735. namespace:
  6736. description: |-
  6737. The namespace of the Secret resource being referred to.
  6738. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6739. maxLength: 63
  6740. minLength: 1
  6741. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6742. type: string
  6743. type: object
  6744. required:
  6745. - path
  6746. - secretRef
  6747. type: object
  6748. x-kubernetes-validations:
  6749. - message: exactly one of the fields in [roleId roleRef] must be set
  6750. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  6751. kubernetes:
  6752. description: |-
  6753. Kubernetes authenticates with OpenBao by passing a ServiceAccount
  6754. token to the [Kubernetes auth mechanism].
  6755. [Kubernetes auth mechanism]: https://openbao.org/docs/auth/kubernetes/
  6756. properties:
  6757. path:
  6758. default: kubernetes
  6759. description: |-
  6760. Path where the Kubernetes authentication backend is mounted in OpenBao, e.g:
  6761. "kubernetes"
  6762. type: string
  6763. role:
  6764. description: |-
  6765. A required field containing the OpenBao Role to assume. A Role binds a
  6766. Kubernetes ServiceAccount with a set of OpenBao policies.
  6767. minLength: 1
  6768. type: string
  6769. secretRef:
  6770. description: |-
  6771. Optional secret field containing a Kubernetes ServiceAccount JWT used
  6772. for authenticating with OpenBao. If a name is specified without a key,
  6773. `token` is the default.
  6774. properties:
  6775. key:
  6776. description: |-
  6777. A key in the referenced Secret.
  6778. Some instances of this field may be defaulted, in others it may be required.
  6779. maxLength: 253
  6780. minLength: 1
  6781. pattern: ^[-._a-zA-Z0-9]+$
  6782. type: string
  6783. name:
  6784. description: The name of the Secret resource being referred to.
  6785. maxLength: 253
  6786. minLength: 1
  6787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6788. type: string
  6789. namespace:
  6790. description: |-
  6791. The namespace of the Secret resource being referred to.
  6792. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6793. maxLength: 63
  6794. minLength: 1
  6795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6796. type: string
  6797. type: object
  6798. serviceAccountRef:
  6799. description: |-
  6800. Optional service account field containing the name of a Kubernetes ServiceAccount.
  6801. If the service account is specified, a token will be requested from the Kubernetes
  6802. TokenRequest API for authenticating with OpenBao.
  6803. Any configured audiences will be passed to the TokenRequest as-is.
  6804. properties:
  6805. audiences:
  6806. description: |-
  6807. Audience specifies the `aud` claim for the service account token
  6808. Some providers automatically extend the audience field based on well-known annotations for workload
  6809. identity (e.g. IRSA or GCP Workload Identity)
  6810. items:
  6811. type: string
  6812. type: array
  6813. name:
  6814. description: The name of the ServiceAccount resource being referred to.
  6815. maxLength: 253
  6816. minLength: 1
  6817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6818. type: string
  6819. namespace:
  6820. description: |-
  6821. Namespace of the resource being referred to.
  6822. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6823. maxLength: 63
  6824. minLength: 1
  6825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6826. type: string
  6827. required:
  6828. - name
  6829. type: object
  6830. required:
  6831. - path
  6832. - role
  6833. type: object
  6834. x-kubernetes-validations:
  6835. - message: exactly one of the fields in [serviceAccountRef secretRef] must be set
  6836. rule: '[has(self.serviceAccountRef),has(self.secretRef)].filter(x,x==true).size() == 1'
  6837. namespace:
  6838. description: |-
  6839. Name of the [OpenBao Namespace] to authenticate to. This can be different
  6840. than the namespace your secret is in. Namespaces is a set of features
  6841. within OpenBao that allows OpenBao environments to support secure
  6842. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  6843. if set, or empty otherwise
  6844. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6845. type: string
  6846. tokenSecretRef:
  6847. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  6848. properties:
  6849. key:
  6850. description: |-
  6851. A key in the referenced Secret.
  6852. Some instances of this field may be defaulted, in others it may be required.
  6853. maxLength: 253
  6854. minLength: 1
  6855. pattern: ^[-._a-zA-Z0-9]+$
  6856. type: string
  6857. name:
  6858. description: The name of the Secret resource being referred to.
  6859. maxLength: 253
  6860. minLength: 1
  6861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6862. type: string
  6863. namespace:
  6864. description: |-
  6865. The namespace of the Secret resource being referred to.
  6866. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6867. maxLength: 63
  6868. minLength: 1
  6869. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6870. type: string
  6871. type: object
  6872. userPass:
  6873. description: UserPass authenticates with OpenBao by passing a username/password pair
  6874. properties:
  6875. path:
  6876. default: userpass
  6877. description: |-
  6878. Path where the UserPassword authentication backend is mounted
  6879. in OpenBao, e.g: "userpass"
  6880. type: string
  6881. secretRef:
  6882. description: |-
  6883. SecretRef to a key in a Secret resource containing password for the user
  6884. used to authenticate with OpenBao using the [UserPass authentication
  6885. method]
  6886. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6887. properties:
  6888. key:
  6889. description: |-
  6890. A key in the referenced Secret.
  6891. Some instances of this field may be defaulted, in others it may be required.
  6892. maxLength: 253
  6893. minLength: 1
  6894. pattern: ^[-._a-zA-Z0-9]+$
  6895. type: string
  6896. name:
  6897. description: The name of the Secret resource being referred to.
  6898. maxLength: 253
  6899. minLength: 1
  6900. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6901. type: string
  6902. namespace:
  6903. description: |-
  6904. The namespace of the Secret resource being referred to.
  6905. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6906. maxLength: 63
  6907. minLength: 1
  6908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6909. type: string
  6910. type: object
  6911. username:
  6912. description: |-
  6913. Username is a username used to authenticate using the [UserPass
  6914. authentication method]
  6915. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6916. type: string
  6917. required:
  6918. - path
  6919. - username
  6920. type: object
  6921. type: object
  6922. x-kubernetes-validations:
  6923. - message: exactly one of the fields in [appRole tokenSecretRef userPass kubernetes] must be set
  6924. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass),has(self.kubernetes)].filter(x,x==true).size() == 1'
  6925. caBundle:
  6926. description: |-
  6927. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  6928. this and `caProvider` are not set the system root certificates are used
  6929. to validate the TLS connection.
  6930. format: byte
  6931. type: string
  6932. caProvider:
  6933. description: |-
  6934. The provider for the CA bundle to use to validate OpenBao server
  6935. certificate. If this and `caBundle` are not set the system root
  6936. certificates are used to validate the TLS connection.
  6937. properties:
  6938. key:
  6939. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6940. maxLength: 253
  6941. minLength: 1
  6942. pattern: ^[-._a-zA-Z0-9]+$
  6943. type: string
  6944. name:
  6945. description: The name of the object located at the provider type.
  6946. maxLength: 253
  6947. minLength: 1
  6948. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6949. type: string
  6950. namespace:
  6951. description: |-
  6952. The namespace the Provider type is in.
  6953. Can only be defined when used in a ClusterSecretStore.
  6954. maxLength: 63
  6955. minLength: 1
  6956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6957. type: string
  6958. type:
  6959. description: The type of provider to use such as "Secret", or "ConfigMap".
  6960. enum:
  6961. - Secret
  6962. - ConfigMap
  6963. type: string
  6964. required:
  6965. - name
  6966. - type
  6967. type: object
  6968. namespace:
  6969. description: |-
  6970. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  6971. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  6972. e.g: "ns1".
  6973. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6974. type: string
  6975. path:
  6976. description: |-
  6977. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  6978. "secret". The v2 KV secret engine version specific "/data" path suffix
  6979. for fetching secrets from OpenBao is optional and will be appended
  6980. if not present in specified path.
  6981. type: string
  6982. server:
  6983. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  6984. type: string
  6985. version:
  6986. default: v2
  6987. description: |-
  6988. Version is the OpenBao KV secret engine version. This can be either "v1" or
  6989. "v2". Version defaults to "v2".
  6990. enum:
  6991. - v1
  6992. - v2
  6993. type: string
  6994. required:
  6995. - server
  6996. type: object
  6997. x-kubernetes-validations:
  6998. - message: at most one of the fields in [caBundle caProvider] may be set
  6999. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  7000. oracle:
  7001. description: Oracle configures this store to sync secrets using Oracle Vault provider
  7002. properties:
  7003. auth:
  7004. description: |-
  7005. Auth configures how secret-manager authenticates with the Oracle Vault.
  7006. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  7007. properties:
  7008. secretRef:
  7009. description: SecretRef to pass through sensitive information.
  7010. properties:
  7011. fingerprint:
  7012. description: Fingerprint is the fingerprint of the API private key.
  7013. properties:
  7014. key:
  7015. description: |-
  7016. A key in the referenced Secret.
  7017. Some instances of this field may be defaulted, in others it may be required.
  7018. maxLength: 253
  7019. minLength: 1
  7020. pattern: ^[-._a-zA-Z0-9]+$
  7021. type: string
  7022. name:
  7023. description: The name of the Secret resource being referred to.
  7024. maxLength: 253
  7025. minLength: 1
  7026. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7027. type: string
  7028. namespace:
  7029. description: |-
  7030. The namespace of the Secret resource being referred to.
  7031. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7032. maxLength: 63
  7033. minLength: 1
  7034. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7035. type: string
  7036. type: object
  7037. privatekey:
  7038. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  7039. properties:
  7040. key:
  7041. description: |-
  7042. A key in the referenced Secret.
  7043. Some instances of this field may be defaulted, in others it may be required.
  7044. maxLength: 253
  7045. minLength: 1
  7046. pattern: ^[-._a-zA-Z0-9]+$
  7047. type: string
  7048. name:
  7049. description: The name of the Secret resource being referred to.
  7050. maxLength: 253
  7051. minLength: 1
  7052. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7053. type: string
  7054. namespace:
  7055. description: |-
  7056. The namespace of the Secret resource being referred to.
  7057. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7058. maxLength: 63
  7059. minLength: 1
  7060. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7061. type: string
  7062. type: object
  7063. required:
  7064. - fingerprint
  7065. - privatekey
  7066. type: object
  7067. tenancy:
  7068. description: Tenancy is the tenancy OCID where user is located.
  7069. type: string
  7070. user:
  7071. description: User is an access OCID specific to the account.
  7072. type: string
  7073. required:
  7074. - secretRef
  7075. - tenancy
  7076. - user
  7077. type: object
  7078. compartment:
  7079. description: |-
  7080. Compartment is the vault compartment OCID.
  7081. Required for PushSecret
  7082. type: string
  7083. encryptionKey:
  7084. description: |-
  7085. EncryptionKey is the OCID of the encryption key within the vault.
  7086. Required for PushSecret
  7087. type: string
  7088. principalType:
  7089. description: |-
  7090. The type of principal to use for authentication. If left blank, the Auth struct will
  7091. determine the principal type. This optional field must be specified if using
  7092. workload identity.
  7093. enum:
  7094. - ""
  7095. - UserPrincipal
  7096. - InstancePrincipal
  7097. - Workload
  7098. type: string
  7099. region:
  7100. description: Region is the region where vault is located.
  7101. type: string
  7102. serviceAccountRef:
  7103. description: |-
  7104. ServiceAccountRef specified the service account
  7105. that should be used when authenticating with WorkloadIdentity.
  7106. properties:
  7107. audiences:
  7108. description: |-
  7109. Audience specifies the `aud` claim for the service account token
  7110. Some providers automatically extend the audience field based on well-known annotations for workload
  7111. identity (e.g. IRSA or GCP Workload Identity)
  7112. items:
  7113. type: string
  7114. type: array
  7115. name:
  7116. description: The name of the ServiceAccount resource being referred to.
  7117. maxLength: 253
  7118. minLength: 1
  7119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7120. type: string
  7121. namespace:
  7122. description: |-
  7123. Namespace of the resource being referred to.
  7124. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7125. maxLength: 63
  7126. minLength: 1
  7127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7128. type: string
  7129. required:
  7130. - name
  7131. type: object
  7132. vault:
  7133. description: Vault is the vault's OCID of the specific vault where secret is located.
  7134. type: string
  7135. required:
  7136. - region
  7137. - vault
  7138. type: object
  7139. ovh:
  7140. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  7141. properties:
  7142. auth:
  7143. description: Authentication method (mtls or token).
  7144. properties:
  7145. mtls:
  7146. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  7147. properties:
  7148. caBundle:
  7149. format: byte
  7150. type: string
  7151. caProvider:
  7152. description: |-
  7153. CAProvider provides a custom certificate authority for accessing the provider's store.
  7154. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  7155. properties:
  7156. key:
  7157. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7158. maxLength: 253
  7159. minLength: 1
  7160. pattern: ^[-._a-zA-Z0-9]+$
  7161. type: string
  7162. name:
  7163. description: The name of the object located at the provider type.
  7164. maxLength: 253
  7165. minLength: 1
  7166. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7167. type: string
  7168. namespace:
  7169. description: |-
  7170. The namespace the Provider type is in.
  7171. Can only be defined when used in a ClusterSecretStore.
  7172. maxLength: 63
  7173. minLength: 1
  7174. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7175. type: string
  7176. type:
  7177. description: The type of provider to use such as "Secret", or "ConfigMap".
  7178. enum:
  7179. - Secret
  7180. - ConfigMap
  7181. type: string
  7182. required:
  7183. - name
  7184. - type
  7185. type: object
  7186. certSecretRef:
  7187. description: |-
  7188. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7189. In some instances, `key` is a required field.
  7190. properties:
  7191. key:
  7192. description: |-
  7193. A key in the referenced Secret.
  7194. Some instances of this field may be defaulted, in others it may be required.
  7195. maxLength: 253
  7196. minLength: 1
  7197. pattern: ^[-._a-zA-Z0-9]+$
  7198. type: string
  7199. name:
  7200. description: The name of the Secret resource being referred to.
  7201. maxLength: 253
  7202. minLength: 1
  7203. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7204. type: string
  7205. namespace:
  7206. description: |-
  7207. The namespace of the Secret resource being referred to.
  7208. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7209. maxLength: 63
  7210. minLength: 1
  7211. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7212. type: string
  7213. type: object
  7214. keySecretRef:
  7215. description: |-
  7216. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7217. In some instances, `key` is a required field.
  7218. properties:
  7219. key:
  7220. description: |-
  7221. A key in the referenced Secret.
  7222. Some instances of this field may be defaulted, in others it may be required.
  7223. maxLength: 253
  7224. minLength: 1
  7225. pattern: ^[-._a-zA-Z0-9]+$
  7226. type: string
  7227. name:
  7228. description: The name of the Secret resource being referred to.
  7229. maxLength: 253
  7230. minLength: 1
  7231. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7232. type: string
  7233. namespace:
  7234. description: |-
  7235. The namespace of the Secret resource being referred to.
  7236. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7237. maxLength: 63
  7238. minLength: 1
  7239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7240. type: string
  7241. type: object
  7242. required:
  7243. - certSecretRef
  7244. - keySecretRef
  7245. type: object
  7246. token:
  7247. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  7248. properties:
  7249. tokenSecretRef:
  7250. description: |-
  7251. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7252. In some instances, `key` is a required field.
  7253. properties:
  7254. key:
  7255. description: |-
  7256. A key in the referenced Secret.
  7257. Some instances of this field may be defaulted, in others it may be required.
  7258. maxLength: 253
  7259. minLength: 1
  7260. pattern: ^[-._a-zA-Z0-9]+$
  7261. type: string
  7262. name:
  7263. description: The name of the Secret resource being referred to.
  7264. maxLength: 253
  7265. minLength: 1
  7266. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7267. type: string
  7268. namespace:
  7269. description: |-
  7270. The namespace of the Secret resource being referred to.
  7271. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7272. maxLength: 63
  7273. minLength: 1
  7274. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7275. type: string
  7276. type: object
  7277. required:
  7278. - tokenSecretRef
  7279. type: object
  7280. type: object
  7281. casRequired:
  7282. description: 'Enables or disables check-and-set (CAS) (default: false).'
  7283. type: boolean
  7284. okmsTimeout:
  7285. default: 30
  7286. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  7287. format: int32
  7288. minimum: 1
  7289. type: integer
  7290. okmsid:
  7291. description: specifies the OKMS ID.
  7292. type: string
  7293. server:
  7294. description: specifies the OKMS server endpoint.
  7295. type: string
  7296. required:
  7297. - auth
  7298. - okmsid
  7299. - server
  7300. type: object
  7301. passbolt:
  7302. description: |-
  7303. PassboltProvider provides access to Passbolt secrets manager.
  7304. See: https://www.passbolt.com.
  7305. properties:
  7306. auth:
  7307. description: Auth defines the information necessary to authenticate against Passbolt Server
  7308. properties:
  7309. passwordSecretRef:
  7310. description: |-
  7311. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7312. In some instances, `key` is a required field.
  7313. properties:
  7314. key:
  7315. description: |-
  7316. A key in the referenced Secret.
  7317. Some instances of this field may be defaulted, in others it may be required.
  7318. maxLength: 253
  7319. minLength: 1
  7320. pattern: ^[-._a-zA-Z0-9]+$
  7321. type: string
  7322. name:
  7323. description: The name of the Secret resource being referred to.
  7324. maxLength: 253
  7325. minLength: 1
  7326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7327. type: string
  7328. namespace:
  7329. description: |-
  7330. The namespace of the Secret resource being referred to.
  7331. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7332. maxLength: 63
  7333. minLength: 1
  7334. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7335. type: string
  7336. type: object
  7337. privateKeySecretRef:
  7338. description: |-
  7339. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7340. In some instances, `key` is a required field.
  7341. properties:
  7342. key:
  7343. description: |-
  7344. A key in the referenced Secret.
  7345. Some instances of this field may be defaulted, in others it may be required.
  7346. maxLength: 253
  7347. minLength: 1
  7348. pattern: ^[-._a-zA-Z0-9]+$
  7349. type: string
  7350. name:
  7351. description: The name of the Secret resource being referred to.
  7352. maxLength: 253
  7353. minLength: 1
  7354. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7355. type: string
  7356. namespace:
  7357. description: |-
  7358. The namespace of the Secret resource being referred to.
  7359. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7360. maxLength: 63
  7361. minLength: 1
  7362. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7363. type: string
  7364. type: object
  7365. required:
  7366. - passwordSecretRef
  7367. - privateKeySecretRef
  7368. type: object
  7369. caBundle:
  7370. description: |-
  7371. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  7372. if the Host URL is using HTTPS protocol. If not set the system root certificates
  7373. are used to validate the TLS connection.
  7374. format: byte
  7375. type: string
  7376. caProvider:
  7377. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  7378. properties:
  7379. key:
  7380. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7381. maxLength: 253
  7382. minLength: 1
  7383. pattern: ^[-._a-zA-Z0-9]+$
  7384. type: string
  7385. name:
  7386. description: The name of the object located at the provider type.
  7387. maxLength: 253
  7388. minLength: 1
  7389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7390. type: string
  7391. namespace:
  7392. description: |-
  7393. The namespace the Provider type is in.
  7394. Can only be defined when used in a ClusterSecretStore.
  7395. maxLength: 63
  7396. minLength: 1
  7397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7398. type: string
  7399. type:
  7400. description: The type of provider to use such as "Secret", or "ConfigMap".
  7401. enum:
  7402. - Secret
  7403. - ConfigMap
  7404. type: string
  7405. required:
  7406. - name
  7407. - type
  7408. type: object
  7409. host:
  7410. description: Host defines the Passbolt Server to connect to
  7411. type: string
  7412. required:
  7413. - auth
  7414. - host
  7415. type: object
  7416. passworddepot:
  7417. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  7418. properties:
  7419. auth:
  7420. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  7421. properties:
  7422. secretRef:
  7423. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  7424. properties:
  7425. credentials:
  7426. description: Username / Password is used for authentication.
  7427. properties:
  7428. key:
  7429. description: |-
  7430. A key in the referenced Secret.
  7431. Some instances of this field may be defaulted, in others it may be required.
  7432. maxLength: 253
  7433. minLength: 1
  7434. pattern: ^[-._a-zA-Z0-9]+$
  7435. type: string
  7436. name:
  7437. description: The name of the Secret resource being referred to.
  7438. maxLength: 253
  7439. minLength: 1
  7440. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7441. type: string
  7442. namespace:
  7443. description: |-
  7444. The namespace of the Secret resource being referred to.
  7445. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7446. maxLength: 63
  7447. minLength: 1
  7448. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7449. type: string
  7450. type: object
  7451. type: object
  7452. required:
  7453. - secretRef
  7454. type: object
  7455. database:
  7456. description: Database to use as source
  7457. type: string
  7458. host:
  7459. description: URL configures the Password Depot instance URL.
  7460. type: string
  7461. required:
  7462. - auth
  7463. - database
  7464. - host
  7465. type: object
  7466. previder:
  7467. description: Previder configures this store to sync secrets using the Previder provider
  7468. properties:
  7469. auth:
  7470. description: PreviderAuth contains a secretRef for credentials.
  7471. properties:
  7472. secretRef:
  7473. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  7474. properties:
  7475. accessToken:
  7476. description: The AccessToken is used for authentication
  7477. properties:
  7478. key:
  7479. description: |-
  7480. A key in the referenced Secret.
  7481. Some instances of this field may be defaulted, in others it may be required.
  7482. maxLength: 253
  7483. minLength: 1
  7484. pattern: ^[-._a-zA-Z0-9]+$
  7485. type: string
  7486. name:
  7487. description: The name of the Secret resource being referred to.
  7488. maxLength: 253
  7489. minLength: 1
  7490. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7491. type: string
  7492. namespace:
  7493. description: |-
  7494. The namespace of the Secret resource being referred to.
  7495. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7496. maxLength: 63
  7497. minLength: 1
  7498. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7499. type: string
  7500. type: object
  7501. required:
  7502. - accessToken
  7503. type: object
  7504. type: object
  7505. baseUri:
  7506. type: string
  7507. required:
  7508. - auth
  7509. type: object
  7510. pulumi:
  7511. description: Pulumi configures this store to sync secrets using the Pulumi provider
  7512. properties:
  7513. accessToken:
  7514. description: |-
  7515. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  7516. Deprecated: Use auth.accessToken instead.
  7517. properties:
  7518. secretRef:
  7519. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7520. properties:
  7521. key:
  7522. description: |-
  7523. A key in the referenced Secret.
  7524. Some instances of this field may be defaulted, in others it may be required.
  7525. maxLength: 253
  7526. minLength: 1
  7527. pattern: ^[-._a-zA-Z0-9]+$
  7528. type: string
  7529. name:
  7530. description: The name of the Secret resource being referred to.
  7531. maxLength: 253
  7532. minLength: 1
  7533. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7534. type: string
  7535. namespace:
  7536. description: |-
  7537. The namespace of the Secret resource being referred to.
  7538. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7539. maxLength: 63
  7540. minLength: 1
  7541. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7542. type: string
  7543. type: object
  7544. type: object
  7545. apiUrl:
  7546. default: https://api.pulumi.com/api/esc
  7547. description: APIURL is the URL of the Pulumi API.
  7548. type: string
  7549. auth:
  7550. description: |-
  7551. Auth configures how the Operator authenticates with the Pulumi API.
  7552. Either auth or the deprecated accessToken field must be specified.
  7553. properties:
  7554. accessToken:
  7555. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  7556. properties:
  7557. secretRef:
  7558. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7559. properties:
  7560. key:
  7561. description: |-
  7562. A key in the referenced Secret.
  7563. Some instances of this field may be defaulted, in others it may be required.
  7564. maxLength: 253
  7565. minLength: 1
  7566. pattern: ^[-._a-zA-Z0-9]+$
  7567. type: string
  7568. name:
  7569. description: The name of the Secret resource being referred to.
  7570. maxLength: 253
  7571. minLength: 1
  7572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7573. type: string
  7574. namespace:
  7575. description: |-
  7576. The namespace of the Secret resource being referred to.
  7577. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7578. maxLength: 63
  7579. minLength: 1
  7580. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7581. type: string
  7582. type: object
  7583. type: object
  7584. oidcConfig:
  7585. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  7586. properties:
  7587. expirationSeconds:
  7588. default: 600
  7589. description: |-
  7590. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  7591. Defaults to 10 minutes.
  7592. format: int64
  7593. minimum: 600
  7594. type: integer
  7595. organization:
  7596. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  7597. type: string
  7598. serviceAccountRef:
  7599. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  7600. properties:
  7601. audiences:
  7602. description: |-
  7603. Audience specifies the `aud` claim for the service account token
  7604. Some providers automatically extend the audience field based on well-known annotations for workload
  7605. identity (e.g. IRSA or GCP Workload Identity)
  7606. items:
  7607. type: string
  7608. type: array
  7609. name:
  7610. description: The name of the ServiceAccount resource being referred to.
  7611. maxLength: 253
  7612. minLength: 1
  7613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7614. type: string
  7615. namespace:
  7616. description: |-
  7617. Namespace of the resource being referred to.
  7618. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7619. maxLength: 63
  7620. minLength: 1
  7621. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7622. type: string
  7623. required:
  7624. - name
  7625. type: object
  7626. required:
  7627. - organization
  7628. - serviceAccountRef
  7629. type: object
  7630. type: object
  7631. x-kubernetes-validations:
  7632. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  7633. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  7634. environment:
  7635. description: |-
  7636. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  7637. dynamically retrieved values from supported providers including all major clouds,
  7638. and other Pulumi ESC environments.
  7639. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  7640. type: string
  7641. organization:
  7642. description: |-
  7643. Organization are a space to collaborate on shared projects and stacks.
  7644. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  7645. type: string
  7646. project:
  7647. description: Project is the name of the Pulumi ESC project the environment belongs to.
  7648. type: string
  7649. required:
  7650. - environment
  7651. - organization
  7652. - project
  7653. type: object
  7654. x-kubernetes-validations:
  7655. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  7656. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  7657. scaleway:
  7658. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  7659. properties:
  7660. accessKey:
  7661. description: AccessKey is the non-secret part of the api key.
  7662. properties:
  7663. secretRef:
  7664. description: SecretRef references a key in a secret that will be used as value.
  7665. properties:
  7666. key:
  7667. description: |-
  7668. A key in the referenced Secret.
  7669. Some instances of this field may be defaulted, in others it may be required.
  7670. maxLength: 253
  7671. minLength: 1
  7672. pattern: ^[-._a-zA-Z0-9]+$
  7673. type: string
  7674. name:
  7675. description: The name of the Secret resource being referred to.
  7676. maxLength: 253
  7677. minLength: 1
  7678. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7679. type: string
  7680. namespace:
  7681. description: |-
  7682. The namespace of the Secret resource being referred to.
  7683. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7684. maxLength: 63
  7685. minLength: 1
  7686. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7687. type: string
  7688. type: object
  7689. value:
  7690. description: Value can be specified directly to set a value without using a secret.
  7691. type: string
  7692. type: object
  7693. apiUrl:
  7694. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  7695. type: string
  7696. projectId:
  7697. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  7698. type: string
  7699. region:
  7700. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  7701. type: string
  7702. secretKey:
  7703. description: SecretKey is the non-secret part of the api key.
  7704. properties:
  7705. secretRef:
  7706. description: SecretRef references a key in a secret that will be used as value.
  7707. properties:
  7708. key:
  7709. description: |-
  7710. A key in the referenced Secret.
  7711. Some instances of this field may be defaulted, in others it may be required.
  7712. maxLength: 253
  7713. minLength: 1
  7714. pattern: ^[-._a-zA-Z0-9]+$
  7715. type: string
  7716. name:
  7717. description: The name of the Secret resource being referred to.
  7718. maxLength: 253
  7719. minLength: 1
  7720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7721. type: string
  7722. namespace:
  7723. description: |-
  7724. The namespace of the Secret resource being referred to.
  7725. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7726. maxLength: 63
  7727. minLength: 1
  7728. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7729. type: string
  7730. type: object
  7731. value:
  7732. description: Value can be specified directly to set a value without using a secret.
  7733. type: string
  7734. type: object
  7735. required:
  7736. - accessKey
  7737. - projectId
  7738. - region
  7739. - secretKey
  7740. type: object
  7741. secretserver:
  7742. description: |-
  7743. SecretServer configures this store to sync secrets using SecretServer provider
  7744. https://docs.delinea.com/online-help/secret-server/start.htm
  7745. properties:
  7746. caBundle:
  7747. description: |-
  7748. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  7749. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  7750. are used to validate the TLS connection.
  7751. format: byte
  7752. type: string
  7753. caProvider:
  7754. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  7755. properties:
  7756. key:
  7757. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7758. maxLength: 253
  7759. minLength: 1
  7760. pattern: ^[-._a-zA-Z0-9]+$
  7761. type: string
  7762. name:
  7763. description: The name of the object located at the provider type.
  7764. maxLength: 253
  7765. minLength: 1
  7766. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7767. type: string
  7768. namespace:
  7769. description: |-
  7770. The namespace the Provider type is in.
  7771. Can only be defined when used in a ClusterSecretStore.
  7772. maxLength: 63
  7773. minLength: 1
  7774. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7775. type: string
  7776. type:
  7777. description: The type of provider to use such as "Secret", or "ConfigMap".
  7778. enum:
  7779. - Secret
  7780. - ConfigMap
  7781. type: string
  7782. required:
  7783. - name
  7784. - type
  7785. type: object
  7786. disableSiteIDValidation:
  7787. description: |-
  7788. DisableSiteIDValidation permits a missing site ID for new secrets.
  7789. The provider sends 0 if no site ID is set.
  7790. type: boolean
  7791. domain:
  7792. description: Domain is the secret server domain.
  7793. type: string
  7794. password:
  7795. description: |-
  7796. Password is the secret server account password.
  7797. Required unless Token is set.
  7798. properties:
  7799. secretRef:
  7800. description: SecretRef references a key in a secret that will be used as value.
  7801. properties:
  7802. key:
  7803. description: |-
  7804. A key in the referenced Secret.
  7805. Some instances of this field may be defaulted, in others it may be required.
  7806. maxLength: 253
  7807. minLength: 1
  7808. pattern: ^[-._a-zA-Z0-9]+$
  7809. type: string
  7810. name:
  7811. description: The name of the Secret resource being referred to.
  7812. maxLength: 253
  7813. minLength: 1
  7814. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7815. type: string
  7816. namespace:
  7817. description: |-
  7818. The namespace of the Secret resource being referred to.
  7819. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7820. maxLength: 63
  7821. minLength: 1
  7822. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7823. type: string
  7824. type: object
  7825. value:
  7826. description: Value can be specified directly to set a value without using a secret.
  7827. minLength: 1
  7828. type: string
  7829. type: object
  7830. x-kubernetes-validations:
  7831. - message: exactly one of value or secretRef must be set
  7832. rule: has(self.value) != has(self.secretRef)
  7833. serverURL:
  7834. description: |-
  7835. ServerURL
  7836. URL to your secret server installation
  7837. type: string
  7838. siteId:
  7839. description: |-
  7840. SiteID is the ID of the Secret Server site for new secrets.
  7841. PushSecret metadata can override this value for one secret.
  7842. The provider uses 1 if this field is not set.
  7843. minimum: 1
  7844. type: integer
  7845. token:
  7846. description: |-
  7847. Token is an access token used to authenticate to the secret server,
  7848. as an alternative to Username and Password. When set, Username and
  7849. Password are not required and are ignored.
  7850. properties:
  7851. secretRef:
  7852. description: SecretRef references a key in a secret that will be used as value.
  7853. properties:
  7854. key:
  7855. description: |-
  7856. A key in the referenced Secret.
  7857. Some instances of this field may be defaulted, in others it may be required.
  7858. maxLength: 253
  7859. minLength: 1
  7860. pattern: ^[-._a-zA-Z0-9]+$
  7861. type: string
  7862. name:
  7863. description: The name of the Secret resource being referred to.
  7864. maxLength: 253
  7865. minLength: 1
  7866. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7867. type: string
  7868. namespace:
  7869. description: |-
  7870. The namespace of the Secret resource being referred to.
  7871. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7872. maxLength: 63
  7873. minLength: 1
  7874. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7875. type: string
  7876. type: object
  7877. value:
  7878. description: Value can be specified directly to set a value without using a secret.
  7879. minLength: 1
  7880. type: string
  7881. type: object
  7882. x-kubernetes-validations:
  7883. - message: exactly one of value or secretRef must be set
  7884. rule: has(self.value) != has(self.secretRef)
  7885. username:
  7886. description: |-
  7887. Username is the secret server account username.
  7888. Required unless Token is set.
  7889. properties:
  7890. secretRef:
  7891. description: SecretRef references a key in a secret that will be used as value.
  7892. properties:
  7893. key:
  7894. description: |-
  7895. A key in the referenced Secret.
  7896. Some instances of this field may be defaulted, in others it may be required.
  7897. maxLength: 253
  7898. minLength: 1
  7899. pattern: ^[-._a-zA-Z0-9]+$
  7900. type: string
  7901. name:
  7902. description: The name of the Secret resource being referred to.
  7903. maxLength: 253
  7904. minLength: 1
  7905. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7906. type: string
  7907. namespace:
  7908. description: |-
  7909. The namespace of the Secret resource being referred to.
  7910. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7911. maxLength: 63
  7912. minLength: 1
  7913. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7914. type: string
  7915. type: object
  7916. value:
  7917. description: Value can be specified directly to set a value without using a secret.
  7918. minLength: 1
  7919. type: string
  7920. type: object
  7921. x-kubernetes-validations:
  7922. - message: exactly one of value or secretRef must be set
  7923. rule: has(self.value) != has(self.secretRef)
  7924. required:
  7925. - serverURL
  7926. type: object
  7927. x-kubernetes-validations:
  7928. - message: either token, or both username and password, must be set
  7929. rule: has(self.token) || (has(self.username) && has(self.password))
  7930. senhasegura:
  7931. description: Senhasegura configures this store to sync secrets using senhasegura provider
  7932. properties:
  7933. auth:
  7934. description: Auth defines parameters to authenticate in senhasegura
  7935. properties:
  7936. clientId:
  7937. type: string
  7938. clientSecretSecretRef:
  7939. description: |-
  7940. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7941. In some instances, `key` is a required field.
  7942. properties:
  7943. key:
  7944. description: |-
  7945. A key in the referenced Secret.
  7946. Some instances of this field may be defaulted, in others it may be required.
  7947. maxLength: 253
  7948. minLength: 1
  7949. pattern: ^[-._a-zA-Z0-9]+$
  7950. type: string
  7951. name:
  7952. description: The name of the Secret resource being referred to.
  7953. maxLength: 253
  7954. minLength: 1
  7955. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7956. type: string
  7957. namespace:
  7958. description: |-
  7959. The namespace of the Secret resource being referred to.
  7960. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7961. maxLength: 63
  7962. minLength: 1
  7963. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7964. type: string
  7965. type: object
  7966. required:
  7967. - clientId
  7968. - clientSecretSecretRef
  7969. type: object
  7970. ignoreSslCertificate:
  7971. default: false
  7972. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  7973. type: boolean
  7974. module:
  7975. description: Module defines which senhasegura module should be used to get secrets
  7976. type: string
  7977. url:
  7978. description: URL of senhasegura
  7979. type: string
  7980. required:
  7981. - auth
  7982. - module
  7983. - url
  7984. type: object
  7985. vault:
  7986. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  7987. properties:
  7988. auth:
  7989. description: Auth configures how secret-manager authenticates with the Vault server.
  7990. properties:
  7991. appRole:
  7992. description: |-
  7993. AppRole authenticates with Vault using the App Role auth mechanism,
  7994. with the role and secret stored in a Kubernetes Secret resource.
  7995. properties:
  7996. path:
  7997. default: approle
  7998. description: |-
  7999. Path where the App Role authentication backend is mounted
  8000. in Vault, e.g: "approle"
  8001. type: string
  8002. roleId:
  8003. description: |-
  8004. RoleID configured in the App Role authentication backend when setting
  8005. up the authentication backend in Vault.
  8006. type: string
  8007. roleRef:
  8008. description: |-
  8009. Reference to a key in a Secret that contains the App Role ID used
  8010. to authenticate with Vault.
  8011. The `key` field must be specified and denotes which entry within the Secret
  8012. resource is used as the app role id.
  8013. properties:
  8014. key:
  8015. description: |-
  8016. A key in the referenced Secret.
  8017. Some instances of this field may be defaulted, in others it may be required.
  8018. maxLength: 253
  8019. minLength: 1
  8020. pattern: ^[-._a-zA-Z0-9]+$
  8021. type: string
  8022. name:
  8023. description: The name of the Secret resource being referred to.
  8024. maxLength: 253
  8025. minLength: 1
  8026. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8027. type: string
  8028. namespace:
  8029. description: |-
  8030. The namespace of the Secret resource being referred to.
  8031. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8032. maxLength: 63
  8033. minLength: 1
  8034. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8035. type: string
  8036. type: object
  8037. secretRef:
  8038. description: |-
  8039. Reference to a key in a Secret that contains the App Role secret used
  8040. to authenticate with Vault.
  8041. The `key` field must be specified and denotes which entry within the Secret
  8042. resource is used as the app role secret.
  8043. properties:
  8044. key:
  8045. description: |-
  8046. A key in the referenced Secret.
  8047. Some instances of this field may be defaulted, in others it may be required.
  8048. maxLength: 253
  8049. minLength: 1
  8050. pattern: ^[-._a-zA-Z0-9]+$
  8051. type: string
  8052. name:
  8053. description: The name of the Secret resource being referred to.
  8054. maxLength: 253
  8055. minLength: 1
  8056. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8057. type: string
  8058. namespace:
  8059. description: |-
  8060. The namespace of the Secret resource being referred to.
  8061. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8062. maxLength: 63
  8063. minLength: 1
  8064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8065. type: string
  8066. type: object
  8067. required:
  8068. - path
  8069. - secretRef
  8070. type: object
  8071. cert:
  8072. description: |-
  8073. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  8074. Cert authentication method
  8075. properties:
  8076. clientCert:
  8077. description: |-
  8078. ClientCert is a certificate to authenticate using the Cert Vault
  8079. authentication method
  8080. properties:
  8081. key:
  8082. description: |-
  8083. A key in the referenced Secret.
  8084. Some instances of this field may be defaulted, in others it may be required.
  8085. maxLength: 253
  8086. minLength: 1
  8087. pattern: ^[-._a-zA-Z0-9]+$
  8088. type: string
  8089. name:
  8090. description: The name of the Secret resource being referred to.
  8091. maxLength: 253
  8092. minLength: 1
  8093. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8094. type: string
  8095. namespace:
  8096. description: |-
  8097. The namespace of the Secret resource being referred to.
  8098. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8099. maxLength: 63
  8100. minLength: 1
  8101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8102. type: string
  8103. type: object
  8104. path:
  8105. default: cert
  8106. description: |-
  8107. Path where the Certificate authentication backend is mounted
  8108. in Vault, e.g: "cert"
  8109. type: string
  8110. secretRef:
  8111. description: |-
  8112. SecretRef to a key in a Secret resource containing client private key to
  8113. authenticate with Vault using the Cert authentication method
  8114. properties:
  8115. key:
  8116. description: |-
  8117. A key in the referenced Secret.
  8118. Some instances of this field may be defaulted, in others it may be required.
  8119. maxLength: 253
  8120. minLength: 1
  8121. pattern: ^[-._a-zA-Z0-9]+$
  8122. type: string
  8123. name:
  8124. description: The name of the Secret resource being referred to.
  8125. maxLength: 253
  8126. minLength: 1
  8127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8128. type: string
  8129. namespace:
  8130. description: |-
  8131. The namespace of the Secret resource being referred to.
  8132. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8133. maxLength: 63
  8134. minLength: 1
  8135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8136. type: string
  8137. type: object
  8138. vaultRole:
  8139. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  8140. type: string
  8141. type: object
  8142. gcp:
  8143. description: |-
  8144. Gcp authenticates with Vault using Google Cloud Platform authentication method
  8145. GCP authentication method
  8146. properties:
  8147. location:
  8148. description: Location optionally defines a location/region for the secret
  8149. type: string
  8150. path:
  8151. default: gcp
  8152. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  8153. type: string
  8154. projectID:
  8155. description: Project ID of the Google Cloud Platform project
  8156. type: string
  8157. role:
  8158. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  8159. type: string
  8160. secretRef:
  8161. description: Specify credentials in a Secret object
  8162. properties:
  8163. secretAccessKeySecretRef:
  8164. description: The SecretAccessKey is used for authentication
  8165. properties:
  8166. key:
  8167. description: |-
  8168. A key in the referenced Secret.
  8169. Some instances of this field may be defaulted, in others it may be required.
  8170. maxLength: 253
  8171. minLength: 1
  8172. pattern: ^[-._a-zA-Z0-9]+$
  8173. type: string
  8174. name:
  8175. description: The name of the Secret resource being referred to.
  8176. maxLength: 253
  8177. minLength: 1
  8178. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8179. type: string
  8180. namespace:
  8181. description: |-
  8182. The namespace of the Secret resource being referred to.
  8183. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8184. maxLength: 63
  8185. minLength: 1
  8186. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8187. type: string
  8188. type: object
  8189. type: object
  8190. serviceAccountRef:
  8191. description: ServiceAccountRef to a service account for impersonation
  8192. properties:
  8193. audiences:
  8194. description: |-
  8195. Audience specifies the `aud` claim for the service account token
  8196. Some providers automatically extend the audience field based on well-known annotations for workload
  8197. identity (e.g. IRSA or GCP Workload Identity)
  8198. items:
  8199. type: string
  8200. type: array
  8201. name:
  8202. description: The name of the ServiceAccount resource being referred to.
  8203. maxLength: 253
  8204. minLength: 1
  8205. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8206. type: string
  8207. namespace:
  8208. description: |-
  8209. Namespace of the resource being referred to.
  8210. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8211. maxLength: 63
  8212. minLength: 1
  8213. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8214. type: string
  8215. required:
  8216. - name
  8217. type: object
  8218. workloadIdentity:
  8219. description: Specify a service account with Workload Identity
  8220. properties:
  8221. clusterLocation:
  8222. description: |-
  8223. ClusterLocation is the location of the cluster
  8224. If not specified, it fetches information from the metadata server
  8225. type: string
  8226. clusterName:
  8227. description: |-
  8228. ClusterName is the name of the cluster
  8229. If not specified, it fetches information from the metadata server
  8230. type: string
  8231. clusterProjectID:
  8232. description: |-
  8233. ClusterProjectID is the project ID of the cluster
  8234. If not specified, it fetches information from the metadata server
  8235. type: string
  8236. serviceAccountRef:
  8237. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  8238. properties:
  8239. audiences:
  8240. description: |-
  8241. Audience specifies the `aud` claim for the service account token
  8242. Some providers automatically extend the audience field based on well-known annotations for workload
  8243. identity (e.g. IRSA or GCP Workload Identity)
  8244. items:
  8245. type: string
  8246. type: array
  8247. name:
  8248. description: The name of the ServiceAccount resource being referred to.
  8249. maxLength: 253
  8250. minLength: 1
  8251. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8252. type: string
  8253. namespace:
  8254. description: |-
  8255. Namespace of the resource being referred to.
  8256. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8257. maxLength: 63
  8258. minLength: 1
  8259. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8260. type: string
  8261. required:
  8262. - name
  8263. type: object
  8264. required:
  8265. - serviceAccountRef
  8266. type: object
  8267. required:
  8268. - role
  8269. type: object
  8270. iam:
  8271. description: |-
  8272. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  8273. AWS IAM authentication method
  8274. properties:
  8275. externalID:
  8276. description: AWS External ID set on assumed IAM roles
  8277. type: string
  8278. jwt:
  8279. description: Specify a service account with IRSA enabled
  8280. properties:
  8281. serviceAccountRef:
  8282. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  8283. properties:
  8284. audiences:
  8285. description: |-
  8286. Audience specifies the `aud` claim for the service account token
  8287. Some providers automatically extend the audience field based on well-known annotations for workload
  8288. identity (e.g. IRSA or GCP Workload Identity)
  8289. items:
  8290. type: string
  8291. type: array
  8292. name:
  8293. description: The name of the ServiceAccount resource being referred to.
  8294. maxLength: 253
  8295. minLength: 1
  8296. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8297. type: string
  8298. namespace:
  8299. description: |-
  8300. Namespace of the resource being referred to.
  8301. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8302. maxLength: 63
  8303. minLength: 1
  8304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8305. type: string
  8306. required:
  8307. - name
  8308. type: object
  8309. type: object
  8310. path:
  8311. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  8312. type: string
  8313. region:
  8314. description: AWS region
  8315. type: string
  8316. role:
  8317. description: This is the AWS role to be assumed before talking to vault
  8318. type: string
  8319. secretRef:
  8320. description: Specify credentials in a Secret object
  8321. properties:
  8322. accessKeyIDSecretRef:
  8323. description: The AccessKeyID is used for authentication
  8324. properties:
  8325. key:
  8326. description: |-
  8327. A key in the referenced Secret.
  8328. Some instances of this field may be defaulted, in others it may be required.
  8329. maxLength: 253
  8330. minLength: 1
  8331. pattern: ^[-._a-zA-Z0-9]+$
  8332. type: string
  8333. name:
  8334. description: The name of the Secret resource being referred to.
  8335. maxLength: 253
  8336. minLength: 1
  8337. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8338. type: string
  8339. namespace:
  8340. description: |-
  8341. The namespace of the Secret resource being referred to.
  8342. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8343. maxLength: 63
  8344. minLength: 1
  8345. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8346. type: string
  8347. type: object
  8348. secretAccessKeySecretRef:
  8349. description: The SecretAccessKey is used for authentication
  8350. properties:
  8351. key:
  8352. description: |-
  8353. A key in the referenced Secret.
  8354. Some instances of this field may be defaulted, in others it may be required.
  8355. maxLength: 253
  8356. minLength: 1
  8357. pattern: ^[-._a-zA-Z0-9]+$
  8358. type: string
  8359. name:
  8360. description: The name of the Secret resource being referred to.
  8361. maxLength: 253
  8362. minLength: 1
  8363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8364. type: string
  8365. namespace:
  8366. description: |-
  8367. The namespace of the Secret resource being referred to.
  8368. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8369. maxLength: 63
  8370. minLength: 1
  8371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8372. type: string
  8373. type: object
  8374. sessionTokenSecretRef:
  8375. description: |-
  8376. The SessionToken used for authentication
  8377. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  8378. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  8379. properties:
  8380. key:
  8381. description: |-
  8382. A key in the referenced Secret.
  8383. Some instances of this field may be defaulted, in others it may be required.
  8384. maxLength: 253
  8385. minLength: 1
  8386. pattern: ^[-._a-zA-Z0-9]+$
  8387. type: string
  8388. name:
  8389. description: The name of the Secret resource being referred to.
  8390. maxLength: 253
  8391. minLength: 1
  8392. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8393. type: string
  8394. namespace:
  8395. description: |-
  8396. The namespace of the Secret resource being referred to.
  8397. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8398. maxLength: 63
  8399. minLength: 1
  8400. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8401. type: string
  8402. type: object
  8403. type: object
  8404. vaultAwsIamServerID:
  8405. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  8406. type: string
  8407. vaultRole:
  8408. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  8409. type: string
  8410. required:
  8411. - vaultRole
  8412. type: object
  8413. jwt:
  8414. description: |-
  8415. Jwt authenticates with Vault by passing role and JWT token using the
  8416. JWT/OIDC authentication method
  8417. properties:
  8418. kubernetesServiceAccountToken:
  8419. description: |-
  8420. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  8421. a token for with the `TokenRequest` API.
  8422. properties:
  8423. audiences:
  8424. description: |-
  8425. Optional audiences field that will be used to request a temporary Kubernetes service
  8426. account token for the service account referenced by `serviceAccountRef`.
  8427. Defaults to a single audience `vault` it not specified.
  8428. Deprecated: use serviceAccountRef.Audiences instead
  8429. items:
  8430. type: string
  8431. type: array
  8432. expirationSeconds:
  8433. description: |-
  8434. Optional expiration time in seconds that will be used to request a temporary
  8435. Kubernetes service account token for the service account referenced by
  8436. `serviceAccountRef`.
  8437. Deprecated: this will be removed in the future.
  8438. Defaults to 10 minutes.
  8439. format: int64
  8440. type: integer
  8441. serviceAccountRef:
  8442. description: Service account field containing the name of a kubernetes ServiceAccount.
  8443. properties:
  8444. audiences:
  8445. description: |-
  8446. Audience specifies the `aud` claim for the service account token
  8447. Some providers automatically extend the audience field based on well-known annotations for workload
  8448. identity (e.g. IRSA or GCP Workload Identity)
  8449. items:
  8450. type: string
  8451. type: array
  8452. name:
  8453. description: The name of the ServiceAccount resource being referred to.
  8454. maxLength: 253
  8455. minLength: 1
  8456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8457. type: string
  8458. namespace:
  8459. description: |-
  8460. Namespace of the resource being referred to.
  8461. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8462. maxLength: 63
  8463. minLength: 1
  8464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8465. type: string
  8466. required:
  8467. - name
  8468. type: object
  8469. required:
  8470. - serviceAccountRef
  8471. type: object
  8472. path:
  8473. default: jwt
  8474. description: |-
  8475. Path where the JWT authentication backend is mounted
  8476. in Vault, e.g: "jwt"
  8477. type: string
  8478. role:
  8479. description: |-
  8480. Role is a JWT role to authenticate using the JWT/OIDC Vault
  8481. authentication method
  8482. type: string
  8483. secretRef:
  8484. description: |-
  8485. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  8486. authenticate with Vault using the JWT/OIDC authentication method.
  8487. properties:
  8488. key:
  8489. description: |-
  8490. A key in the referenced Secret.
  8491. Some instances of this field may be defaulted, in others it may be required.
  8492. maxLength: 253
  8493. minLength: 1
  8494. pattern: ^[-._a-zA-Z0-9]+$
  8495. type: string
  8496. name:
  8497. description: The name of the Secret resource being referred to.
  8498. maxLength: 253
  8499. minLength: 1
  8500. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8501. type: string
  8502. namespace:
  8503. description: |-
  8504. The namespace of the Secret resource being referred to.
  8505. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8506. maxLength: 63
  8507. minLength: 1
  8508. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8509. type: string
  8510. type: object
  8511. required:
  8512. - path
  8513. type: object
  8514. kubernetes:
  8515. description: |-
  8516. Kubernetes authenticates with Vault by passing the ServiceAccount
  8517. token stored in the named Secret resource to the Vault server.
  8518. properties:
  8519. mountPath:
  8520. default: kubernetes
  8521. description: |-
  8522. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  8523. "kubernetes"
  8524. type: string
  8525. role:
  8526. description: |-
  8527. A required field containing the Vault Role to assume. A Role binds a
  8528. Kubernetes ServiceAccount with a set of Vault policies.
  8529. type: string
  8530. secretRef:
  8531. description: |-
  8532. Optional secret field containing a Kubernetes ServiceAccount JWT used
  8533. for authenticating with Vault. If a name is specified without a key,
  8534. `token` is the default. If one is not specified, the one bound to
  8535. the controller will be used.
  8536. properties:
  8537. key:
  8538. description: |-
  8539. A key in the referenced Secret.
  8540. Some instances of this field may be defaulted, in others it may be required.
  8541. maxLength: 253
  8542. minLength: 1
  8543. pattern: ^[-._a-zA-Z0-9]+$
  8544. type: string
  8545. name:
  8546. description: The name of the Secret resource being referred to.
  8547. maxLength: 253
  8548. minLength: 1
  8549. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8550. type: string
  8551. namespace:
  8552. description: |-
  8553. The namespace of the Secret resource being referred to.
  8554. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8555. maxLength: 63
  8556. minLength: 1
  8557. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8558. type: string
  8559. type: object
  8560. serviceAccountRef:
  8561. description: |-
  8562. Optional service account field containing the name of a kubernetes ServiceAccount.
  8563. If the service account is specified, the service account secret token JWT will be used
  8564. for authenticating with Vault. If the service account selector is not supplied,
  8565. the secretRef will be used instead.
  8566. properties:
  8567. audiences:
  8568. description: |-
  8569. Audience specifies the `aud` claim for the service account token
  8570. Some providers automatically extend the audience field based on well-known annotations for workload
  8571. identity (e.g. IRSA or GCP Workload Identity)
  8572. items:
  8573. type: string
  8574. type: array
  8575. name:
  8576. description: The name of the ServiceAccount resource being referred to.
  8577. maxLength: 253
  8578. minLength: 1
  8579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8580. type: string
  8581. namespace:
  8582. description: |-
  8583. Namespace of the resource being referred to.
  8584. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8585. maxLength: 63
  8586. minLength: 1
  8587. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8588. type: string
  8589. required:
  8590. - name
  8591. type: object
  8592. required:
  8593. - mountPath
  8594. - role
  8595. type: object
  8596. ldap:
  8597. description: |-
  8598. Ldap authenticates with Vault by passing username/password pair using
  8599. the LDAP authentication method
  8600. properties:
  8601. path:
  8602. default: ldap
  8603. description: |-
  8604. Path where the LDAP authentication backend is mounted
  8605. in Vault, e.g: "ldap"
  8606. type: string
  8607. secretRef:
  8608. description: |-
  8609. SecretRef to a key in a Secret resource containing password for the LDAP
  8610. user used to authenticate with Vault using the LDAP authentication
  8611. method
  8612. properties:
  8613. key:
  8614. description: |-
  8615. A key in the referenced Secret.
  8616. Some instances of this field may be defaulted, in others it may be required.
  8617. maxLength: 253
  8618. minLength: 1
  8619. pattern: ^[-._a-zA-Z0-9]+$
  8620. type: string
  8621. name:
  8622. description: The name of the Secret resource being referred to.
  8623. maxLength: 253
  8624. minLength: 1
  8625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8626. type: string
  8627. namespace:
  8628. description: |-
  8629. The namespace of the Secret resource being referred to.
  8630. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8631. maxLength: 63
  8632. minLength: 1
  8633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8634. type: string
  8635. type: object
  8636. username:
  8637. description: |-
  8638. Username is an LDAP username used to authenticate using the LDAP Vault
  8639. authentication method
  8640. type: string
  8641. required:
  8642. - path
  8643. - username
  8644. type: object
  8645. namespace:
  8646. description: |-
  8647. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  8648. Namespaces is a set of features within Vault Enterprise that allows
  8649. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8650. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8651. This will default to Vault.Namespace field if set, or empty otherwise
  8652. type: string
  8653. tokenSecretRef:
  8654. description: TokenSecretRef authenticates with Vault by presenting a token.
  8655. properties:
  8656. key:
  8657. description: |-
  8658. A key in the referenced Secret.
  8659. Some instances of this field may be defaulted, in others it may be required.
  8660. maxLength: 253
  8661. minLength: 1
  8662. pattern: ^[-._a-zA-Z0-9]+$
  8663. type: string
  8664. name:
  8665. description: The name of the Secret resource being referred to.
  8666. maxLength: 253
  8667. minLength: 1
  8668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8669. type: string
  8670. namespace:
  8671. description: |-
  8672. The namespace of the Secret resource being referred to.
  8673. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8674. maxLength: 63
  8675. minLength: 1
  8676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8677. type: string
  8678. type: object
  8679. userPass:
  8680. description: UserPass authenticates with Vault by passing username/password pair
  8681. properties:
  8682. path:
  8683. default: userpass
  8684. description: |-
  8685. Path where the UserPassword authentication backend is mounted
  8686. in Vault, e.g: "userpass"
  8687. type: string
  8688. secretRef:
  8689. description: |-
  8690. SecretRef to a key in a Secret resource containing password for the
  8691. user used to authenticate with Vault using the UserPass authentication
  8692. method
  8693. properties:
  8694. key:
  8695. description: |-
  8696. A key in the referenced Secret.
  8697. Some instances of this field may be defaulted, in others it may be required.
  8698. maxLength: 253
  8699. minLength: 1
  8700. pattern: ^[-._a-zA-Z0-9]+$
  8701. type: string
  8702. name:
  8703. description: The name of the Secret resource being referred to.
  8704. maxLength: 253
  8705. minLength: 1
  8706. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8707. type: string
  8708. namespace:
  8709. description: |-
  8710. The namespace of the Secret resource being referred to.
  8711. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8712. maxLength: 63
  8713. minLength: 1
  8714. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8715. type: string
  8716. type: object
  8717. username:
  8718. description: |-
  8719. Username is a username used to authenticate using the UserPass Vault
  8720. authentication method
  8721. type: string
  8722. required:
  8723. - path
  8724. - username
  8725. type: object
  8726. type: object
  8727. caBundle:
  8728. description: |-
  8729. PEM encoded CA bundle used to validate Vault server certificate. Only used
  8730. if the Server URL is using HTTPS protocol. This parameter is ignored for
  8731. plain HTTP protocol connection. If not set the system root certificates
  8732. are used to validate the TLS connection.
  8733. format: byte
  8734. type: string
  8735. caProvider:
  8736. description: The provider for the CA bundle to use to validate Vault server certificate.
  8737. properties:
  8738. key:
  8739. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8740. maxLength: 253
  8741. minLength: 1
  8742. pattern: ^[-._a-zA-Z0-9]+$
  8743. type: string
  8744. name:
  8745. description: The name of the object located at the provider type.
  8746. maxLength: 253
  8747. minLength: 1
  8748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8749. type: string
  8750. namespace:
  8751. description: |-
  8752. The namespace the Provider type is in.
  8753. Can only be defined when used in a ClusterSecretStore.
  8754. maxLength: 63
  8755. minLength: 1
  8756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8757. type: string
  8758. type:
  8759. description: The type of provider to use such as "Secret", or "ConfigMap".
  8760. enum:
  8761. - Secret
  8762. - ConfigMap
  8763. type: string
  8764. required:
  8765. - name
  8766. - type
  8767. type: object
  8768. checkAndSet:
  8769. description: |-
  8770. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  8771. Only applies to Vault KV v2 stores. When enabled, write operations must include
  8772. the current version of the secret to prevent unintentional overwrites.
  8773. properties:
  8774. required:
  8775. description: |-
  8776. Required when true, all write operations must include a check-and-set parameter.
  8777. This helps prevent unintentional overwrites of secrets.
  8778. type: boolean
  8779. type: object
  8780. forwardInconsistent:
  8781. description: |-
  8782. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  8783. leader instead of simply retrying within a loop. This can increase performance if
  8784. the option is enabled serverside.
  8785. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  8786. type: boolean
  8787. headers:
  8788. additionalProperties:
  8789. type: string
  8790. description: Headers to be added in Vault request
  8791. type: object
  8792. namespace:
  8793. description: |-
  8794. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  8795. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8796. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8797. type: string
  8798. path:
  8799. description: |-
  8800. Path is the mount path of the Vault KV backend endpoint, e.g:
  8801. "secret". The v2 KV secret engine version specific "/data" path suffix
  8802. for fetching secrets from Vault is optional and will be appended
  8803. if not present in specified path.
  8804. type: string
  8805. readYourWrites:
  8806. description: |-
  8807. ReadYourWrites ensures isolated read-after-write semantics by
  8808. providing discovered cluster replication states in each request.
  8809. More information about eventual consistency in Vault can be found here
  8810. https://www.vaultproject.io/docs/enterprise/consistency
  8811. type: boolean
  8812. server:
  8813. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  8814. type: string
  8815. tls:
  8816. description: |-
  8817. The configuration used for client side related TLS communication, when the Vault server
  8818. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  8819. This parameter is ignored for plain HTTP protocol connection.
  8820. It's worth noting this configuration is different from the "TLS certificates auth method",
  8821. which is available under the `auth.cert` section.
  8822. properties:
  8823. certSecretRef:
  8824. description: |-
  8825. CertSecretRef is a certificate added to the transport layer
  8826. when communicating with the Vault server.
  8827. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  8828. properties:
  8829. key:
  8830. description: |-
  8831. A key in the referenced Secret.
  8832. Some instances of this field may be defaulted, in others it may be required.
  8833. maxLength: 253
  8834. minLength: 1
  8835. pattern: ^[-._a-zA-Z0-9]+$
  8836. type: string
  8837. name:
  8838. description: The name of the Secret resource being referred to.
  8839. maxLength: 253
  8840. minLength: 1
  8841. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8842. type: string
  8843. namespace:
  8844. description: |-
  8845. The namespace of the Secret resource being referred to.
  8846. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8847. maxLength: 63
  8848. minLength: 1
  8849. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8850. type: string
  8851. type: object
  8852. keySecretRef:
  8853. description: |-
  8854. KeySecretRef to a key in a Secret resource containing client private key
  8855. added to the transport layer when communicating with the Vault server.
  8856. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  8857. properties:
  8858. key:
  8859. description: |-
  8860. A key in the referenced Secret.
  8861. Some instances of this field may be defaulted, in others it may be required.
  8862. maxLength: 253
  8863. minLength: 1
  8864. pattern: ^[-._a-zA-Z0-9]+$
  8865. type: string
  8866. name:
  8867. description: The name of the Secret resource being referred to.
  8868. maxLength: 253
  8869. minLength: 1
  8870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8871. type: string
  8872. namespace:
  8873. description: |-
  8874. The namespace of the Secret resource being referred to.
  8875. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8876. maxLength: 63
  8877. minLength: 1
  8878. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8879. type: string
  8880. type: object
  8881. type: object
  8882. version:
  8883. default: v2
  8884. description: |-
  8885. Version is the Vault KV secret engine version. This can be either "v1" or
  8886. "v2". Version defaults to "v2".
  8887. enum:
  8888. - v1
  8889. - v2
  8890. type: string
  8891. required:
  8892. - server
  8893. type: object
  8894. volcengine:
  8895. description: Volcengine configures this store to sync secrets using the Volcengine provider
  8896. properties:
  8897. auth:
  8898. description: |-
  8899. Auth defines the authentication method to use.
  8900. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  8901. properties:
  8902. secretRef:
  8903. description: |-
  8904. SecretRef defines the static credentials to use for authentication.
  8905. If not set, IRSA is used.
  8906. properties:
  8907. accessKeyID:
  8908. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  8909. properties:
  8910. key:
  8911. description: |-
  8912. A key in the referenced Secret.
  8913. Some instances of this field may be defaulted, in others it may be required.
  8914. maxLength: 253
  8915. minLength: 1
  8916. pattern: ^[-._a-zA-Z0-9]+$
  8917. type: string
  8918. name:
  8919. description: The name of the Secret resource being referred to.
  8920. maxLength: 253
  8921. minLength: 1
  8922. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8923. type: string
  8924. namespace:
  8925. description: |-
  8926. The namespace of the Secret resource being referred to.
  8927. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8928. maxLength: 63
  8929. minLength: 1
  8930. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8931. type: string
  8932. type: object
  8933. secretAccessKey:
  8934. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  8935. properties:
  8936. key:
  8937. description: |-
  8938. A key in the referenced Secret.
  8939. Some instances of this field may be defaulted, in others it may be required.
  8940. maxLength: 253
  8941. minLength: 1
  8942. pattern: ^[-._a-zA-Z0-9]+$
  8943. type: string
  8944. name:
  8945. description: The name of the Secret resource being referred to.
  8946. maxLength: 253
  8947. minLength: 1
  8948. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8949. type: string
  8950. namespace:
  8951. description: |-
  8952. The namespace of the Secret resource being referred to.
  8953. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8954. maxLength: 63
  8955. minLength: 1
  8956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8957. type: string
  8958. type: object
  8959. token:
  8960. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  8961. properties:
  8962. key:
  8963. description: |-
  8964. A key in the referenced Secret.
  8965. Some instances of this field may be defaulted, in others it may be required.
  8966. maxLength: 253
  8967. minLength: 1
  8968. pattern: ^[-._a-zA-Z0-9]+$
  8969. type: string
  8970. name:
  8971. description: The name of the Secret resource being referred to.
  8972. maxLength: 253
  8973. minLength: 1
  8974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8975. type: string
  8976. namespace:
  8977. description: |-
  8978. The namespace of the Secret resource being referred to.
  8979. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8980. maxLength: 63
  8981. minLength: 1
  8982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8983. type: string
  8984. type: object
  8985. required:
  8986. - accessKeyID
  8987. - secretAccessKey
  8988. type: object
  8989. type: object
  8990. region:
  8991. description: Region specifies the Volcengine region to connect to.
  8992. type: string
  8993. required:
  8994. - region
  8995. type: object
  8996. webhook:
  8997. description: Webhook configures this store to sync secrets using a generic templated webhook
  8998. properties:
  8999. auth:
  9000. description: Auth specifies a authorization protocol. Only one protocol may be set.
  9001. maxProperties: 1
  9002. minProperties: 1
  9003. properties:
  9004. ntlm:
  9005. description: NTLMProtocol configures the store to use NTLM for auth
  9006. properties:
  9007. passwordSecret:
  9008. description: |-
  9009. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9010. In some instances, `key` is a required field.
  9011. properties:
  9012. key:
  9013. description: |-
  9014. A key in the referenced Secret.
  9015. Some instances of this field may be defaulted, in others it may be required.
  9016. maxLength: 253
  9017. minLength: 1
  9018. pattern: ^[-._a-zA-Z0-9]+$
  9019. type: string
  9020. name:
  9021. description: The name of the Secret resource being referred to.
  9022. maxLength: 253
  9023. minLength: 1
  9024. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9025. type: string
  9026. namespace:
  9027. description: |-
  9028. The namespace of the Secret resource being referred to.
  9029. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9030. maxLength: 63
  9031. minLength: 1
  9032. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9033. type: string
  9034. type: object
  9035. usernameSecret:
  9036. description: |-
  9037. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9038. In some instances, `key` is a required field.
  9039. properties:
  9040. key:
  9041. description: |-
  9042. A key in the referenced Secret.
  9043. Some instances of this field may be defaulted, in others it may be required.
  9044. maxLength: 253
  9045. minLength: 1
  9046. pattern: ^[-._a-zA-Z0-9]+$
  9047. type: string
  9048. name:
  9049. description: The name of the Secret resource being referred to.
  9050. maxLength: 253
  9051. minLength: 1
  9052. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9053. type: string
  9054. namespace:
  9055. description: |-
  9056. The namespace of the Secret resource being referred to.
  9057. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9058. maxLength: 63
  9059. minLength: 1
  9060. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9061. type: string
  9062. type: object
  9063. required:
  9064. - passwordSecret
  9065. - usernameSecret
  9066. type: object
  9067. type: object
  9068. body:
  9069. description: Body
  9070. type: string
  9071. caBundle:
  9072. description: |-
  9073. PEM encoded CA bundle used to validate webhook server certificate. Only used
  9074. if the Server URL is using HTTPS protocol. This parameter is ignored for
  9075. plain HTTP protocol connection. If not set the system root certificates
  9076. are used to validate the TLS connection.
  9077. format: byte
  9078. type: string
  9079. caProvider:
  9080. description: The provider for the CA bundle to use to validate webhook server certificate.
  9081. properties:
  9082. key:
  9083. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9084. maxLength: 253
  9085. minLength: 1
  9086. pattern: ^[-._a-zA-Z0-9]+$
  9087. type: string
  9088. name:
  9089. description: The name of the object located at the provider type.
  9090. maxLength: 253
  9091. minLength: 1
  9092. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9093. type: string
  9094. namespace:
  9095. description: The namespace the Provider type is in.
  9096. maxLength: 63
  9097. minLength: 1
  9098. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9099. type: string
  9100. type:
  9101. description: The type of provider to use such as "Secret", or "ConfigMap".
  9102. enum:
  9103. - Secret
  9104. - ConfigMap
  9105. type: string
  9106. required:
  9107. - name
  9108. - type
  9109. type: object
  9110. headers:
  9111. additionalProperties:
  9112. type: string
  9113. description: Headers
  9114. type: object
  9115. method:
  9116. description: Webhook Method
  9117. type: string
  9118. result:
  9119. description: Result formatting
  9120. properties:
  9121. jsonPath:
  9122. description: Json path of return value
  9123. type: string
  9124. type: object
  9125. secrets:
  9126. description: |-
  9127. Secrets to fill in templates
  9128. These secrets will be passed to the templating function as key value pairs under the given name
  9129. items:
  9130. description: WebhookSecret defines a secret that will be passed to the webhook request.
  9131. properties:
  9132. name:
  9133. description: Name of this secret in templates
  9134. type: string
  9135. secretRef:
  9136. description: Secret ref to fill in credentials
  9137. properties:
  9138. key:
  9139. description: |-
  9140. A key in the referenced Secret.
  9141. Some instances of this field may be defaulted, in others it may be required.
  9142. maxLength: 253
  9143. minLength: 1
  9144. pattern: ^[-._a-zA-Z0-9]+$
  9145. type: string
  9146. name:
  9147. description: The name of the Secret resource being referred to.
  9148. maxLength: 253
  9149. minLength: 1
  9150. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9151. type: string
  9152. namespace:
  9153. description: |-
  9154. The namespace of the Secret resource being referred to.
  9155. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9156. maxLength: 63
  9157. minLength: 1
  9158. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9159. type: string
  9160. type: object
  9161. required:
  9162. - name
  9163. - secretRef
  9164. type: object
  9165. type: array
  9166. timeout:
  9167. description: Timeout
  9168. type: string
  9169. url:
  9170. description: Webhook url to call
  9171. type: string
  9172. required:
  9173. - url
  9174. type: object
  9175. yandexcertificatemanager:
  9176. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  9177. properties:
  9178. apiEndpoint:
  9179. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9180. type: string
  9181. auth:
  9182. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  9183. properties:
  9184. authorizedKeySecretRef:
  9185. description: The authorized key used for authentication
  9186. properties:
  9187. key:
  9188. description: |-
  9189. A key in the referenced Secret.
  9190. Some instances of this field may be defaulted, in others it may be required.
  9191. maxLength: 253
  9192. minLength: 1
  9193. pattern: ^[-._a-zA-Z0-9]+$
  9194. type: string
  9195. name:
  9196. description: The name of the Secret resource being referred to.
  9197. maxLength: 253
  9198. minLength: 1
  9199. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9200. type: string
  9201. namespace:
  9202. description: |-
  9203. The namespace of the Secret resource being referred to.
  9204. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9205. maxLength: 63
  9206. minLength: 1
  9207. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9208. type: string
  9209. type: object
  9210. type: object
  9211. caProvider:
  9212. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9213. properties:
  9214. certSecretRef:
  9215. description: |-
  9216. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9217. In some instances, `key` is a required field.
  9218. properties:
  9219. key:
  9220. description: |-
  9221. A key in the referenced Secret.
  9222. Some instances of this field may be defaulted, in others it may be required.
  9223. maxLength: 253
  9224. minLength: 1
  9225. pattern: ^[-._a-zA-Z0-9]+$
  9226. type: string
  9227. name:
  9228. description: The name of the Secret resource being referred to.
  9229. maxLength: 253
  9230. minLength: 1
  9231. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9232. type: string
  9233. namespace:
  9234. description: |-
  9235. The namespace of the Secret resource being referred to.
  9236. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9237. maxLength: 63
  9238. minLength: 1
  9239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9240. type: string
  9241. type: object
  9242. type: object
  9243. fetching:
  9244. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  9245. maxProperties: 1
  9246. minProperties: 1
  9247. properties:
  9248. byID:
  9249. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  9250. type: object
  9251. byName:
  9252. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  9253. properties:
  9254. folderID:
  9255. description: The folder to fetch secrets from
  9256. type: string
  9257. required:
  9258. - folderID
  9259. type: object
  9260. type: object
  9261. required:
  9262. - auth
  9263. type: object
  9264. yandexlockbox:
  9265. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  9266. properties:
  9267. apiEndpoint:
  9268. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9269. type: string
  9270. auth:
  9271. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  9272. properties:
  9273. authorizedKeySecretRef:
  9274. description: The authorized key used for authentication
  9275. properties:
  9276. key:
  9277. description: |-
  9278. A key in the referenced Secret.
  9279. Some instances of this field may be defaulted, in others it may be required.
  9280. maxLength: 253
  9281. minLength: 1
  9282. pattern: ^[-._a-zA-Z0-9]+$
  9283. type: string
  9284. name:
  9285. description: The name of the Secret resource being referred to.
  9286. maxLength: 253
  9287. minLength: 1
  9288. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9289. type: string
  9290. namespace:
  9291. description: |-
  9292. The namespace of the Secret resource being referred to.
  9293. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9294. maxLength: 63
  9295. minLength: 1
  9296. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9297. type: string
  9298. type: object
  9299. type: object
  9300. caProvider:
  9301. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9302. properties:
  9303. certSecretRef:
  9304. description: |-
  9305. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9306. In some instances, `key` is a required field.
  9307. properties:
  9308. key:
  9309. description: |-
  9310. A key in the referenced Secret.
  9311. Some instances of this field may be defaulted, in others it may be required.
  9312. maxLength: 253
  9313. minLength: 1
  9314. pattern: ^[-._a-zA-Z0-9]+$
  9315. type: string
  9316. name:
  9317. description: The name of the Secret resource being referred to.
  9318. maxLength: 253
  9319. minLength: 1
  9320. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9321. type: string
  9322. namespace:
  9323. description: |-
  9324. The namespace of the Secret resource being referred to.
  9325. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9326. maxLength: 63
  9327. minLength: 1
  9328. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9329. type: string
  9330. type: object
  9331. type: object
  9332. fetching:
  9333. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  9334. maxProperties: 1
  9335. minProperties: 1
  9336. properties:
  9337. byID:
  9338. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  9339. type: object
  9340. byName:
  9341. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  9342. properties:
  9343. folderID:
  9344. description: The folder to fetch secrets from
  9345. type: string
  9346. required:
  9347. - folderID
  9348. type: object
  9349. type: object
  9350. required:
  9351. - auth
  9352. type: object
  9353. type: object
  9354. refreshInterval:
  9355. anyOf:
  9356. - type: integer
  9357. - type: string
  9358. description: |-
  9359. Used to configure store refresh interval. Accepts either an integer number
  9360. of seconds (legacy) or a Go duration string such as "1h" or "5m". Empty or
  9361. 0 will default to the controller config.
  9362. x-kubernetes-int-or-string: true
  9363. retrySettings:
  9364. description: Used to configure HTTP retries on failures.
  9365. properties:
  9366. maxRetries:
  9367. format: int32
  9368. type: integer
  9369. retryInterval:
  9370. type: string
  9371. type: object
  9372. required:
  9373. - provider
  9374. type: object
  9375. status:
  9376. description: SecretStoreStatus defines the observed state of the SecretStore.
  9377. properties:
  9378. capabilities:
  9379. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  9380. type: string
  9381. conditions:
  9382. items:
  9383. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  9384. properties:
  9385. lastTransitionTime:
  9386. format: date-time
  9387. type: string
  9388. message:
  9389. type: string
  9390. reason:
  9391. type: string
  9392. status:
  9393. type: string
  9394. type:
  9395. description: SecretStoreConditionType represents the condition of the SecretStore.
  9396. type: string
  9397. required:
  9398. - status
  9399. - type
  9400. type: object
  9401. type: array
  9402. type: object
  9403. type: object
  9404. served: true
  9405. storage: true
  9406. subresources:
  9407. status: {}
  9408. - additionalPrinterColumns:
  9409. - jsonPath: .metadata.creationTimestamp
  9410. name: AGE
  9411. type: date
  9412. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  9413. name: Status
  9414. type: string
  9415. - jsonPath: .status.capabilities
  9416. name: Capabilities
  9417. type: string
  9418. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  9419. name: Ready
  9420. type: string
  9421. deprecated: true
  9422. name: v1beta1
  9423. schema:
  9424. openAPIV3Schema:
  9425. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  9426. properties:
  9427. apiVersion:
  9428. description: |-
  9429. APIVersion defines the versioned schema of this representation of an object.
  9430. Servers should convert recognized schemas to the latest internal value, and
  9431. may reject unrecognized values.
  9432. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  9433. type: string
  9434. kind:
  9435. description: |-
  9436. Kind is a string value representing the REST resource this object represents.
  9437. Servers may infer this from the endpoint the client submits requests to.
  9438. Cannot be updated.
  9439. In CamelCase.
  9440. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  9441. type: string
  9442. metadata:
  9443. type: object
  9444. spec:
  9445. description: SecretStoreSpec defines the desired state of SecretStore.
  9446. properties:
  9447. conditions:
  9448. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  9449. items:
  9450. description: |-
  9451. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  9452. for a ClusterSecretStore instance.
  9453. properties:
  9454. namespaceRegexes:
  9455. description: Choose namespaces by using regex matching
  9456. items:
  9457. type: string
  9458. type: array
  9459. namespaceSelector:
  9460. description: Choose namespace using a labelSelector
  9461. properties:
  9462. matchExpressions:
  9463. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  9464. items:
  9465. description: |-
  9466. A label selector requirement is a selector that contains values, a key, and an operator that
  9467. relates the key and values.
  9468. properties:
  9469. key:
  9470. description: key is the label key that the selector applies to.
  9471. type: string
  9472. operator:
  9473. description: |-
  9474. operator represents a key's relationship to a set of values.
  9475. Valid operators are In, NotIn, Exists and DoesNotExist.
  9476. type: string
  9477. values:
  9478. description: |-
  9479. values is an array of string values. If the operator is In or NotIn,
  9480. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  9481. the values array must be empty. This array is replaced during a strategic
  9482. merge patch.
  9483. items:
  9484. type: string
  9485. type: array
  9486. x-kubernetes-list-type: atomic
  9487. required:
  9488. - key
  9489. - operator
  9490. type: object
  9491. type: array
  9492. x-kubernetes-list-type: atomic
  9493. matchLabels:
  9494. additionalProperties:
  9495. type: string
  9496. description: |-
  9497. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  9498. map is equivalent to an element of matchExpressions, whose key field is "key", the
  9499. operator is "In", and the values array contains only "value". The requirements are ANDed.
  9500. type: object
  9501. type: object
  9502. x-kubernetes-map-type: atomic
  9503. namespaces:
  9504. description: Choose namespaces by name
  9505. items:
  9506. maxLength: 63
  9507. minLength: 1
  9508. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9509. type: string
  9510. type: array
  9511. type: object
  9512. type: array
  9513. controller:
  9514. description: |-
  9515. Used to select the correct ESO controller (think: ingress.ingressClassName)
  9516. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  9517. type: string
  9518. provider:
  9519. description: Used to configure the provider. Only one provider may be set
  9520. maxProperties: 1
  9521. minProperties: 1
  9522. properties:
  9523. akeyless:
  9524. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  9525. properties:
  9526. akeylessGWApiURL:
  9527. description: Akeyless GW API Url from which the secrets to be fetched from.
  9528. type: string
  9529. authSecretRef:
  9530. description: Auth configures how the operator authenticates with Akeyless.
  9531. properties:
  9532. kubernetesAuth:
  9533. description: |-
  9534. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  9535. token stored in the named Secret resource.
  9536. properties:
  9537. accessID:
  9538. description: the Akeyless Kubernetes auth-method access-id
  9539. type: string
  9540. k8sConfName:
  9541. description: Kubernetes-auth configuration name in Akeyless-Gateway
  9542. type: string
  9543. secretRef:
  9544. description: |-
  9545. Optional secret field containing a Kubernetes ServiceAccount JWT used
  9546. for authenticating with Akeyless. If a name is specified without a key,
  9547. `token` is the default. If one is not specified, the one bound to
  9548. the controller will be used.
  9549. properties:
  9550. key:
  9551. description: |-
  9552. A key in the referenced Secret.
  9553. Some instances of this field may be defaulted, in others it may be required.
  9554. maxLength: 253
  9555. minLength: 1
  9556. pattern: ^[-._a-zA-Z0-9]+$
  9557. type: string
  9558. name:
  9559. description: The name of the Secret resource being referred to.
  9560. maxLength: 253
  9561. minLength: 1
  9562. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9563. type: string
  9564. namespace:
  9565. description: |-
  9566. The namespace of the Secret resource being referred to.
  9567. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9568. maxLength: 63
  9569. minLength: 1
  9570. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9571. type: string
  9572. type: object
  9573. serviceAccountRef:
  9574. description: |-
  9575. Optional service account field containing the name of a kubernetes ServiceAccount.
  9576. If the service account is specified, the service account secret token JWT will be used
  9577. for authenticating with Akeyless. If the service account selector is not supplied,
  9578. the secretRef will be used instead.
  9579. properties:
  9580. audiences:
  9581. description: |-
  9582. Audience specifies the `aud` claim for the service account token
  9583. Some providers automatically extend the audience field based on well-known annotations for workload
  9584. identity (e.g. IRSA or GCP Workload Identity)
  9585. items:
  9586. type: string
  9587. type: array
  9588. name:
  9589. description: The name of the ServiceAccount resource being referred to.
  9590. maxLength: 253
  9591. minLength: 1
  9592. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9593. type: string
  9594. namespace:
  9595. description: |-
  9596. Namespace of the resource being referred to.
  9597. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9598. maxLength: 63
  9599. minLength: 1
  9600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9601. type: string
  9602. required:
  9603. - name
  9604. type: object
  9605. required:
  9606. - accessID
  9607. - k8sConfName
  9608. type: object
  9609. secretRef:
  9610. description: |-
  9611. Reference to a Secret that contains the details
  9612. to authenticate with Akeyless.
  9613. properties:
  9614. accessID:
  9615. description: The SecretAccessID is used for authentication
  9616. properties:
  9617. key:
  9618. description: |-
  9619. A key in the referenced Secret.
  9620. Some instances of this field may be defaulted, in others it may be required.
  9621. maxLength: 253
  9622. minLength: 1
  9623. pattern: ^[-._a-zA-Z0-9]+$
  9624. type: string
  9625. name:
  9626. description: The name of the Secret resource being referred to.
  9627. maxLength: 253
  9628. minLength: 1
  9629. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9630. type: string
  9631. namespace:
  9632. description: |-
  9633. The namespace of the Secret resource being referred to.
  9634. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9635. maxLength: 63
  9636. minLength: 1
  9637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9638. type: string
  9639. type: object
  9640. accessType:
  9641. description: |-
  9642. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9643. In some instances, `key` is a required field.
  9644. properties:
  9645. key:
  9646. description: |-
  9647. A key in the referenced Secret.
  9648. Some instances of this field may be defaulted, in others it may be required.
  9649. maxLength: 253
  9650. minLength: 1
  9651. pattern: ^[-._a-zA-Z0-9]+$
  9652. type: string
  9653. name:
  9654. description: The name of the Secret resource being referred to.
  9655. maxLength: 253
  9656. minLength: 1
  9657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9658. type: string
  9659. namespace:
  9660. description: |-
  9661. The namespace of the Secret resource being referred to.
  9662. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9663. maxLength: 63
  9664. minLength: 1
  9665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9666. type: string
  9667. type: object
  9668. accessTypeParam:
  9669. description: |-
  9670. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9671. In some instances, `key` is a required field.
  9672. properties:
  9673. key:
  9674. description: |-
  9675. A key in the referenced Secret.
  9676. Some instances of this field may be defaulted, in others it may be required.
  9677. maxLength: 253
  9678. minLength: 1
  9679. pattern: ^[-._a-zA-Z0-9]+$
  9680. type: string
  9681. name:
  9682. description: The name of the Secret resource being referred to.
  9683. maxLength: 253
  9684. minLength: 1
  9685. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9686. type: string
  9687. namespace:
  9688. description: |-
  9689. The namespace of the Secret resource being referred to.
  9690. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9691. maxLength: 63
  9692. minLength: 1
  9693. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9694. type: string
  9695. type: object
  9696. type: object
  9697. type: object
  9698. caBundle:
  9699. description: |-
  9700. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  9701. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  9702. are used to validate the TLS connection.
  9703. format: byte
  9704. type: string
  9705. caProvider:
  9706. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  9707. properties:
  9708. key:
  9709. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9710. maxLength: 253
  9711. minLength: 1
  9712. pattern: ^[-._a-zA-Z0-9]+$
  9713. type: string
  9714. name:
  9715. description: The name of the object located at the provider type.
  9716. maxLength: 253
  9717. minLength: 1
  9718. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9719. type: string
  9720. namespace:
  9721. description: |-
  9722. The namespace the Provider type is in.
  9723. Can only be defined when used in a ClusterSecretStore.
  9724. maxLength: 63
  9725. minLength: 1
  9726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9727. type: string
  9728. type:
  9729. description: The type of provider to use such as "Secret", or "ConfigMap".
  9730. enum:
  9731. - Secret
  9732. - ConfigMap
  9733. type: string
  9734. required:
  9735. - name
  9736. - type
  9737. type: object
  9738. required:
  9739. - akeylessGWApiURL
  9740. - authSecretRef
  9741. type: object
  9742. alibaba:
  9743. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  9744. properties:
  9745. auth:
  9746. description: AlibabaAuth contains a secretRef for credentials.
  9747. properties:
  9748. rrsa:
  9749. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  9750. properties:
  9751. oidcProviderArn:
  9752. type: string
  9753. oidcTokenFilePath:
  9754. type: string
  9755. roleArn:
  9756. type: string
  9757. sessionName:
  9758. type: string
  9759. required:
  9760. - oidcProviderArn
  9761. - oidcTokenFilePath
  9762. - roleArn
  9763. - sessionName
  9764. type: object
  9765. secretRef:
  9766. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  9767. properties:
  9768. accessKeyIDSecretRef:
  9769. description: The AccessKeyID is used for authentication
  9770. properties:
  9771. key:
  9772. description: |-
  9773. A key in the referenced Secret.
  9774. Some instances of this field may be defaulted, in others it may be required.
  9775. maxLength: 253
  9776. minLength: 1
  9777. pattern: ^[-._a-zA-Z0-9]+$
  9778. type: string
  9779. name:
  9780. description: The name of the Secret resource being referred to.
  9781. maxLength: 253
  9782. minLength: 1
  9783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9784. type: string
  9785. namespace:
  9786. description: |-
  9787. The namespace of the Secret resource being referred to.
  9788. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9789. maxLength: 63
  9790. minLength: 1
  9791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9792. type: string
  9793. type: object
  9794. accessKeySecretSecretRef:
  9795. description: The AccessKeySecret is used for authentication
  9796. properties:
  9797. key:
  9798. description: |-
  9799. A key in the referenced Secret.
  9800. Some instances of this field may be defaulted, in others it may be required.
  9801. maxLength: 253
  9802. minLength: 1
  9803. pattern: ^[-._a-zA-Z0-9]+$
  9804. type: string
  9805. name:
  9806. description: The name of the Secret resource being referred to.
  9807. maxLength: 253
  9808. minLength: 1
  9809. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9810. type: string
  9811. namespace:
  9812. description: |-
  9813. The namespace of the Secret resource being referred to.
  9814. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9815. maxLength: 63
  9816. minLength: 1
  9817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9818. type: string
  9819. type: object
  9820. required:
  9821. - accessKeyIDSecretRef
  9822. - accessKeySecretSecretRef
  9823. type: object
  9824. type: object
  9825. regionID:
  9826. description: Alibaba Region to be used for the provider
  9827. type: string
  9828. required:
  9829. - auth
  9830. - regionID
  9831. type: object
  9832. aws:
  9833. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  9834. properties:
  9835. additionalRoles:
  9836. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  9837. items:
  9838. type: string
  9839. type: array
  9840. auth:
  9841. description: |-
  9842. Auth defines the information necessary to authenticate against AWS
  9843. if not set aws sdk will infer credentials from your environment
  9844. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  9845. properties:
  9846. jwt:
  9847. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  9848. properties:
  9849. serviceAccountRef:
  9850. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  9851. properties:
  9852. audiences:
  9853. description: |-
  9854. Audience specifies the `aud` claim for the service account token
  9855. Some providers automatically extend the audience field based on well-known annotations for workload
  9856. identity (e.g. IRSA or GCP Workload Identity)
  9857. items:
  9858. type: string
  9859. type: array
  9860. name:
  9861. description: The name of the ServiceAccount resource being referred to.
  9862. maxLength: 253
  9863. minLength: 1
  9864. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9865. type: string
  9866. namespace:
  9867. description: |-
  9868. Namespace of the resource being referred to.
  9869. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9870. maxLength: 63
  9871. minLength: 1
  9872. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9873. type: string
  9874. required:
  9875. - name
  9876. type: object
  9877. type: object
  9878. secretRef:
  9879. description: |-
  9880. AWSAuthSecretRef holds secret references for AWS credentials
  9881. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  9882. properties:
  9883. accessKeyIDSecretRef:
  9884. description: The AccessKeyID is used for authentication
  9885. properties:
  9886. key:
  9887. description: |-
  9888. A key in the referenced Secret.
  9889. Some instances of this field may be defaulted, in others it may be required.
  9890. maxLength: 253
  9891. minLength: 1
  9892. pattern: ^[-._a-zA-Z0-9]+$
  9893. type: string
  9894. name:
  9895. description: The name of the Secret resource being referred to.
  9896. maxLength: 253
  9897. minLength: 1
  9898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9899. type: string
  9900. namespace:
  9901. description: |-
  9902. The namespace of the Secret resource being referred to.
  9903. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9904. maxLength: 63
  9905. minLength: 1
  9906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9907. type: string
  9908. type: object
  9909. secretAccessKeySecretRef:
  9910. description: The SecretAccessKey is used for authentication
  9911. properties:
  9912. key:
  9913. description: |-
  9914. A key in the referenced Secret.
  9915. Some instances of this field may be defaulted, in others it may be required.
  9916. maxLength: 253
  9917. minLength: 1
  9918. pattern: ^[-._a-zA-Z0-9]+$
  9919. type: string
  9920. name:
  9921. description: The name of the Secret resource being referred to.
  9922. maxLength: 253
  9923. minLength: 1
  9924. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9925. type: string
  9926. namespace:
  9927. description: |-
  9928. The namespace of the Secret resource being referred to.
  9929. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9930. maxLength: 63
  9931. minLength: 1
  9932. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9933. type: string
  9934. type: object
  9935. sessionTokenSecretRef:
  9936. description: |-
  9937. The SessionToken used for authentication
  9938. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  9939. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  9940. properties:
  9941. key:
  9942. description: |-
  9943. A key in the referenced Secret.
  9944. Some instances of this field may be defaulted, in others it may be required.
  9945. maxLength: 253
  9946. minLength: 1
  9947. pattern: ^[-._a-zA-Z0-9]+$
  9948. type: string
  9949. name:
  9950. description: The name of the Secret resource being referred to.
  9951. maxLength: 253
  9952. minLength: 1
  9953. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9954. type: string
  9955. namespace:
  9956. description: |-
  9957. The namespace of the Secret resource being referred to.
  9958. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9959. maxLength: 63
  9960. minLength: 1
  9961. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9962. type: string
  9963. type: object
  9964. type: object
  9965. type: object
  9966. externalID:
  9967. description: AWS External ID set on assumed IAM roles
  9968. type: string
  9969. prefix:
  9970. description: Prefix adds a prefix to all retrieved values.
  9971. type: string
  9972. region:
  9973. description: AWS Region to be used for the provider
  9974. type: string
  9975. role:
  9976. description: Role is a Role ARN which the provider will assume
  9977. type: string
  9978. secretsManager:
  9979. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  9980. properties:
  9981. forceDeleteWithoutRecovery:
  9982. description: |-
  9983. Specifies whether to delete the secret without any recovery window. You
  9984. can't use both this parameter and RecoveryWindowInDays in the same call.
  9985. If you don't use either, then by default Secrets Manager uses a 30 day
  9986. recovery window.
  9987. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  9988. type: boolean
  9989. recoveryWindowInDays:
  9990. description: |-
  9991. The number of days from 7 to 30 that Secrets Manager waits before
  9992. permanently deleting the secret. You can't use both this parameter and
  9993. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  9994. then by default Secrets Manager uses a 30 day recovery window.
  9995. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  9996. format: int64
  9997. type: integer
  9998. type: object
  9999. service:
  10000. description: Service defines which service should be used to fetch the secrets
  10001. enum:
  10002. - SecretsManager
  10003. - ParameterStore
  10004. type: string
  10005. sessionTags:
  10006. description: AWS STS assume role session tags
  10007. items:
  10008. description: Tag defines a tag key and value for AWS resources.
  10009. properties:
  10010. key:
  10011. type: string
  10012. value:
  10013. type: string
  10014. required:
  10015. - key
  10016. - value
  10017. type: object
  10018. type: array
  10019. transitiveTagKeys:
  10020. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  10021. items:
  10022. type: string
  10023. type: array
  10024. required:
  10025. - region
  10026. - service
  10027. type: object
  10028. azurekv:
  10029. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  10030. properties:
  10031. authSecretRef:
  10032. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  10033. properties:
  10034. clientCertificate:
  10035. description: The Azure ClientCertificate of the service principle used for authentication.
  10036. properties:
  10037. key:
  10038. description: |-
  10039. A key in the referenced Secret.
  10040. Some instances of this field may be defaulted, in others it may be required.
  10041. maxLength: 253
  10042. minLength: 1
  10043. pattern: ^[-._a-zA-Z0-9]+$
  10044. type: string
  10045. name:
  10046. description: The name of the Secret resource being referred to.
  10047. maxLength: 253
  10048. minLength: 1
  10049. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10050. type: string
  10051. namespace:
  10052. description: |-
  10053. The namespace of the Secret resource being referred to.
  10054. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10055. maxLength: 63
  10056. minLength: 1
  10057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10058. type: string
  10059. type: object
  10060. clientId:
  10061. description: The Azure clientId of the service principle or managed identity used for authentication.
  10062. properties:
  10063. key:
  10064. description: |-
  10065. A key in the referenced Secret.
  10066. Some instances of this field may be defaulted, in others it may be required.
  10067. maxLength: 253
  10068. minLength: 1
  10069. pattern: ^[-._a-zA-Z0-9]+$
  10070. type: string
  10071. name:
  10072. description: The name of the Secret resource being referred to.
  10073. maxLength: 253
  10074. minLength: 1
  10075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10076. type: string
  10077. namespace:
  10078. description: |-
  10079. The namespace of the Secret resource being referred to.
  10080. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10081. maxLength: 63
  10082. minLength: 1
  10083. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10084. type: string
  10085. type: object
  10086. clientSecret:
  10087. description: The Azure ClientSecret of the service principle used for authentication.
  10088. properties:
  10089. key:
  10090. description: |-
  10091. A key in the referenced Secret.
  10092. Some instances of this field may be defaulted, in others it may be required.
  10093. maxLength: 253
  10094. minLength: 1
  10095. pattern: ^[-._a-zA-Z0-9]+$
  10096. type: string
  10097. name:
  10098. description: The name of the Secret resource being referred to.
  10099. maxLength: 253
  10100. minLength: 1
  10101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10102. type: string
  10103. namespace:
  10104. description: |-
  10105. The namespace of the Secret resource being referred to.
  10106. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10107. maxLength: 63
  10108. minLength: 1
  10109. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10110. type: string
  10111. type: object
  10112. tenantId:
  10113. description: The Azure tenantId of the managed identity used for authentication.
  10114. properties:
  10115. key:
  10116. description: |-
  10117. A key in the referenced Secret.
  10118. Some instances of this field may be defaulted, in others it may be required.
  10119. maxLength: 253
  10120. minLength: 1
  10121. pattern: ^[-._a-zA-Z0-9]+$
  10122. type: string
  10123. name:
  10124. description: The name of the Secret resource being referred to.
  10125. maxLength: 253
  10126. minLength: 1
  10127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10128. type: string
  10129. namespace:
  10130. description: |-
  10131. The namespace of the Secret resource being referred to.
  10132. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10133. maxLength: 63
  10134. minLength: 1
  10135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10136. type: string
  10137. type: object
  10138. type: object
  10139. authType:
  10140. default: ServicePrincipal
  10141. description: |-
  10142. Auth type defines how to authenticate to the keyvault service.
  10143. Valid values are:
  10144. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  10145. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  10146. enum:
  10147. - ServicePrincipal
  10148. - ManagedIdentity
  10149. - WorkloadIdentity
  10150. type: string
  10151. environmentType:
  10152. default: PublicCloud
  10153. description: |-
  10154. EnvironmentType specifies the Azure cloud environment endpoints to use for
  10155. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  10156. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  10157. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  10158. enum:
  10159. - PublicCloud
  10160. - USGovernmentCloud
  10161. - ChinaCloud
  10162. - GermanCloud
  10163. type: string
  10164. identityId:
  10165. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  10166. type: string
  10167. serviceAccountRef:
  10168. description: |-
  10169. ServiceAccountRef specified the service account
  10170. that should be used when authenticating with WorkloadIdentity.
  10171. properties:
  10172. audiences:
  10173. description: |-
  10174. Audience specifies the `aud` claim for the service account token
  10175. Some providers automatically extend the audience field based on well-known annotations for workload
  10176. identity (e.g. IRSA or GCP Workload Identity)
  10177. items:
  10178. type: string
  10179. type: array
  10180. name:
  10181. description: The name of the ServiceAccount resource being referred to.
  10182. maxLength: 253
  10183. minLength: 1
  10184. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10185. type: string
  10186. namespace:
  10187. description: |-
  10188. Namespace of the resource being referred to.
  10189. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10190. maxLength: 63
  10191. minLength: 1
  10192. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10193. type: string
  10194. required:
  10195. - name
  10196. type: object
  10197. tenantId:
  10198. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  10199. type: string
  10200. vaultUrl:
  10201. description: Vault Url from which the secrets to be fetched from.
  10202. type: string
  10203. required:
  10204. - vaultUrl
  10205. type: object
  10206. beyondtrust:
  10207. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  10208. properties:
  10209. auth:
  10210. description: Auth configures how the operator authenticates with Beyondtrust.
  10211. properties:
  10212. apiKey:
  10213. description: APIKey If not provided then ClientID/ClientSecret become required.
  10214. properties:
  10215. secretRef:
  10216. description: SecretRef references a key in a secret that will be used as value.
  10217. properties:
  10218. key:
  10219. description: |-
  10220. A key in the referenced Secret.
  10221. Some instances of this field may be defaulted, in others it may be required.
  10222. maxLength: 253
  10223. minLength: 1
  10224. pattern: ^[-._a-zA-Z0-9]+$
  10225. type: string
  10226. name:
  10227. description: The name of the Secret resource being referred to.
  10228. maxLength: 253
  10229. minLength: 1
  10230. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10231. type: string
  10232. namespace:
  10233. description: |-
  10234. The namespace of the Secret resource being referred to.
  10235. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10236. maxLength: 63
  10237. minLength: 1
  10238. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10239. type: string
  10240. type: object
  10241. value:
  10242. description: Value can be specified directly to set a value without using a secret.
  10243. type: string
  10244. type: object
  10245. certificate:
  10246. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  10247. properties:
  10248. secretRef:
  10249. description: SecretRef references a key in a secret that will be used as value.
  10250. properties:
  10251. key:
  10252. description: |-
  10253. A key in the referenced Secret.
  10254. Some instances of this field may be defaulted, in others it may be required.
  10255. maxLength: 253
  10256. minLength: 1
  10257. pattern: ^[-._a-zA-Z0-9]+$
  10258. type: string
  10259. name:
  10260. description: The name of the Secret resource being referred to.
  10261. maxLength: 253
  10262. minLength: 1
  10263. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10264. type: string
  10265. namespace:
  10266. description: |-
  10267. The namespace of the Secret resource being referred to.
  10268. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10269. maxLength: 63
  10270. minLength: 1
  10271. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10272. type: string
  10273. type: object
  10274. value:
  10275. description: Value can be specified directly to set a value without using a secret.
  10276. type: string
  10277. type: object
  10278. certificateKey:
  10279. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  10280. properties:
  10281. secretRef:
  10282. description: SecretRef references a key in a secret that will be used as value.
  10283. properties:
  10284. key:
  10285. description: |-
  10286. A key in the referenced Secret.
  10287. Some instances of this field may be defaulted, in others it may be required.
  10288. maxLength: 253
  10289. minLength: 1
  10290. pattern: ^[-._a-zA-Z0-9]+$
  10291. type: string
  10292. name:
  10293. description: The name of the Secret resource being referred to.
  10294. maxLength: 253
  10295. minLength: 1
  10296. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10297. type: string
  10298. namespace:
  10299. description: |-
  10300. The namespace of the Secret resource being referred to.
  10301. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10302. maxLength: 63
  10303. minLength: 1
  10304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10305. type: string
  10306. type: object
  10307. value:
  10308. description: Value can be specified directly to set a value without using a secret.
  10309. type: string
  10310. type: object
  10311. clientId:
  10312. description: ClientID is the API OAuth Client ID.
  10313. properties:
  10314. secretRef:
  10315. description: SecretRef references a key in a secret that will be used as value.
  10316. properties:
  10317. key:
  10318. description: |-
  10319. A key in the referenced Secret.
  10320. Some instances of this field may be defaulted, in others it may be required.
  10321. maxLength: 253
  10322. minLength: 1
  10323. pattern: ^[-._a-zA-Z0-9]+$
  10324. type: string
  10325. name:
  10326. description: The name of the Secret resource being referred to.
  10327. maxLength: 253
  10328. minLength: 1
  10329. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10330. type: string
  10331. namespace:
  10332. description: |-
  10333. The namespace of the Secret resource being referred to.
  10334. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10335. maxLength: 63
  10336. minLength: 1
  10337. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10338. type: string
  10339. type: object
  10340. value:
  10341. description: Value can be specified directly to set a value without using a secret.
  10342. type: string
  10343. type: object
  10344. clientSecret:
  10345. description: ClientSecret is the API OAuth Client Secret.
  10346. properties:
  10347. secretRef:
  10348. description: SecretRef references a key in a secret that will be used as value.
  10349. properties:
  10350. key:
  10351. description: |-
  10352. A key in the referenced Secret.
  10353. Some instances of this field may be defaulted, in others it may be required.
  10354. maxLength: 253
  10355. minLength: 1
  10356. pattern: ^[-._a-zA-Z0-9]+$
  10357. type: string
  10358. name:
  10359. description: The name of the Secret resource being referred to.
  10360. maxLength: 253
  10361. minLength: 1
  10362. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10363. type: string
  10364. namespace:
  10365. description: |-
  10366. The namespace of the Secret resource being referred to.
  10367. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10368. maxLength: 63
  10369. minLength: 1
  10370. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10371. type: string
  10372. type: object
  10373. value:
  10374. description: Value can be specified directly to set a value without using a secret.
  10375. type: string
  10376. type: object
  10377. type: object
  10378. server:
  10379. description: Auth configures how API server works.
  10380. properties:
  10381. apiUrl:
  10382. type: string
  10383. apiVersion:
  10384. type: string
  10385. clientTimeOutSeconds:
  10386. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  10387. type: integer
  10388. decrypt:
  10389. default: true
  10390. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  10391. type: boolean
  10392. retrievalType:
  10393. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  10394. type: string
  10395. separator:
  10396. description: A character that separates the folder names.
  10397. type: string
  10398. verifyCA:
  10399. type: boolean
  10400. required:
  10401. - apiUrl
  10402. - verifyCA
  10403. type: object
  10404. required:
  10405. - auth
  10406. - server
  10407. type: object
  10408. bitwardensecretsmanager:
  10409. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  10410. properties:
  10411. apiURL:
  10412. type: string
  10413. auth:
  10414. description: |-
  10415. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  10416. Make sure that the token being used has permissions on the given secret.
  10417. properties:
  10418. secretRef:
  10419. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  10420. properties:
  10421. credentials:
  10422. description: AccessToken used for the bitwarden instance.
  10423. properties:
  10424. key:
  10425. description: |-
  10426. A key in the referenced Secret.
  10427. Some instances of this field may be defaulted, in others it may be required.
  10428. maxLength: 253
  10429. minLength: 1
  10430. pattern: ^[-._a-zA-Z0-9]+$
  10431. type: string
  10432. name:
  10433. description: The name of the Secret resource being referred to.
  10434. maxLength: 253
  10435. minLength: 1
  10436. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10437. type: string
  10438. namespace:
  10439. description: |-
  10440. The namespace of the Secret resource being referred to.
  10441. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10442. maxLength: 63
  10443. minLength: 1
  10444. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10445. type: string
  10446. type: object
  10447. required:
  10448. - credentials
  10449. type: object
  10450. required:
  10451. - secretRef
  10452. type: object
  10453. bitwardenServerSDKURL:
  10454. type: string
  10455. caBundle:
  10456. description: |-
  10457. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  10458. can be performed.
  10459. type: string
  10460. caProvider:
  10461. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  10462. properties:
  10463. key:
  10464. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10465. maxLength: 253
  10466. minLength: 1
  10467. pattern: ^[-._a-zA-Z0-9]+$
  10468. type: string
  10469. name:
  10470. description: The name of the object located at the provider type.
  10471. maxLength: 253
  10472. minLength: 1
  10473. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10474. type: string
  10475. namespace:
  10476. description: |-
  10477. The namespace the Provider type is in.
  10478. Can only be defined when used in a ClusterSecretStore.
  10479. maxLength: 63
  10480. minLength: 1
  10481. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10482. type: string
  10483. type:
  10484. description: The type of provider to use such as "Secret", or "ConfigMap".
  10485. enum:
  10486. - Secret
  10487. - ConfigMap
  10488. type: string
  10489. required:
  10490. - name
  10491. - type
  10492. type: object
  10493. identityURL:
  10494. type: string
  10495. organizationID:
  10496. description: OrganizationID determines which organization this secret store manages.
  10497. type: string
  10498. projectID:
  10499. description: ProjectID determines which project this secret store manages.
  10500. type: string
  10501. required:
  10502. - auth
  10503. - organizationID
  10504. - projectID
  10505. type: object
  10506. chef:
  10507. description: Chef configures this store to sync secrets with chef server
  10508. properties:
  10509. auth:
  10510. description: Auth defines the information necessary to authenticate against chef Server
  10511. properties:
  10512. secretRef:
  10513. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  10514. properties:
  10515. privateKeySecretRef:
  10516. description: SecretKey is the Signing Key in PEM format, used for authentication.
  10517. properties:
  10518. key:
  10519. description: |-
  10520. A key in the referenced Secret.
  10521. Some instances of this field may be defaulted, in others it may be required.
  10522. maxLength: 253
  10523. minLength: 1
  10524. pattern: ^[-._a-zA-Z0-9]+$
  10525. type: string
  10526. name:
  10527. description: The name of the Secret resource being referred to.
  10528. maxLength: 253
  10529. minLength: 1
  10530. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10531. type: string
  10532. namespace:
  10533. description: |-
  10534. The namespace of the Secret resource being referred to.
  10535. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10536. maxLength: 63
  10537. minLength: 1
  10538. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10539. type: string
  10540. type: object
  10541. required:
  10542. - privateKeySecretRef
  10543. type: object
  10544. required:
  10545. - secretRef
  10546. type: object
  10547. serverUrl:
  10548. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  10549. type: string
  10550. username:
  10551. description: UserName should be the user ID on the chef server
  10552. type: string
  10553. required:
  10554. - auth
  10555. - serverUrl
  10556. - username
  10557. type: object
  10558. cloudrusm:
  10559. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  10560. properties:
  10561. auth:
  10562. description: CSMAuth contains a secretRef for credentials.
  10563. properties:
  10564. secretRef:
  10565. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  10566. properties:
  10567. accessKeyIDSecretRef:
  10568. description: The AccessKeyID is used for authentication
  10569. properties:
  10570. key:
  10571. description: |-
  10572. A key in the referenced Secret.
  10573. Some instances of this field may be defaulted, in others it may be required.
  10574. maxLength: 253
  10575. minLength: 1
  10576. pattern: ^[-._a-zA-Z0-9]+$
  10577. type: string
  10578. name:
  10579. description: The name of the Secret resource being referred to.
  10580. maxLength: 253
  10581. minLength: 1
  10582. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10583. type: string
  10584. namespace:
  10585. description: |-
  10586. The namespace of the Secret resource being referred to.
  10587. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10588. maxLength: 63
  10589. minLength: 1
  10590. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10591. type: string
  10592. type: object
  10593. accessKeySecretSecretRef:
  10594. description: The AccessKeySecret is used for authentication
  10595. properties:
  10596. key:
  10597. description: |-
  10598. A key in the referenced Secret.
  10599. Some instances of this field may be defaulted, in others it may be required.
  10600. maxLength: 253
  10601. minLength: 1
  10602. pattern: ^[-._a-zA-Z0-9]+$
  10603. type: string
  10604. name:
  10605. description: The name of the Secret resource being referred to.
  10606. maxLength: 253
  10607. minLength: 1
  10608. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10609. type: string
  10610. namespace:
  10611. description: |-
  10612. The namespace of the Secret resource being referred to.
  10613. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10614. maxLength: 63
  10615. minLength: 1
  10616. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10617. type: string
  10618. type: object
  10619. required:
  10620. - accessKeyIDSecretRef
  10621. - accessKeySecretSecretRef
  10622. type: object
  10623. type: object
  10624. projectID:
  10625. description: ProjectID is the project, which the secrets are stored in.
  10626. type: string
  10627. required:
  10628. - auth
  10629. type: object
  10630. conjur:
  10631. description: Conjur configures this store to sync secrets using conjur provider
  10632. properties:
  10633. auth:
  10634. description: Defines authentication settings for connecting to Conjur.
  10635. properties:
  10636. apikey:
  10637. description: Authenticates with Conjur using an API key.
  10638. properties:
  10639. account:
  10640. description: Account is the Conjur organization account name.
  10641. type: string
  10642. apiKeyRef:
  10643. description: |-
  10644. A reference to a specific 'key' containing the Conjur API key
  10645. within a Secret resource. In some instances, `key` is a required field.
  10646. properties:
  10647. key:
  10648. description: |-
  10649. A key in the referenced Secret.
  10650. Some instances of this field may be defaulted, in others it may be required.
  10651. maxLength: 253
  10652. minLength: 1
  10653. pattern: ^[-._a-zA-Z0-9]+$
  10654. type: string
  10655. name:
  10656. description: The name of the Secret resource being referred to.
  10657. maxLength: 253
  10658. minLength: 1
  10659. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10660. type: string
  10661. namespace:
  10662. description: |-
  10663. The namespace of the Secret resource being referred to.
  10664. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10665. maxLength: 63
  10666. minLength: 1
  10667. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10668. type: string
  10669. type: object
  10670. userRef:
  10671. description: |-
  10672. A reference to a specific 'key' containing the Conjur username
  10673. within a Secret resource. In some instances, `key` is a required field.
  10674. properties:
  10675. key:
  10676. description: |-
  10677. A key in the referenced Secret.
  10678. Some instances of this field may be defaulted, in others it may be required.
  10679. maxLength: 253
  10680. minLength: 1
  10681. pattern: ^[-._a-zA-Z0-9]+$
  10682. type: string
  10683. name:
  10684. description: The name of the Secret resource being referred to.
  10685. maxLength: 253
  10686. minLength: 1
  10687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10688. type: string
  10689. namespace:
  10690. description: |-
  10691. The namespace of the Secret resource being referred to.
  10692. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10693. maxLength: 63
  10694. minLength: 1
  10695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10696. type: string
  10697. type: object
  10698. required:
  10699. - account
  10700. - apiKeyRef
  10701. - userRef
  10702. type: object
  10703. jwt:
  10704. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  10705. properties:
  10706. account:
  10707. description: Account is the Conjur organization account name.
  10708. type: string
  10709. hostId:
  10710. description: |-
  10711. Optional HostID for JWT authentication. This may be used depending
  10712. on how the Conjur JWT authenticator policy is configured.
  10713. type: string
  10714. secretRef:
  10715. description: |-
  10716. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  10717. authenticate with Conjur using the JWT authentication method.
  10718. properties:
  10719. key:
  10720. description: |-
  10721. A key in the referenced Secret.
  10722. Some instances of this field may be defaulted, in others it may be required.
  10723. maxLength: 253
  10724. minLength: 1
  10725. pattern: ^[-._a-zA-Z0-9]+$
  10726. type: string
  10727. name:
  10728. description: The name of the Secret resource being referred to.
  10729. maxLength: 253
  10730. minLength: 1
  10731. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10732. type: string
  10733. namespace:
  10734. description: |-
  10735. The namespace of the Secret resource being referred to.
  10736. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10737. maxLength: 63
  10738. minLength: 1
  10739. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10740. type: string
  10741. type: object
  10742. serviceAccountRef:
  10743. description: |-
  10744. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  10745. a token for with the `TokenRequest` API.
  10746. properties:
  10747. audiences:
  10748. description: |-
  10749. Audience specifies the `aud` claim for the service account token
  10750. Some providers automatically extend the audience field based on well-known annotations for workload
  10751. identity (e.g. IRSA or GCP Workload Identity)
  10752. items:
  10753. type: string
  10754. type: array
  10755. name:
  10756. description: The name of the ServiceAccount resource being referred to.
  10757. maxLength: 253
  10758. minLength: 1
  10759. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10760. type: string
  10761. namespace:
  10762. description: |-
  10763. Namespace of the resource being referred to.
  10764. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10765. maxLength: 63
  10766. minLength: 1
  10767. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10768. type: string
  10769. required:
  10770. - name
  10771. type: object
  10772. serviceID:
  10773. description: The conjur authn jwt webservice id
  10774. type: string
  10775. required:
  10776. - account
  10777. - serviceID
  10778. type: object
  10779. type: object
  10780. caBundle:
  10781. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  10782. type: string
  10783. caProvider:
  10784. description: |-
  10785. Used to provide custom certificate authority (CA) certificates
  10786. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  10787. that contains a PEM-encoded certificate.
  10788. properties:
  10789. key:
  10790. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10791. maxLength: 253
  10792. minLength: 1
  10793. pattern: ^[-._a-zA-Z0-9]+$
  10794. type: string
  10795. name:
  10796. description: The name of the object located at the provider type.
  10797. maxLength: 253
  10798. minLength: 1
  10799. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10800. type: string
  10801. namespace:
  10802. description: |-
  10803. The namespace the Provider type is in.
  10804. Can only be defined when used in a ClusterSecretStore.
  10805. maxLength: 63
  10806. minLength: 1
  10807. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10808. type: string
  10809. type:
  10810. description: The type of provider to use such as "Secret", or "ConfigMap".
  10811. enum:
  10812. - Secret
  10813. - ConfigMap
  10814. type: string
  10815. required:
  10816. - name
  10817. - type
  10818. type: object
  10819. url:
  10820. description: URL is the endpoint of the Conjur instance.
  10821. type: string
  10822. required:
  10823. - auth
  10824. - url
  10825. type: object
  10826. delinea:
  10827. description: |-
  10828. Delinea DevOps Secrets Vault
  10829. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  10830. properties:
  10831. clientId:
  10832. description: ClientID is the non-secret part of the credential.
  10833. properties:
  10834. secretRef:
  10835. description: SecretRef references a key in a secret that will be used as value.
  10836. properties:
  10837. key:
  10838. description: |-
  10839. A key in the referenced Secret.
  10840. Some instances of this field may be defaulted, in others it may be required.
  10841. maxLength: 253
  10842. minLength: 1
  10843. pattern: ^[-._a-zA-Z0-9]+$
  10844. type: string
  10845. name:
  10846. description: The name of the Secret resource being referred to.
  10847. maxLength: 253
  10848. minLength: 1
  10849. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10850. type: string
  10851. namespace:
  10852. description: |-
  10853. The namespace of the Secret resource being referred to.
  10854. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10855. maxLength: 63
  10856. minLength: 1
  10857. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10858. type: string
  10859. type: object
  10860. value:
  10861. description: Value can be specified directly to set a value without using a secret.
  10862. type: string
  10863. type: object
  10864. clientSecret:
  10865. description: ClientSecret is the secret part of the credential.
  10866. properties:
  10867. secretRef:
  10868. description: SecretRef references a key in a secret that will be used as value.
  10869. properties:
  10870. key:
  10871. description: |-
  10872. A key in the referenced Secret.
  10873. Some instances of this field may be defaulted, in others it may be required.
  10874. maxLength: 253
  10875. minLength: 1
  10876. pattern: ^[-._a-zA-Z0-9]+$
  10877. type: string
  10878. name:
  10879. description: The name of the Secret resource being referred to.
  10880. maxLength: 253
  10881. minLength: 1
  10882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10883. type: string
  10884. namespace:
  10885. description: |-
  10886. The namespace of the Secret resource being referred to.
  10887. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10888. maxLength: 63
  10889. minLength: 1
  10890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10891. type: string
  10892. type: object
  10893. value:
  10894. description: Value can be specified directly to set a value without using a secret.
  10895. type: string
  10896. type: object
  10897. tenant:
  10898. description: Tenant is the chosen hostname / site name.
  10899. type: string
  10900. tld:
  10901. description: |-
  10902. TLD is based on the server location that was chosen during provisioning.
  10903. If unset, defaults to "com".
  10904. type: string
  10905. urlTemplate:
  10906. description: |-
  10907. URLTemplate
  10908. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  10909. type: string
  10910. required:
  10911. - clientId
  10912. - clientSecret
  10913. - tenant
  10914. type: object
  10915. device42:
  10916. description: Device42 configures this store to sync secrets using the Device42 provider
  10917. properties:
  10918. auth:
  10919. description: Auth configures how secret-manager authenticates with a Device42 instance.
  10920. properties:
  10921. secretRef:
  10922. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  10923. properties:
  10924. credentials:
  10925. description: Username / Password is used for authentication.
  10926. properties:
  10927. key:
  10928. description: |-
  10929. A key in the referenced Secret.
  10930. Some instances of this field may be defaulted, in others it may be required.
  10931. maxLength: 253
  10932. minLength: 1
  10933. pattern: ^[-._a-zA-Z0-9]+$
  10934. type: string
  10935. name:
  10936. description: The name of the Secret resource being referred to.
  10937. maxLength: 253
  10938. minLength: 1
  10939. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10940. type: string
  10941. namespace:
  10942. description: |-
  10943. The namespace of the Secret resource being referred to.
  10944. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10945. maxLength: 63
  10946. minLength: 1
  10947. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10948. type: string
  10949. type: object
  10950. type: object
  10951. required:
  10952. - secretRef
  10953. type: object
  10954. host:
  10955. description: URL configures the Device42 instance URL.
  10956. type: string
  10957. required:
  10958. - auth
  10959. - host
  10960. type: object
  10961. doppler:
  10962. description: Doppler configures this store to sync secrets using the Doppler provider
  10963. properties:
  10964. auth:
  10965. description: Auth configures how the Operator authenticates with the Doppler API
  10966. properties:
  10967. secretRef:
  10968. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  10969. properties:
  10970. dopplerToken:
  10971. description: |-
  10972. The DopplerToken is used for authentication.
  10973. See https://docs.doppler.com/reference/api#authentication for auth token types.
  10974. The Key attribute defaults to dopplerToken if not specified.
  10975. properties:
  10976. key:
  10977. description: |-
  10978. A key in the referenced Secret.
  10979. Some instances of this field may be defaulted, in others it may be required.
  10980. maxLength: 253
  10981. minLength: 1
  10982. pattern: ^[-._a-zA-Z0-9]+$
  10983. type: string
  10984. name:
  10985. description: The name of the Secret resource being referred to.
  10986. maxLength: 253
  10987. minLength: 1
  10988. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10989. type: string
  10990. namespace:
  10991. description: |-
  10992. The namespace of the Secret resource being referred to.
  10993. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10994. maxLength: 63
  10995. minLength: 1
  10996. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10997. type: string
  10998. type: object
  10999. required:
  11000. - dopplerToken
  11001. type: object
  11002. required:
  11003. - secretRef
  11004. type: object
  11005. config:
  11006. description: Doppler config (required if not using a Service Token)
  11007. type: string
  11008. format:
  11009. description: Format enables the downloading of secrets as a file (string)
  11010. enum:
  11011. - json
  11012. - dotnet-json
  11013. - env
  11014. - yaml
  11015. - docker
  11016. type: string
  11017. nameTransformer:
  11018. description: Environment variable compatible name transforms that change secret names to a different format
  11019. enum:
  11020. - upper-camel
  11021. - camel
  11022. - lower-snake
  11023. - tf-var
  11024. - dotnet-env
  11025. - lower-kebab
  11026. type: string
  11027. project:
  11028. description: Doppler project (required if not using a Service Token)
  11029. type: string
  11030. required:
  11031. - auth
  11032. type: object
  11033. fake:
  11034. description: Fake configures a store with static key/value pairs
  11035. properties:
  11036. data:
  11037. items:
  11038. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  11039. properties:
  11040. key:
  11041. type: string
  11042. value:
  11043. type: string
  11044. version:
  11045. type: string
  11046. required:
  11047. - key
  11048. - value
  11049. type: object
  11050. type: array
  11051. required:
  11052. - data
  11053. type: object
  11054. fortanix:
  11055. description: Fortanix configures this store to sync secrets using the Fortanix provider
  11056. properties:
  11057. apiKey:
  11058. description: APIKey is the API token to access SDKMS Applications.
  11059. properties:
  11060. secretRef:
  11061. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  11062. properties:
  11063. key:
  11064. description: |-
  11065. A key in the referenced Secret.
  11066. Some instances of this field may be defaulted, in others it may be required.
  11067. maxLength: 253
  11068. minLength: 1
  11069. pattern: ^[-._a-zA-Z0-9]+$
  11070. type: string
  11071. name:
  11072. description: The name of the Secret resource being referred to.
  11073. maxLength: 253
  11074. minLength: 1
  11075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11076. type: string
  11077. namespace:
  11078. description: |-
  11079. The namespace of the Secret resource being referred to.
  11080. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11081. maxLength: 63
  11082. minLength: 1
  11083. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11084. type: string
  11085. type: object
  11086. type: object
  11087. apiUrl:
  11088. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  11089. type: string
  11090. type: object
  11091. gcpsm:
  11092. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  11093. properties:
  11094. auth:
  11095. description: Auth defines the information necessary to authenticate against GCP
  11096. properties:
  11097. secretRef:
  11098. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  11099. properties:
  11100. secretAccessKeySecretRef:
  11101. description: The SecretAccessKey is used for authentication
  11102. properties:
  11103. key:
  11104. description: |-
  11105. A key in the referenced Secret.
  11106. Some instances of this field may be defaulted, in others it may be required.
  11107. maxLength: 253
  11108. minLength: 1
  11109. pattern: ^[-._a-zA-Z0-9]+$
  11110. type: string
  11111. name:
  11112. description: The name of the Secret resource being referred to.
  11113. maxLength: 253
  11114. minLength: 1
  11115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11116. type: string
  11117. namespace:
  11118. description: |-
  11119. The namespace of the Secret resource being referred to.
  11120. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11121. maxLength: 63
  11122. minLength: 1
  11123. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11124. type: string
  11125. type: object
  11126. type: object
  11127. workloadIdentity:
  11128. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  11129. properties:
  11130. clusterLocation:
  11131. description: |-
  11132. ClusterLocation is the location of the cluster
  11133. If not specified, it fetches information from the metadata server
  11134. type: string
  11135. clusterName:
  11136. description: |-
  11137. ClusterName is the name of the cluster
  11138. If not specified, it fetches information from the metadata server
  11139. type: string
  11140. clusterProjectID:
  11141. description: |-
  11142. ClusterProjectID is the project ID of the cluster
  11143. If not specified, it fetches information from the metadata server
  11144. type: string
  11145. serviceAccountRef:
  11146. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  11147. properties:
  11148. audiences:
  11149. description: |-
  11150. Audience specifies the `aud` claim for the service account token
  11151. Some providers automatically extend the audience field based on well-known annotations for workload
  11152. identity (e.g. IRSA or GCP Workload Identity)
  11153. items:
  11154. type: string
  11155. type: array
  11156. name:
  11157. description: The name of the ServiceAccount resource being referred to.
  11158. maxLength: 253
  11159. minLength: 1
  11160. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11161. type: string
  11162. namespace:
  11163. description: |-
  11164. Namespace of the resource being referred to.
  11165. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11166. maxLength: 63
  11167. minLength: 1
  11168. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11169. type: string
  11170. required:
  11171. - name
  11172. type: object
  11173. required:
  11174. - serviceAccountRef
  11175. type: object
  11176. type: object
  11177. location:
  11178. description: Location optionally defines a location for a secret
  11179. type: string
  11180. projectID:
  11181. description: ProjectID project where secret is located
  11182. type: string
  11183. type: object
  11184. github:
  11185. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  11186. properties:
  11187. appID:
  11188. description: appID specifies the Github APP that will be used to authenticate the client
  11189. format: int64
  11190. type: integer
  11191. auth:
  11192. description: auth configures how secret-manager authenticates with a Github instance.
  11193. properties:
  11194. privateKey:
  11195. description: |-
  11196. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11197. In some instances, `key` is a required field.
  11198. properties:
  11199. key:
  11200. description: |-
  11201. A key in the referenced Secret.
  11202. Some instances of this field may be defaulted, in others it may be required.
  11203. maxLength: 253
  11204. minLength: 1
  11205. pattern: ^[-._a-zA-Z0-9]+$
  11206. type: string
  11207. name:
  11208. description: The name of the Secret resource being referred to.
  11209. maxLength: 253
  11210. minLength: 1
  11211. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11212. type: string
  11213. namespace:
  11214. description: |-
  11215. The namespace of the Secret resource being referred to.
  11216. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11217. maxLength: 63
  11218. minLength: 1
  11219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11220. type: string
  11221. type: object
  11222. required:
  11223. - privateKey
  11224. type: object
  11225. environment:
  11226. description: environment will be used to fetch secrets from a particular environment within a github repository
  11227. type: string
  11228. installationID:
  11229. description: installationID specifies the Github APP installation that will be used to authenticate the client
  11230. format: int64
  11231. type: integer
  11232. organization:
  11233. description: organization will be used to fetch secrets from the Github organization
  11234. type: string
  11235. repository:
  11236. description: repository will be used to fetch secrets from the Github repository within an organization
  11237. type: string
  11238. uploadURL:
  11239. description: Upload URL for enterprise instances. Default to URL.
  11240. type: string
  11241. url:
  11242. default: https://github.com/
  11243. description: URL configures the Github instance URL. Defaults to https://github.com/.
  11244. type: string
  11245. required:
  11246. - appID
  11247. - auth
  11248. - installationID
  11249. - organization
  11250. type: object
  11251. gitlab:
  11252. description: GitLab configures this store to sync secrets using GitLab Variables provider
  11253. properties:
  11254. auth:
  11255. description: Auth configures how secret-manager authenticates with a GitLab instance.
  11256. properties:
  11257. SecretRef:
  11258. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  11259. properties:
  11260. accessToken:
  11261. description: AccessToken is used for authentication.
  11262. properties:
  11263. key:
  11264. description: |-
  11265. A key in the referenced Secret.
  11266. Some instances of this field may be defaulted, in others it may be required.
  11267. maxLength: 253
  11268. minLength: 1
  11269. pattern: ^[-._a-zA-Z0-9]+$
  11270. type: string
  11271. name:
  11272. description: The name of the Secret resource being referred to.
  11273. maxLength: 253
  11274. minLength: 1
  11275. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11276. type: string
  11277. namespace:
  11278. description: |-
  11279. The namespace of the Secret resource being referred to.
  11280. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11281. maxLength: 63
  11282. minLength: 1
  11283. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11284. type: string
  11285. type: object
  11286. type: object
  11287. required:
  11288. - SecretRef
  11289. type: object
  11290. caBundle:
  11291. description: |-
  11292. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  11293. can be performed.
  11294. format: byte
  11295. type: string
  11296. caProvider:
  11297. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  11298. properties:
  11299. key:
  11300. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11301. maxLength: 253
  11302. minLength: 1
  11303. pattern: ^[-._a-zA-Z0-9]+$
  11304. type: string
  11305. name:
  11306. description: The name of the object located at the provider type.
  11307. maxLength: 253
  11308. minLength: 1
  11309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11310. type: string
  11311. namespace:
  11312. description: |-
  11313. The namespace the Provider type is in.
  11314. Can only be defined when used in a ClusterSecretStore.
  11315. maxLength: 63
  11316. minLength: 1
  11317. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11318. type: string
  11319. type:
  11320. description: The type of provider to use such as "Secret", or "ConfigMap".
  11321. enum:
  11322. - Secret
  11323. - ConfigMap
  11324. type: string
  11325. required:
  11326. - name
  11327. - type
  11328. type: object
  11329. environment:
  11330. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  11331. type: string
  11332. groupIDs:
  11333. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  11334. items:
  11335. type: string
  11336. type: array
  11337. inheritFromGroups:
  11338. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  11339. type: boolean
  11340. projectID:
  11341. description: ProjectID specifies a project where secrets are located.
  11342. type: string
  11343. url:
  11344. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  11345. type: string
  11346. required:
  11347. - auth
  11348. type: object
  11349. ibm:
  11350. description: IBM configures this store to sync secrets using IBM Cloud provider
  11351. properties:
  11352. auth:
  11353. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  11354. maxProperties: 1
  11355. minProperties: 1
  11356. properties:
  11357. containerAuth:
  11358. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  11359. properties:
  11360. iamEndpoint:
  11361. type: string
  11362. profile:
  11363. description: the IBM Trusted Profile
  11364. type: string
  11365. tokenLocation:
  11366. description: Location the token is mounted on the pod
  11367. type: string
  11368. required:
  11369. - profile
  11370. type: object
  11371. secretRef:
  11372. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  11373. properties:
  11374. secretApiKeySecretRef:
  11375. description: The SecretAccessKey is used for authentication
  11376. properties:
  11377. key:
  11378. description: |-
  11379. A key in the referenced Secret.
  11380. Some instances of this field may be defaulted, in others it may be required.
  11381. maxLength: 253
  11382. minLength: 1
  11383. pattern: ^[-._a-zA-Z0-9]+$
  11384. type: string
  11385. name:
  11386. description: The name of the Secret resource being referred to.
  11387. maxLength: 253
  11388. minLength: 1
  11389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11390. type: string
  11391. namespace:
  11392. description: |-
  11393. The namespace of the Secret resource being referred to.
  11394. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11395. maxLength: 63
  11396. minLength: 1
  11397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11398. type: string
  11399. type: object
  11400. type: object
  11401. type: object
  11402. serviceUrl:
  11403. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  11404. type: string
  11405. required:
  11406. - auth
  11407. type: object
  11408. infisical:
  11409. description: Infisical configures this store to sync secrets using the Infisical provider
  11410. properties:
  11411. auth:
  11412. description: Auth configures how the Operator authenticates with the Infisical API
  11413. properties:
  11414. universalAuthCredentials:
  11415. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  11416. properties:
  11417. clientId:
  11418. description: |-
  11419. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11420. In some instances, `key` is a required field.
  11421. properties:
  11422. key:
  11423. description: |-
  11424. A key in the referenced Secret.
  11425. Some instances of this field may be defaulted, in others it may be required.
  11426. maxLength: 253
  11427. minLength: 1
  11428. pattern: ^[-._a-zA-Z0-9]+$
  11429. type: string
  11430. name:
  11431. description: The name of the Secret resource being referred to.
  11432. maxLength: 253
  11433. minLength: 1
  11434. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11435. type: string
  11436. namespace:
  11437. description: |-
  11438. The namespace of the Secret resource being referred to.
  11439. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11440. maxLength: 63
  11441. minLength: 1
  11442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11443. type: string
  11444. type: object
  11445. clientSecret:
  11446. description: |-
  11447. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11448. In some instances, `key` is a required field.
  11449. properties:
  11450. key:
  11451. description: |-
  11452. A key in the referenced Secret.
  11453. Some instances of this field may be defaulted, in others it may be required.
  11454. maxLength: 253
  11455. minLength: 1
  11456. pattern: ^[-._a-zA-Z0-9]+$
  11457. type: string
  11458. name:
  11459. description: The name of the Secret resource being referred to.
  11460. maxLength: 253
  11461. minLength: 1
  11462. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11463. type: string
  11464. namespace:
  11465. description: |-
  11466. The namespace of the Secret resource being referred to.
  11467. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11468. maxLength: 63
  11469. minLength: 1
  11470. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11471. type: string
  11472. type: object
  11473. required:
  11474. - clientId
  11475. - clientSecret
  11476. type: object
  11477. type: object
  11478. hostAPI:
  11479. default: https://app.infisical.com/api
  11480. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  11481. type: string
  11482. secretsScope:
  11483. description: SecretsScope defines the scope of the secrets within the workspace
  11484. properties:
  11485. environmentSlug:
  11486. description: EnvironmentSlug is the required slug identifier for the environment.
  11487. type: string
  11488. expandSecretReferences:
  11489. default: true
  11490. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  11491. type: boolean
  11492. projectSlug:
  11493. description: ProjectSlug is the required slug identifier for the project.
  11494. type: string
  11495. recursive:
  11496. default: false
  11497. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  11498. type: boolean
  11499. secretsPath:
  11500. default: /
  11501. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  11502. type: string
  11503. required:
  11504. - environmentSlug
  11505. - projectSlug
  11506. type: object
  11507. required:
  11508. - auth
  11509. - secretsScope
  11510. type: object
  11511. keepersecurity:
  11512. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  11513. properties:
  11514. authRef:
  11515. description: |-
  11516. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11517. In some instances, `key` is a required field.
  11518. properties:
  11519. key:
  11520. description: |-
  11521. A key in the referenced Secret.
  11522. Some instances of this field may be defaulted, in others it may be required.
  11523. maxLength: 253
  11524. minLength: 1
  11525. pattern: ^[-._a-zA-Z0-9]+$
  11526. type: string
  11527. name:
  11528. description: The name of the Secret resource being referred to.
  11529. maxLength: 253
  11530. minLength: 1
  11531. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11532. type: string
  11533. namespace:
  11534. description: |-
  11535. The namespace of the Secret resource being referred to.
  11536. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11537. maxLength: 63
  11538. minLength: 1
  11539. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11540. type: string
  11541. type: object
  11542. folderID:
  11543. type: string
  11544. required:
  11545. - authRef
  11546. - folderID
  11547. type: object
  11548. kubernetes:
  11549. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  11550. properties:
  11551. auth:
  11552. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  11553. maxProperties: 1
  11554. minProperties: 1
  11555. properties:
  11556. cert:
  11557. description: has both clientCert and clientKey as secretKeySelector
  11558. properties:
  11559. clientCert:
  11560. description: |-
  11561. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11562. In some instances, `key` is a required field.
  11563. properties:
  11564. key:
  11565. description: |-
  11566. A key in the referenced Secret.
  11567. Some instances of this field may be defaulted, in others it may be required.
  11568. maxLength: 253
  11569. minLength: 1
  11570. pattern: ^[-._a-zA-Z0-9]+$
  11571. type: string
  11572. name:
  11573. description: The name of the Secret resource being referred to.
  11574. maxLength: 253
  11575. minLength: 1
  11576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11577. type: string
  11578. namespace:
  11579. description: |-
  11580. The namespace of the Secret resource being referred to.
  11581. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11582. maxLength: 63
  11583. minLength: 1
  11584. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11585. type: string
  11586. type: object
  11587. clientKey:
  11588. description: |-
  11589. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11590. In some instances, `key` is a required field.
  11591. properties:
  11592. key:
  11593. description: |-
  11594. A key in the referenced Secret.
  11595. Some instances of this field may be defaulted, in others it may be required.
  11596. maxLength: 253
  11597. minLength: 1
  11598. pattern: ^[-._a-zA-Z0-9]+$
  11599. type: string
  11600. name:
  11601. description: The name of the Secret resource being referred to.
  11602. maxLength: 253
  11603. minLength: 1
  11604. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11605. type: string
  11606. namespace:
  11607. description: |-
  11608. The namespace of the Secret resource being referred to.
  11609. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11610. maxLength: 63
  11611. minLength: 1
  11612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11613. type: string
  11614. type: object
  11615. type: object
  11616. serviceAccount:
  11617. description: points to a service account that should be used for authentication
  11618. properties:
  11619. audiences:
  11620. description: |-
  11621. Audience specifies the `aud` claim for the service account token
  11622. Some providers automatically extend the audience field based on well-known annotations for workload
  11623. identity (e.g. IRSA or GCP Workload Identity)
  11624. items:
  11625. type: string
  11626. type: array
  11627. name:
  11628. description: The name of the ServiceAccount resource being referred to.
  11629. maxLength: 253
  11630. minLength: 1
  11631. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11632. type: string
  11633. namespace:
  11634. description: |-
  11635. Namespace of the resource being referred to.
  11636. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11637. maxLength: 63
  11638. minLength: 1
  11639. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11640. type: string
  11641. required:
  11642. - name
  11643. type: object
  11644. token:
  11645. description: use static token to authenticate with
  11646. properties:
  11647. bearerToken:
  11648. description: |-
  11649. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11650. In some instances, `key` is a required field.
  11651. properties:
  11652. key:
  11653. description: |-
  11654. A key in the referenced Secret.
  11655. Some instances of this field may be defaulted, in others it may be required.
  11656. maxLength: 253
  11657. minLength: 1
  11658. pattern: ^[-._a-zA-Z0-9]+$
  11659. type: string
  11660. name:
  11661. description: The name of the Secret resource being referred to.
  11662. maxLength: 253
  11663. minLength: 1
  11664. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11665. type: string
  11666. namespace:
  11667. description: |-
  11668. The namespace of the Secret resource being referred to.
  11669. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11670. maxLength: 63
  11671. minLength: 1
  11672. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11673. type: string
  11674. type: object
  11675. type: object
  11676. type: object
  11677. authRef:
  11678. description: A reference to a secret that contains the auth information.
  11679. properties:
  11680. key:
  11681. description: |-
  11682. A key in the referenced Secret.
  11683. Some instances of this field may be defaulted, in others it may be required.
  11684. maxLength: 253
  11685. minLength: 1
  11686. pattern: ^[-._a-zA-Z0-9]+$
  11687. type: string
  11688. name:
  11689. description: The name of the Secret resource being referred to.
  11690. maxLength: 253
  11691. minLength: 1
  11692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11693. type: string
  11694. namespace:
  11695. description: |-
  11696. The namespace of the Secret resource being referred to.
  11697. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11698. maxLength: 63
  11699. minLength: 1
  11700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11701. type: string
  11702. type: object
  11703. remoteNamespace:
  11704. default: default
  11705. description: Remote namespace to fetch the secrets from
  11706. maxLength: 63
  11707. minLength: 1
  11708. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11709. type: string
  11710. server:
  11711. description: configures the Kubernetes server Address.
  11712. properties:
  11713. caBundle:
  11714. description: CABundle is a base64-encoded CA certificate
  11715. format: byte
  11716. type: string
  11717. caProvider:
  11718. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  11719. properties:
  11720. key:
  11721. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11722. maxLength: 253
  11723. minLength: 1
  11724. pattern: ^[-._a-zA-Z0-9]+$
  11725. type: string
  11726. name:
  11727. description: The name of the object located at the provider type.
  11728. maxLength: 253
  11729. minLength: 1
  11730. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11731. type: string
  11732. namespace:
  11733. description: |-
  11734. The namespace the Provider type is in.
  11735. Can only be defined when used in a ClusterSecretStore.
  11736. maxLength: 63
  11737. minLength: 1
  11738. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11739. type: string
  11740. type:
  11741. description: The type of provider to use such as "Secret", or "ConfigMap".
  11742. enum:
  11743. - Secret
  11744. - ConfigMap
  11745. type: string
  11746. required:
  11747. - name
  11748. - type
  11749. type: object
  11750. url:
  11751. default: kubernetes.default
  11752. description: configures the Kubernetes server Address.
  11753. type: string
  11754. type: object
  11755. type: object
  11756. onboardbase:
  11757. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  11758. properties:
  11759. apiHost:
  11760. default: https://public.onboardbase.com/api/v1/
  11761. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  11762. type: string
  11763. auth:
  11764. description: Auth configures how the Operator authenticates with the Onboardbase API
  11765. properties:
  11766. apiKeyRef:
  11767. description: |-
  11768. OnboardbaseAPIKey is the APIKey generated by an admin account.
  11769. It is used to recognize and authorize access to a project and environment within onboardbase
  11770. properties:
  11771. key:
  11772. description: |-
  11773. A key in the referenced Secret.
  11774. Some instances of this field may be defaulted, in others it may be required.
  11775. maxLength: 253
  11776. minLength: 1
  11777. pattern: ^[-._a-zA-Z0-9]+$
  11778. type: string
  11779. name:
  11780. description: The name of the Secret resource being referred to.
  11781. maxLength: 253
  11782. minLength: 1
  11783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11784. type: string
  11785. namespace:
  11786. description: |-
  11787. The namespace of the Secret resource being referred to.
  11788. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11789. maxLength: 63
  11790. minLength: 1
  11791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11792. type: string
  11793. type: object
  11794. passcodeRef:
  11795. description: OnboardbasePasscode is the passcode attached to the API Key
  11796. properties:
  11797. key:
  11798. description: |-
  11799. A key in the referenced Secret.
  11800. Some instances of this field may be defaulted, in others it may be required.
  11801. maxLength: 253
  11802. minLength: 1
  11803. pattern: ^[-._a-zA-Z0-9]+$
  11804. type: string
  11805. name:
  11806. description: The name of the Secret resource being referred to.
  11807. maxLength: 253
  11808. minLength: 1
  11809. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11810. type: string
  11811. namespace:
  11812. description: |-
  11813. The namespace of the Secret resource being referred to.
  11814. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11815. maxLength: 63
  11816. minLength: 1
  11817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11818. type: string
  11819. type: object
  11820. required:
  11821. - apiKeyRef
  11822. - passcodeRef
  11823. type: object
  11824. environment:
  11825. default: development
  11826. description: Environment is the name of an environmnent within a project to pull the secrets from
  11827. type: string
  11828. project:
  11829. default: development
  11830. description: Project is an onboardbase project that the secrets should be pulled from
  11831. type: string
  11832. required:
  11833. - apiHost
  11834. - auth
  11835. - environment
  11836. - project
  11837. type: object
  11838. onepassword:
  11839. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  11840. properties:
  11841. auth:
  11842. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  11843. properties:
  11844. secretRef:
  11845. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  11846. properties:
  11847. connectTokenSecretRef:
  11848. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  11849. properties:
  11850. key:
  11851. description: |-
  11852. A key in the referenced Secret.
  11853. Some instances of this field may be defaulted, in others it may be required.
  11854. maxLength: 253
  11855. minLength: 1
  11856. pattern: ^[-._a-zA-Z0-9]+$
  11857. type: string
  11858. name:
  11859. description: The name of the Secret resource being referred to.
  11860. maxLength: 253
  11861. minLength: 1
  11862. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11863. type: string
  11864. namespace:
  11865. description: |-
  11866. The namespace of the Secret resource being referred to.
  11867. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11868. maxLength: 63
  11869. minLength: 1
  11870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11871. type: string
  11872. type: object
  11873. required:
  11874. - connectTokenSecretRef
  11875. type: object
  11876. required:
  11877. - secretRef
  11878. type: object
  11879. connectHost:
  11880. description: ConnectHost defines the OnePassword Connect Server to connect to
  11881. type: string
  11882. vaults:
  11883. additionalProperties:
  11884. type: integer
  11885. description: Vaults defines which OnePassword vaults to search in which order
  11886. type: object
  11887. required:
  11888. - auth
  11889. - connectHost
  11890. - vaults
  11891. type: object
  11892. oracle:
  11893. description: Oracle configures this store to sync secrets using Oracle Vault provider
  11894. properties:
  11895. auth:
  11896. description: |-
  11897. Auth configures how secret-manager authenticates with the Oracle Vault.
  11898. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  11899. properties:
  11900. secretRef:
  11901. description: SecretRef to pass through sensitive information.
  11902. properties:
  11903. fingerprint:
  11904. description: Fingerprint is the fingerprint of the API private key.
  11905. properties:
  11906. key:
  11907. description: |-
  11908. A key in the referenced Secret.
  11909. Some instances of this field may be defaulted, in others it may be required.
  11910. maxLength: 253
  11911. minLength: 1
  11912. pattern: ^[-._a-zA-Z0-9]+$
  11913. type: string
  11914. name:
  11915. description: The name of the Secret resource being referred to.
  11916. maxLength: 253
  11917. minLength: 1
  11918. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11919. type: string
  11920. namespace:
  11921. description: |-
  11922. The namespace of the Secret resource being referred to.
  11923. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11924. maxLength: 63
  11925. minLength: 1
  11926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11927. type: string
  11928. type: object
  11929. privatekey:
  11930. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  11931. properties:
  11932. key:
  11933. description: |-
  11934. A key in the referenced Secret.
  11935. Some instances of this field may be defaulted, in others it may be required.
  11936. maxLength: 253
  11937. minLength: 1
  11938. pattern: ^[-._a-zA-Z0-9]+$
  11939. type: string
  11940. name:
  11941. description: The name of the Secret resource being referred to.
  11942. maxLength: 253
  11943. minLength: 1
  11944. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11945. type: string
  11946. namespace:
  11947. description: |-
  11948. The namespace of the Secret resource being referred to.
  11949. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11950. maxLength: 63
  11951. minLength: 1
  11952. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11953. type: string
  11954. type: object
  11955. required:
  11956. - fingerprint
  11957. - privatekey
  11958. type: object
  11959. tenancy:
  11960. description: Tenancy is the tenancy OCID where user is located.
  11961. type: string
  11962. user:
  11963. description: User is an access OCID specific to the account.
  11964. type: string
  11965. required:
  11966. - secretRef
  11967. - tenancy
  11968. - user
  11969. type: object
  11970. compartment:
  11971. description: |-
  11972. Compartment is the vault compartment OCID.
  11973. Required for PushSecret
  11974. type: string
  11975. encryptionKey:
  11976. description: |-
  11977. EncryptionKey is the OCID of the encryption key within the vault.
  11978. Required for PushSecret
  11979. type: string
  11980. principalType:
  11981. description: |-
  11982. The type of principal to use for authentication. If left blank, the Auth struct will
  11983. determine the principal type. This optional field must be specified if using
  11984. workload identity.
  11985. enum:
  11986. - ""
  11987. - UserPrincipal
  11988. - InstancePrincipal
  11989. - Workload
  11990. type: string
  11991. region:
  11992. description: Region is the region where vault is located.
  11993. type: string
  11994. serviceAccountRef:
  11995. description: |-
  11996. ServiceAccountRef specified the service account
  11997. that should be used when authenticating with WorkloadIdentity.
  11998. properties:
  11999. audiences:
  12000. description: |-
  12001. Audience specifies the `aud` claim for the service account token
  12002. Some providers automatically extend the audience field based on well-known annotations for workload
  12003. identity (e.g. IRSA or GCP Workload Identity)
  12004. items:
  12005. type: string
  12006. type: array
  12007. name:
  12008. description: The name of the ServiceAccount resource being referred to.
  12009. maxLength: 253
  12010. minLength: 1
  12011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12012. type: string
  12013. namespace:
  12014. description: |-
  12015. Namespace of the resource being referred to.
  12016. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12017. maxLength: 63
  12018. minLength: 1
  12019. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12020. type: string
  12021. required:
  12022. - name
  12023. type: object
  12024. vault:
  12025. description: Vault is the vault's OCID of the specific vault where secret is located.
  12026. type: string
  12027. required:
  12028. - region
  12029. - vault
  12030. type: object
  12031. passbolt:
  12032. description: PassboltProvider defines configuration for the Passbolt provider.
  12033. properties:
  12034. auth:
  12035. description: Auth defines the information necessary to authenticate against Passbolt Server
  12036. properties:
  12037. passwordSecretRef:
  12038. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  12039. properties:
  12040. key:
  12041. description: |-
  12042. A key in the referenced Secret.
  12043. Some instances of this field may be defaulted, in others it may be required.
  12044. maxLength: 253
  12045. minLength: 1
  12046. pattern: ^[-._a-zA-Z0-9]+$
  12047. type: string
  12048. name:
  12049. description: The name of the Secret resource being referred to.
  12050. maxLength: 253
  12051. minLength: 1
  12052. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12053. type: string
  12054. namespace:
  12055. description: |-
  12056. The namespace of the Secret resource being referred to.
  12057. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12058. maxLength: 63
  12059. minLength: 1
  12060. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12061. type: string
  12062. type: object
  12063. privateKeySecretRef:
  12064. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  12065. properties:
  12066. key:
  12067. description: |-
  12068. A key in the referenced Secret.
  12069. Some instances of this field may be defaulted, in others it may be required.
  12070. maxLength: 253
  12071. minLength: 1
  12072. pattern: ^[-._a-zA-Z0-9]+$
  12073. type: string
  12074. name:
  12075. description: The name of the Secret resource being referred to.
  12076. maxLength: 253
  12077. minLength: 1
  12078. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12079. type: string
  12080. namespace:
  12081. description: |-
  12082. The namespace of the Secret resource being referred to.
  12083. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12084. maxLength: 63
  12085. minLength: 1
  12086. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12087. type: string
  12088. type: object
  12089. required:
  12090. - passwordSecretRef
  12091. - privateKeySecretRef
  12092. type: object
  12093. host:
  12094. description: Host defines the Passbolt Server to connect to
  12095. type: string
  12096. required:
  12097. - auth
  12098. - host
  12099. type: object
  12100. passworddepot:
  12101. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  12102. properties:
  12103. auth:
  12104. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  12105. properties:
  12106. secretRef:
  12107. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  12108. properties:
  12109. credentials:
  12110. description: Username / Password is used for authentication.
  12111. properties:
  12112. key:
  12113. description: |-
  12114. A key in the referenced Secret.
  12115. Some instances of this field may be defaulted, in others it may be required.
  12116. maxLength: 253
  12117. minLength: 1
  12118. pattern: ^[-._a-zA-Z0-9]+$
  12119. type: string
  12120. name:
  12121. description: The name of the Secret resource being referred to.
  12122. maxLength: 253
  12123. minLength: 1
  12124. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12125. type: string
  12126. namespace:
  12127. description: |-
  12128. The namespace of the Secret resource being referred to.
  12129. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12130. maxLength: 63
  12131. minLength: 1
  12132. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12133. type: string
  12134. type: object
  12135. type: object
  12136. required:
  12137. - secretRef
  12138. type: object
  12139. database:
  12140. description: Database to use as source
  12141. type: string
  12142. host:
  12143. description: URL configures the Password Depot instance URL.
  12144. type: string
  12145. required:
  12146. - auth
  12147. - database
  12148. - host
  12149. type: object
  12150. previder:
  12151. description: Previder configures this store to sync secrets using the Previder provider
  12152. properties:
  12153. auth:
  12154. description: PreviderAuth contains a secretRef for credentials.
  12155. properties:
  12156. secretRef:
  12157. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  12158. properties:
  12159. accessToken:
  12160. description: The AccessToken is used for authentication
  12161. properties:
  12162. key:
  12163. description: |-
  12164. A key in the referenced Secret.
  12165. Some instances of this field may be defaulted, in others it may be required.
  12166. maxLength: 253
  12167. minLength: 1
  12168. pattern: ^[-._a-zA-Z0-9]+$
  12169. type: string
  12170. name:
  12171. description: The name of the Secret resource being referred to.
  12172. maxLength: 253
  12173. minLength: 1
  12174. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12175. type: string
  12176. namespace:
  12177. description: |-
  12178. The namespace of the Secret resource being referred to.
  12179. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12180. maxLength: 63
  12181. minLength: 1
  12182. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12183. type: string
  12184. type: object
  12185. required:
  12186. - accessToken
  12187. type: object
  12188. type: object
  12189. baseUri:
  12190. type: string
  12191. required:
  12192. - auth
  12193. type: object
  12194. pulumi:
  12195. description: Pulumi configures this store to sync secrets using the Pulumi provider
  12196. properties:
  12197. accessToken:
  12198. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  12199. properties:
  12200. secretRef:
  12201. description: SecretRef is a reference to a secret containing the Pulumi API token.
  12202. properties:
  12203. key:
  12204. description: |-
  12205. A key in the referenced Secret.
  12206. Some instances of this field may be defaulted, in others it may be required.
  12207. maxLength: 253
  12208. minLength: 1
  12209. pattern: ^[-._a-zA-Z0-9]+$
  12210. type: string
  12211. name:
  12212. description: The name of the Secret resource being referred to.
  12213. maxLength: 253
  12214. minLength: 1
  12215. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12216. type: string
  12217. namespace:
  12218. description: |-
  12219. The namespace of the Secret resource being referred to.
  12220. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12221. maxLength: 63
  12222. minLength: 1
  12223. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12224. type: string
  12225. type: object
  12226. type: object
  12227. apiUrl:
  12228. default: https://api.pulumi.com/api/esc
  12229. description: APIURL is the URL of the Pulumi API.
  12230. type: string
  12231. environment:
  12232. description: |-
  12233. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  12234. dynamically retrieved values from supported providers including all major clouds,
  12235. and other Pulumi ESC environments.
  12236. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  12237. type: string
  12238. organization:
  12239. description: |-
  12240. Organization are a space to collaborate on shared projects and stacks.
  12241. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  12242. type: string
  12243. project:
  12244. description: Project is the name of the Pulumi ESC project the environment belongs to.
  12245. type: string
  12246. required:
  12247. - accessToken
  12248. - environment
  12249. - organization
  12250. - project
  12251. type: object
  12252. scaleway:
  12253. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  12254. properties:
  12255. accessKey:
  12256. description: AccessKey is the non-secret part of the api key.
  12257. properties:
  12258. secretRef:
  12259. description: SecretRef references a key in a secret that will be used as value.
  12260. properties:
  12261. key:
  12262. description: |-
  12263. A key in the referenced Secret.
  12264. Some instances of this field may be defaulted, in others it may be required.
  12265. maxLength: 253
  12266. minLength: 1
  12267. pattern: ^[-._a-zA-Z0-9]+$
  12268. type: string
  12269. name:
  12270. description: The name of the Secret resource being referred to.
  12271. maxLength: 253
  12272. minLength: 1
  12273. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12274. type: string
  12275. namespace:
  12276. description: |-
  12277. The namespace of the Secret resource being referred to.
  12278. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12279. maxLength: 63
  12280. minLength: 1
  12281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12282. type: string
  12283. type: object
  12284. value:
  12285. description: Value can be specified directly to set a value without using a secret.
  12286. type: string
  12287. type: object
  12288. apiUrl:
  12289. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  12290. type: string
  12291. projectId:
  12292. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  12293. type: string
  12294. region:
  12295. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  12296. type: string
  12297. secretKey:
  12298. description: SecretKey is the non-secret part of the api key.
  12299. properties:
  12300. secretRef:
  12301. description: SecretRef references a key in a secret that will be used as value.
  12302. properties:
  12303. key:
  12304. description: |-
  12305. A key in the referenced Secret.
  12306. Some instances of this field may be defaulted, in others it may be required.
  12307. maxLength: 253
  12308. minLength: 1
  12309. pattern: ^[-._a-zA-Z0-9]+$
  12310. type: string
  12311. name:
  12312. description: The name of the Secret resource being referred to.
  12313. maxLength: 253
  12314. minLength: 1
  12315. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12316. type: string
  12317. namespace:
  12318. description: |-
  12319. The namespace of the Secret resource being referred to.
  12320. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12321. maxLength: 63
  12322. minLength: 1
  12323. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12324. type: string
  12325. type: object
  12326. value:
  12327. description: Value can be specified directly to set a value without using a secret.
  12328. type: string
  12329. type: object
  12330. required:
  12331. - accessKey
  12332. - projectId
  12333. - region
  12334. - secretKey
  12335. type: object
  12336. secretserver:
  12337. description: |-
  12338. SecretServer configures this store to sync secrets using SecretServer provider
  12339. https://docs.delinea.com/online-help/secret-server/start.htm
  12340. properties:
  12341. password:
  12342. description: Password is the secret server account password.
  12343. properties:
  12344. secretRef:
  12345. description: SecretRef references a key in a secret that will be used as value.
  12346. properties:
  12347. key:
  12348. description: |-
  12349. A key in the referenced Secret.
  12350. Some instances of this field may be defaulted, in others it may be required.
  12351. maxLength: 253
  12352. minLength: 1
  12353. pattern: ^[-._a-zA-Z0-9]+$
  12354. type: string
  12355. name:
  12356. description: The name of the Secret resource being referred to.
  12357. maxLength: 253
  12358. minLength: 1
  12359. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12360. type: string
  12361. namespace:
  12362. description: |-
  12363. The namespace of the Secret resource being referred to.
  12364. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12365. maxLength: 63
  12366. minLength: 1
  12367. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12368. type: string
  12369. type: object
  12370. value:
  12371. description: Value can be specified directly to set a value without using a secret.
  12372. type: string
  12373. type: object
  12374. serverURL:
  12375. description: |-
  12376. ServerURL
  12377. URL to your secret server installation
  12378. type: string
  12379. username:
  12380. description: Username is the secret server account username.
  12381. properties:
  12382. secretRef:
  12383. description: SecretRef references a key in a secret that will be used as value.
  12384. properties:
  12385. key:
  12386. description: |-
  12387. A key in the referenced Secret.
  12388. Some instances of this field may be defaulted, in others it may be required.
  12389. maxLength: 253
  12390. minLength: 1
  12391. pattern: ^[-._a-zA-Z0-9]+$
  12392. type: string
  12393. name:
  12394. description: The name of the Secret resource being referred to.
  12395. maxLength: 253
  12396. minLength: 1
  12397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12398. type: string
  12399. namespace:
  12400. description: |-
  12401. The namespace of the Secret resource being referred to.
  12402. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12403. maxLength: 63
  12404. minLength: 1
  12405. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12406. type: string
  12407. type: object
  12408. value:
  12409. description: Value can be specified directly to set a value without using a secret.
  12410. type: string
  12411. type: object
  12412. required:
  12413. - password
  12414. - serverURL
  12415. - username
  12416. type: object
  12417. senhasegura:
  12418. description: Senhasegura configures this store to sync secrets using senhasegura provider
  12419. properties:
  12420. auth:
  12421. description: Auth defines parameters to authenticate in senhasegura
  12422. properties:
  12423. clientId:
  12424. type: string
  12425. clientSecretSecretRef:
  12426. description: |-
  12427. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  12428. In some instances, `key` is a required field.
  12429. properties:
  12430. key:
  12431. description: |-
  12432. A key in the referenced Secret.
  12433. Some instances of this field may be defaulted, in others it may be required.
  12434. maxLength: 253
  12435. minLength: 1
  12436. pattern: ^[-._a-zA-Z0-9]+$
  12437. type: string
  12438. name:
  12439. description: The name of the Secret resource being referred to.
  12440. maxLength: 253
  12441. minLength: 1
  12442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12443. type: string
  12444. namespace:
  12445. description: |-
  12446. The namespace of the Secret resource being referred to.
  12447. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12448. maxLength: 63
  12449. minLength: 1
  12450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12451. type: string
  12452. type: object
  12453. required:
  12454. - clientId
  12455. - clientSecretSecretRef
  12456. type: object
  12457. ignoreSslCertificate:
  12458. default: false
  12459. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  12460. type: boolean
  12461. module:
  12462. description: Module defines which senhasegura module should be used to get secrets
  12463. type: string
  12464. url:
  12465. description: URL of senhasegura
  12466. type: string
  12467. required:
  12468. - auth
  12469. - module
  12470. - url
  12471. type: object
  12472. vault:
  12473. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  12474. properties:
  12475. auth:
  12476. description: Auth configures how secret-manager authenticates with the Vault server.
  12477. properties:
  12478. appRole:
  12479. description: |-
  12480. AppRole authenticates with Vault using the App Role auth mechanism,
  12481. with the role and secret stored in a Kubernetes Secret resource.
  12482. properties:
  12483. path:
  12484. default: approle
  12485. description: |-
  12486. Path where the App Role authentication backend is mounted
  12487. in Vault, e.g: "approle"
  12488. type: string
  12489. roleId:
  12490. description: |-
  12491. RoleID configured in the App Role authentication backend when setting
  12492. up the authentication backend in Vault.
  12493. type: string
  12494. roleRef:
  12495. description: |-
  12496. Reference to a key in a Secret that contains the App Role ID used
  12497. to authenticate with Vault.
  12498. The `key` field must be specified and denotes which entry within the Secret
  12499. resource is used as the app role id.
  12500. properties:
  12501. key:
  12502. description: |-
  12503. A key in the referenced Secret.
  12504. Some instances of this field may be defaulted, in others it may be required.
  12505. maxLength: 253
  12506. minLength: 1
  12507. pattern: ^[-._a-zA-Z0-9]+$
  12508. type: string
  12509. name:
  12510. description: The name of the Secret resource being referred to.
  12511. maxLength: 253
  12512. minLength: 1
  12513. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12514. type: string
  12515. namespace:
  12516. description: |-
  12517. The namespace of the Secret resource being referred to.
  12518. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12519. maxLength: 63
  12520. minLength: 1
  12521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12522. type: string
  12523. type: object
  12524. secretRef:
  12525. description: |-
  12526. Reference to a key in a Secret that contains the App Role secret used
  12527. to authenticate with Vault.
  12528. The `key` field must be specified and denotes which entry within the Secret
  12529. resource is used as the app role secret.
  12530. properties:
  12531. key:
  12532. description: |-
  12533. A key in the referenced Secret.
  12534. Some instances of this field may be defaulted, in others it may be required.
  12535. maxLength: 253
  12536. minLength: 1
  12537. pattern: ^[-._a-zA-Z0-9]+$
  12538. type: string
  12539. name:
  12540. description: The name of the Secret resource being referred to.
  12541. maxLength: 253
  12542. minLength: 1
  12543. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12544. type: string
  12545. namespace:
  12546. description: |-
  12547. The namespace of the Secret resource being referred to.
  12548. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12549. maxLength: 63
  12550. minLength: 1
  12551. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12552. type: string
  12553. type: object
  12554. required:
  12555. - path
  12556. - secretRef
  12557. type: object
  12558. cert:
  12559. description: |-
  12560. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  12561. Cert authentication method
  12562. properties:
  12563. clientCert:
  12564. description: |-
  12565. ClientCert is a certificate to authenticate using the Cert Vault
  12566. authentication method
  12567. properties:
  12568. key:
  12569. description: |-
  12570. A key in the referenced Secret.
  12571. Some instances of this field may be defaulted, in others it may be required.
  12572. maxLength: 253
  12573. minLength: 1
  12574. pattern: ^[-._a-zA-Z0-9]+$
  12575. type: string
  12576. name:
  12577. description: The name of the Secret resource being referred to.
  12578. maxLength: 253
  12579. minLength: 1
  12580. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12581. type: string
  12582. namespace:
  12583. description: |-
  12584. The namespace of the Secret resource being referred to.
  12585. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12586. maxLength: 63
  12587. minLength: 1
  12588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12589. type: string
  12590. type: object
  12591. secretRef:
  12592. description: |-
  12593. SecretRef to a key in a Secret resource containing client private key to
  12594. authenticate with Vault using the Cert authentication method
  12595. properties:
  12596. key:
  12597. description: |-
  12598. A key in the referenced Secret.
  12599. Some instances of this field may be defaulted, in others it may be required.
  12600. maxLength: 253
  12601. minLength: 1
  12602. pattern: ^[-._a-zA-Z0-9]+$
  12603. type: string
  12604. name:
  12605. description: The name of the Secret resource being referred to.
  12606. maxLength: 253
  12607. minLength: 1
  12608. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12609. type: string
  12610. namespace:
  12611. description: |-
  12612. The namespace of the Secret resource being referred to.
  12613. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12614. maxLength: 63
  12615. minLength: 1
  12616. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12617. type: string
  12618. type: object
  12619. type: object
  12620. iam:
  12621. description: |-
  12622. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  12623. AWS IAM authentication method
  12624. properties:
  12625. externalID:
  12626. description: AWS External ID set on assumed IAM roles
  12627. type: string
  12628. jwt:
  12629. description: Specify a service account with IRSA enabled
  12630. properties:
  12631. serviceAccountRef:
  12632. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  12633. properties:
  12634. audiences:
  12635. description: |-
  12636. Audience specifies the `aud` claim for the service account token
  12637. Some providers automatically extend the audience field based on well-known annotations for workload
  12638. identity (e.g. IRSA or GCP Workload Identity)
  12639. items:
  12640. type: string
  12641. type: array
  12642. name:
  12643. description: The name of the ServiceAccount resource being referred to.
  12644. maxLength: 253
  12645. minLength: 1
  12646. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12647. type: string
  12648. namespace:
  12649. description: |-
  12650. Namespace of the resource being referred to.
  12651. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12652. maxLength: 63
  12653. minLength: 1
  12654. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12655. type: string
  12656. required:
  12657. - name
  12658. type: object
  12659. type: object
  12660. path:
  12661. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  12662. type: string
  12663. region:
  12664. description: AWS region
  12665. type: string
  12666. role:
  12667. description: This is the AWS role to be assumed before talking to vault
  12668. type: string
  12669. secretRef:
  12670. description: Specify credentials in a Secret object
  12671. properties:
  12672. accessKeyIDSecretRef:
  12673. description: The AccessKeyID is used for authentication
  12674. properties:
  12675. key:
  12676. description: |-
  12677. A key in the referenced Secret.
  12678. Some instances of this field may be defaulted, in others it may be required.
  12679. maxLength: 253
  12680. minLength: 1
  12681. pattern: ^[-._a-zA-Z0-9]+$
  12682. type: string
  12683. name:
  12684. description: The name of the Secret resource being referred to.
  12685. maxLength: 253
  12686. minLength: 1
  12687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12688. type: string
  12689. namespace:
  12690. description: |-
  12691. The namespace of the Secret resource being referred to.
  12692. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12693. maxLength: 63
  12694. minLength: 1
  12695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12696. type: string
  12697. type: object
  12698. secretAccessKeySecretRef:
  12699. description: The SecretAccessKey is used for authentication
  12700. properties:
  12701. key:
  12702. description: |-
  12703. A key in the referenced Secret.
  12704. Some instances of this field may be defaulted, in others it may be required.
  12705. maxLength: 253
  12706. minLength: 1
  12707. pattern: ^[-._a-zA-Z0-9]+$
  12708. type: string
  12709. name:
  12710. description: The name of the Secret resource being referred to.
  12711. maxLength: 253
  12712. minLength: 1
  12713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12714. type: string
  12715. namespace:
  12716. description: |-
  12717. The namespace of the Secret resource being referred to.
  12718. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12719. maxLength: 63
  12720. minLength: 1
  12721. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12722. type: string
  12723. type: object
  12724. sessionTokenSecretRef:
  12725. description: |-
  12726. The SessionToken used for authentication
  12727. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  12728. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  12729. properties:
  12730. key:
  12731. description: |-
  12732. A key in the referenced Secret.
  12733. Some instances of this field may be defaulted, in others it may be required.
  12734. maxLength: 253
  12735. minLength: 1
  12736. pattern: ^[-._a-zA-Z0-9]+$
  12737. type: string
  12738. name:
  12739. description: The name of the Secret resource being referred to.
  12740. maxLength: 253
  12741. minLength: 1
  12742. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12743. type: string
  12744. namespace:
  12745. description: |-
  12746. The namespace of the Secret resource being referred to.
  12747. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12748. maxLength: 63
  12749. minLength: 1
  12750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12751. type: string
  12752. type: object
  12753. type: object
  12754. vaultAwsIamServerID:
  12755. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  12756. type: string
  12757. vaultRole:
  12758. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  12759. type: string
  12760. required:
  12761. - vaultRole
  12762. type: object
  12763. jwt:
  12764. description: |-
  12765. Jwt authenticates with Vault by passing role and JWT token using the
  12766. JWT/OIDC authentication method
  12767. properties:
  12768. kubernetesServiceAccountToken:
  12769. description: |-
  12770. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  12771. a token for with the `TokenRequest` API.
  12772. properties:
  12773. audiences:
  12774. description: |-
  12775. Optional audiences field that will be used to request a temporary Kubernetes service
  12776. account token for the service account referenced by `serviceAccountRef`.
  12777. Defaults to a single audience `vault` it not specified.
  12778. Deprecated: use serviceAccountRef.Audiences instead
  12779. items:
  12780. type: string
  12781. type: array
  12782. expirationSeconds:
  12783. description: |-
  12784. Optional expiration time in seconds that will be used to request a temporary
  12785. Kubernetes service account token for the service account referenced by
  12786. `serviceAccountRef`.
  12787. Deprecated: this will be removed in the future.
  12788. Defaults to 10 minutes.
  12789. format: int64
  12790. type: integer
  12791. serviceAccountRef:
  12792. description: Service account field containing the name of a kubernetes ServiceAccount.
  12793. properties:
  12794. audiences:
  12795. description: |-
  12796. Audience specifies the `aud` claim for the service account token
  12797. Some providers automatically extend the audience field based on well-known annotations for workload
  12798. identity (e.g. IRSA or GCP Workload Identity)
  12799. items:
  12800. type: string
  12801. type: array
  12802. name:
  12803. description: The name of the ServiceAccount resource being referred to.
  12804. maxLength: 253
  12805. minLength: 1
  12806. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12807. type: string
  12808. namespace:
  12809. description: |-
  12810. Namespace of the resource being referred to.
  12811. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12812. maxLength: 63
  12813. minLength: 1
  12814. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12815. type: string
  12816. required:
  12817. - name
  12818. type: object
  12819. required:
  12820. - serviceAccountRef
  12821. type: object
  12822. path:
  12823. default: jwt
  12824. description: |-
  12825. Path where the JWT authentication backend is mounted
  12826. in Vault, e.g: "jwt"
  12827. type: string
  12828. role:
  12829. description: |-
  12830. Role is a JWT role to authenticate using the JWT/OIDC Vault
  12831. authentication method
  12832. type: string
  12833. secretRef:
  12834. description: |-
  12835. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  12836. authenticate with Vault using the JWT/OIDC authentication method.
  12837. properties:
  12838. key:
  12839. description: |-
  12840. A key in the referenced Secret.
  12841. Some instances of this field may be defaulted, in others it may be required.
  12842. maxLength: 253
  12843. minLength: 1
  12844. pattern: ^[-._a-zA-Z0-9]+$
  12845. type: string
  12846. name:
  12847. description: The name of the Secret resource being referred to.
  12848. maxLength: 253
  12849. minLength: 1
  12850. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12851. type: string
  12852. namespace:
  12853. description: |-
  12854. The namespace of the Secret resource being referred to.
  12855. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12856. maxLength: 63
  12857. minLength: 1
  12858. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12859. type: string
  12860. type: object
  12861. required:
  12862. - path
  12863. type: object
  12864. kubernetes:
  12865. description: |-
  12866. Kubernetes authenticates with Vault by passing the ServiceAccount
  12867. token stored in the named Secret resource to the Vault server.
  12868. properties:
  12869. mountPath:
  12870. default: kubernetes
  12871. description: |-
  12872. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  12873. "kubernetes"
  12874. type: string
  12875. role:
  12876. description: |-
  12877. A required field containing the Vault Role to assume. A Role binds a
  12878. Kubernetes ServiceAccount with a set of Vault policies.
  12879. type: string
  12880. secretRef:
  12881. description: |-
  12882. Optional secret field containing a Kubernetes ServiceAccount JWT used
  12883. for authenticating with Vault. If a name is specified without a key,
  12884. `token` is the default. If one is not specified, the one bound to
  12885. the controller will be used.
  12886. properties:
  12887. key:
  12888. description: |-
  12889. A key in the referenced Secret.
  12890. Some instances of this field may be defaulted, in others it may be required.
  12891. maxLength: 253
  12892. minLength: 1
  12893. pattern: ^[-._a-zA-Z0-9]+$
  12894. type: string
  12895. name:
  12896. description: The name of the Secret resource being referred to.
  12897. maxLength: 253
  12898. minLength: 1
  12899. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12900. type: string
  12901. namespace:
  12902. description: |-
  12903. The namespace of the Secret resource being referred to.
  12904. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12905. maxLength: 63
  12906. minLength: 1
  12907. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12908. type: string
  12909. type: object
  12910. serviceAccountRef:
  12911. description: |-
  12912. Optional service account field containing the name of a kubernetes ServiceAccount.
  12913. If the service account is specified, the service account secret token JWT will be used
  12914. for authenticating with Vault. If the service account selector is not supplied,
  12915. the secretRef will be used instead.
  12916. properties:
  12917. audiences:
  12918. description: |-
  12919. Audience specifies the `aud` claim for the service account token
  12920. Some providers automatically extend the audience field based on well-known annotations for workload
  12921. identity (e.g. IRSA or GCP Workload Identity)
  12922. items:
  12923. type: string
  12924. type: array
  12925. name:
  12926. description: The name of the ServiceAccount resource being referred to.
  12927. maxLength: 253
  12928. minLength: 1
  12929. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12930. type: string
  12931. namespace:
  12932. description: |-
  12933. Namespace of the resource being referred to.
  12934. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12935. maxLength: 63
  12936. minLength: 1
  12937. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12938. type: string
  12939. required:
  12940. - name
  12941. type: object
  12942. required:
  12943. - mountPath
  12944. - role
  12945. type: object
  12946. ldap:
  12947. description: |-
  12948. Ldap authenticates with Vault by passing username/password pair using
  12949. the LDAP authentication method
  12950. properties:
  12951. path:
  12952. default: ldap
  12953. description: |-
  12954. Path where the LDAP authentication backend is mounted
  12955. in Vault, e.g: "ldap"
  12956. type: string
  12957. secretRef:
  12958. description: |-
  12959. SecretRef to a key in a Secret resource containing password for the LDAP
  12960. user used to authenticate with Vault using the LDAP authentication
  12961. method
  12962. properties:
  12963. key:
  12964. description: |-
  12965. A key in the referenced Secret.
  12966. Some instances of this field may be defaulted, in others it may be required.
  12967. maxLength: 253
  12968. minLength: 1
  12969. pattern: ^[-._a-zA-Z0-9]+$
  12970. type: string
  12971. name:
  12972. description: The name of the Secret resource being referred to.
  12973. maxLength: 253
  12974. minLength: 1
  12975. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12976. type: string
  12977. namespace:
  12978. description: |-
  12979. The namespace of the Secret resource being referred to.
  12980. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12981. maxLength: 63
  12982. minLength: 1
  12983. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12984. type: string
  12985. type: object
  12986. username:
  12987. description: |-
  12988. Username is an LDAP username used to authenticate using the LDAP Vault
  12989. authentication method
  12990. type: string
  12991. required:
  12992. - path
  12993. - username
  12994. type: object
  12995. namespace:
  12996. description: |-
  12997. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  12998. Namespaces is a set of features within Vault Enterprise that allows
  12999. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  13000. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  13001. This will default to Vault.Namespace field if set, or empty otherwise
  13002. type: string
  13003. tokenSecretRef:
  13004. description: TokenSecretRef authenticates with Vault by presenting a token.
  13005. properties:
  13006. key:
  13007. description: |-
  13008. A key in the referenced Secret.
  13009. Some instances of this field may be defaulted, in others it may be required.
  13010. maxLength: 253
  13011. minLength: 1
  13012. pattern: ^[-._a-zA-Z0-9]+$
  13013. type: string
  13014. name:
  13015. description: The name of the Secret resource being referred to.
  13016. maxLength: 253
  13017. minLength: 1
  13018. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13019. type: string
  13020. namespace:
  13021. description: |-
  13022. The namespace of the Secret resource being referred to.
  13023. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13024. maxLength: 63
  13025. minLength: 1
  13026. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13027. type: string
  13028. type: object
  13029. userPass:
  13030. description: UserPass authenticates with Vault by passing username/password pair
  13031. properties:
  13032. path:
  13033. default: userpass
  13034. description: |-
  13035. Path where the UserPassword authentication backend is mounted
  13036. in Vault, e.g: "userpass"
  13037. type: string
  13038. secretRef:
  13039. description: |-
  13040. SecretRef to a key in a Secret resource containing password for the
  13041. user used to authenticate with Vault using the UserPass authentication
  13042. method
  13043. properties:
  13044. key:
  13045. description: |-
  13046. A key in the referenced Secret.
  13047. Some instances of this field may be defaulted, in others it may be required.
  13048. maxLength: 253
  13049. minLength: 1
  13050. pattern: ^[-._a-zA-Z0-9]+$
  13051. type: string
  13052. name:
  13053. description: The name of the Secret resource being referred to.
  13054. maxLength: 253
  13055. minLength: 1
  13056. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13057. type: string
  13058. namespace:
  13059. description: |-
  13060. The namespace of the Secret resource being referred to.
  13061. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13062. maxLength: 63
  13063. minLength: 1
  13064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13065. type: string
  13066. type: object
  13067. username:
  13068. description: |-
  13069. Username is a username used to authenticate using the UserPass Vault
  13070. authentication method
  13071. type: string
  13072. required:
  13073. - path
  13074. - username
  13075. type: object
  13076. type: object
  13077. caBundle:
  13078. description: |-
  13079. PEM encoded CA bundle used to validate Vault server certificate. Only used
  13080. if the Server URL is using HTTPS protocol. This parameter is ignored for
  13081. plain HTTP protocol connection. If not set the system root certificates
  13082. are used to validate the TLS connection.
  13083. format: byte
  13084. type: string
  13085. caProvider:
  13086. description: The provider for the CA bundle to use to validate Vault server certificate.
  13087. properties:
  13088. key:
  13089. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  13090. maxLength: 253
  13091. minLength: 1
  13092. pattern: ^[-._a-zA-Z0-9]+$
  13093. type: string
  13094. name:
  13095. description: The name of the object located at the provider type.
  13096. maxLength: 253
  13097. minLength: 1
  13098. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13099. type: string
  13100. namespace:
  13101. description: |-
  13102. The namespace the Provider type is in.
  13103. Can only be defined when used in a ClusterSecretStore.
  13104. maxLength: 63
  13105. minLength: 1
  13106. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13107. type: string
  13108. type:
  13109. description: The type of provider to use such as "Secret", or "ConfigMap".
  13110. enum:
  13111. - Secret
  13112. - ConfigMap
  13113. type: string
  13114. required:
  13115. - name
  13116. - type
  13117. type: object
  13118. forwardInconsistent:
  13119. description: |-
  13120. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  13121. leader instead of simply retrying within a loop. This can increase performance if
  13122. the option is enabled serverside.
  13123. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  13124. type: boolean
  13125. headers:
  13126. additionalProperties:
  13127. type: string
  13128. description: Headers to be added in Vault request
  13129. type: object
  13130. namespace:
  13131. description: |-
  13132. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  13133. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  13134. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  13135. type: string
  13136. path:
  13137. description: |-
  13138. Path is the mount path of the Vault KV backend endpoint, e.g:
  13139. "secret". The v2 KV secret engine version specific "/data" path suffix
  13140. for fetching secrets from Vault is optional and will be appended
  13141. if not present in specified path.
  13142. type: string
  13143. readYourWrites:
  13144. description: |-
  13145. ReadYourWrites ensures isolated read-after-write semantics by
  13146. providing discovered cluster replication states in each request.
  13147. More information about eventual consistency in Vault can be found here
  13148. https://www.vaultproject.io/docs/enterprise/consistency
  13149. type: boolean
  13150. server:
  13151. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  13152. type: string
  13153. tls:
  13154. description: |-
  13155. The configuration used for client side related TLS communication, when the Vault server
  13156. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  13157. This parameter is ignored for plain HTTP protocol connection.
  13158. It's worth noting this configuration is different from the "TLS certificates auth method",
  13159. which is available under the `auth.cert` section.
  13160. properties:
  13161. certSecretRef:
  13162. description: |-
  13163. CertSecretRef is a certificate added to the transport layer
  13164. when communicating with the Vault server.
  13165. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  13166. properties:
  13167. key:
  13168. description: |-
  13169. A key in the referenced Secret.
  13170. Some instances of this field may be defaulted, in others it may be required.
  13171. maxLength: 253
  13172. minLength: 1
  13173. pattern: ^[-._a-zA-Z0-9]+$
  13174. type: string
  13175. name:
  13176. description: The name of the Secret resource being referred to.
  13177. maxLength: 253
  13178. minLength: 1
  13179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13180. type: string
  13181. namespace:
  13182. description: |-
  13183. The namespace of the Secret resource being referred to.
  13184. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13185. maxLength: 63
  13186. minLength: 1
  13187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13188. type: string
  13189. type: object
  13190. keySecretRef:
  13191. description: |-
  13192. KeySecretRef to a key in a Secret resource containing client private key
  13193. added to the transport layer when communicating with the Vault server.
  13194. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  13195. properties:
  13196. key:
  13197. description: |-
  13198. A key in the referenced Secret.
  13199. Some instances of this field may be defaulted, in others it may be required.
  13200. maxLength: 253
  13201. minLength: 1
  13202. pattern: ^[-._a-zA-Z0-9]+$
  13203. type: string
  13204. name:
  13205. description: The name of the Secret resource being referred to.
  13206. maxLength: 253
  13207. minLength: 1
  13208. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13209. type: string
  13210. namespace:
  13211. description: |-
  13212. The namespace of the Secret resource being referred to.
  13213. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13214. maxLength: 63
  13215. minLength: 1
  13216. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13217. type: string
  13218. type: object
  13219. type: object
  13220. version:
  13221. default: v2
  13222. description: |-
  13223. Version is the Vault KV secret engine version. This can be either "v1" or
  13224. "v2". Version defaults to "v2".
  13225. enum:
  13226. - v1
  13227. - v2
  13228. type: string
  13229. required:
  13230. - server
  13231. type: object
  13232. webhook:
  13233. description: Webhook configures this store to sync secrets using a generic templated webhook
  13234. properties:
  13235. auth:
  13236. description: Auth specifies a authorization protocol. Only one protocol may be set.
  13237. maxProperties: 1
  13238. minProperties: 1
  13239. properties:
  13240. ntlm:
  13241. description: NTLMProtocol configures the store to use NTLM for auth
  13242. properties:
  13243. passwordSecret:
  13244. description: |-
  13245. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13246. In some instances, `key` is a required field.
  13247. properties:
  13248. key:
  13249. description: |-
  13250. A key in the referenced Secret.
  13251. Some instances of this field may be defaulted, in others it may be required.
  13252. maxLength: 253
  13253. minLength: 1
  13254. pattern: ^[-._a-zA-Z0-9]+$
  13255. type: string
  13256. name:
  13257. description: The name of the Secret resource being referred to.
  13258. maxLength: 253
  13259. minLength: 1
  13260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13261. type: string
  13262. namespace:
  13263. description: |-
  13264. The namespace of the Secret resource being referred to.
  13265. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13266. maxLength: 63
  13267. minLength: 1
  13268. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13269. type: string
  13270. type: object
  13271. usernameSecret:
  13272. description: |-
  13273. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13274. In some instances, `key` is a required field.
  13275. properties:
  13276. key:
  13277. description: |-
  13278. A key in the referenced Secret.
  13279. Some instances of this field may be defaulted, in others it may be required.
  13280. maxLength: 253
  13281. minLength: 1
  13282. pattern: ^[-._a-zA-Z0-9]+$
  13283. type: string
  13284. name:
  13285. description: The name of the Secret resource being referred to.
  13286. maxLength: 253
  13287. minLength: 1
  13288. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13289. type: string
  13290. namespace:
  13291. description: |-
  13292. The namespace of the Secret resource being referred to.
  13293. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13294. maxLength: 63
  13295. minLength: 1
  13296. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13297. type: string
  13298. type: object
  13299. required:
  13300. - passwordSecret
  13301. - usernameSecret
  13302. type: object
  13303. type: object
  13304. body:
  13305. description: Body
  13306. type: string
  13307. caBundle:
  13308. description: |-
  13309. PEM encoded CA bundle used to validate webhook server certificate. Only used
  13310. if the Server URL is using HTTPS protocol. This parameter is ignored for
  13311. plain HTTP protocol connection. If not set the system root certificates
  13312. are used to validate the TLS connection.
  13313. format: byte
  13314. type: string
  13315. caProvider:
  13316. description: The provider for the CA bundle to use to validate webhook server certificate.
  13317. properties:
  13318. key:
  13319. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  13320. maxLength: 253
  13321. minLength: 1
  13322. pattern: ^[-._a-zA-Z0-9]+$
  13323. type: string
  13324. name:
  13325. description: The name of the object located at the provider type.
  13326. maxLength: 253
  13327. minLength: 1
  13328. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13329. type: string
  13330. namespace:
  13331. description: The namespace the Provider type is in.
  13332. maxLength: 63
  13333. minLength: 1
  13334. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13335. type: string
  13336. type:
  13337. description: The type of provider to use such as "Secret", or "ConfigMap".
  13338. enum:
  13339. - Secret
  13340. - ConfigMap
  13341. type: string
  13342. required:
  13343. - name
  13344. - type
  13345. type: object
  13346. headers:
  13347. additionalProperties:
  13348. type: string
  13349. description: Headers
  13350. type: object
  13351. method:
  13352. description: Webhook Method
  13353. type: string
  13354. result:
  13355. description: Result formatting
  13356. properties:
  13357. jsonPath:
  13358. description: Json path of return value
  13359. type: string
  13360. type: object
  13361. secrets:
  13362. description: |-
  13363. Secrets to fill in templates
  13364. These secrets will be passed to the templating function as key value pairs under the given name
  13365. items:
  13366. description: WebhookSecret defines a secret to be used in webhook templates.
  13367. properties:
  13368. name:
  13369. description: Name of this secret in templates
  13370. type: string
  13371. secretRef:
  13372. description: Secret ref to fill in credentials
  13373. properties:
  13374. key:
  13375. description: |-
  13376. A key in the referenced Secret.
  13377. Some instances of this field may be defaulted, in others it may be required.
  13378. maxLength: 253
  13379. minLength: 1
  13380. pattern: ^[-._a-zA-Z0-9]+$
  13381. type: string
  13382. name:
  13383. description: The name of the Secret resource being referred to.
  13384. maxLength: 253
  13385. minLength: 1
  13386. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13387. type: string
  13388. namespace:
  13389. description: |-
  13390. The namespace of the Secret resource being referred to.
  13391. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13392. maxLength: 63
  13393. minLength: 1
  13394. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13395. type: string
  13396. type: object
  13397. required:
  13398. - name
  13399. - secretRef
  13400. type: object
  13401. type: array
  13402. timeout:
  13403. description: Timeout
  13404. type: string
  13405. url:
  13406. description: Webhook url to call
  13407. type: string
  13408. required:
  13409. - result
  13410. - url
  13411. type: object
  13412. yandexcertificatemanager:
  13413. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  13414. properties:
  13415. apiEndpoint:
  13416. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13417. type: string
  13418. auth:
  13419. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  13420. properties:
  13421. authorizedKeySecretRef:
  13422. description: The authorized key used for authentication
  13423. properties:
  13424. key:
  13425. description: |-
  13426. A key in the referenced Secret.
  13427. Some instances of this field may be defaulted, in others it may be required.
  13428. maxLength: 253
  13429. minLength: 1
  13430. pattern: ^[-._a-zA-Z0-9]+$
  13431. type: string
  13432. name:
  13433. description: The name of the Secret resource being referred to.
  13434. maxLength: 253
  13435. minLength: 1
  13436. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13437. type: string
  13438. namespace:
  13439. description: |-
  13440. The namespace of the Secret resource being referred to.
  13441. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13442. maxLength: 63
  13443. minLength: 1
  13444. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13445. type: string
  13446. type: object
  13447. type: object
  13448. caProvider:
  13449. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13450. properties:
  13451. certSecretRef:
  13452. description: |-
  13453. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13454. In some instances, `key` is a required field.
  13455. properties:
  13456. key:
  13457. description: |-
  13458. A key in the referenced Secret.
  13459. Some instances of this field may be defaulted, in others it may be required.
  13460. maxLength: 253
  13461. minLength: 1
  13462. pattern: ^[-._a-zA-Z0-9]+$
  13463. type: string
  13464. name:
  13465. description: The name of the Secret resource being referred to.
  13466. maxLength: 253
  13467. minLength: 1
  13468. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13469. type: string
  13470. namespace:
  13471. description: |-
  13472. The namespace of the Secret resource being referred to.
  13473. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13474. maxLength: 63
  13475. minLength: 1
  13476. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13477. type: string
  13478. type: object
  13479. type: object
  13480. required:
  13481. - auth
  13482. type: object
  13483. yandexlockbox:
  13484. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  13485. properties:
  13486. apiEndpoint:
  13487. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13488. type: string
  13489. auth:
  13490. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  13491. properties:
  13492. authorizedKeySecretRef:
  13493. description: The authorized key used for authentication
  13494. properties:
  13495. key:
  13496. description: |-
  13497. A key in the referenced Secret.
  13498. Some instances of this field may be defaulted, in others it may be required.
  13499. maxLength: 253
  13500. minLength: 1
  13501. pattern: ^[-._a-zA-Z0-9]+$
  13502. type: string
  13503. name:
  13504. description: The name of the Secret resource being referred to.
  13505. maxLength: 253
  13506. minLength: 1
  13507. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13508. type: string
  13509. namespace:
  13510. description: |-
  13511. The namespace of the Secret resource being referred to.
  13512. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13513. maxLength: 63
  13514. minLength: 1
  13515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13516. type: string
  13517. type: object
  13518. type: object
  13519. caProvider:
  13520. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13521. properties:
  13522. certSecretRef:
  13523. description: |-
  13524. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13525. In some instances, `key` is a required field.
  13526. properties:
  13527. key:
  13528. description: |-
  13529. A key in the referenced Secret.
  13530. Some instances of this field may be defaulted, in others it may be required.
  13531. maxLength: 253
  13532. minLength: 1
  13533. pattern: ^[-._a-zA-Z0-9]+$
  13534. type: string
  13535. name:
  13536. description: The name of the Secret resource being referred to.
  13537. maxLength: 253
  13538. minLength: 1
  13539. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13540. type: string
  13541. namespace:
  13542. description: |-
  13543. The namespace of the Secret resource being referred to.
  13544. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13545. maxLength: 63
  13546. minLength: 1
  13547. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13548. type: string
  13549. type: object
  13550. type: object
  13551. required:
  13552. - auth
  13553. type: object
  13554. type: object
  13555. refreshInterval:
  13556. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  13557. type: integer
  13558. retrySettings:
  13559. description: Used to configure HTTP retries on failures.
  13560. properties:
  13561. maxRetries:
  13562. description: MaxRetries is the maximum number of retry attempts.
  13563. format: int32
  13564. type: integer
  13565. retryInterval:
  13566. description: RetryInterval is the interval between retry attempts.
  13567. type: string
  13568. type: object
  13569. required:
  13570. - provider
  13571. type: object
  13572. status:
  13573. description: SecretStoreStatus defines the observed state of the SecretStore.
  13574. properties:
  13575. capabilities:
  13576. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  13577. type: string
  13578. conditions:
  13579. items:
  13580. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  13581. properties:
  13582. lastTransitionTime:
  13583. format: date-time
  13584. type: string
  13585. message:
  13586. type: string
  13587. reason:
  13588. type: string
  13589. status:
  13590. type: string
  13591. type:
  13592. description: SecretStoreConditionType represents the condition type of the SecretStore.
  13593. type: string
  13594. required:
  13595. - status
  13596. - type
  13597. type: object
  13598. type: array
  13599. type: object
  13600. type: object
  13601. served: false
  13602. storage: false
  13603. subresources:
  13604. status: {}
  13605. ---
  13606. apiVersion: apiextensions.k8s.io/v1
  13607. kind: CustomResourceDefinition
  13608. metadata:
  13609. annotations:
  13610. controller-gen.kubebuilder.io/version: v0.19.0
  13611. labels:
  13612. external-secrets.io/component: controller
  13613. name: externalsecrets.external-secrets.io
  13614. spec:
  13615. group: external-secrets.io
  13616. names:
  13617. categories:
  13618. - external-secrets
  13619. kind: ExternalSecret
  13620. listKind: ExternalSecretList
  13621. plural: externalsecrets
  13622. shortNames:
  13623. - es
  13624. singular: externalsecret
  13625. scope: Namespaced
  13626. versions:
  13627. - additionalPrinterColumns:
  13628. - jsonPath: .spec.secretStoreRef.kind
  13629. name: StoreType
  13630. type: string
  13631. - jsonPath: .spec.secretStoreRef.name
  13632. name: Store
  13633. type: string
  13634. - jsonPath: .spec.refreshInterval
  13635. name: Refresh Interval
  13636. type: string
  13637. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  13638. name: Status
  13639. type: string
  13640. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  13641. name: Ready
  13642. type: string
  13643. - jsonPath: .status.refreshTime
  13644. name: Last Sync
  13645. type: date
  13646. name: v1
  13647. schema:
  13648. openAPIV3Schema:
  13649. description: |-
  13650. ExternalSecret is the Schema for the external-secrets API.
  13651. It defines how to fetch data from external APIs and make it available as Kubernetes Secrets.
  13652. properties:
  13653. apiVersion:
  13654. description: |-
  13655. APIVersion defines the versioned schema of this representation of an object.
  13656. Servers should convert recognized schemas to the latest internal value, and
  13657. may reject unrecognized values.
  13658. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  13659. type: string
  13660. kind:
  13661. description: |-
  13662. Kind is a string value representing the REST resource this object represents.
  13663. Servers may infer this from the endpoint the client submits requests to.
  13664. Cannot be updated.
  13665. In CamelCase.
  13666. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  13667. type: string
  13668. metadata:
  13669. type: object
  13670. spec:
  13671. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  13672. properties:
  13673. data:
  13674. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  13675. items:
  13676. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  13677. properties:
  13678. remoteRef:
  13679. description: |-
  13680. RemoteRef points to the remote secret and defines
  13681. which secret (version/property/..) to fetch.
  13682. properties:
  13683. conversionStrategy:
  13684. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  13685. enum:
  13686. - Default
  13687. - Unicode
  13688. type: string
  13689. decodingStrategy:
  13690. description: Used to define a decoding Strategy. Defaults to None when omitted.
  13691. enum:
  13692. - Auto
  13693. - Base64
  13694. - Base64URL
  13695. - None
  13696. type: string
  13697. key:
  13698. description: Key is the key used in the Provider, mandatory
  13699. type: string
  13700. metadataPolicy:
  13701. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13702. enum:
  13703. - None
  13704. - Fetch
  13705. type: string
  13706. nullBytePolicy:
  13707. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13708. enum:
  13709. - Ignore
  13710. - Fail
  13711. type: string
  13712. property:
  13713. description: Used to select a specific property of the Provider value (if a map), if supported
  13714. type: string
  13715. version:
  13716. description: Used to select a specific version of the Provider value, if supported
  13717. type: string
  13718. required:
  13719. - key
  13720. type: object
  13721. secretKey:
  13722. description: The key in the Kubernetes Secret to store the value.
  13723. maxLength: 253
  13724. minLength: 1
  13725. pattern: ^[-._a-zA-Z0-9]+$
  13726. type: string
  13727. sourceRef:
  13728. description: |-
  13729. SourceRef allows you to override the source
  13730. from which the value will be pulled.
  13731. maxProperties: 1
  13732. minProperties: 1
  13733. properties:
  13734. generatorRef:
  13735. description: |-
  13736. GeneratorRef points to a generator custom resource.
  13737. Deprecated: The generatorRef is not implemented in .data[].
  13738. this will be removed with v1.
  13739. properties:
  13740. apiVersion:
  13741. default: generators.external-secrets.io/v1alpha1
  13742. description: Specify the apiVersion of the generator resource
  13743. type: string
  13744. kind:
  13745. description: Specify the Kind of the generator resource
  13746. enum:
  13747. - ACRAccessToken
  13748. - BeyondtrustWorkloadCredentialsDynamicSecret
  13749. - ClusterGenerator
  13750. - CloudsmithAccessToken
  13751. - ECRAuthorizationToken
  13752. - Fake
  13753. - GCRAccessToken
  13754. - GithubAccessToken
  13755. - GitlabDeployToken
  13756. - QuayAccessToken
  13757. - Password
  13758. - SSHKey
  13759. - STSSessionToken
  13760. - UUID
  13761. - VaultDynamicSecret
  13762. - Webhook
  13763. - Grafana
  13764. - MFA
  13765. type: string
  13766. name:
  13767. description: Specify the name of the generator resource
  13768. maxLength: 253
  13769. minLength: 1
  13770. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13771. type: string
  13772. required:
  13773. - kind
  13774. - name
  13775. type: object
  13776. storeRef:
  13777. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13778. properties:
  13779. kind:
  13780. description: |-
  13781. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13782. Defaults to `SecretStore`
  13783. enum:
  13784. - SecretStore
  13785. - ClusterSecretStore
  13786. type: string
  13787. name:
  13788. description: Name of the SecretStore resource
  13789. maxLength: 253
  13790. minLength: 1
  13791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13792. type: string
  13793. type: object
  13794. type: object
  13795. required:
  13796. - remoteRef
  13797. - secretKey
  13798. type: object
  13799. type: array
  13800. dataFrom:
  13801. description: |-
  13802. DataFrom is used to fetch all properties from a specific Provider data
  13803. If multiple entries are specified, the Secret keys are merged in the specified order
  13804. items:
  13805. description: |-
  13806. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  13807. when using DataFrom to fetch multiple values from a Provider.
  13808. properties:
  13809. extract:
  13810. description: |-
  13811. Used to extract multiple key/value pairs from one secret
  13812. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13813. properties:
  13814. conversionStrategy:
  13815. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  13816. enum:
  13817. - Default
  13818. - Unicode
  13819. type: string
  13820. decodingStrategy:
  13821. description: Used to define a decoding Strategy. Defaults to None when omitted.
  13822. enum:
  13823. - Auto
  13824. - Base64
  13825. - Base64URL
  13826. - None
  13827. type: string
  13828. key:
  13829. description: Key is the key used in the Provider, mandatory
  13830. type: string
  13831. metadataPolicy:
  13832. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13833. enum:
  13834. - None
  13835. - Fetch
  13836. type: string
  13837. nullBytePolicy:
  13838. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13839. enum:
  13840. - Ignore
  13841. - Fail
  13842. type: string
  13843. property:
  13844. description: Used to select a specific property of the Provider value (if a map), if supported
  13845. type: string
  13846. version:
  13847. description: Used to select a specific version of the Provider value, if supported
  13848. type: string
  13849. required:
  13850. - key
  13851. type: object
  13852. find:
  13853. description: |-
  13854. Used to find secrets based on tags or regular expressions
  13855. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13856. properties:
  13857. conversionStrategy:
  13858. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  13859. enum:
  13860. - Default
  13861. - Unicode
  13862. type: string
  13863. decodingStrategy:
  13864. description: Used to define a decoding Strategy. Defaults to None when omitted.
  13865. enum:
  13866. - Auto
  13867. - Base64
  13868. - Base64URL
  13869. - None
  13870. type: string
  13871. name:
  13872. description: Finds secrets based on the name.
  13873. properties:
  13874. regexp:
  13875. description: Finds secrets base
  13876. type: string
  13877. type: object
  13878. nullBytePolicy:
  13879. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  13880. enum:
  13881. - Ignore
  13882. - Fail
  13883. type: string
  13884. path:
  13885. description: A root path to start the find operations.
  13886. type: string
  13887. tags:
  13888. additionalProperties:
  13889. type: string
  13890. description: Find secrets based on tags.
  13891. type: object
  13892. type: object
  13893. rewrite:
  13894. description: |-
  13895. Used to rewrite secret Keys after getting them from the secret Provider
  13896. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  13897. items:
  13898. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  13899. maxProperties: 1
  13900. minProperties: 1
  13901. properties:
  13902. merge:
  13903. description: |-
  13904. Used to merge key/values in one single Secret
  13905. The resulting key will contain all values from the specified secrets
  13906. properties:
  13907. conflictPolicy:
  13908. default: Error
  13909. description: Used to define the policy to use in conflict resolution.
  13910. enum:
  13911. - Ignore
  13912. - Error
  13913. type: string
  13914. into:
  13915. default: ""
  13916. description: |-
  13917. Used to define the target key of the merge operation.
  13918. Required if strategy is JSON. Ignored otherwise.
  13919. type: string
  13920. priority:
  13921. description: Used to define key priority in conflict resolution.
  13922. items:
  13923. type: string
  13924. type: array
  13925. priorityPolicy:
  13926. default: Strict
  13927. description: Used to define the policy when a key in the priority list does not exist in the input.
  13928. enum:
  13929. - IgnoreNotFound
  13930. - Strict
  13931. type: string
  13932. strategy:
  13933. default: Extract
  13934. description: Used to define the strategy to use in the merge operation.
  13935. enum:
  13936. - Extract
  13937. - JSON
  13938. type: string
  13939. type: object
  13940. regexp:
  13941. description: |-
  13942. Used to rewrite with regular expressions.
  13943. The resulting key will be the output of a regexp.ReplaceAll operation.
  13944. properties:
  13945. source:
  13946. description: Used to define the regular expression of a re.Compiler.
  13947. type: string
  13948. target:
  13949. description: Used to define the target pattern of a ReplaceAll operation.
  13950. type: string
  13951. required:
  13952. - source
  13953. - target
  13954. type: object
  13955. transform:
  13956. description: |-
  13957. Used to apply string transformation on the secrets.
  13958. The resulting key will be the output of the template applied by the operation.
  13959. properties:
  13960. template:
  13961. description: |-
  13962. Used to define the template to apply on the secret name.
  13963. `.value ` will specify the secret name in the template.
  13964. type: string
  13965. required:
  13966. - template
  13967. type: object
  13968. type: object
  13969. type: array
  13970. sourceRef:
  13971. description: |-
  13972. SourceRef points to a store or generator
  13973. which contains secret values ready to use.
  13974. Use this in combination with Extract or Find pull values out of
  13975. a specific SecretStore.
  13976. When sourceRef points to a generator Extract or Find is not supported.
  13977. The generator returns a static map of values
  13978. maxProperties: 1
  13979. minProperties: 1
  13980. properties:
  13981. generatorRef:
  13982. description: GeneratorRef points to a generator custom resource.
  13983. properties:
  13984. apiVersion:
  13985. default: generators.external-secrets.io/v1alpha1
  13986. description: Specify the apiVersion of the generator resource
  13987. type: string
  13988. kind:
  13989. description: Specify the Kind of the generator resource
  13990. enum:
  13991. - ACRAccessToken
  13992. - BeyondtrustWorkloadCredentialsDynamicSecret
  13993. - ClusterGenerator
  13994. - CloudsmithAccessToken
  13995. - ECRAuthorizationToken
  13996. - Fake
  13997. - GCRAccessToken
  13998. - GithubAccessToken
  13999. - GitlabDeployToken
  14000. - QuayAccessToken
  14001. - Password
  14002. - SSHKey
  14003. - STSSessionToken
  14004. - UUID
  14005. - VaultDynamicSecret
  14006. - Webhook
  14007. - Grafana
  14008. - MFA
  14009. type: string
  14010. name:
  14011. description: Specify the name of the generator resource
  14012. maxLength: 253
  14013. minLength: 1
  14014. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14015. type: string
  14016. required:
  14017. - kind
  14018. - name
  14019. type: object
  14020. storeRef:
  14021. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14022. properties:
  14023. kind:
  14024. description: |-
  14025. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14026. Defaults to `SecretStore`
  14027. enum:
  14028. - SecretStore
  14029. - ClusterSecretStore
  14030. type: string
  14031. name:
  14032. description: Name of the SecretStore resource
  14033. maxLength: 253
  14034. minLength: 1
  14035. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14036. type: string
  14037. type: object
  14038. type: object
  14039. type: object
  14040. type: array
  14041. refreshInterval:
  14042. default: 1h0m0s
  14043. description: |-
  14044. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  14045. specified as Golang Duration strings.
  14046. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  14047. Example values: "1h0m0s", "2h30m0s", "10m0s"
  14048. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  14049. type: string
  14050. refreshPolicy:
  14051. description: |-
  14052. RefreshPolicy determines how the ExternalSecret should be refreshed:
  14053. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  14054. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  14055. No periodic updates occur if refreshInterval is 0.
  14056. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  14057. enum:
  14058. - CreatedOnce
  14059. - Periodic
  14060. - OnChange
  14061. type: string
  14062. secretStoreRef:
  14063. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14064. properties:
  14065. kind:
  14066. description: |-
  14067. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14068. Defaults to `SecretStore`
  14069. enum:
  14070. - SecretStore
  14071. - ClusterSecretStore
  14072. type: string
  14073. name:
  14074. description: Name of the SecretStore resource
  14075. maxLength: 253
  14076. minLength: 1
  14077. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14078. type: string
  14079. type: object
  14080. syncWindows:
  14081. description: |-
  14082. SyncWindows optionally restricts when periodic refreshes may occur.
  14083. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  14084. properties:
  14085. kind:
  14086. description: |-
  14087. Kind applies to every window in the list.
  14088. "allow" -- syncs are permitted only while at least one window is active;
  14089. all other times are blocked.
  14090. "deny" -- syncs are blocked while any window is active;
  14091. all other times are permitted.
  14092. enum:
  14093. - allow
  14094. - deny
  14095. type: string
  14096. windows:
  14097. description: Windows is the list of schedule+duration pairs.
  14098. items:
  14099. description: |-
  14100. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  14101. within a SyncWindows block.
  14102. properties:
  14103. duration:
  14104. description: |-
  14105. Duration specifies how long the window stays open after each Schedule
  14106. firing. Example: "8h".
  14107. type: string
  14108. schedule:
  14109. description: |-
  14110. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  14111. named shorthand such as @daily or @every 1h. It marks the start time of
  14112. each window occurrence.
  14113. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  14114. minLength: 1
  14115. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  14116. type: string
  14117. required:
  14118. - duration
  14119. - schedule
  14120. type: object
  14121. minItems: 1
  14122. type: array
  14123. required:
  14124. - kind
  14125. - windows
  14126. type: object
  14127. target:
  14128. default:
  14129. creationPolicy: Owner
  14130. deletionPolicy: Retain
  14131. description: |-
  14132. ExternalSecretTarget defines the Kubernetes Secret to be created,
  14133. there can be only one target per ExternalSecret.
  14134. properties:
  14135. creationPolicy:
  14136. default: Owner
  14137. description: |-
  14138. CreationPolicy defines rules on how to create the resulting Secret.
  14139. Defaults to "Owner"
  14140. enum:
  14141. - Owner
  14142. - Orphan
  14143. - Merge
  14144. - None
  14145. - CreateOrMerge
  14146. type: string
  14147. deletionPolicy:
  14148. default: Retain
  14149. description: |-
  14150. DeletionPolicy defines rules on how to delete the resulting Secret.
  14151. Defaults to "Retain"
  14152. enum:
  14153. - Delete
  14154. - Merge
  14155. - Retain
  14156. type: string
  14157. immutable:
  14158. description: Immutable defines if the final secret will be immutable
  14159. type: boolean
  14160. manifest:
  14161. description: |-
  14162. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  14163. When specified, ExternalSecret will create the resource type defined here
  14164. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  14165. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  14166. properties:
  14167. apiVersion:
  14168. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  14169. minLength: 1
  14170. type: string
  14171. kind:
  14172. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  14173. minLength: 1
  14174. type: string
  14175. required:
  14176. - apiVersion
  14177. - kind
  14178. type: object
  14179. name:
  14180. description: |-
  14181. The name of the Secret resource to be managed.
  14182. Defaults to the .metadata.name of the ExternalSecret resource
  14183. maxLength: 253
  14184. minLength: 1
  14185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14186. type: string
  14187. template:
  14188. description: Template defines a blueprint for the created Secret resource.
  14189. properties:
  14190. data:
  14191. additionalProperties:
  14192. type: string
  14193. type: object
  14194. engineVersion:
  14195. default: v2
  14196. description: |-
  14197. EngineVersion specifies the template engine version
  14198. that should be used to compile/execute the
  14199. template specified in .data and .templateFrom[].
  14200. enum:
  14201. - v2
  14202. type: string
  14203. mergePolicy:
  14204. default: Replace
  14205. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  14206. enum:
  14207. - Replace
  14208. - Merge
  14209. type: string
  14210. metadata:
  14211. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14212. properties:
  14213. annotations:
  14214. additionalProperties:
  14215. type: string
  14216. type: object
  14217. finalizers:
  14218. items:
  14219. type: string
  14220. type: array
  14221. labels:
  14222. additionalProperties:
  14223. type: string
  14224. type: object
  14225. type: object
  14226. templateFrom:
  14227. items:
  14228. description: |-
  14229. TemplateFrom specifies a source for templates.
  14230. Each item in the list can either reference a ConfigMap or a Secret resource.
  14231. properties:
  14232. configMap:
  14233. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14234. properties:
  14235. items:
  14236. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14237. items:
  14238. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14239. properties:
  14240. key:
  14241. description: A key in the ConfigMap/Secret
  14242. maxLength: 253
  14243. minLength: 1
  14244. pattern: ^[-._a-zA-Z0-9]+$
  14245. type: string
  14246. templateAs:
  14247. default: Values
  14248. description: TemplateScope specifies how the template keys should be interpreted.
  14249. enum:
  14250. - Values
  14251. - KeysAndValues
  14252. type: string
  14253. required:
  14254. - key
  14255. type: object
  14256. type: array
  14257. name:
  14258. description: The name of the ConfigMap/Secret resource
  14259. maxLength: 253
  14260. minLength: 1
  14261. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14262. type: string
  14263. required:
  14264. - items
  14265. - name
  14266. type: object
  14267. literal:
  14268. type: string
  14269. secret:
  14270. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14271. properties:
  14272. items:
  14273. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14274. items:
  14275. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14276. properties:
  14277. key:
  14278. description: A key in the ConfigMap/Secret
  14279. maxLength: 253
  14280. minLength: 1
  14281. pattern: ^[-._a-zA-Z0-9]+$
  14282. type: string
  14283. templateAs:
  14284. default: Values
  14285. description: TemplateScope specifies how the template keys should be interpreted.
  14286. enum:
  14287. - Values
  14288. - KeysAndValues
  14289. type: string
  14290. required:
  14291. - key
  14292. type: object
  14293. type: array
  14294. name:
  14295. description: The name of the ConfigMap/Secret resource
  14296. maxLength: 253
  14297. minLength: 1
  14298. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14299. type: string
  14300. required:
  14301. - items
  14302. - name
  14303. type: object
  14304. target:
  14305. default: Data
  14306. description: |-
  14307. Target specifies where to place the template result.
  14308. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  14309. any other value is rejected because it would allow writes to privileged Secret fields.
  14310. For custom resources (when spec.target.manifest is set), this supports
  14311. nested paths like "spec.database.config" or "data".
  14312. type: string
  14313. valuesDecodingStrategy:
  14314. description: |-
  14315. Used to define a decoding Strategy for the rendered template values.
  14316. Defaults to None when omitted.
  14317. enum:
  14318. - Auto
  14319. - Base64
  14320. - Base64URL
  14321. - None
  14322. type: string
  14323. type: object
  14324. type: array
  14325. type:
  14326. type: string
  14327. type: object
  14328. type: object
  14329. type: object
  14330. status:
  14331. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  14332. properties:
  14333. binding:
  14334. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  14335. properties:
  14336. name:
  14337. default: ""
  14338. description: |-
  14339. Name of the referent.
  14340. This field is effectively required, but due to backwards compatibility is
  14341. allowed to be empty. Instances of this type with an empty value here are
  14342. almost certainly wrong.
  14343. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  14344. type: string
  14345. type: object
  14346. x-kubernetes-map-type: atomic
  14347. conditions:
  14348. items:
  14349. description: ExternalSecretStatusCondition defines a status condition of an ExternalSecret resource.
  14350. properties:
  14351. lastTransitionTime:
  14352. format: date-time
  14353. type: string
  14354. message:
  14355. type: string
  14356. reason:
  14357. type: string
  14358. status:
  14359. type: string
  14360. type:
  14361. description: ExternalSecretConditionType defines a value type for ExternalSecret conditions.
  14362. enum:
  14363. - Ready
  14364. - Deleted
  14365. type: string
  14366. required:
  14367. - status
  14368. - type
  14369. type: object
  14370. type: array
  14371. refreshTime:
  14372. description: |-
  14373. refreshTime is the time and date the external secret was fetched and
  14374. the target secret updated
  14375. format: date-time
  14376. nullable: true
  14377. type: string
  14378. syncedResourceVersion:
  14379. description: SyncedResourceVersion keeps track of the last synced version
  14380. type: string
  14381. type: object
  14382. type: object
  14383. selectableFields:
  14384. - jsonPath: .spec.secretStoreRef.name
  14385. - jsonPath: .spec.secretStoreRef.kind
  14386. - jsonPath: .spec.target.name
  14387. - jsonPath: .spec.refreshInterval
  14388. served: true
  14389. storage: true
  14390. subresources:
  14391. status: {}
  14392. - additionalPrinterColumns:
  14393. - jsonPath: .spec.secretStoreRef.kind
  14394. name: StoreType
  14395. type: string
  14396. - jsonPath: .spec.secretStoreRef.name
  14397. name: Store
  14398. type: string
  14399. - jsonPath: .spec.refreshInterval
  14400. name: Refresh Interval
  14401. type: string
  14402. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  14403. name: Status
  14404. type: string
  14405. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  14406. name: Ready
  14407. type: string
  14408. - jsonPath: .status.refreshTime
  14409. name: Last Sync
  14410. type: date
  14411. deprecated: true
  14412. name: v1beta1
  14413. schema:
  14414. openAPIV3Schema:
  14415. description: ExternalSecret is the schema for the external-secrets API.
  14416. properties:
  14417. apiVersion:
  14418. description: |-
  14419. APIVersion defines the versioned schema of this representation of an object.
  14420. Servers should convert recognized schemas to the latest internal value, and
  14421. may reject unrecognized values.
  14422. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  14423. type: string
  14424. kind:
  14425. description: |-
  14426. Kind is a string value representing the REST resource this object represents.
  14427. Servers may infer this from the endpoint the client submits requests to.
  14428. Cannot be updated.
  14429. In CamelCase.
  14430. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  14431. type: string
  14432. metadata:
  14433. type: object
  14434. spec:
  14435. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  14436. properties:
  14437. data:
  14438. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  14439. items:
  14440. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  14441. properties:
  14442. remoteRef:
  14443. description: |-
  14444. RemoteRef points to the remote secret and defines
  14445. which secret (version/property/..) to fetch.
  14446. properties:
  14447. conversionStrategy:
  14448. default: Default
  14449. description: Used to define a conversion Strategy
  14450. enum:
  14451. - Default
  14452. - Unicode
  14453. type: string
  14454. decodingStrategy:
  14455. default: None
  14456. description: Used to define a decoding Strategy
  14457. enum:
  14458. - Auto
  14459. - Base64
  14460. - Base64URL
  14461. - None
  14462. type: string
  14463. key:
  14464. description: Key is the key used in the Provider, mandatory
  14465. type: string
  14466. metadataPolicy:
  14467. default: None
  14468. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14469. enum:
  14470. - None
  14471. - Fetch
  14472. type: string
  14473. property:
  14474. description: Used to select a specific property of the Provider value (if a map), if supported
  14475. type: string
  14476. version:
  14477. description: Used to select a specific version of the Provider value, if supported
  14478. type: string
  14479. required:
  14480. - key
  14481. type: object
  14482. secretKey:
  14483. description: The key in the Kubernetes Secret to store the value.
  14484. maxLength: 253
  14485. minLength: 1
  14486. pattern: ^[-._a-zA-Z0-9]+$
  14487. type: string
  14488. sourceRef:
  14489. description: |-
  14490. SourceRef allows you to override the source
  14491. from which the value will be pulled.
  14492. maxProperties: 1
  14493. minProperties: 1
  14494. properties:
  14495. generatorRef:
  14496. description: |-
  14497. GeneratorRef points to a generator custom resource.
  14498. Deprecated: The generatorRef is not implemented in .data[].
  14499. this will be removed with v1.
  14500. properties:
  14501. apiVersion:
  14502. default: generators.external-secrets.io/v1alpha1
  14503. description: Specify the apiVersion of the generator resource
  14504. type: string
  14505. kind:
  14506. description: Specify the Kind of the generator resource
  14507. enum:
  14508. - ACRAccessToken
  14509. - ClusterGenerator
  14510. - ECRAuthorizationToken
  14511. - Fake
  14512. - GCRAccessToken
  14513. - GithubAccessToken
  14514. - QuayAccessToken
  14515. - Password
  14516. - SSHKey
  14517. - STSSessionToken
  14518. - UUID
  14519. - VaultDynamicSecret
  14520. - Webhook
  14521. - Grafana
  14522. type: string
  14523. name:
  14524. description: Specify the name of the generator resource
  14525. maxLength: 253
  14526. minLength: 1
  14527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14528. type: string
  14529. required:
  14530. - kind
  14531. - name
  14532. type: object
  14533. storeRef:
  14534. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14535. properties:
  14536. kind:
  14537. description: |-
  14538. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14539. Defaults to `SecretStore`
  14540. enum:
  14541. - SecretStore
  14542. - ClusterSecretStore
  14543. type: string
  14544. name:
  14545. description: Name of the SecretStore resource
  14546. maxLength: 253
  14547. minLength: 1
  14548. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14549. type: string
  14550. type: object
  14551. type: object
  14552. required:
  14553. - remoteRef
  14554. - secretKey
  14555. type: object
  14556. type: array
  14557. dataFrom:
  14558. description: |-
  14559. DataFrom is used to fetch all properties from a specific Provider data
  14560. If multiple entries are specified, the Secret keys are merged in the specified order
  14561. items:
  14562. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  14563. properties:
  14564. extract:
  14565. description: |-
  14566. Used to extract multiple key/value pairs from one secret
  14567. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14568. properties:
  14569. conversionStrategy:
  14570. default: Default
  14571. description: Used to define a conversion Strategy
  14572. enum:
  14573. - Default
  14574. - Unicode
  14575. type: string
  14576. decodingStrategy:
  14577. default: None
  14578. description: Used to define a decoding Strategy
  14579. enum:
  14580. - Auto
  14581. - Base64
  14582. - Base64URL
  14583. - None
  14584. type: string
  14585. key:
  14586. description: Key is the key used in the Provider, mandatory
  14587. type: string
  14588. metadataPolicy:
  14589. default: None
  14590. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14591. enum:
  14592. - None
  14593. - Fetch
  14594. type: string
  14595. property:
  14596. description: Used to select a specific property of the Provider value (if a map), if supported
  14597. type: string
  14598. version:
  14599. description: Used to select a specific version of the Provider value, if supported
  14600. type: string
  14601. required:
  14602. - key
  14603. type: object
  14604. find:
  14605. description: |-
  14606. Used to find secrets based on tags or regular expressions
  14607. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14608. properties:
  14609. conversionStrategy:
  14610. default: Default
  14611. description: Used to define a conversion Strategy
  14612. enum:
  14613. - Default
  14614. - Unicode
  14615. type: string
  14616. decodingStrategy:
  14617. default: None
  14618. description: Used to define a decoding Strategy
  14619. enum:
  14620. - Auto
  14621. - Base64
  14622. - Base64URL
  14623. - None
  14624. type: string
  14625. name:
  14626. description: Finds secrets based on the name.
  14627. properties:
  14628. regexp:
  14629. description: Finds secrets base
  14630. type: string
  14631. type: object
  14632. path:
  14633. description: A root path to start the find operations.
  14634. type: string
  14635. tags:
  14636. additionalProperties:
  14637. type: string
  14638. description: Find secrets based on tags.
  14639. type: object
  14640. type: object
  14641. rewrite:
  14642. description: |-
  14643. Used to rewrite secret Keys after getting them from the secret Provider
  14644. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  14645. items:
  14646. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  14647. maxProperties: 1
  14648. minProperties: 1
  14649. properties:
  14650. regexp:
  14651. description: |-
  14652. Used to rewrite with regular expressions.
  14653. The resulting key will be the output of a regexp.ReplaceAll operation.
  14654. properties:
  14655. source:
  14656. description: Used to define the regular expression of a re.Compiler.
  14657. type: string
  14658. target:
  14659. description: Used to define the target pattern of a ReplaceAll operation.
  14660. type: string
  14661. required:
  14662. - source
  14663. - target
  14664. type: object
  14665. transform:
  14666. description: |-
  14667. Used to apply string transformation on the secrets.
  14668. The resulting key will be the output of the template applied by the operation.
  14669. properties:
  14670. template:
  14671. description: |-
  14672. Used to define the template to apply on the secret name.
  14673. `.value ` will specify the secret name in the template.
  14674. type: string
  14675. required:
  14676. - template
  14677. type: object
  14678. type: object
  14679. type: array
  14680. sourceRef:
  14681. description: |-
  14682. SourceRef points to a store or generator
  14683. which contains secret values ready to use.
  14684. Use this in combination with Extract or Find pull values out of
  14685. a specific SecretStore.
  14686. When sourceRef points to a generator Extract or Find is not supported.
  14687. The generator returns a static map of values
  14688. maxProperties: 1
  14689. minProperties: 1
  14690. properties:
  14691. generatorRef:
  14692. description: GeneratorRef points to a generator custom resource.
  14693. properties:
  14694. apiVersion:
  14695. default: generators.external-secrets.io/v1alpha1
  14696. description: Specify the apiVersion of the generator resource
  14697. type: string
  14698. kind:
  14699. description: Specify the Kind of the generator resource
  14700. enum:
  14701. - ACRAccessToken
  14702. - ClusterGenerator
  14703. - ECRAuthorizationToken
  14704. - Fake
  14705. - GCRAccessToken
  14706. - GithubAccessToken
  14707. - QuayAccessToken
  14708. - Password
  14709. - SSHKey
  14710. - STSSessionToken
  14711. - UUID
  14712. - VaultDynamicSecret
  14713. - Webhook
  14714. - Grafana
  14715. type: string
  14716. name:
  14717. description: Specify the name of the generator resource
  14718. maxLength: 253
  14719. minLength: 1
  14720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14721. type: string
  14722. required:
  14723. - kind
  14724. - name
  14725. type: object
  14726. storeRef:
  14727. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14728. properties:
  14729. kind:
  14730. description: |-
  14731. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14732. Defaults to `SecretStore`
  14733. enum:
  14734. - SecretStore
  14735. - ClusterSecretStore
  14736. type: string
  14737. name:
  14738. description: Name of the SecretStore resource
  14739. maxLength: 253
  14740. minLength: 1
  14741. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14742. type: string
  14743. type: object
  14744. type: object
  14745. type: object
  14746. type: array
  14747. refreshInterval:
  14748. default: 1h0m0s
  14749. description: |-
  14750. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  14751. specified as Golang Duration strings.
  14752. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  14753. Example values: "1h0m0s", "2h30m0s", "10m0s"
  14754. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  14755. type: string
  14756. refreshPolicy:
  14757. description: |-
  14758. RefreshPolicy determines how the ExternalSecret should be refreshed:
  14759. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  14760. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  14761. No periodic updates occur if refreshInterval is 0.
  14762. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  14763. enum:
  14764. - CreatedOnce
  14765. - Periodic
  14766. - OnChange
  14767. type: string
  14768. secretStoreRef:
  14769. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14770. properties:
  14771. kind:
  14772. description: |-
  14773. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14774. Defaults to `SecretStore`
  14775. enum:
  14776. - SecretStore
  14777. - ClusterSecretStore
  14778. type: string
  14779. name:
  14780. description: Name of the SecretStore resource
  14781. maxLength: 253
  14782. minLength: 1
  14783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14784. type: string
  14785. type: object
  14786. target:
  14787. default:
  14788. creationPolicy: Owner
  14789. deletionPolicy: Retain
  14790. description: |-
  14791. ExternalSecretTarget defines the Kubernetes Secret to be created
  14792. There can be only one target per ExternalSecret.
  14793. properties:
  14794. creationPolicy:
  14795. default: Owner
  14796. description: |-
  14797. CreationPolicy defines rules on how to create the resulting Secret.
  14798. Defaults to "Owner"
  14799. enum:
  14800. - Owner
  14801. - Orphan
  14802. - Merge
  14803. - None
  14804. type: string
  14805. deletionPolicy:
  14806. default: Retain
  14807. description: |-
  14808. DeletionPolicy defines rules on how to delete the resulting Secret.
  14809. Defaults to "Retain"
  14810. enum:
  14811. - Delete
  14812. - Merge
  14813. - Retain
  14814. type: string
  14815. immutable:
  14816. description: Immutable defines if the final secret will be immutable
  14817. type: boolean
  14818. name:
  14819. description: |-
  14820. The name of the Secret resource to be managed.
  14821. Defaults to the .metadata.name of the ExternalSecret resource
  14822. maxLength: 253
  14823. minLength: 1
  14824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14825. type: string
  14826. template:
  14827. description: Template defines a blueprint for the created Secret resource.
  14828. properties:
  14829. data:
  14830. additionalProperties:
  14831. type: string
  14832. type: object
  14833. engineVersion:
  14834. default: v2
  14835. description: |-
  14836. EngineVersion specifies the template engine version
  14837. that should be used to compile/execute the
  14838. template specified in .data and .templateFrom[].
  14839. enum:
  14840. - v2
  14841. type: string
  14842. mergePolicy:
  14843. default: Replace
  14844. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  14845. enum:
  14846. - Replace
  14847. - Merge
  14848. type: string
  14849. metadata:
  14850. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14851. properties:
  14852. annotations:
  14853. additionalProperties:
  14854. type: string
  14855. type: object
  14856. labels:
  14857. additionalProperties:
  14858. type: string
  14859. type: object
  14860. type: object
  14861. templateFrom:
  14862. items:
  14863. description: TemplateFrom defines a source for template data.
  14864. properties:
  14865. configMap:
  14866. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14867. properties:
  14868. items:
  14869. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14870. items:
  14871. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14872. properties:
  14873. key:
  14874. description: A key in the ConfigMap/Secret
  14875. maxLength: 253
  14876. minLength: 1
  14877. pattern: ^[-._a-zA-Z0-9]+$
  14878. type: string
  14879. templateAs:
  14880. default: Values
  14881. description: TemplateScope defines the scope of the template when processing template data.
  14882. enum:
  14883. - Values
  14884. - KeysAndValues
  14885. type: string
  14886. required:
  14887. - key
  14888. type: object
  14889. type: array
  14890. name:
  14891. description: The name of the ConfigMap/Secret resource
  14892. maxLength: 253
  14893. minLength: 1
  14894. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14895. type: string
  14896. required:
  14897. - items
  14898. - name
  14899. type: object
  14900. literal:
  14901. type: string
  14902. secret:
  14903. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14904. properties:
  14905. items:
  14906. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14907. items:
  14908. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14909. properties:
  14910. key:
  14911. description: A key in the ConfigMap/Secret
  14912. maxLength: 253
  14913. minLength: 1
  14914. pattern: ^[-._a-zA-Z0-9]+$
  14915. type: string
  14916. templateAs:
  14917. default: Values
  14918. description: TemplateScope defines the scope of the template when processing template data.
  14919. enum:
  14920. - Values
  14921. - KeysAndValues
  14922. type: string
  14923. required:
  14924. - key
  14925. type: object
  14926. type: array
  14927. name:
  14928. description: The name of the ConfigMap/Secret resource
  14929. maxLength: 253
  14930. minLength: 1
  14931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14932. type: string
  14933. required:
  14934. - items
  14935. - name
  14936. type: object
  14937. target:
  14938. default: Data
  14939. description: TemplateTarget defines the target field where the template result will be stored.
  14940. enum:
  14941. - Data
  14942. - Annotations
  14943. - Labels
  14944. type: string
  14945. type: object
  14946. type: array
  14947. type:
  14948. type: string
  14949. type: object
  14950. type: object
  14951. type: object
  14952. status:
  14953. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  14954. properties:
  14955. binding:
  14956. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  14957. properties:
  14958. name:
  14959. default: ""
  14960. description: |-
  14961. Name of the referent.
  14962. This field is effectively required, but due to backwards compatibility is
  14963. allowed to be empty. Instances of this type with an empty value here are
  14964. almost certainly wrong.
  14965. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  14966. type: string
  14967. type: object
  14968. x-kubernetes-map-type: atomic
  14969. conditions:
  14970. items:
  14971. description: ExternalSecretStatusCondition contains condition information for an ExternalSecret.
  14972. properties:
  14973. lastTransitionTime:
  14974. format: date-time
  14975. type: string
  14976. message:
  14977. type: string
  14978. reason:
  14979. type: string
  14980. status:
  14981. type: string
  14982. type:
  14983. description: ExternalSecretConditionType defines the condition type for an ExternalSecret.
  14984. type: string
  14985. required:
  14986. - status
  14987. - type
  14988. type: object
  14989. type: array
  14990. refreshTime:
  14991. description: |-
  14992. refreshTime is the time and date the external secret was fetched and
  14993. the target secret updated
  14994. format: date-time
  14995. nullable: true
  14996. type: string
  14997. syncedResourceVersion:
  14998. description: SyncedResourceVersion keeps track of the last synced version
  14999. type: string
  15000. type: object
  15001. type: object
  15002. served: false
  15003. storage: false
  15004. subresources:
  15005. status: {}
  15006. ---
  15007. apiVersion: apiextensions.k8s.io/v1
  15008. kind: CustomResourceDefinition
  15009. metadata:
  15010. annotations:
  15011. controller-gen.kubebuilder.io/version: v0.19.0
  15012. labels:
  15013. external-secrets.io/component: controller
  15014. name: pushsecrets.external-secrets.io
  15015. spec:
  15016. group: external-secrets.io
  15017. names:
  15018. categories:
  15019. - external-secrets
  15020. kind: PushSecret
  15021. listKind: PushSecretList
  15022. plural: pushsecrets
  15023. shortNames:
  15024. - ps
  15025. singular: pushsecret
  15026. scope: Namespaced
  15027. versions:
  15028. - additionalPrinterColumns:
  15029. - jsonPath: .metadata.creationTimestamp
  15030. name: AGE
  15031. type: date
  15032. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  15033. name: Status
  15034. type: string
  15035. - jsonPath: .status.refreshTime
  15036. name: Last Sync
  15037. type: date
  15038. name: v1alpha1
  15039. schema:
  15040. openAPIV3Schema:
  15041. description: PushSecret is the Schema for the PushSecrets API that enables pushing Kubernetes secrets to external secret providers.
  15042. properties:
  15043. apiVersion:
  15044. description: |-
  15045. APIVersion defines the versioned schema of this representation of an object.
  15046. Servers should convert recognized schemas to the latest internal value, and
  15047. may reject unrecognized values.
  15048. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15049. type: string
  15050. kind:
  15051. description: |-
  15052. Kind is a string value representing the REST resource this object represents.
  15053. Servers may infer this from the endpoint the client submits requests to.
  15054. Cannot be updated.
  15055. In CamelCase.
  15056. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15057. type: string
  15058. metadata:
  15059. type: object
  15060. spec:
  15061. description: PushSecretSpec configures the behavior of the PushSecret.
  15062. properties:
  15063. data:
  15064. description: Secret Data that should be pushed to providers
  15065. items:
  15066. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  15067. properties:
  15068. conversionStrategy:
  15069. default: None
  15070. description: Used to define a conversion Strategy for the secret keys
  15071. enum:
  15072. - None
  15073. - ReverseUnicode
  15074. type: string
  15075. match:
  15076. description: Match a given Secret Key to be pushed to the provider.
  15077. properties:
  15078. remoteRef:
  15079. description: Remote Refs to push to providers.
  15080. properties:
  15081. property:
  15082. description: Name of the property in the resulting secret
  15083. type: string
  15084. remoteKey:
  15085. description: Name of the resulting provider secret.
  15086. type: string
  15087. required:
  15088. - remoteKey
  15089. type: object
  15090. secretKey:
  15091. description: Secret Key to be pushed
  15092. type: string
  15093. required:
  15094. - remoteRef
  15095. type: object
  15096. metadata:
  15097. description: |-
  15098. Metadata is metadata attached to the secret.
  15099. The structure of metadata is provider specific, please look it up in the provider documentation.
  15100. x-kubernetes-preserve-unknown-fields: true
  15101. required:
  15102. - match
  15103. type: object
  15104. type: array
  15105. dataTo:
  15106. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  15107. items:
  15108. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  15109. properties:
  15110. conversionStrategy:
  15111. default: None
  15112. description: Used to define a conversion Strategy for the secret keys
  15113. enum:
  15114. - None
  15115. - ReverseUnicode
  15116. type: string
  15117. match:
  15118. description: |-
  15119. Match pattern for selecting keys from the source Secret.
  15120. If not specified, all keys are selected.
  15121. properties:
  15122. regexp:
  15123. description: |-
  15124. Regexp matches keys by regular expression.
  15125. If not specified, all keys are matched.
  15126. type: string
  15127. type: object
  15128. metadata:
  15129. description: |-
  15130. Metadata is metadata attached to the secret.
  15131. The structure of metadata is provider specific, please look it up in the provider documentation.
  15132. x-kubernetes-preserve-unknown-fields: true
  15133. remoteKey:
  15134. description: |-
  15135. RemoteKey is the name of the single provider secret that will receive ALL
  15136. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  15137. When set, per-key expansion is skipped and a single push is performed.
  15138. The provider's store prefix (if any) is still prepended to this value.
  15139. When not set, each matched key is pushed as its own individual provider secret.
  15140. type: string
  15141. rewrite:
  15142. description: |-
  15143. Rewrite operations to transform keys before pushing to the provider.
  15144. Operations are applied sequentially.
  15145. items:
  15146. description: PushSecretRewrite defines how to transform secret keys before pushing.
  15147. properties:
  15148. regexp:
  15149. description: Used to rewrite with regular expressions.
  15150. properties:
  15151. source:
  15152. description: Used to define the regular expression of a re.Compiler.
  15153. type: string
  15154. target:
  15155. description: Used to define the target pattern of a ReplaceAll operation.
  15156. type: string
  15157. required:
  15158. - source
  15159. - target
  15160. type: object
  15161. transform:
  15162. description: Used to apply string transformation on the secrets.
  15163. properties:
  15164. template:
  15165. description: |-
  15166. Used to define the template to apply on the secret name.
  15167. `.value ` will specify the secret name in the template.
  15168. type: string
  15169. required:
  15170. - template
  15171. type: object
  15172. type: object
  15173. x-kubernetes-validations:
  15174. - message: exactly one of regexp or transform must be set
  15175. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  15176. type: array
  15177. storeRef:
  15178. description: StoreRef specifies which SecretStore to push to. Required.
  15179. properties:
  15180. kind:
  15181. default: SecretStore
  15182. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  15183. enum:
  15184. - SecretStore
  15185. - ClusterSecretStore
  15186. type: string
  15187. labelSelector:
  15188. description: Optionally, sync to secret stores with label selector
  15189. properties:
  15190. matchExpressions:
  15191. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15192. items:
  15193. description: |-
  15194. A label selector requirement is a selector that contains values, a key, and an operator that
  15195. relates the key and values.
  15196. properties:
  15197. key:
  15198. description: key is the label key that the selector applies to.
  15199. type: string
  15200. operator:
  15201. description: |-
  15202. operator represents a key's relationship to a set of values.
  15203. Valid operators are In, NotIn, Exists and DoesNotExist.
  15204. type: string
  15205. values:
  15206. description: |-
  15207. values is an array of string values. If the operator is In or NotIn,
  15208. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15209. the values array must be empty. This array is replaced during a strategic
  15210. merge patch.
  15211. items:
  15212. type: string
  15213. type: array
  15214. x-kubernetes-list-type: atomic
  15215. required:
  15216. - key
  15217. - operator
  15218. type: object
  15219. type: array
  15220. x-kubernetes-list-type: atomic
  15221. matchLabels:
  15222. additionalProperties:
  15223. type: string
  15224. description: |-
  15225. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15226. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15227. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15228. type: object
  15229. type: object
  15230. x-kubernetes-map-type: atomic
  15231. name:
  15232. description: Optionally, sync to the SecretStore of the given name
  15233. maxLength: 253
  15234. minLength: 1
  15235. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15236. type: string
  15237. type: object
  15238. type: object
  15239. x-kubernetes-validations:
  15240. - message: storeRef must specify either name or labelSelector
  15241. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  15242. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  15243. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  15244. type: array
  15245. deletionPolicy:
  15246. default: None
  15247. description: Deletion Policy to handle Secrets in the provider.
  15248. enum:
  15249. - Delete
  15250. - None
  15251. type: string
  15252. refreshInterval:
  15253. default: 1h0m0s
  15254. description: The Interval to which External Secrets will try to push a secret definition
  15255. type: string
  15256. secretStoreRefs:
  15257. items:
  15258. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  15259. properties:
  15260. kind:
  15261. default: SecretStore
  15262. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  15263. enum:
  15264. - SecretStore
  15265. - ClusterSecretStore
  15266. type: string
  15267. labelSelector:
  15268. description: Optionally, sync to secret stores with label selector
  15269. properties:
  15270. matchExpressions:
  15271. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15272. items:
  15273. description: |-
  15274. A label selector requirement is a selector that contains values, a key, and an operator that
  15275. relates the key and values.
  15276. properties:
  15277. key:
  15278. description: key is the label key that the selector applies to.
  15279. type: string
  15280. operator:
  15281. description: |-
  15282. operator represents a key's relationship to a set of values.
  15283. Valid operators are In, NotIn, Exists and DoesNotExist.
  15284. type: string
  15285. values:
  15286. description: |-
  15287. values is an array of string values. If the operator is In or NotIn,
  15288. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15289. the values array must be empty. This array is replaced during a strategic
  15290. merge patch.
  15291. items:
  15292. type: string
  15293. type: array
  15294. x-kubernetes-list-type: atomic
  15295. required:
  15296. - key
  15297. - operator
  15298. type: object
  15299. type: array
  15300. x-kubernetes-list-type: atomic
  15301. matchLabels:
  15302. additionalProperties:
  15303. type: string
  15304. description: |-
  15305. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15306. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15307. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15308. type: object
  15309. type: object
  15310. x-kubernetes-map-type: atomic
  15311. name:
  15312. description: Optionally, sync to the SecretStore of the given name
  15313. maxLength: 253
  15314. minLength: 1
  15315. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15316. type: string
  15317. type: object
  15318. type: array
  15319. selector:
  15320. description: The Secret Selector (k8s source) for the Push Secret
  15321. maxProperties: 1
  15322. minProperties: 1
  15323. properties:
  15324. generatorRef:
  15325. description: Point to a generator to create a Secret.
  15326. properties:
  15327. apiVersion:
  15328. default: generators.external-secrets.io/v1alpha1
  15329. description: Specify the apiVersion of the generator resource
  15330. type: string
  15331. kind:
  15332. description: Specify the Kind of the generator resource
  15333. enum:
  15334. - ACRAccessToken
  15335. - BeyondtrustWorkloadCredentialsDynamicSecret
  15336. - ClusterGenerator
  15337. - CloudsmithAccessToken
  15338. - ECRAuthorizationToken
  15339. - Fake
  15340. - GCRAccessToken
  15341. - GithubAccessToken
  15342. - GitlabDeployToken
  15343. - QuayAccessToken
  15344. - Password
  15345. - SSHKey
  15346. - STSSessionToken
  15347. - UUID
  15348. - VaultDynamicSecret
  15349. - Webhook
  15350. - Grafana
  15351. - MFA
  15352. type: string
  15353. name:
  15354. description: Specify the name of the generator resource
  15355. maxLength: 253
  15356. minLength: 1
  15357. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15358. type: string
  15359. required:
  15360. - kind
  15361. - name
  15362. type: object
  15363. secret:
  15364. description: Select a Secret to Push.
  15365. properties:
  15366. name:
  15367. description: |-
  15368. Name of the Secret.
  15369. The Secret must exist in the same namespace as the PushSecret manifest.
  15370. maxLength: 253
  15371. minLength: 1
  15372. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15373. type: string
  15374. selector:
  15375. description: Selector chooses secrets using a labelSelector.
  15376. properties:
  15377. matchExpressions:
  15378. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15379. items:
  15380. description: |-
  15381. A label selector requirement is a selector that contains values, a key, and an operator that
  15382. relates the key and values.
  15383. properties:
  15384. key:
  15385. description: key is the label key that the selector applies to.
  15386. type: string
  15387. operator:
  15388. description: |-
  15389. operator represents a key's relationship to a set of values.
  15390. Valid operators are In, NotIn, Exists and DoesNotExist.
  15391. type: string
  15392. values:
  15393. description: |-
  15394. values is an array of string values. If the operator is In or NotIn,
  15395. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15396. the values array must be empty. This array is replaced during a strategic
  15397. merge patch.
  15398. items:
  15399. type: string
  15400. type: array
  15401. x-kubernetes-list-type: atomic
  15402. required:
  15403. - key
  15404. - operator
  15405. type: object
  15406. type: array
  15407. x-kubernetes-list-type: atomic
  15408. matchLabels:
  15409. additionalProperties:
  15410. type: string
  15411. description: |-
  15412. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15413. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15414. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15415. type: object
  15416. type: object
  15417. x-kubernetes-map-type: atomic
  15418. type: object
  15419. type: object
  15420. template:
  15421. description: Template defines a blueprint for the created Secret resource.
  15422. properties:
  15423. data:
  15424. additionalProperties:
  15425. type: string
  15426. type: object
  15427. engineVersion:
  15428. default: v2
  15429. description: |-
  15430. EngineVersion specifies the template engine version
  15431. that should be used to compile/execute the
  15432. template specified in .data and .templateFrom[].
  15433. enum:
  15434. - v2
  15435. type: string
  15436. mergePolicy:
  15437. default: Replace
  15438. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  15439. enum:
  15440. - Replace
  15441. - Merge
  15442. type: string
  15443. metadata:
  15444. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  15445. properties:
  15446. annotations:
  15447. additionalProperties:
  15448. type: string
  15449. type: object
  15450. finalizers:
  15451. items:
  15452. type: string
  15453. type: array
  15454. labels:
  15455. additionalProperties:
  15456. type: string
  15457. type: object
  15458. type: object
  15459. templateFrom:
  15460. items:
  15461. description: |-
  15462. TemplateFrom specifies a source for templates.
  15463. Each item in the list can either reference a ConfigMap or a Secret resource.
  15464. properties:
  15465. configMap:
  15466. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15467. properties:
  15468. items:
  15469. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15470. items:
  15471. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15472. properties:
  15473. key:
  15474. description: A key in the ConfigMap/Secret
  15475. maxLength: 253
  15476. minLength: 1
  15477. pattern: ^[-._a-zA-Z0-9]+$
  15478. type: string
  15479. templateAs:
  15480. default: Values
  15481. description: TemplateScope specifies how the template keys should be interpreted.
  15482. enum:
  15483. - Values
  15484. - KeysAndValues
  15485. type: string
  15486. required:
  15487. - key
  15488. type: object
  15489. type: array
  15490. name:
  15491. description: The name of the ConfigMap/Secret resource
  15492. maxLength: 253
  15493. minLength: 1
  15494. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15495. type: string
  15496. required:
  15497. - items
  15498. - name
  15499. type: object
  15500. literal:
  15501. type: string
  15502. secret:
  15503. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15504. properties:
  15505. items:
  15506. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15507. items:
  15508. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15509. properties:
  15510. key:
  15511. description: A key in the ConfigMap/Secret
  15512. maxLength: 253
  15513. minLength: 1
  15514. pattern: ^[-._a-zA-Z0-9]+$
  15515. type: string
  15516. templateAs:
  15517. default: Values
  15518. description: TemplateScope specifies how the template keys should be interpreted.
  15519. enum:
  15520. - Values
  15521. - KeysAndValues
  15522. type: string
  15523. required:
  15524. - key
  15525. type: object
  15526. type: array
  15527. name:
  15528. description: The name of the ConfigMap/Secret resource
  15529. maxLength: 253
  15530. minLength: 1
  15531. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15532. type: string
  15533. required:
  15534. - items
  15535. - name
  15536. type: object
  15537. target:
  15538. default: Data
  15539. description: |-
  15540. Target specifies where to place the template result.
  15541. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  15542. any other value is rejected because it would allow writes to privileged Secret fields.
  15543. For custom resources (when spec.target.manifest is set), this supports
  15544. nested paths like "spec.database.config" or "data".
  15545. type: string
  15546. valuesDecodingStrategy:
  15547. description: |-
  15548. Used to define a decoding Strategy for the rendered template values.
  15549. Defaults to None when omitted.
  15550. enum:
  15551. - Auto
  15552. - Base64
  15553. - Base64URL
  15554. - None
  15555. type: string
  15556. type: object
  15557. type: array
  15558. type:
  15559. type: string
  15560. type: object
  15561. updatePolicy:
  15562. default: Replace
  15563. description: UpdatePolicy to handle Secrets in the provider.
  15564. enum:
  15565. - Replace
  15566. - IfNotExists
  15567. type: string
  15568. required:
  15569. - secretStoreRefs
  15570. - selector
  15571. type: object
  15572. status:
  15573. description: PushSecretStatus indicates the history of the status of PushSecret.
  15574. properties:
  15575. conditions:
  15576. items:
  15577. description: PushSecretStatusCondition indicates the status of the PushSecret.
  15578. properties:
  15579. lastTransitionTime:
  15580. format: date-time
  15581. type: string
  15582. message:
  15583. type: string
  15584. reason:
  15585. type: string
  15586. status:
  15587. type: string
  15588. type:
  15589. description: PushSecretConditionType indicates the condition of the PushSecret.
  15590. type: string
  15591. required:
  15592. - status
  15593. - type
  15594. type: object
  15595. type: array
  15596. refreshTime:
  15597. description: |-
  15598. refreshTime is the time and date the external secret was fetched and
  15599. the target secret updated
  15600. format: date-time
  15601. nullable: true
  15602. type: string
  15603. syncedPushSecrets:
  15604. additionalProperties:
  15605. additionalProperties:
  15606. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  15607. properties:
  15608. conversionStrategy:
  15609. default: None
  15610. description: Used to define a conversion Strategy for the secret keys
  15611. enum:
  15612. - None
  15613. - ReverseUnicode
  15614. type: string
  15615. match:
  15616. description: Match a given Secret Key to be pushed to the provider.
  15617. properties:
  15618. remoteRef:
  15619. description: Remote Refs to push to providers.
  15620. properties:
  15621. property:
  15622. description: Name of the property in the resulting secret
  15623. type: string
  15624. remoteKey:
  15625. description: Name of the resulting provider secret.
  15626. type: string
  15627. required:
  15628. - remoteKey
  15629. type: object
  15630. secretKey:
  15631. description: Secret Key to be pushed
  15632. type: string
  15633. required:
  15634. - remoteRef
  15635. type: object
  15636. metadata:
  15637. description: |-
  15638. Metadata is metadata attached to the secret.
  15639. The structure of metadata is provider specific, please look it up in the provider documentation.
  15640. x-kubernetes-preserve-unknown-fields: true
  15641. required:
  15642. - match
  15643. type: object
  15644. type: object
  15645. description: |-
  15646. Synced PushSecrets, including secrets that already exist in provider.
  15647. Matches secret stores to PushSecretData that was stored to that secret store.
  15648. type: object
  15649. syncedResourceVersion:
  15650. description: SyncedResourceVersion keeps track of the last synced version.
  15651. type: string
  15652. type: object
  15653. type: object
  15654. served: true
  15655. storage: true
  15656. subresources:
  15657. status: {}
  15658. ---
  15659. apiVersion: apiextensions.k8s.io/v1
  15660. kind: CustomResourceDefinition
  15661. metadata:
  15662. annotations:
  15663. controller-gen.kubebuilder.io/version: v0.19.0
  15664. labels:
  15665. external-secrets.io/component: controller
  15666. name: secretstores.external-secrets.io
  15667. spec:
  15668. group: external-secrets.io
  15669. names:
  15670. categories:
  15671. - external-secrets
  15672. kind: SecretStore
  15673. listKind: SecretStoreList
  15674. plural: secretstores
  15675. shortNames:
  15676. - ss
  15677. singular: secretstore
  15678. scope: Namespaced
  15679. versions:
  15680. - additionalPrinterColumns:
  15681. - jsonPath: .metadata.creationTimestamp
  15682. name: AGE
  15683. type: date
  15684. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  15685. name: Status
  15686. type: string
  15687. - jsonPath: .status.capabilities
  15688. name: Capabilities
  15689. type: string
  15690. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  15691. name: Ready
  15692. type: string
  15693. name: v1
  15694. schema:
  15695. openAPIV3Schema:
  15696. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  15697. properties:
  15698. apiVersion:
  15699. description: |-
  15700. APIVersion defines the versioned schema of this representation of an object.
  15701. Servers should convert recognized schemas to the latest internal value, and
  15702. may reject unrecognized values.
  15703. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15704. type: string
  15705. kind:
  15706. description: |-
  15707. Kind is a string value representing the REST resource this object represents.
  15708. Servers may infer this from the endpoint the client submits requests to.
  15709. Cannot be updated.
  15710. In CamelCase.
  15711. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15712. type: string
  15713. metadata:
  15714. type: object
  15715. spec:
  15716. description: SecretStoreSpec defines the desired state of SecretStore.
  15717. properties:
  15718. conditions:
  15719. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  15720. items:
  15721. description: |-
  15722. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  15723. for a ClusterSecretStore instance.
  15724. properties:
  15725. namespaceRegexes:
  15726. description: Choose namespaces by using regex matching
  15727. items:
  15728. type: string
  15729. type: array
  15730. namespaceSelector:
  15731. description: Choose namespace using a labelSelector
  15732. properties:
  15733. matchExpressions:
  15734. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15735. items:
  15736. description: |-
  15737. A label selector requirement is a selector that contains values, a key, and an operator that
  15738. relates the key and values.
  15739. properties:
  15740. key:
  15741. description: key is the label key that the selector applies to.
  15742. type: string
  15743. operator:
  15744. description: |-
  15745. operator represents a key's relationship to a set of values.
  15746. Valid operators are In, NotIn, Exists and DoesNotExist.
  15747. type: string
  15748. values:
  15749. description: |-
  15750. values is an array of string values. If the operator is In or NotIn,
  15751. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15752. the values array must be empty. This array is replaced during a strategic
  15753. merge patch.
  15754. items:
  15755. type: string
  15756. type: array
  15757. x-kubernetes-list-type: atomic
  15758. required:
  15759. - key
  15760. - operator
  15761. type: object
  15762. type: array
  15763. x-kubernetes-list-type: atomic
  15764. matchLabels:
  15765. additionalProperties:
  15766. type: string
  15767. description: |-
  15768. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15769. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15770. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15771. type: object
  15772. type: object
  15773. x-kubernetes-map-type: atomic
  15774. namespaces:
  15775. description: Choose namespaces by name
  15776. items:
  15777. maxLength: 63
  15778. minLength: 1
  15779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15780. type: string
  15781. type: array
  15782. type: object
  15783. type: array
  15784. controller:
  15785. description: |-
  15786. Used to select the correct ESO controller (think: ingress.ingressClassName)
  15787. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  15788. type: string
  15789. provider:
  15790. description: Used to configure the provider. Only one provider may be set
  15791. maxProperties: 1
  15792. minProperties: 1
  15793. properties:
  15794. akeyless:
  15795. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  15796. properties:
  15797. akeylessGWApiURL:
  15798. description: Akeyless GW API Url from which the secrets to be fetched from.
  15799. type: string
  15800. authSecretRef:
  15801. description: Auth configures how the operator authenticates with Akeyless.
  15802. properties:
  15803. kubernetesAuth:
  15804. description: |-
  15805. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  15806. token stored in the named Secret resource.
  15807. properties:
  15808. accessID:
  15809. description: the Akeyless Kubernetes auth-method access-id
  15810. type: string
  15811. k8sConfName:
  15812. description: Kubernetes-auth configuration name in Akeyless-Gateway
  15813. type: string
  15814. secretRef:
  15815. description: |-
  15816. Optional secret field containing a Kubernetes ServiceAccount JWT used
  15817. for authenticating with Akeyless. If a name is specified without a key,
  15818. `token` is the default. If one is not specified, the one bound to
  15819. the controller will be used.
  15820. properties:
  15821. key:
  15822. description: |-
  15823. A key in the referenced Secret.
  15824. Some instances of this field may be defaulted, in others it may be required.
  15825. maxLength: 253
  15826. minLength: 1
  15827. pattern: ^[-._a-zA-Z0-9]+$
  15828. type: string
  15829. name:
  15830. description: The name of the Secret resource being referred to.
  15831. maxLength: 253
  15832. minLength: 1
  15833. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15834. type: string
  15835. namespace:
  15836. description: |-
  15837. The namespace of the Secret resource being referred to.
  15838. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15839. maxLength: 63
  15840. minLength: 1
  15841. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15842. type: string
  15843. type: object
  15844. serviceAccountRef:
  15845. description: |-
  15846. Optional service account field containing the name of a kubernetes ServiceAccount.
  15847. If the service account is specified, the service account secret token JWT will be used
  15848. for authenticating with Akeyless. If the service account selector is not supplied,
  15849. the secretRef will be used instead.
  15850. properties:
  15851. audiences:
  15852. description: |-
  15853. Audience specifies the `aud` claim for the service account token
  15854. Some providers automatically extend the audience field based on well-known annotations for workload
  15855. identity (e.g. IRSA or GCP Workload Identity)
  15856. items:
  15857. type: string
  15858. type: array
  15859. name:
  15860. description: The name of the ServiceAccount resource being referred to.
  15861. maxLength: 253
  15862. minLength: 1
  15863. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15864. type: string
  15865. namespace:
  15866. description: |-
  15867. Namespace of the resource being referred to.
  15868. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15869. maxLength: 63
  15870. minLength: 1
  15871. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15872. type: string
  15873. required:
  15874. - name
  15875. type: object
  15876. required:
  15877. - accessID
  15878. - k8sConfName
  15879. type: object
  15880. secretRef:
  15881. description: |-
  15882. Reference to a Secret that contains the details
  15883. to authenticate with Akeyless.
  15884. properties:
  15885. accessID:
  15886. description: The SecretAccessID is used for authentication
  15887. properties:
  15888. key:
  15889. description: |-
  15890. A key in the referenced Secret.
  15891. Some instances of this field may be defaulted, in others it may be required.
  15892. maxLength: 253
  15893. minLength: 1
  15894. pattern: ^[-._a-zA-Z0-9]+$
  15895. type: string
  15896. name:
  15897. description: The name of the Secret resource being referred to.
  15898. maxLength: 253
  15899. minLength: 1
  15900. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15901. type: string
  15902. namespace:
  15903. description: |-
  15904. The namespace of the Secret resource being referred to.
  15905. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15906. maxLength: 63
  15907. minLength: 1
  15908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15909. type: string
  15910. type: object
  15911. accessType:
  15912. description: |-
  15913. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15914. In some instances, `key` is a required field.
  15915. properties:
  15916. key:
  15917. description: |-
  15918. A key in the referenced Secret.
  15919. Some instances of this field may be defaulted, in others it may be required.
  15920. maxLength: 253
  15921. minLength: 1
  15922. pattern: ^[-._a-zA-Z0-9]+$
  15923. type: string
  15924. name:
  15925. description: The name of the Secret resource being referred to.
  15926. maxLength: 253
  15927. minLength: 1
  15928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15929. type: string
  15930. namespace:
  15931. description: |-
  15932. The namespace of the Secret resource being referred to.
  15933. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15934. maxLength: 63
  15935. minLength: 1
  15936. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15937. type: string
  15938. type: object
  15939. accessTypeParam:
  15940. description: |-
  15941. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15942. In some instances, `key` is a required field.
  15943. properties:
  15944. key:
  15945. description: |-
  15946. A key in the referenced Secret.
  15947. Some instances of this field may be defaulted, in others it may be required.
  15948. maxLength: 253
  15949. minLength: 1
  15950. pattern: ^[-._a-zA-Z0-9]+$
  15951. type: string
  15952. name:
  15953. description: The name of the Secret resource being referred to.
  15954. maxLength: 253
  15955. minLength: 1
  15956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15957. type: string
  15958. namespace:
  15959. description: |-
  15960. The namespace of the Secret resource being referred to.
  15961. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15962. maxLength: 63
  15963. minLength: 1
  15964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15965. type: string
  15966. type: object
  15967. type: object
  15968. serviceAccountRef:
  15969. description: |-
  15970. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  15971. authentication on AKS Workload Identity. The operator obtains a federated
  15972. identity token from this ServiceAccount via the TokenRequest API instead
  15973. of using the ESO controller pod identity. Ignored for other access types.
  15974. properties:
  15975. audiences:
  15976. description: |-
  15977. Audience specifies the `aud` claim for the service account token
  15978. Some providers automatically extend the audience field based on well-known annotations for workload
  15979. identity (e.g. IRSA or GCP Workload Identity)
  15980. items:
  15981. type: string
  15982. type: array
  15983. name:
  15984. description: The name of the ServiceAccount resource being referred to.
  15985. maxLength: 253
  15986. minLength: 1
  15987. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15988. type: string
  15989. namespace:
  15990. description: |-
  15991. Namespace of the resource being referred to.
  15992. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15993. maxLength: 63
  15994. minLength: 1
  15995. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15996. type: string
  15997. required:
  15998. - name
  15999. type: object
  16000. type: object
  16001. caBundle:
  16002. description: |-
  16003. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  16004. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  16005. are used to validate the TLS connection.
  16006. format: byte
  16007. type: string
  16008. caProvider:
  16009. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  16010. properties:
  16011. key:
  16012. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16013. maxLength: 253
  16014. minLength: 1
  16015. pattern: ^[-._a-zA-Z0-9]+$
  16016. type: string
  16017. name:
  16018. description: The name of the object located at the provider type.
  16019. maxLength: 253
  16020. minLength: 1
  16021. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16022. type: string
  16023. namespace:
  16024. description: |-
  16025. The namespace the Provider type is in.
  16026. Can only be defined when used in a ClusterSecretStore.
  16027. maxLength: 63
  16028. minLength: 1
  16029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16030. type: string
  16031. type:
  16032. description: The type of provider to use such as "Secret", or "ConfigMap".
  16033. enum:
  16034. - Secret
  16035. - ConfigMap
  16036. type: string
  16037. required:
  16038. - name
  16039. - type
  16040. type: object
  16041. ignoreCache:
  16042. description: |-
  16043. IgnoreCache bypasses the Gateway cache for secret reads when true.
  16044. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  16045. type: boolean
  16046. required:
  16047. - akeylessGWApiURL
  16048. - authSecretRef
  16049. type: object
  16050. aws:
  16051. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  16052. properties:
  16053. additionalRoles:
  16054. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  16055. items:
  16056. type: string
  16057. type: array
  16058. auth:
  16059. description: |-
  16060. Auth defines the information necessary to authenticate against AWS
  16061. if not set aws sdk will infer credentials from your environment
  16062. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  16063. properties:
  16064. jwt:
  16065. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  16066. properties:
  16067. serviceAccountRef:
  16068. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  16069. properties:
  16070. audiences:
  16071. description: |-
  16072. Audience specifies the `aud` claim for the service account token
  16073. Some providers automatically extend the audience field based on well-known annotations for workload
  16074. identity (e.g. IRSA or GCP Workload Identity)
  16075. items:
  16076. type: string
  16077. type: array
  16078. name:
  16079. description: The name of the ServiceAccount resource being referred to.
  16080. maxLength: 253
  16081. minLength: 1
  16082. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16083. type: string
  16084. namespace:
  16085. description: |-
  16086. Namespace of the resource being referred to.
  16087. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16088. maxLength: 63
  16089. minLength: 1
  16090. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16091. type: string
  16092. required:
  16093. - name
  16094. type: object
  16095. type: object
  16096. secretRef:
  16097. description: |-
  16098. AWSAuthSecretRef holds secret references for AWS credentials
  16099. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  16100. properties:
  16101. accessKeyIDSecretRef:
  16102. description: The AccessKeyID is used for authentication
  16103. properties:
  16104. key:
  16105. description: |-
  16106. A key in the referenced Secret.
  16107. Some instances of this field may be defaulted, in others it may be required.
  16108. maxLength: 253
  16109. minLength: 1
  16110. pattern: ^[-._a-zA-Z0-9]+$
  16111. type: string
  16112. name:
  16113. description: The name of the Secret resource being referred to.
  16114. maxLength: 253
  16115. minLength: 1
  16116. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16117. type: string
  16118. namespace:
  16119. description: |-
  16120. The namespace of the Secret resource being referred to.
  16121. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16122. maxLength: 63
  16123. minLength: 1
  16124. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16125. type: string
  16126. type: object
  16127. secretAccessKeySecretRef:
  16128. description: The SecretAccessKey is used for authentication
  16129. properties:
  16130. key:
  16131. description: |-
  16132. A key in the referenced Secret.
  16133. Some instances of this field may be defaulted, in others it may be required.
  16134. maxLength: 253
  16135. minLength: 1
  16136. pattern: ^[-._a-zA-Z0-9]+$
  16137. type: string
  16138. name:
  16139. description: The name of the Secret resource being referred to.
  16140. maxLength: 253
  16141. minLength: 1
  16142. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16143. type: string
  16144. namespace:
  16145. description: |-
  16146. The namespace of the Secret resource being referred to.
  16147. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16148. maxLength: 63
  16149. minLength: 1
  16150. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16151. type: string
  16152. type: object
  16153. sessionTokenSecretRef:
  16154. description: |-
  16155. The SessionToken used for authentication
  16156. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  16157. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  16158. properties:
  16159. key:
  16160. description: |-
  16161. A key in the referenced Secret.
  16162. Some instances of this field may be defaulted, in others it may be required.
  16163. maxLength: 253
  16164. minLength: 1
  16165. pattern: ^[-._a-zA-Z0-9]+$
  16166. type: string
  16167. name:
  16168. description: The name of the Secret resource being referred to.
  16169. maxLength: 253
  16170. minLength: 1
  16171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16172. type: string
  16173. namespace:
  16174. description: |-
  16175. The namespace of the Secret resource being referred to.
  16176. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16177. maxLength: 63
  16178. minLength: 1
  16179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16180. type: string
  16181. type: object
  16182. type: object
  16183. type: object
  16184. customSessionTags:
  16185. additionalProperties:
  16186. type: string
  16187. description: |-
  16188. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  16189. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  16190. type: object
  16191. x-kubernetes-validations:
  16192. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  16193. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  16194. externalID:
  16195. description: AWS External ID set on assumed IAM roles
  16196. type: string
  16197. prefix:
  16198. description: Prefix adds a prefix to all retrieved values.
  16199. type: string
  16200. region:
  16201. description: AWS Region to be used for the provider
  16202. type: string
  16203. role:
  16204. description: Role is a Role ARN which the provider will assume
  16205. type: string
  16206. secretsManager:
  16207. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  16208. properties:
  16209. forceDeleteWithoutRecovery:
  16210. description: |-
  16211. Specifies whether to delete the secret without any recovery window. You
  16212. can't use both this parameter and RecoveryWindowInDays in the same call.
  16213. If you don't use either, then by default Secrets Manager uses a 30 day
  16214. recovery window.
  16215. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  16216. type: boolean
  16217. recoveryWindowInDays:
  16218. description: |-
  16219. The number of days from 7 to 30 that Secrets Manager waits before
  16220. permanently deleting the secret. You can't use both this parameter and
  16221. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  16222. then by default Secrets Manager uses a 30-day recovery window.
  16223. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  16224. format: int64
  16225. type: integer
  16226. type: object
  16227. service:
  16228. description: Service defines which service should be used to fetch the secrets
  16229. enum:
  16230. - SecretsManager
  16231. - ParameterStore
  16232. - CertificateManager
  16233. type: string
  16234. sessionTags:
  16235. description: AWS STS assume role session tags
  16236. items:
  16237. description: |-
  16238. Tag is a key-value pair that can be attached to an AWS resource.
  16239. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  16240. properties:
  16241. key:
  16242. type: string
  16243. value:
  16244. type: string
  16245. required:
  16246. - key
  16247. - value
  16248. type: object
  16249. type: array
  16250. sessionTagsPolicy:
  16251. default: None
  16252. description: |-
  16253. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  16254. None (default): no tags are added.
  16255. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  16256. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  16257. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  16258. enum:
  16259. - None
  16260. - Simple
  16261. - Custom
  16262. type: string
  16263. transitiveTagKeys:
  16264. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  16265. items:
  16266. type: string
  16267. type: array
  16268. required:
  16269. - region
  16270. - service
  16271. type: object
  16272. azurekv:
  16273. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  16274. properties:
  16275. authSecretRef:
  16276. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16277. properties:
  16278. clientCertificate:
  16279. description: The Azure ClientCertificate of the service principle used for authentication.
  16280. properties:
  16281. key:
  16282. description: |-
  16283. A key in the referenced Secret.
  16284. Some instances of this field may be defaulted, in others it may be required.
  16285. maxLength: 253
  16286. minLength: 1
  16287. pattern: ^[-._a-zA-Z0-9]+$
  16288. type: string
  16289. name:
  16290. description: The name of the Secret resource being referred to.
  16291. maxLength: 253
  16292. minLength: 1
  16293. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16294. type: string
  16295. namespace:
  16296. description: |-
  16297. The namespace of the Secret resource being referred to.
  16298. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16299. maxLength: 63
  16300. minLength: 1
  16301. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16302. type: string
  16303. type: object
  16304. clientId:
  16305. description: The Azure clientId of the service principle or managed identity used for authentication.
  16306. properties:
  16307. key:
  16308. description: |-
  16309. A key in the referenced Secret.
  16310. Some instances of this field may be defaulted, in others it may be required.
  16311. maxLength: 253
  16312. minLength: 1
  16313. pattern: ^[-._a-zA-Z0-9]+$
  16314. type: string
  16315. name:
  16316. description: The name of the Secret resource being referred to.
  16317. maxLength: 253
  16318. minLength: 1
  16319. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16320. type: string
  16321. namespace:
  16322. description: |-
  16323. The namespace of the Secret resource being referred to.
  16324. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16325. maxLength: 63
  16326. minLength: 1
  16327. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16328. type: string
  16329. type: object
  16330. clientSecret:
  16331. description: The Azure ClientSecret of the service principle used for authentication.
  16332. properties:
  16333. key:
  16334. description: |-
  16335. A key in the referenced Secret.
  16336. Some instances of this field may be defaulted, in others it may be required.
  16337. maxLength: 253
  16338. minLength: 1
  16339. pattern: ^[-._a-zA-Z0-9]+$
  16340. type: string
  16341. name:
  16342. description: The name of the Secret resource being referred to.
  16343. maxLength: 253
  16344. minLength: 1
  16345. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16346. type: string
  16347. namespace:
  16348. description: |-
  16349. The namespace of the Secret resource being referred to.
  16350. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16351. maxLength: 63
  16352. minLength: 1
  16353. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16354. type: string
  16355. type: object
  16356. tenantId:
  16357. description: The Azure tenantId of the managed identity used for authentication.
  16358. properties:
  16359. key:
  16360. description: |-
  16361. A key in the referenced Secret.
  16362. Some instances of this field may be defaulted, in others it may be required.
  16363. maxLength: 253
  16364. minLength: 1
  16365. pattern: ^[-._a-zA-Z0-9]+$
  16366. type: string
  16367. name:
  16368. description: The name of the Secret resource being referred to.
  16369. maxLength: 253
  16370. minLength: 1
  16371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16372. type: string
  16373. namespace:
  16374. description: |-
  16375. The namespace of the Secret resource being referred to.
  16376. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16377. maxLength: 63
  16378. minLength: 1
  16379. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16380. type: string
  16381. type: object
  16382. type: object
  16383. authType:
  16384. default: ServicePrincipal
  16385. description: |-
  16386. Auth type defines how to authenticate to the keyvault service.
  16387. Valid values are:
  16388. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  16389. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  16390. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  16391. enum:
  16392. - ServicePrincipal
  16393. - ManagedIdentity
  16394. - WorkloadIdentity
  16395. type: string
  16396. customCloudConfig:
  16397. description: |-
  16398. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  16399. Required when EnvironmentType is AzureStackCloud.
  16400. Optional for other environment types - useful for Azure China when using Workload Identity
  16401. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  16402. standard China Cloud endpoint (login.chinacloudapi.cn).
  16403. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  16404. configuration is not supported with the legacy go-autorest SDK.
  16405. properties:
  16406. activeDirectoryEndpoint:
  16407. description: |-
  16408. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  16409. Required when using custom cloud configuration
  16410. type: string
  16411. keyVaultDNSSuffix:
  16412. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  16413. type: string
  16414. keyVaultEndpoint:
  16415. description: KeyVaultEndpoint is the Key Vault service endpoint
  16416. type: string
  16417. resourceManagerEndpoint:
  16418. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  16419. type: string
  16420. required:
  16421. - activeDirectoryEndpoint
  16422. type: object
  16423. environmentType:
  16424. default: PublicCloud
  16425. description: |-
  16426. EnvironmentType specifies the Azure cloud environment endpoints to use for
  16427. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  16428. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  16429. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  16430. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  16431. enum:
  16432. - PublicCloud
  16433. - USGovernmentCloud
  16434. - ChinaCloud
  16435. - GermanCloud
  16436. - AzureStackCloud
  16437. type: string
  16438. identityId:
  16439. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  16440. type: string
  16441. serviceAccountRef:
  16442. description: |-
  16443. ServiceAccountRef specified the service account
  16444. that should be used when authenticating with WorkloadIdentity.
  16445. properties:
  16446. audiences:
  16447. description: |-
  16448. Audience specifies the `aud` claim for the service account token
  16449. Some providers automatically extend the audience field based on well-known annotations for workload
  16450. identity (e.g. IRSA or GCP Workload Identity)
  16451. items:
  16452. type: string
  16453. type: array
  16454. name:
  16455. description: The name of the ServiceAccount resource being referred to.
  16456. maxLength: 253
  16457. minLength: 1
  16458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16459. type: string
  16460. namespace:
  16461. description: |-
  16462. Namespace of the resource being referred to.
  16463. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16464. maxLength: 63
  16465. minLength: 1
  16466. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16467. type: string
  16468. required:
  16469. - name
  16470. type: object
  16471. tenantId:
  16472. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16473. type: string
  16474. useAzureSDK:
  16475. default: false
  16476. description: |-
  16477. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  16478. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  16479. type: boolean
  16480. vaultUrl:
  16481. description: Vault Url from which the secrets to be fetched from.
  16482. type: string
  16483. required:
  16484. - vaultUrl
  16485. type: object
  16486. barbican:
  16487. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  16488. properties:
  16489. auth:
  16490. description: BarbicanAuth contains the authentication information for Barbican.
  16491. properties:
  16492. password:
  16493. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  16494. properties:
  16495. secretRef:
  16496. description: |-
  16497. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16498. In some instances, `key` is a required field.
  16499. properties:
  16500. key:
  16501. description: |-
  16502. A key in the referenced Secret.
  16503. Some instances of this field may be defaulted, in others it may be required.
  16504. maxLength: 253
  16505. minLength: 1
  16506. pattern: ^[-._a-zA-Z0-9]+$
  16507. type: string
  16508. name:
  16509. description: The name of the Secret resource being referred to.
  16510. maxLength: 253
  16511. minLength: 1
  16512. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16513. type: string
  16514. namespace:
  16515. description: |-
  16516. The namespace of the Secret resource being referred to.
  16517. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16518. maxLength: 63
  16519. minLength: 1
  16520. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16521. type: string
  16522. type: object
  16523. required:
  16524. - secretRef
  16525. type: object
  16526. username:
  16527. description: BarbicanProviderUsernameRef defines a reference to a secret containing username for the Barbican provider.
  16528. maxProperties: 1
  16529. minProperties: 1
  16530. properties:
  16531. secretRef:
  16532. description: |-
  16533. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16534. In some instances, `key` is a required field.
  16535. properties:
  16536. key:
  16537. description: |-
  16538. A key in the referenced Secret.
  16539. Some instances of this field may be defaulted, in others it may be required.
  16540. maxLength: 253
  16541. minLength: 1
  16542. pattern: ^[-._a-zA-Z0-9]+$
  16543. type: string
  16544. name:
  16545. description: The name of the Secret resource being referred to.
  16546. maxLength: 253
  16547. minLength: 1
  16548. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16549. type: string
  16550. namespace:
  16551. description: |-
  16552. The namespace of the Secret resource being referred to.
  16553. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16554. maxLength: 63
  16555. minLength: 1
  16556. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16557. type: string
  16558. type: object
  16559. value:
  16560. type: string
  16561. type: object
  16562. required:
  16563. - password
  16564. - username
  16565. type: object
  16566. authURL:
  16567. type: string
  16568. domainName:
  16569. type: string
  16570. region:
  16571. type: string
  16572. tenantName:
  16573. type: string
  16574. required:
  16575. - auth
  16576. type: object
  16577. beyondtrust:
  16578. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  16579. properties:
  16580. auth:
  16581. description: Auth configures how the operator authenticates with Beyondtrust.
  16582. properties:
  16583. apiKey:
  16584. description: APIKey If not provided then ClientID/ClientSecret become required.
  16585. properties:
  16586. secretRef:
  16587. description: SecretRef references a key in a secret that will be used as value.
  16588. properties:
  16589. key:
  16590. description: |-
  16591. A key in the referenced Secret.
  16592. Some instances of this field may be defaulted, in others it may be required.
  16593. maxLength: 253
  16594. minLength: 1
  16595. pattern: ^[-._a-zA-Z0-9]+$
  16596. type: string
  16597. name:
  16598. description: The name of the Secret resource being referred to.
  16599. maxLength: 253
  16600. minLength: 1
  16601. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16602. type: string
  16603. namespace:
  16604. description: |-
  16605. The namespace of the Secret resource being referred to.
  16606. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16607. maxLength: 63
  16608. minLength: 1
  16609. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16610. type: string
  16611. type: object
  16612. value:
  16613. description: Value can be specified directly to set a value without using a secret.
  16614. type: string
  16615. type: object
  16616. certificate:
  16617. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  16618. properties:
  16619. secretRef:
  16620. description: SecretRef references a key in a secret that will be used as value.
  16621. properties:
  16622. key:
  16623. description: |-
  16624. A key in the referenced Secret.
  16625. Some instances of this field may be defaulted, in others it may be required.
  16626. maxLength: 253
  16627. minLength: 1
  16628. pattern: ^[-._a-zA-Z0-9]+$
  16629. type: string
  16630. name:
  16631. description: The name of the Secret resource being referred to.
  16632. maxLength: 253
  16633. minLength: 1
  16634. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16635. type: string
  16636. namespace:
  16637. description: |-
  16638. The namespace of the Secret resource being referred to.
  16639. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16640. maxLength: 63
  16641. minLength: 1
  16642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16643. type: string
  16644. type: object
  16645. value:
  16646. description: Value can be specified directly to set a value without using a secret.
  16647. type: string
  16648. type: object
  16649. certificateKey:
  16650. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  16651. properties:
  16652. secretRef:
  16653. description: SecretRef references a key in a secret that will be used as value.
  16654. properties:
  16655. key:
  16656. description: |-
  16657. A key in the referenced Secret.
  16658. Some instances of this field may be defaulted, in others it may be required.
  16659. maxLength: 253
  16660. minLength: 1
  16661. pattern: ^[-._a-zA-Z0-9]+$
  16662. type: string
  16663. name:
  16664. description: The name of the Secret resource being referred to.
  16665. maxLength: 253
  16666. minLength: 1
  16667. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16668. type: string
  16669. namespace:
  16670. description: |-
  16671. The namespace of the Secret resource being referred to.
  16672. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16673. maxLength: 63
  16674. minLength: 1
  16675. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16676. type: string
  16677. type: object
  16678. value:
  16679. description: Value can be specified directly to set a value without using a secret.
  16680. type: string
  16681. type: object
  16682. clientId:
  16683. description: ClientID is the API OAuth Client ID.
  16684. properties:
  16685. secretRef:
  16686. description: SecretRef references a key in a secret that will be used as value.
  16687. properties:
  16688. key:
  16689. description: |-
  16690. A key in the referenced Secret.
  16691. Some instances of this field may be defaulted, in others it may be required.
  16692. maxLength: 253
  16693. minLength: 1
  16694. pattern: ^[-._a-zA-Z0-9]+$
  16695. type: string
  16696. name:
  16697. description: The name of the Secret resource being referred to.
  16698. maxLength: 253
  16699. minLength: 1
  16700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16701. type: string
  16702. namespace:
  16703. description: |-
  16704. The namespace of the Secret resource being referred to.
  16705. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16706. maxLength: 63
  16707. minLength: 1
  16708. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16709. type: string
  16710. type: object
  16711. value:
  16712. description: Value can be specified directly to set a value without using a secret.
  16713. type: string
  16714. type: object
  16715. clientSecret:
  16716. description: ClientSecret is the API OAuth Client Secret.
  16717. properties:
  16718. secretRef:
  16719. description: SecretRef references a key in a secret that will be used as value.
  16720. properties:
  16721. key:
  16722. description: |-
  16723. A key in the referenced Secret.
  16724. Some instances of this field may be defaulted, in others it may be required.
  16725. maxLength: 253
  16726. minLength: 1
  16727. pattern: ^[-._a-zA-Z0-9]+$
  16728. type: string
  16729. name:
  16730. description: The name of the Secret resource being referred to.
  16731. maxLength: 253
  16732. minLength: 1
  16733. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16734. type: string
  16735. namespace:
  16736. description: |-
  16737. The namespace of the Secret resource being referred to.
  16738. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16739. maxLength: 63
  16740. minLength: 1
  16741. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16742. type: string
  16743. type: object
  16744. value:
  16745. description: Value can be specified directly to set a value without using a secret.
  16746. type: string
  16747. type: object
  16748. type: object
  16749. server:
  16750. description: Auth configures how API server works.
  16751. properties:
  16752. apiUrl:
  16753. type: string
  16754. apiVersion:
  16755. type: string
  16756. clientTimeOutSeconds:
  16757. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  16758. type: integer
  16759. decrypt:
  16760. default: true
  16761. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  16762. type: boolean
  16763. retrievalType:
  16764. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  16765. type: string
  16766. separator:
  16767. description: A character that separates the folder names.
  16768. type: string
  16769. verifyCA:
  16770. type: boolean
  16771. required:
  16772. - apiUrl
  16773. - verifyCA
  16774. type: object
  16775. required:
  16776. - auth
  16777. - server
  16778. type: object
  16779. beyondtrustworkloadcredentials:
  16780. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  16781. properties:
  16782. auth:
  16783. description: |-
  16784. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  16785. Currently supports API key authentication via Kubernetes secret reference.
  16786. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16787. properties:
  16788. apikey:
  16789. description: |-
  16790. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  16791. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  16792. properties:
  16793. token:
  16794. description: |-
  16795. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  16796. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  16797. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  16798. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16799. properties:
  16800. key:
  16801. description: |-
  16802. A key in the referenced Secret.
  16803. Some instances of this field may be defaulted, in others it may be required.
  16804. maxLength: 253
  16805. minLength: 1
  16806. pattern: ^[-._a-zA-Z0-9]+$
  16807. type: string
  16808. name:
  16809. description: The name of the Secret resource being referred to.
  16810. maxLength: 253
  16811. minLength: 1
  16812. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16813. type: string
  16814. namespace:
  16815. description: |-
  16816. The namespace of the Secret resource being referred to.
  16817. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16818. maxLength: 63
  16819. minLength: 1
  16820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16821. type: string
  16822. type: object
  16823. required:
  16824. - token
  16825. type: object
  16826. required:
  16827. - apikey
  16828. type: object
  16829. caBundle:
  16830. description: |-
  16831. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  16832. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  16833. If not set, the system's trusted root certificates are used.
  16834. format: byte
  16835. type: string
  16836. caProvider:
  16837. description: |-
  16838. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  16839. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  16840. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  16841. properties:
  16842. key:
  16843. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16844. maxLength: 253
  16845. minLength: 1
  16846. pattern: ^[-._a-zA-Z0-9]+$
  16847. type: string
  16848. name:
  16849. description: The name of the object located at the provider type.
  16850. maxLength: 253
  16851. minLength: 1
  16852. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16853. type: string
  16854. namespace:
  16855. description: |-
  16856. The namespace the Provider type is in.
  16857. Can only be defined when used in a ClusterSecretStore.
  16858. maxLength: 63
  16859. minLength: 1
  16860. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16861. type: string
  16862. type:
  16863. description: The type of provider to use such as "Secret", or "ConfigMap".
  16864. enum:
  16865. - Secret
  16866. - ConfigMap
  16867. type: string
  16868. required:
  16869. - name
  16870. - type
  16871. type: object
  16872. folderPath:
  16873. description: |-
  16874. FolderPath specifies the default folder path for secret retrieval.
  16875. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  16876. Example: "production/database" or "dev/api-keys"
  16877. Leave empty to retrieve secrets from the root folder.
  16878. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  16879. type: string
  16880. server:
  16881. description: |-
  16882. Server configures the BeyondTrust Workload Credentials server connection details.
  16883. Includes the API URL and Site ID for your BeyondTrust instance.
  16884. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  16885. properties:
  16886. apiUrl:
  16887. description: |-
  16888. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  16889. This should be the full URL to your BeyondTrust instance.
  16890. Example: https://api.beyondtrust.io/siie
  16891. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  16892. type: string
  16893. siteId:
  16894. description: |-
  16895. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  16896. This identifier is unique to your BeyondTrust Workload Credentials instance.
  16897. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  16898. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  16899. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  16900. type: string
  16901. required:
  16902. - apiUrl
  16903. - siteId
  16904. type: object
  16905. required:
  16906. - auth
  16907. - server
  16908. type: object
  16909. bitwardensecretsmanager:
  16910. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  16911. properties:
  16912. apiURL:
  16913. type: string
  16914. auth:
  16915. description: |-
  16916. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  16917. Make sure that the token being used has permissions on the given secret.
  16918. properties:
  16919. secretRef:
  16920. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  16921. properties:
  16922. credentials:
  16923. description: AccessToken used for the bitwarden instance.
  16924. properties:
  16925. key:
  16926. description: |-
  16927. A key in the referenced Secret.
  16928. Some instances of this field may be defaulted, in others it may be required.
  16929. maxLength: 253
  16930. minLength: 1
  16931. pattern: ^[-._a-zA-Z0-9]+$
  16932. type: string
  16933. name:
  16934. description: The name of the Secret resource being referred to.
  16935. maxLength: 253
  16936. minLength: 1
  16937. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16938. type: string
  16939. namespace:
  16940. description: |-
  16941. The namespace of the Secret resource being referred to.
  16942. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16943. maxLength: 63
  16944. minLength: 1
  16945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16946. type: string
  16947. type: object
  16948. required:
  16949. - credentials
  16950. type: object
  16951. required:
  16952. - secretRef
  16953. type: object
  16954. bitwardenServerSDKURL:
  16955. type: string
  16956. caBundle:
  16957. description: |-
  16958. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  16959. can be performed.
  16960. type: string
  16961. caProvider:
  16962. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  16963. properties:
  16964. key:
  16965. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16966. maxLength: 253
  16967. minLength: 1
  16968. pattern: ^[-._a-zA-Z0-9]+$
  16969. type: string
  16970. name:
  16971. description: The name of the object located at the provider type.
  16972. maxLength: 253
  16973. minLength: 1
  16974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16975. type: string
  16976. namespace:
  16977. description: |-
  16978. The namespace the Provider type is in.
  16979. Can only be defined when used in a ClusterSecretStore.
  16980. maxLength: 63
  16981. minLength: 1
  16982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16983. type: string
  16984. type:
  16985. description: The type of provider to use such as "Secret", or "ConfigMap".
  16986. enum:
  16987. - Secret
  16988. - ConfigMap
  16989. type: string
  16990. required:
  16991. - name
  16992. - type
  16993. type: object
  16994. identityURL:
  16995. type: string
  16996. organizationID:
  16997. description: OrganizationID determines which organization this secret store manages.
  16998. type: string
  16999. projectID:
  17000. description: ProjectID determines which project this secret store manages.
  17001. type: string
  17002. required:
  17003. - auth
  17004. - organizationID
  17005. - projectID
  17006. type: object
  17007. chef:
  17008. description: Chef configures this store to sync secrets with chef server
  17009. properties:
  17010. auth:
  17011. description: Auth defines the information necessary to authenticate against chef Server
  17012. properties:
  17013. secretRef:
  17014. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  17015. properties:
  17016. privateKeySecretRef:
  17017. description: SecretKey is the Signing Key in PEM format, used for authentication.
  17018. properties:
  17019. key:
  17020. description: |-
  17021. A key in the referenced Secret.
  17022. Some instances of this field may be defaulted, in others it may be required.
  17023. maxLength: 253
  17024. minLength: 1
  17025. pattern: ^[-._a-zA-Z0-9]+$
  17026. type: string
  17027. name:
  17028. description: The name of the Secret resource being referred to.
  17029. maxLength: 253
  17030. minLength: 1
  17031. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17032. type: string
  17033. namespace:
  17034. description: |-
  17035. The namespace of the Secret resource being referred to.
  17036. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17037. maxLength: 63
  17038. minLength: 1
  17039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17040. type: string
  17041. type: object
  17042. required:
  17043. - privateKeySecretRef
  17044. type: object
  17045. required:
  17046. - secretRef
  17047. type: object
  17048. serverUrl:
  17049. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  17050. type: string
  17051. username:
  17052. description: UserName should be the user ID on the chef server
  17053. type: string
  17054. required:
  17055. - auth
  17056. - serverUrl
  17057. - username
  17058. type: object
  17059. cloudrusm:
  17060. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  17061. properties:
  17062. auth:
  17063. description: CSMAuth contains a secretRef for credentials.
  17064. properties:
  17065. secretRef:
  17066. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  17067. properties:
  17068. accessKeyIDSecretRef:
  17069. description: The AccessKeyID is used for authentication
  17070. properties:
  17071. key:
  17072. description: |-
  17073. A key in the referenced Secret.
  17074. Some instances of this field may be defaulted, in others it may be required.
  17075. maxLength: 253
  17076. minLength: 1
  17077. pattern: ^[-._a-zA-Z0-9]+$
  17078. type: string
  17079. name:
  17080. description: The name of the Secret resource being referred to.
  17081. maxLength: 253
  17082. minLength: 1
  17083. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17084. type: string
  17085. namespace:
  17086. description: |-
  17087. The namespace of the Secret resource being referred to.
  17088. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17089. maxLength: 63
  17090. minLength: 1
  17091. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17092. type: string
  17093. type: object
  17094. accessKeySecretSecretRef:
  17095. description: The AccessKeySecret is used for authentication
  17096. properties:
  17097. key:
  17098. description: |-
  17099. A key in the referenced Secret.
  17100. Some instances of this field may be defaulted, in others it may be required.
  17101. maxLength: 253
  17102. minLength: 1
  17103. pattern: ^[-._a-zA-Z0-9]+$
  17104. type: string
  17105. name:
  17106. description: The name of the Secret resource being referred to.
  17107. maxLength: 253
  17108. minLength: 1
  17109. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17110. type: string
  17111. namespace:
  17112. description: |-
  17113. The namespace of the Secret resource being referred to.
  17114. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17115. maxLength: 63
  17116. minLength: 1
  17117. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17118. type: string
  17119. type: object
  17120. required:
  17121. - accessKeyIDSecretRef
  17122. - accessKeySecretSecretRef
  17123. type: object
  17124. type: object
  17125. projectID:
  17126. description: ProjectID is the project, which the secrets are stored in.
  17127. type: string
  17128. required:
  17129. - auth
  17130. type: object
  17131. conjur:
  17132. description: Conjur configures this store to sync secrets using conjur provider
  17133. properties:
  17134. auth:
  17135. description: Defines authentication settings for connecting to Conjur.
  17136. maxProperties: 1
  17137. minProperties: 1
  17138. properties:
  17139. apikey:
  17140. description: Authenticates with Conjur using an API key.
  17141. properties:
  17142. account:
  17143. description: Account is the Conjur organization account name.
  17144. type: string
  17145. apiKeyRef:
  17146. description: |-
  17147. A reference to a specific 'key' containing the Conjur API key
  17148. within a Secret resource. In some instances, `key` is a required field.
  17149. properties:
  17150. key:
  17151. description: |-
  17152. A key in the referenced Secret.
  17153. Some instances of this field may be defaulted, in others it may be required.
  17154. maxLength: 253
  17155. minLength: 1
  17156. pattern: ^[-._a-zA-Z0-9]+$
  17157. type: string
  17158. name:
  17159. description: The name of the Secret resource being referred to.
  17160. maxLength: 253
  17161. minLength: 1
  17162. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17163. type: string
  17164. namespace:
  17165. description: |-
  17166. The namespace of the Secret resource being referred to.
  17167. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17168. maxLength: 63
  17169. minLength: 1
  17170. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17171. type: string
  17172. type: object
  17173. userRef:
  17174. description: |-
  17175. A reference to a specific 'key' containing the Conjur username
  17176. within a Secret resource. In some instances, `key` is a required field.
  17177. properties:
  17178. key:
  17179. description: |-
  17180. A key in the referenced Secret.
  17181. Some instances of this field may be defaulted, in others it may be required.
  17182. maxLength: 253
  17183. minLength: 1
  17184. pattern: ^[-._a-zA-Z0-9]+$
  17185. type: string
  17186. name:
  17187. description: The name of the Secret resource being referred to.
  17188. maxLength: 253
  17189. minLength: 1
  17190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17191. type: string
  17192. namespace:
  17193. description: |-
  17194. The namespace of the Secret resource being referred to.
  17195. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17196. maxLength: 63
  17197. minLength: 1
  17198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17199. type: string
  17200. type: object
  17201. required:
  17202. - account
  17203. - apiKeyRef
  17204. - userRef
  17205. type: object
  17206. cert:
  17207. description: Cert enables certificate-based authentication using a client certificate and key.
  17208. properties:
  17209. account:
  17210. description: Account is the Conjur organization account name.
  17211. type: string
  17212. clientCertRef:
  17213. description: |-
  17214. ClientCertRef is a reference to a specific 'key' containing the client certificate
  17215. within a Secret resource. The certificate must be PEM-encoded.
  17216. properties:
  17217. key:
  17218. description: |-
  17219. A key in the referenced Secret.
  17220. Some instances of this field may be defaulted, in others it may be required.
  17221. maxLength: 253
  17222. minLength: 1
  17223. pattern: ^[-._a-zA-Z0-9]+$
  17224. type: string
  17225. name:
  17226. description: The name of the Secret resource being referred to.
  17227. maxLength: 253
  17228. minLength: 1
  17229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17230. type: string
  17231. namespace:
  17232. description: |-
  17233. The namespace of the Secret resource being referred to.
  17234. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17235. maxLength: 63
  17236. minLength: 1
  17237. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17238. type: string
  17239. type: object
  17240. clientKeyRef:
  17241. description: |-
  17242. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  17243. within a Secret resource. The key must be PEM-encoded.
  17244. properties:
  17245. key:
  17246. description: |-
  17247. A key in the referenced Secret.
  17248. Some instances of this field may be defaulted, in others it may be required.
  17249. maxLength: 253
  17250. minLength: 1
  17251. pattern: ^[-._a-zA-Z0-9]+$
  17252. type: string
  17253. name:
  17254. description: The name of the Secret resource being referred to.
  17255. maxLength: 253
  17256. minLength: 1
  17257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17258. type: string
  17259. namespace:
  17260. description: |-
  17261. The namespace of the Secret resource being referred to.
  17262. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17263. maxLength: 63
  17264. minLength: 1
  17265. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17266. type: string
  17267. type: object
  17268. hostId:
  17269. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  17270. type: string
  17271. serviceID:
  17272. description: The conjur authn cert webservice id
  17273. type: string
  17274. required:
  17275. - account
  17276. - clientCertRef
  17277. - clientKeyRef
  17278. - serviceID
  17279. type: object
  17280. jwt:
  17281. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  17282. properties:
  17283. account:
  17284. description: Account is the Conjur organization account name.
  17285. type: string
  17286. hostId:
  17287. description: |-
  17288. Optional HostID for JWT authentication. This may be used depending
  17289. on how the Conjur JWT authenticator policy is configured.
  17290. type: string
  17291. secretRef:
  17292. description: |-
  17293. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  17294. authenticate with Conjur using the JWT authentication method.
  17295. properties:
  17296. key:
  17297. description: |-
  17298. A key in the referenced Secret.
  17299. Some instances of this field may be defaulted, in others it may be required.
  17300. maxLength: 253
  17301. minLength: 1
  17302. pattern: ^[-._a-zA-Z0-9]+$
  17303. type: string
  17304. name:
  17305. description: The name of the Secret resource being referred to.
  17306. maxLength: 253
  17307. minLength: 1
  17308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17309. type: string
  17310. namespace:
  17311. description: |-
  17312. The namespace of the Secret resource being referred to.
  17313. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17314. maxLength: 63
  17315. minLength: 1
  17316. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17317. type: string
  17318. type: object
  17319. serviceAccountRef:
  17320. description: |-
  17321. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  17322. a token for with the `TokenRequest` API.
  17323. properties:
  17324. audiences:
  17325. description: |-
  17326. Audience specifies the `aud` claim for the service account token
  17327. Some providers automatically extend the audience field based on well-known annotations for workload
  17328. identity (e.g. IRSA or GCP Workload Identity)
  17329. items:
  17330. type: string
  17331. type: array
  17332. name:
  17333. description: The name of the ServiceAccount resource being referred to.
  17334. maxLength: 253
  17335. minLength: 1
  17336. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17337. type: string
  17338. namespace:
  17339. description: |-
  17340. Namespace of the resource being referred to.
  17341. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17342. maxLength: 63
  17343. minLength: 1
  17344. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17345. type: string
  17346. required:
  17347. - name
  17348. type: object
  17349. serviceID:
  17350. description: The conjur authn jwt webservice id
  17351. type: string
  17352. required:
  17353. - account
  17354. - serviceID
  17355. type: object
  17356. type: object
  17357. caBundle:
  17358. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  17359. type: string
  17360. caProvider:
  17361. description: |-
  17362. Used to provide custom certificate authority (CA) certificates
  17363. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  17364. that contains a PEM-encoded certificate.
  17365. properties:
  17366. key:
  17367. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17368. maxLength: 253
  17369. minLength: 1
  17370. pattern: ^[-._a-zA-Z0-9]+$
  17371. type: string
  17372. name:
  17373. description: The name of the object located at the provider type.
  17374. maxLength: 253
  17375. minLength: 1
  17376. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17377. type: string
  17378. namespace:
  17379. description: |-
  17380. The namespace the Provider type is in.
  17381. Can only be defined when used in a ClusterSecretStore.
  17382. maxLength: 63
  17383. minLength: 1
  17384. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17385. type: string
  17386. type:
  17387. description: The type of provider to use such as "Secret", or "ConfigMap".
  17388. enum:
  17389. - Secret
  17390. - ConfigMap
  17391. type: string
  17392. required:
  17393. - name
  17394. - type
  17395. type: object
  17396. url:
  17397. description: URL is the endpoint of the Conjur instance.
  17398. type: string
  17399. required:
  17400. - auth
  17401. - url
  17402. type: object
  17403. crd:
  17404. description: |-
  17405. CRD configures this store to sync secrets from arbitrary Kubernetes resources,
  17406. including both custom resources (CRDs) and core API resources. Resources are
  17407. selected by API group, version and kind, where group can be "" (empty string)
  17408. for core resources such as ConfigMap. Reading the core v1 Secret is
  17409. intentionally blocked — use the Kubernetes provider for that.
  17410. properties:
  17411. auth:
  17412. description: |-
  17413. Auth configures authentication to the Kubernetes API, same as the
  17414. Kubernetes provider. Required when Server.URL is set (unless using AuthRef).
  17415. maxProperties: 1
  17416. minProperties: 1
  17417. properties:
  17418. cert:
  17419. description: has both clientCert and clientKey as secretKeySelector
  17420. properties:
  17421. clientCert:
  17422. description: |-
  17423. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17424. In some instances, `key` is a required field.
  17425. properties:
  17426. key:
  17427. description: |-
  17428. A key in the referenced Secret.
  17429. Some instances of this field may be defaulted, in others it may be required.
  17430. maxLength: 253
  17431. minLength: 1
  17432. pattern: ^[-._a-zA-Z0-9]+$
  17433. type: string
  17434. name:
  17435. description: The name of the Secret resource being referred to.
  17436. maxLength: 253
  17437. minLength: 1
  17438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17439. type: string
  17440. namespace:
  17441. description: |-
  17442. The namespace of the Secret resource being referred to.
  17443. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17444. maxLength: 63
  17445. minLength: 1
  17446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17447. type: string
  17448. type: object
  17449. clientKey:
  17450. description: |-
  17451. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17452. In some instances, `key` is a required field.
  17453. properties:
  17454. key:
  17455. description: |-
  17456. A key in the referenced Secret.
  17457. Some instances of this field may be defaulted, in others it may be required.
  17458. maxLength: 253
  17459. minLength: 1
  17460. pattern: ^[-._a-zA-Z0-9]+$
  17461. type: string
  17462. name:
  17463. description: The name of the Secret resource being referred to.
  17464. maxLength: 253
  17465. minLength: 1
  17466. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17467. type: string
  17468. namespace:
  17469. description: |-
  17470. The namespace of the Secret resource being referred to.
  17471. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17472. maxLength: 63
  17473. minLength: 1
  17474. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17475. type: string
  17476. type: object
  17477. required:
  17478. - clientCert
  17479. - clientKey
  17480. type: object
  17481. serviceAccount:
  17482. description: points to a service account that should be used for authentication
  17483. properties:
  17484. audiences:
  17485. description: |-
  17486. Audience specifies the `aud` claim for the service account token
  17487. Some providers automatically extend the audience field based on well-known annotations for workload
  17488. identity (e.g. IRSA or GCP Workload Identity)
  17489. items:
  17490. type: string
  17491. type: array
  17492. name:
  17493. description: The name of the ServiceAccount resource being referred to.
  17494. maxLength: 253
  17495. minLength: 1
  17496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17497. type: string
  17498. namespace:
  17499. description: |-
  17500. Namespace of the resource being referred to.
  17501. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17502. maxLength: 63
  17503. minLength: 1
  17504. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17505. type: string
  17506. required:
  17507. - name
  17508. type: object
  17509. token:
  17510. description: use static token to authenticate with
  17511. properties:
  17512. bearerToken:
  17513. description: |-
  17514. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17515. In some instances, `key` is a required field.
  17516. properties:
  17517. key:
  17518. description: |-
  17519. A key in the referenced Secret.
  17520. Some instances of this field may be defaulted, in others it may be required.
  17521. maxLength: 253
  17522. minLength: 1
  17523. pattern: ^[-._a-zA-Z0-9]+$
  17524. type: string
  17525. name:
  17526. description: The name of the Secret resource being referred to.
  17527. maxLength: 253
  17528. minLength: 1
  17529. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17530. type: string
  17531. namespace:
  17532. description: |-
  17533. The namespace of the Secret resource being referred to.
  17534. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17535. maxLength: 63
  17536. minLength: 1
  17537. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17538. type: string
  17539. type: object
  17540. required:
  17541. - bearerToken
  17542. type: object
  17543. type: object
  17544. authRef:
  17545. description: |-
  17546. AuthRef references a Secret containing a kubeconfig. Same semantics as the
  17547. Kubernetes provider.
  17548. properties:
  17549. key:
  17550. description: |-
  17551. A key in the referenced Secret.
  17552. Some instances of this field may be defaulted, in others it may be required.
  17553. maxLength: 253
  17554. minLength: 1
  17555. pattern: ^[-._a-zA-Z0-9]+$
  17556. type: string
  17557. name:
  17558. description: The name of the Secret resource being referred to.
  17559. maxLength: 253
  17560. minLength: 1
  17561. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17562. type: string
  17563. namespace:
  17564. description: |-
  17565. The namespace of the Secret resource being referred to.
  17566. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17567. maxLength: 63
  17568. minLength: 1
  17569. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17570. type: string
  17571. type: object
  17572. resource:
  17573. description: Resource identifies the CRD by its API group, version and kind.
  17574. properties:
  17575. group:
  17576. description: |-
  17577. Group is the API group of the resource. Use "" (empty string) for core
  17578. Kubernetes resources such as ConfigMap; use e.g. "config.example.io"
  17579. for a CRD. The field is required to be present in the manifest — write
  17580. `group: ""` explicitly for core resources so typos fail at admission
  17581. time rather than later at discovery.
  17582. type: string
  17583. kind:
  17584. description: Kind is the Kubernetes resource kind (e.g. "MyCustomResource").
  17585. minLength: 1
  17586. type: string
  17587. version:
  17588. description: Version is the API version of the resource (e.g. "v1alpha1").
  17589. minLength: 1
  17590. type: string
  17591. required:
  17592. - group
  17593. - kind
  17594. - version
  17595. type: object
  17596. server:
  17597. description: |-
  17598. Server configures the Kubernetes API address and TLS trust, same as the
  17599. Kubernetes provider. When omitted, the URL defaults to the in-cluster API.
  17600. properties:
  17601. caBundle:
  17602. description: CABundle is a base64-encoded CA certificate
  17603. format: byte
  17604. type: string
  17605. caProvider:
  17606. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  17607. properties:
  17608. key:
  17609. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17610. maxLength: 253
  17611. minLength: 1
  17612. pattern: ^[-._a-zA-Z0-9]+$
  17613. type: string
  17614. name:
  17615. description: The name of the object located at the provider type.
  17616. maxLength: 253
  17617. minLength: 1
  17618. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17619. type: string
  17620. namespace:
  17621. description: |-
  17622. The namespace the Provider type is in.
  17623. Can only be defined when used in a ClusterSecretStore.
  17624. maxLength: 63
  17625. minLength: 1
  17626. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17627. type: string
  17628. type:
  17629. description: The type of provider to use such as "Secret", or "ConfigMap".
  17630. enum:
  17631. - Secret
  17632. - ConfigMap
  17633. type: string
  17634. required:
  17635. - name
  17636. - type
  17637. type: object
  17638. url:
  17639. default: kubernetes.default
  17640. description: configures the Kubernetes server Address.
  17641. type: string
  17642. type: object
  17643. whitelist:
  17644. description: |-
  17645. Whitelist optionally restricts which object names and requested properties
  17646. are allowed to be read.
  17647. properties:
  17648. rules:
  17649. description: |-
  17650. Rules is a list of allow rules. If rules are set, at least one rule must
  17651. match for a request to be allowed.
  17652. items:
  17653. description: CRDProviderWhitelistRule defines a single allow rule for CRD reads.
  17654. properties:
  17655. name:
  17656. description: |-
  17657. Name is an optional regular expression matched against the bare object name.
  17658. For both SecretStore and ClusterSecretStore this is always the object name
  17659. without any namespace prefix (e.g. "my-db-spec", not "prod/my-db-spec").
  17660. type: string
  17661. namespace:
  17662. description: |-
  17663. Namespace is an optional regular expression matched against the namespace of
  17664. the object. Applies only when a ClusterSecretStore is used; it is ignored
  17665. for SecretStore (where the namespace is fixed to the store namespace).
  17666. type: string
  17667. properties:
  17668. description: |-
  17669. Properties is an optional list of regular expressions matched against
  17670. requested property keys (for example: "spec.secretValue").
  17671. items:
  17672. type: string
  17673. type: array
  17674. type: object
  17675. type: array
  17676. type: object
  17677. required:
  17678. - resource
  17679. type: object
  17680. x-kubernetes-validations:
  17681. - message: one of auth or authRef is required
  17682. rule: has(self.auth) || has(self.authRef)
  17683. - message: at most one of the fields in [auth authRef] may be set
  17684. rule: '[has(self.auth),has(self.authRef)].filter(x,x==true).size() <= 1'
  17685. delinea:
  17686. description: |-
  17687. Delinea DevOps Secrets Vault
  17688. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  17689. properties:
  17690. clientId:
  17691. description: ClientID is the non-secret part of the credential.
  17692. properties:
  17693. secretRef:
  17694. description: SecretRef references a key in a secret that will be used as value.
  17695. properties:
  17696. key:
  17697. description: |-
  17698. A key in the referenced Secret.
  17699. Some instances of this field may be defaulted, in others it may be required.
  17700. maxLength: 253
  17701. minLength: 1
  17702. pattern: ^[-._a-zA-Z0-9]+$
  17703. type: string
  17704. name:
  17705. description: The name of the Secret resource being referred to.
  17706. maxLength: 253
  17707. minLength: 1
  17708. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17709. type: string
  17710. namespace:
  17711. description: |-
  17712. The namespace of the Secret resource being referred to.
  17713. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17714. maxLength: 63
  17715. minLength: 1
  17716. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17717. type: string
  17718. type: object
  17719. value:
  17720. description: Value can be specified directly to set a value without using a secret.
  17721. type: string
  17722. type: object
  17723. clientSecret:
  17724. description: ClientSecret is the secret part of the credential.
  17725. properties:
  17726. secretRef:
  17727. description: SecretRef references a key in a secret that will be used as value.
  17728. properties:
  17729. key:
  17730. description: |-
  17731. A key in the referenced Secret.
  17732. Some instances of this field may be defaulted, in others it may be required.
  17733. maxLength: 253
  17734. minLength: 1
  17735. pattern: ^[-._a-zA-Z0-9]+$
  17736. type: string
  17737. name:
  17738. description: The name of the Secret resource being referred to.
  17739. maxLength: 253
  17740. minLength: 1
  17741. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17742. type: string
  17743. namespace:
  17744. description: |-
  17745. The namespace of the Secret resource being referred to.
  17746. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17747. maxLength: 63
  17748. minLength: 1
  17749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17750. type: string
  17751. type: object
  17752. value:
  17753. description: Value can be specified directly to set a value without using a secret.
  17754. type: string
  17755. type: object
  17756. tenant:
  17757. description: Tenant is the chosen hostname / site name.
  17758. type: string
  17759. tld:
  17760. description: |-
  17761. TLD is based on the server location that was chosen during provisioning.
  17762. If unset, defaults to "com".
  17763. type: string
  17764. urlTemplate:
  17765. description: |-
  17766. URLTemplate
  17767. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  17768. type: string
  17769. required:
  17770. - clientId
  17771. - clientSecret
  17772. - tenant
  17773. type: object
  17774. doppler:
  17775. description: Doppler configures this store to sync secrets using the Doppler provider
  17776. properties:
  17777. auth:
  17778. description: Auth configures how the Operator authenticates with the Doppler API
  17779. properties:
  17780. oidcConfig:
  17781. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  17782. properties:
  17783. expirationSeconds:
  17784. default: 600
  17785. description: |-
  17786. ExpirationSeconds sets the ServiceAccount token validity duration.
  17787. Defaults to 10 minutes.
  17788. format: int64
  17789. type: integer
  17790. identity:
  17791. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  17792. type: string
  17793. serviceAccountRef:
  17794. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  17795. properties:
  17796. audiences:
  17797. description: |-
  17798. Audience specifies the `aud` claim for the service account token
  17799. Some providers automatically extend the audience field based on well-known annotations for workload
  17800. identity (e.g. IRSA or GCP Workload Identity)
  17801. items:
  17802. type: string
  17803. type: array
  17804. name:
  17805. description: The name of the ServiceAccount resource being referred to.
  17806. maxLength: 253
  17807. minLength: 1
  17808. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17809. type: string
  17810. namespace:
  17811. description: |-
  17812. Namespace of the resource being referred to.
  17813. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17814. maxLength: 63
  17815. minLength: 1
  17816. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17817. type: string
  17818. required:
  17819. - name
  17820. type: object
  17821. required:
  17822. - identity
  17823. - serviceAccountRef
  17824. type: object
  17825. secretRef:
  17826. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  17827. properties:
  17828. dopplerToken:
  17829. description: |-
  17830. The DopplerToken is used for authentication.
  17831. See https://docs.doppler.com/reference/api#authentication for auth token types.
  17832. The Key attribute defaults to dopplerToken if not specified.
  17833. properties:
  17834. key:
  17835. description: |-
  17836. A key in the referenced Secret.
  17837. Some instances of this field may be defaulted, in others it may be required.
  17838. maxLength: 253
  17839. minLength: 1
  17840. pattern: ^[-._a-zA-Z0-9]+$
  17841. type: string
  17842. name:
  17843. description: The name of the Secret resource being referred to.
  17844. maxLength: 253
  17845. minLength: 1
  17846. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17847. type: string
  17848. namespace:
  17849. description: |-
  17850. The namespace of the Secret resource being referred to.
  17851. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17852. maxLength: 63
  17853. minLength: 1
  17854. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17855. type: string
  17856. type: object
  17857. required:
  17858. - dopplerToken
  17859. type: object
  17860. type: object
  17861. x-kubernetes-validations:
  17862. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  17863. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  17864. config:
  17865. description: Doppler config (required if not using a Service Token)
  17866. type: string
  17867. format:
  17868. description: Format enables the downloading of secrets as a file (string)
  17869. enum:
  17870. - json
  17871. - dotnet-json
  17872. - env
  17873. - yaml
  17874. - docker
  17875. type: string
  17876. nameTransformer:
  17877. description: Environment variable compatible name transforms that change secret names to a different format
  17878. enum:
  17879. - upper-camel
  17880. - camel
  17881. - lower-snake
  17882. - tf-var
  17883. - dotnet-env
  17884. - lower-kebab
  17885. type: string
  17886. project:
  17887. description: Doppler project (required if not using a Service Token)
  17888. type: string
  17889. required:
  17890. - auth
  17891. type: object
  17892. dvls:
  17893. description: DVLS configures this store to sync secrets using Devolutions Server provider
  17894. properties:
  17895. auth:
  17896. description: Auth defines the authentication method to use.
  17897. properties:
  17898. secretRef:
  17899. description: SecretRef contains the Application ID and Application Secret for authentication.
  17900. properties:
  17901. appId:
  17902. description: AppID is the reference to the secret containing the Application ID.
  17903. properties:
  17904. key:
  17905. description: |-
  17906. A key in the referenced Secret.
  17907. Some instances of this field may be defaulted, in others it may be required.
  17908. maxLength: 253
  17909. minLength: 1
  17910. pattern: ^[-._a-zA-Z0-9]+$
  17911. type: string
  17912. name:
  17913. description: The name of the Secret resource being referred to.
  17914. maxLength: 253
  17915. minLength: 1
  17916. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17917. type: string
  17918. namespace:
  17919. description: |-
  17920. The namespace of the Secret resource being referred to.
  17921. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17922. maxLength: 63
  17923. minLength: 1
  17924. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17925. type: string
  17926. type: object
  17927. appSecret:
  17928. description: AppSecret is the reference to the secret containing the Application Secret.
  17929. properties:
  17930. key:
  17931. description: |-
  17932. A key in the referenced Secret.
  17933. Some instances of this field may be defaulted, in others it may be required.
  17934. maxLength: 253
  17935. minLength: 1
  17936. pattern: ^[-._a-zA-Z0-9]+$
  17937. type: string
  17938. name:
  17939. description: The name of the Secret resource being referred to.
  17940. maxLength: 253
  17941. minLength: 1
  17942. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17943. type: string
  17944. namespace:
  17945. description: |-
  17946. The namespace of the Secret resource being referred to.
  17947. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17948. maxLength: 63
  17949. minLength: 1
  17950. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17951. type: string
  17952. type: object
  17953. required:
  17954. - appId
  17955. - appSecret
  17956. type: object
  17957. required:
  17958. - secretRef
  17959. type: object
  17960. insecure:
  17961. description: |-
  17962. Insecure allows connecting to DVLS over plain HTTP.
  17963. This is NOT RECOMMENDED for production use.
  17964. Set to true only if you understand the security implications.
  17965. type: boolean
  17966. serverUrl:
  17967. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  17968. type: string
  17969. vault:
  17970. description: |-
  17971. Vault is the name or UUID of the vault to fetch secrets from.
  17972. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  17973. type: string
  17974. required:
  17975. - auth
  17976. - serverUrl
  17977. type: object
  17978. fake:
  17979. description: Fake configures a store with static key/value pairs
  17980. properties:
  17981. data:
  17982. items:
  17983. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  17984. properties:
  17985. key:
  17986. type: string
  17987. value:
  17988. type: string
  17989. version:
  17990. type: string
  17991. required:
  17992. - key
  17993. - value
  17994. type: object
  17995. type: array
  17996. validationResult:
  17997. description: ValidationResult is defined type for the number of validation results.
  17998. type: integer
  17999. required:
  18000. - data
  18001. type: object
  18002. fortanix:
  18003. description: Fortanix configures this store to sync secrets using the Fortanix provider
  18004. properties:
  18005. apiKey:
  18006. description: APIKey is the API token to access SDKMS Applications.
  18007. properties:
  18008. secretRef:
  18009. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  18010. properties:
  18011. key:
  18012. description: |-
  18013. A key in the referenced Secret.
  18014. Some instances of this field may be defaulted, in others it may be required.
  18015. maxLength: 253
  18016. minLength: 1
  18017. pattern: ^[-._a-zA-Z0-9]+$
  18018. type: string
  18019. name:
  18020. description: The name of the Secret resource being referred to.
  18021. maxLength: 253
  18022. minLength: 1
  18023. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18024. type: string
  18025. namespace:
  18026. description: |-
  18027. The namespace of the Secret resource being referred to.
  18028. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18029. maxLength: 63
  18030. minLength: 1
  18031. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18032. type: string
  18033. type: object
  18034. type: object
  18035. apiUrl:
  18036. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  18037. type: string
  18038. type: object
  18039. gcpsm:
  18040. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  18041. properties:
  18042. auth:
  18043. description: Auth defines the information necessary to authenticate against GCP
  18044. properties:
  18045. secretRef:
  18046. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  18047. properties:
  18048. secretAccessKeySecretRef:
  18049. description: The SecretAccessKey is used for authentication
  18050. properties:
  18051. key:
  18052. description: |-
  18053. A key in the referenced Secret.
  18054. Some instances of this field may be defaulted, in others it may be required.
  18055. maxLength: 253
  18056. minLength: 1
  18057. pattern: ^[-._a-zA-Z0-9]+$
  18058. type: string
  18059. name:
  18060. description: The name of the Secret resource being referred to.
  18061. maxLength: 253
  18062. minLength: 1
  18063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18064. type: string
  18065. namespace:
  18066. description: |-
  18067. The namespace of the Secret resource being referred to.
  18068. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18069. maxLength: 63
  18070. minLength: 1
  18071. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18072. type: string
  18073. type: object
  18074. type: object
  18075. workloadIdentity:
  18076. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  18077. properties:
  18078. clusterLocation:
  18079. description: |-
  18080. ClusterLocation is the location of the cluster
  18081. If not specified, it fetches information from the metadata server
  18082. type: string
  18083. clusterName:
  18084. description: |-
  18085. ClusterName is the name of the cluster
  18086. If not specified, it fetches information from the metadata server
  18087. type: string
  18088. clusterProjectID:
  18089. description: |-
  18090. ClusterProjectID is the project ID of the cluster
  18091. If not specified, it fetches information from the metadata server
  18092. type: string
  18093. serviceAccountRef:
  18094. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  18095. properties:
  18096. audiences:
  18097. description: |-
  18098. Audience specifies the `aud` claim for the service account token
  18099. Some providers automatically extend the audience field based on well-known annotations for workload
  18100. identity (e.g. IRSA or GCP Workload Identity)
  18101. items:
  18102. type: string
  18103. type: array
  18104. name:
  18105. description: The name of the ServiceAccount resource being referred to.
  18106. maxLength: 253
  18107. minLength: 1
  18108. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18109. type: string
  18110. namespace:
  18111. description: |-
  18112. Namespace of the resource being referred to.
  18113. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18114. maxLength: 63
  18115. minLength: 1
  18116. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18117. type: string
  18118. required:
  18119. - name
  18120. type: object
  18121. required:
  18122. - serviceAccountRef
  18123. type: object
  18124. workloadIdentityFederation:
  18125. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  18126. properties:
  18127. audience:
  18128. description: |-
  18129. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  18130. If specified, Audience found in the external account credential config will be overridden with the configured value.
  18131. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  18132. type: string
  18133. awsSecurityCredentials:
  18134. description: |-
  18135. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  18136. when using the AWS metadata server is not an option.
  18137. properties:
  18138. awsCredentialsSecretRef:
  18139. description: |-
  18140. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  18141. Secret should be created with below names for keys
  18142. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  18143. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  18144. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  18145. properties:
  18146. name:
  18147. description: name of the secret.
  18148. maxLength: 253
  18149. minLength: 1
  18150. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18151. type: string
  18152. namespace:
  18153. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  18154. maxLength: 63
  18155. minLength: 1
  18156. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18157. type: string
  18158. required:
  18159. - name
  18160. type: object
  18161. region:
  18162. description: region is for configuring the AWS region to be used.
  18163. example: ap-south-1
  18164. maxLength: 50
  18165. minLength: 1
  18166. pattern: ^[a-z0-9-]+$
  18167. type: string
  18168. required:
  18169. - awsCredentialsSecretRef
  18170. - region
  18171. type: object
  18172. credConfig:
  18173. description: |-
  18174. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  18175. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  18176. serviceAccountRef must be used by providing operators service account details.
  18177. properties:
  18178. key:
  18179. description: key name holding the external account credential config.
  18180. maxLength: 253
  18181. minLength: 1
  18182. pattern: ^[-._a-zA-Z0-9]+$
  18183. type: string
  18184. name:
  18185. description: name of the configmap.
  18186. maxLength: 253
  18187. minLength: 1
  18188. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18189. type: string
  18190. namespace:
  18191. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  18192. maxLength: 63
  18193. minLength: 1
  18194. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18195. type: string
  18196. required:
  18197. - key
  18198. - name
  18199. type: object
  18200. externalTokenEndpoint:
  18201. description: |-
  18202. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  18203. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  18204. URL is having the expected value.
  18205. type: string
  18206. gcpServiceAccountEmail:
  18207. description: |-
  18208. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  18209. after Workload Identity Federation. Use this to grant access through the service account's
  18210. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  18211. service_account_impersonation_url in the external account JSON from credConfig;
  18212. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  18213. on that ServiceAccount.
  18214. example: my-gsa@my-project.iam.gserviceaccount.com
  18215. minLength: 1
  18216. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  18217. type: string
  18218. serviceAccountRef:
  18219. description: |-
  18220. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  18221. when Kubernetes is configured as provider in workload identity pool.
  18222. properties:
  18223. audiences:
  18224. description: |-
  18225. Audience specifies the `aud` claim for the service account token
  18226. Some providers automatically extend the audience field based on well-known annotations for workload
  18227. identity (e.g. IRSA or GCP Workload Identity)
  18228. items:
  18229. type: string
  18230. type: array
  18231. name:
  18232. description: The name of the ServiceAccount resource being referred to.
  18233. maxLength: 253
  18234. minLength: 1
  18235. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18236. type: string
  18237. namespace:
  18238. description: |-
  18239. Namespace of the resource being referred to.
  18240. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18241. maxLength: 63
  18242. minLength: 1
  18243. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18244. type: string
  18245. required:
  18246. - name
  18247. type: object
  18248. type: object
  18249. type: object
  18250. location:
  18251. description: Location optionally defines a location for a secret
  18252. type: string
  18253. projectID:
  18254. description: ProjectID project where secret is located
  18255. type: string
  18256. secretVersionSelectionPolicy:
  18257. default: LatestOrFail
  18258. description: |-
  18259. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  18260. when "latest" is disabled or destroyed.
  18261. Possible values are:
  18262. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  18263. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  18264. type: string
  18265. type: object
  18266. github:
  18267. description: |-
  18268. Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  18269. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  18270. properties:
  18271. appID:
  18272. description: appID specifies the Github APP that will be used to authenticate the client
  18273. format: int64
  18274. type: integer
  18275. auth:
  18276. description: auth configures how secret-manager authenticates with a Github instance.
  18277. properties:
  18278. privateKey:
  18279. description: |-
  18280. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18281. In some instances, `key` is a required field.
  18282. properties:
  18283. key:
  18284. description: |-
  18285. A key in the referenced Secret.
  18286. Some instances of this field may be defaulted, in others it may be required.
  18287. maxLength: 253
  18288. minLength: 1
  18289. pattern: ^[-._a-zA-Z0-9]+$
  18290. type: string
  18291. name:
  18292. description: The name of the Secret resource being referred to.
  18293. maxLength: 253
  18294. minLength: 1
  18295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18296. type: string
  18297. namespace:
  18298. description: |-
  18299. The namespace of the Secret resource being referred to.
  18300. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18301. maxLength: 63
  18302. minLength: 1
  18303. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18304. type: string
  18305. type: object
  18306. required:
  18307. - privateKey
  18308. type: object
  18309. environment:
  18310. description: environment will be used to fetch secrets from a particular environment within a github repository
  18311. type: string
  18312. installationID:
  18313. description: installationID specifies the Github APP installation that will be used to authenticate the client
  18314. format: int64
  18315. type: integer
  18316. orgSecretVisibility:
  18317. description: |-
  18318. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  18319. Valid values are "all" or "private".
  18320. When unset, new secrets are created with visibility "all" and existing secrets preserve
  18321. whatever visibility they already have in GitHub.
  18322. enum:
  18323. - all
  18324. - private
  18325. type: string
  18326. organization:
  18327. description: organization will be used to fetch secrets from the Github organization
  18328. type: string
  18329. repository:
  18330. description: repository will be used to fetch secrets from the Github repository within an organization
  18331. type: string
  18332. uploadURL:
  18333. description: Upload URL for enterprise instances. Default to URL.
  18334. type: string
  18335. url:
  18336. default: https://github.com/
  18337. description: URL configures the Github instance URL. Defaults to https://github.com/.
  18338. type: string
  18339. required:
  18340. - appID
  18341. - auth
  18342. - installationID
  18343. - organization
  18344. type: object
  18345. gitlab:
  18346. description: GitLab configures this store to sync secrets using GitLab Variables provider
  18347. properties:
  18348. auth:
  18349. description: Auth configures how secret-manager authenticates with a GitLab instance.
  18350. properties:
  18351. SecretRef:
  18352. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  18353. properties:
  18354. accessToken:
  18355. description: AccessToken is used for authentication.
  18356. properties:
  18357. key:
  18358. description: |-
  18359. A key in the referenced Secret.
  18360. Some instances of this field may be defaulted, in others it may be required.
  18361. maxLength: 253
  18362. minLength: 1
  18363. pattern: ^[-._a-zA-Z0-9]+$
  18364. type: string
  18365. name:
  18366. description: The name of the Secret resource being referred to.
  18367. maxLength: 253
  18368. minLength: 1
  18369. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18370. type: string
  18371. namespace:
  18372. description: |-
  18373. The namespace of the Secret resource being referred to.
  18374. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18375. maxLength: 63
  18376. minLength: 1
  18377. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18378. type: string
  18379. type: object
  18380. type: object
  18381. required:
  18382. - SecretRef
  18383. type: object
  18384. caBundle:
  18385. description: |-
  18386. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  18387. can be performed.
  18388. format: byte
  18389. type: string
  18390. caProvider:
  18391. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  18392. properties:
  18393. key:
  18394. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  18395. maxLength: 253
  18396. minLength: 1
  18397. pattern: ^[-._a-zA-Z0-9]+$
  18398. type: string
  18399. name:
  18400. description: The name of the object located at the provider type.
  18401. maxLength: 253
  18402. minLength: 1
  18403. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18404. type: string
  18405. namespace:
  18406. description: |-
  18407. The namespace the Provider type is in.
  18408. Can only be defined when used in a ClusterSecretStore.
  18409. maxLength: 63
  18410. minLength: 1
  18411. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18412. type: string
  18413. type:
  18414. description: The type of provider to use such as "Secret", or "ConfigMap".
  18415. enum:
  18416. - Secret
  18417. - ConfigMap
  18418. type: string
  18419. required:
  18420. - name
  18421. - type
  18422. type: object
  18423. environment:
  18424. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  18425. type: string
  18426. groupIDs:
  18427. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  18428. items:
  18429. type: string
  18430. type: array
  18431. inheritFromGroups:
  18432. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  18433. type: boolean
  18434. projectID:
  18435. description: ProjectID specifies a project where secrets are located.
  18436. type: string
  18437. url:
  18438. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  18439. type: string
  18440. required:
  18441. - auth
  18442. type: object
  18443. ibm:
  18444. description: IBM configures this store to sync secrets using IBM Cloud provider
  18445. properties:
  18446. auth:
  18447. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  18448. maxProperties: 1
  18449. minProperties: 1
  18450. properties:
  18451. containerAuth:
  18452. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  18453. properties:
  18454. iamEndpoint:
  18455. type: string
  18456. profile:
  18457. description: the IBM Trusted Profile
  18458. type: string
  18459. tokenLocation:
  18460. description: Location the token is mounted on the pod
  18461. type: string
  18462. required:
  18463. - profile
  18464. type: object
  18465. secretRef:
  18466. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  18467. properties:
  18468. iamEndpoint:
  18469. description: The IAM endpoint used to obain a token
  18470. type: string
  18471. secretApiKeySecretRef:
  18472. description: The SecretAccessKey is used for authentication
  18473. properties:
  18474. key:
  18475. description: |-
  18476. A key in the referenced Secret.
  18477. Some instances of this field may be defaulted, in others it may be required.
  18478. maxLength: 253
  18479. minLength: 1
  18480. pattern: ^[-._a-zA-Z0-9]+$
  18481. type: string
  18482. name:
  18483. description: The name of the Secret resource being referred to.
  18484. maxLength: 253
  18485. minLength: 1
  18486. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18487. type: string
  18488. namespace:
  18489. description: |-
  18490. The namespace of the Secret resource being referred to.
  18491. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18492. maxLength: 63
  18493. minLength: 1
  18494. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18495. type: string
  18496. type: object
  18497. type: object
  18498. type: object
  18499. serviceUrl:
  18500. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  18501. type: string
  18502. required:
  18503. - auth
  18504. type: object
  18505. infisical:
  18506. description: Infisical configures this store to sync secrets using the Infisical provider
  18507. properties:
  18508. auth:
  18509. description: Auth configures how the Operator authenticates with the Infisical API
  18510. properties:
  18511. awsAuthCredentials:
  18512. description: AwsAuthCredentials represents the credentials for AWS authentication.
  18513. properties:
  18514. identityId:
  18515. description: |-
  18516. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18517. In some instances, `key` is a required field.
  18518. properties:
  18519. key:
  18520. description: |-
  18521. A key in the referenced Secret.
  18522. Some instances of this field may be defaulted, in others it may be required.
  18523. maxLength: 253
  18524. minLength: 1
  18525. pattern: ^[-._a-zA-Z0-9]+$
  18526. type: string
  18527. name:
  18528. description: The name of the Secret resource being referred to.
  18529. maxLength: 253
  18530. minLength: 1
  18531. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18532. type: string
  18533. namespace:
  18534. description: |-
  18535. The namespace of the Secret resource being referred to.
  18536. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18537. maxLength: 63
  18538. minLength: 1
  18539. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18540. type: string
  18541. type: object
  18542. required:
  18543. - identityId
  18544. type: object
  18545. azureAuthCredentials:
  18546. description: AzureAuthCredentials represents the credentials for Azure authentication.
  18547. properties:
  18548. identityId:
  18549. description: |-
  18550. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18551. In some instances, `key` is a required field.
  18552. properties:
  18553. key:
  18554. description: |-
  18555. A key in the referenced Secret.
  18556. Some instances of this field may be defaulted, in others it may be required.
  18557. maxLength: 253
  18558. minLength: 1
  18559. pattern: ^[-._a-zA-Z0-9]+$
  18560. type: string
  18561. name:
  18562. description: The name of the Secret resource being referred to.
  18563. maxLength: 253
  18564. minLength: 1
  18565. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18566. type: string
  18567. namespace:
  18568. description: |-
  18569. The namespace of the Secret resource being referred to.
  18570. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18571. maxLength: 63
  18572. minLength: 1
  18573. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18574. type: string
  18575. type: object
  18576. resource:
  18577. description: |-
  18578. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18579. In some instances, `key` is a required field.
  18580. properties:
  18581. key:
  18582. description: |-
  18583. A key in the referenced Secret.
  18584. Some instances of this field may be defaulted, in others it may be required.
  18585. maxLength: 253
  18586. minLength: 1
  18587. pattern: ^[-._a-zA-Z0-9]+$
  18588. type: string
  18589. name:
  18590. description: The name of the Secret resource being referred to.
  18591. maxLength: 253
  18592. minLength: 1
  18593. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18594. type: string
  18595. namespace:
  18596. description: |-
  18597. The namespace of the Secret resource being referred to.
  18598. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18599. maxLength: 63
  18600. minLength: 1
  18601. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18602. type: string
  18603. type: object
  18604. required:
  18605. - identityId
  18606. type: object
  18607. gcpIamAuthCredentials:
  18608. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  18609. properties:
  18610. identityId:
  18611. description: |-
  18612. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18613. In some instances, `key` is a required field.
  18614. properties:
  18615. key:
  18616. description: |-
  18617. A key in the referenced Secret.
  18618. Some instances of this field may be defaulted, in others it may be required.
  18619. maxLength: 253
  18620. minLength: 1
  18621. pattern: ^[-._a-zA-Z0-9]+$
  18622. type: string
  18623. name:
  18624. description: The name of the Secret resource being referred to.
  18625. maxLength: 253
  18626. minLength: 1
  18627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18628. type: string
  18629. namespace:
  18630. description: |-
  18631. The namespace of the Secret resource being referred to.
  18632. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18633. maxLength: 63
  18634. minLength: 1
  18635. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18636. type: string
  18637. type: object
  18638. serviceAccountKeyFilePath:
  18639. description: |-
  18640. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18641. In some instances, `key` is a required field.
  18642. properties:
  18643. key:
  18644. description: |-
  18645. A key in the referenced Secret.
  18646. Some instances of this field may be defaulted, in others it may be required.
  18647. maxLength: 253
  18648. minLength: 1
  18649. pattern: ^[-._a-zA-Z0-9]+$
  18650. type: string
  18651. name:
  18652. description: The name of the Secret resource being referred to.
  18653. maxLength: 253
  18654. minLength: 1
  18655. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18656. type: string
  18657. namespace:
  18658. description: |-
  18659. The namespace of the Secret resource being referred to.
  18660. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18661. maxLength: 63
  18662. minLength: 1
  18663. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18664. type: string
  18665. type: object
  18666. required:
  18667. - identityId
  18668. - serviceAccountKeyFilePath
  18669. type: object
  18670. gcpIdTokenAuthCredentials:
  18671. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  18672. properties:
  18673. identityId:
  18674. description: |-
  18675. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18676. In some instances, `key` is a required field.
  18677. properties:
  18678. key:
  18679. description: |-
  18680. A key in the referenced Secret.
  18681. Some instances of this field may be defaulted, in others it may be required.
  18682. maxLength: 253
  18683. minLength: 1
  18684. pattern: ^[-._a-zA-Z0-9]+$
  18685. type: string
  18686. name:
  18687. description: The name of the Secret resource being referred to.
  18688. maxLength: 253
  18689. minLength: 1
  18690. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18691. type: string
  18692. namespace:
  18693. description: |-
  18694. The namespace of the Secret resource being referred to.
  18695. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18696. maxLength: 63
  18697. minLength: 1
  18698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18699. type: string
  18700. type: object
  18701. required:
  18702. - identityId
  18703. type: object
  18704. jwtAuthCredentials:
  18705. description: JwtAuthCredentials represents the credentials for JWT authentication.
  18706. properties:
  18707. identityId:
  18708. description: |-
  18709. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18710. In some instances, `key` is a required field.
  18711. properties:
  18712. key:
  18713. description: |-
  18714. A key in the referenced Secret.
  18715. Some instances of this field may be defaulted, in others it may be required.
  18716. maxLength: 253
  18717. minLength: 1
  18718. pattern: ^[-._a-zA-Z0-9]+$
  18719. type: string
  18720. name:
  18721. description: The name of the Secret resource being referred to.
  18722. maxLength: 253
  18723. minLength: 1
  18724. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18725. type: string
  18726. namespace:
  18727. description: |-
  18728. The namespace of the Secret resource being referred to.
  18729. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18730. maxLength: 63
  18731. minLength: 1
  18732. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18733. type: string
  18734. type: object
  18735. jwt:
  18736. description: |-
  18737. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18738. In some instances, `key` is a required field.
  18739. properties:
  18740. key:
  18741. description: |-
  18742. A key in the referenced Secret.
  18743. Some instances of this field may be defaulted, in others it may be required.
  18744. maxLength: 253
  18745. minLength: 1
  18746. pattern: ^[-._a-zA-Z0-9]+$
  18747. type: string
  18748. name:
  18749. description: The name of the Secret resource being referred to.
  18750. maxLength: 253
  18751. minLength: 1
  18752. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18753. type: string
  18754. namespace:
  18755. description: |-
  18756. The namespace of the Secret resource being referred to.
  18757. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18758. maxLength: 63
  18759. minLength: 1
  18760. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18761. type: string
  18762. type: object
  18763. required:
  18764. - identityId
  18765. - jwt
  18766. type: object
  18767. kubernetesAuthCredentials:
  18768. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  18769. properties:
  18770. identityId:
  18771. description: |-
  18772. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18773. In some instances, `key` is a required field.
  18774. properties:
  18775. key:
  18776. description: |-
  18777. A key in the referenced Secret.
  18778. Some instances of this field may be defaulted, in others it may be required.
  18779. maxLength: 253
  18780. minLength: 1
  18781. pattern: ^[-._a-zA-Z0-9]+$
  18782. type: string
  18783. name:
  18784. description: The name of the Secret resource being referred to.
  18785. maxLength: 253
  18786. minLength: 1
  18787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18788. type: string
  18789. namespace:
  18790. description: |-
  18791. The namespace of the Secret resource being referred to.
  18792. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18793. maxLength: 63
  18794. minLength: 1
  18795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18796. type: string
  18797. type: object
  18798. serviceAccountTokenPath:
  18799. description: |-
  18800. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18801. In some instances, `key` is a required field.
  18802. properties:
  18803. key:
  18804. description: |-
  18805. A key in the referenced Secret.
  18806. Some instances of this field may be defaulted, in others it may be required.
  18807. maxLength: 253
  18808. minLength: 1
  18809. pattern: ^[-._a-zA-Z0-9]+$
  18810. type: string
  18811. name:
  18812. description: The name of the Secret resource being referred to.
  18813. maxLength: 253
  18814. minLength: 1
  18815. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18816. type: string
  18817. namespace:
  18818. description: |-
  18819. The namespace of the Secret resource being referred to.
  18820. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18821. maxLength: 63
  18822. minLength: 1
  18823. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18824. type: string
  18825. type: object
  18826. required:
  18827. - identityId
  18828. type: object
  18829. ldapAuthCredentials:
  18830. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  18831. properties:
  18832. identityId:
  18833. description: |-
  18834. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18835. In some instances, `key` is a required field.
  18836. properties:
  18837. key:
  18838. description: |-
  18839. A key in the referenced Secret.
  18840. Some instances of this field may be defaulted, in others it may be required.
  18841. maxLength: 253
  18842. minLength: 1
  18843. pattern: ^[-._a-zA-Z0-9]+$
  18844. type: string
  18845. name:
  18846. description: The name of the Secret resource being referred to.
  18847. maxLength: 253
  18848. minLength: 1
  18849. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18850. type: string
  18851. namespace:
  18852. description: |-
  18853. The namespace of the Secret resource being referred to.
  18854. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18855. maxLength: 63
  18856. minLength: 1
  18857. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18858. type: string
  18859. type: object
  18860. ldapPassword:
  18861. description: |-
  18862. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18863. In some instances, `key` is a required field.
  18864. properties:
  18865. key:
  18866. description: |-
  18867. A key in the referenced Secret.
  18868. Some instances of this field may be defaulted, in others it may be required.
  18869. maxLength: 253
  18870. minLength: 1
  18871. pattern: ^[-._a-zA-Z0-9]+$
  18872. type: string
  18873. name:
  18874. description: The name of the Secret resource being referred to.
  18875. maxLength: 253
  18876. minLength: 1
  18877. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18878. type: string
  18879. namespace:
  18880. description: |-
  18881. The namespace of the Secret resource being referred to.
  18882. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18883. maxLength: 63
  18884. minLength: 1
  18885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18886. type: string
  18887. type: object
  18888. ldapUsername:
  18889. description: |-
  18890. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18891. In some instances, `key` is a required field.
  18892. properties:
  18893. key:
  18894. description: |-
  18895. A key in the referenced Secret.
  18896. Some instances of this field may be defaulted, in others it may be required.
  18897. maxLength: 253
  18898. minLength: 1
  18899. pattern: ^[-._a-zA-Z0-9]+$
  18900. type: string
  18901. name:
  18902. description: The name of the Secret resource being referred to.
  18903. maxLength: 253
  18904. minLength: 1
  18905. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18906. type: string
  18907. namespace:
  18908. description: |-
  18909. The namespace of the Secret resource being referred to.
  18910. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18911. maxLength: 63
  18912. minLength: 1
  18913. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18914. type: string
  18915. type: object
  18916. required:
  18917. - identityId
  18918. - ldapPassword
  18919. - ldapUsername
  18920. type: object
  18921. ociAuthCredentials:
  18922. description: OciAuthCredentials represents the credentials for OCI authentication.
  18923. properties:
  18924. fingerprint:
  18925. description: |-
  18926. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18927. In some instances, `key` is a required field.
  18928. properties:
  18929. key:
  18930. description: |-
  18931. A key in the referenced Secret.
  18932. Some instances of this field may be defaulted, in others it may be required.
  18933. maxLength: 253
  18934. minLength: 1
  18935. pattern: ^[-._a-zA-Z0-9]+$
  18936. type: string
  18937. name:
  18938. description: The name of the Secret resource being referred to.
  18939. maxLength: 253
  18940. minLength: 1
  18941. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18942. type: string
  18943. namespace:
  18944. description: |-
  18945. The namespace of the Secret resource being referred to.
  18946. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18947. maxLength: 63
  18948. minLength: 1
  18949. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18950. type: string
  18951. type: object
  18952. identityId:
  18953. description: |-
  18954. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18955. In some instances, `key` is a required field.
  18956. properties:
  18957. key:
  18958. description: |-
  18959. A key in the referenced Secret.
  18960. Some instances of this field may be defaulted, in others it may be required.
  18961. maxLength: 253
  18962. minLength: 1
  18963. pattern: ^[-._a-zA-Z0-9]+$
  18964. type: string
  18965. name:
  18966. description: The name of the Secret resource being referred to.
  18967. maxLength: 253
  18968. minLength: 1
  18969. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18970. type: string
  18971. namespace:
  18972. description: |-
  18973. The namespace of the Secret resource being referred to.
  18974. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18975. maxLength: 63
  18976. minLength: 1
  18977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18978. type: string
  18979. type: object
  18980. privateKey:
  18981. description: |-
  18982. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18983. In some instances, `key` is a required field.
  18984. properties:
  18985. key:
  18986. description: |-
  18987. A key in the referenced Secret.
  18988. Some instances of this field may be defaulted, in others it may be required.
  18989. maxLength: 253
  18990. minLength: 1
  18991. pattern: ^[-._a-zA-Z0-9]+$
  18992. type: string
  18993. name:
  18994. description: The name of the Secret resource being referred to.
  18995. maxLength: 253
  18996. minLength: 1
  18997. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18998. type: string
  18999. namespace:
  19000. description: |-
  19001. The namespace of the Secret resource being referred to.
  19002. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19003. maxLength: 63
  19004. minLength: 1
  19005. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19006. type: string
  19007. type: object
  19008. privateKeyPassphrase:
  19009. description: |-
  19010. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19011. In some instances, `key` is a required field.
  19012. properties:
  19013. key:
  19014. description: |-
  19015. A key in the referenced Secret.
  19016. Some instances of this field may be defaulted, in others it may be required.
  19017. maxLength: 253
  19018. minLength: 1
  19019. pattern: ^[-._a-zA-Z0-9]+$
  19020. type: string
  19021. name:
  19022. description: The name of the Secret resource being referred to.
  19023. maxLength: 253
  19024. minLength: 1
  19025. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19026. type: string
  19027. namespace:
  19028. description: |-
  19029. The namespace of the Secret resource being referred to.
  19030. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19031. maxLength: 63
  19032. minLength: 1
  19033. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19034. type: string
  19035. type: object
  19036. region:
  19037. description: |-
  19038. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19039. In some instances, `key` is a required field.
  19040. properties:
  19041. key:
  19042. description: |-
  19043. A key in the referenced Secret.
  19044. Some instances of this field may be defaulted, in others it may be required.
  19045. maxLength: 253
  19046. minLength: 1
  19047. pattern: ^[-._a-zA-Z0-9]+$
  19048. type: string
  19049. name:
  19050. description: The name of the Secret resource being referred to.
  19051. maxLength: 253
  19052. minLength: 1
  19053. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19054. type: string
  19055. namespace:
  19056. description: |-
  19057. The namespace of the Secret resource being referred to.
  19058. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19059. maxLength: 63
  19060. minLength: 1
  19061. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19062. type: string
  19063. type: object
  19064. tenancyId:
  19065. description: |-
  19066. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19067. In some instances, `key` is a required field.
  19068. properties:
  19069. key:
  19070. description: |-
  19071. A key in the referenced Secret.
  19072. Some instances of this field may be defaulted, in others it may be required.
  19073. maxLength: 253
  19074. minLength: 1
  19075. pattern: ^[-._a-zA-Z0-9]+$
  19076. type: string
  19077. name:
  19078. description: The name of the Secret resource being referred to.
  19079. maxLength: 253
  19080. minLength: 1
  19081. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19082. type: string
  19083. namespace:
  19084. description: |-
  19085. The namespace of the Secret resource being referred to.
  19086. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19087. maxLength: 63
  19088. minLength: 1
  19089. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19090. type: string
  19091. type: object
  19092. userId:
  19093. description: |-
  19094. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19095. In some instances, `key` is a required field.
  19096. properties:
  19097. key:
  19098. description: |-
  19099. A key in the referenced Secret.
  19100. Some instances of this field may be defaulted, in others it may be required.
  19101. maxLength: 253
  19102. minLength: 1
  19103. pattern: ^[-._a-zA-Z0-9]+$
  19104. type: string
  19105. name:
  19106. description: The name of the Secret resource being referred to.
  19107. maxLength: 253
  19108. minLength: 1
  19109. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19110. type: string
  19111. namespace:
  19112. description: |-
  19113. The namespace of the Secret resource being referred to.
  19114. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19115. maxLength: 63
  19116. minLength: 1
  19117. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19118. type: string
  19119. type: object
  19120. required:
  19121. - fingerprint
  19122. - identityId
  19123. - privateKey
  19124. - region
  19125. - tenancyId
  19126. - userId
  19127. type: object
  19128. tokenAuthCredentials:
  19129. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  19130. properties:
  19131. accessToken:
  19132. description: |-
  19133. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19134. In some instances, `key` is a required field.
  19135. properties:
  19136. key:
  19137. description: |-
  19138. A key in the referenced Secret.
  19139. Some instances of this field may be defaulted, in others it may be required.
  19140. maxLength: 253
  19141. minLength: 1
  19142. pattern: ^[-._a-zA-Z0-9]+$
  19143. type: string
  19144. name:
  19145. description: The name of the Secret resource being referred to.
  19146. maxLength: 253
  19147. minLength: 1
  19148. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19149. type: string
  19150. namespace:
  19151. description: |-
  19152. The namespace of the Secret resource being referred to.
  19153. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19154. maxLength: 63
  19155. minLength: 1
  19156. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19157. type: string
  19158. type: object
  19159. required:
  19160. - accessToken
  19161. type: object
  19162. universalAuthCredentials:
  19163. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  19164. properties:
  19165. clientId:
  19166. description: |-
  19167. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19168. In some instances, `key` is a required field.
  19169. properties:
  19170. key:
  19171. description: |-
  19172. A key in the referenced Secret.
  19173. Some instances of this field may be defaulted, in others it may be required.
  19174. maxLength: 253
  19175. minLength: 1
  19176. pattern: ^[-._a-zA-Z0-9]+$
  19177. type: string
  19178. name:
  19179. description: The name of the Secret resource being referred to.
  19180. maxLength: 253
  19181. minLength: 1
  19182. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19183. type: string
  19184. namespace:
  19185. description: |-
  19186. The namespace of the Secret resource being referred to.
  19187. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19188. maxLength: 63
  19189. minLength: 1
  19190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19191. type: string
  19192. type: object
  19193. clientSecret:
  19194. description: |-
  19195. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19196. In some instances, `key` is a required field.
  19197. properties:
  19198. key:
  19199. description: |-
  19200. A key in the referenced Secret.
  19201. Some instances of this field may be defaulted, in others it may be required.
  19202. maxLength: 253
  19203. minLength: 1
  19204. pattern: ^[-._a-zA-Z0-9]+$
  19205. type: string
  19206. name:
  19207. description: The name of the Secret resource being referred to.
  19208. maxLength: 253
  19209. minLength: 1
  19210. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19211. type: string
  19212. namespace:
  19213. description: |-
  19214. The namespace of the Secret resource being referred to.
  19215. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19216. maxLength: 63
  19217. minLength: 1
  19218. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19219. type: string
  19220. type: object
  19221. required:
  19222. - clientId
  19223. - clientSecret
  19224. type: object
  19225. type: object
  19226. caBundle:
  19227. description: |-
  19228. CABundle is a PEM-encoded CA certificate bundle used to validate
  19229. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  19230. format: byte
  19231. type: string
  19232. caProvider:
  19233. description: |-
  19234. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  19235. The certificate is used to validate the Infisical server's TLS certificate.
  19236. Mutually exclusive with CABundle.
  19237. properties:
  19238. key:
  19239. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19240. maxLength: 253
  19241. minLength: 1
  19242. pattern: ^[-._a-zA-Z0-9]+$
  19243. type: string
  19244. name:
  19245. description: The name of the object located at the provider type.
  19246. maxLength: 253
  19247. minLength: 1
  19248. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19249. type: string
  19250. namespace:
  19251. description: |-
  19252. The namespace the Provider type is in.
  19253. Can only be defined when used in a ClusterSecretStore.
  19254. maxLength: 63
  19255. minLength: 1
  19256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19257. type: string
  19258. type:
  19259. description: The type of provider to use such as "Secret", or "ConfigMap".
  19260. enum:
  19261. - Secret
  19262. - ConfigMap
  19263. type: string
  19264. required:
  19265. - name
  19266. - type
  19267. type: object
  19268. hostAPI:
  19269. default: https://app.infisical.com/api
  19270. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  19271. type: string
  19272. secretsScope:
  19273. description: SecretsScope defines the scope of the secrets within the workspace
  19274. properties:
  19275. environmentSlug:
  19276. description: EnvironmentSlug is the required slug identifier for the environment.
  19277. type: string
  19278. expandSecretReferences:
  19279. default: true
  19280. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  19281. type: boolean
  19282. organizationSlug:
  19283. description: |-
  19284. OrganizationSlug is the optional slug that identifies the organization that will be used
  19285. during authentication. Useful for sub-organization setups
  19286. type: string
  19287. projectSlug:
  19288. description: ProjectSlug is the required slug identifier for the project.
  19289. type: string
  19290. recursive:
  19291. default: false
  19292. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  19293. type: boolean
  19294. secretsPath:
  19295. default: /
  19296. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  19297. type: string
  19298. required:
  19299. - environmentSlug
  19300. - projectSlug
  19301. type: object
  19302. required:
  19303. - auth
  19304. - secretsScope
  19305. type: object
  19306. keepersecurity:
  19307. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  19308. properties:
  19309. authRef:
  19310. description: |-
  19311. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19312. In some instances, `key` is a required field.
  19313. properties:
  19314. key:
  19315. description: |-
  19316. A key in the referenced Secret.
  19317. Some instances of this field may be defaulted, in others it may be required.
  19318. maxLength: 253
  19319. minLength: 1
  19320. pattern: ^[-._a-zA-Z0-9]+$
  19321. type: string
  19322. name:
  19323. description: The name of the Secret resource being referred to.
  19324. maxLength: 253
  19325. minLength: 1
  19326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19327. type: string
  19328. namespace:
  19329. description: |-
  19330. The namespace of the Secret resource being referred to.
  19331. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19332. maxLength: 63
  19333. minLength: 1
  19334. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19335. type: string
  19336. type: object
  19337. folderID:
  19338. type: string
  19339. getByTitleFallback:
  19340. type: boolean
  19341. required:
  19342. - authRef
  19343. - folderID
  19344. type: object
  19345. kubernetes:
  19346. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  19347. properties:
  19348. auth:
  19349. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  19350. maxProperties: 1
  19351. minProperties: 1
  19352. properties:
  19353. cert:
  19354. description: has both clientCert and clientKey as secretKeySelector
  19355. properties:
  19356. clientCert:
  19357. description: |-
  19358. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19359. In some instances, `key` is a required field.
  19360. properties:
  19361. key:
  19362. description: |-
  19363. A key in the referenced Secret.
  19364. Some instances of this field may be defaulted, in others it may be required.
  19365. maxLength: 253
  19366. minLength: 1
  19367. pattern: ^[-._a-zA-Z0-9]+$
  19368. type: string
  19369. name:
  19370. description: The name of the Secret resource being referred to.
  19371. maxLength: 253
  19372. minLength: 1
  19373. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19374. type: string
  19375. namespace:
  19376. description: |-
  19377. The namespace of the Secret resource being referred to.
  19378. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19379. maxLength: 63
  19380. minLength: 1
  19381. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19382. type: string
  19383. type: object
  19384. clientKey:
  19385. description: |-
  19386. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19387. In some instances, `key` is a required field.
  19388. properties:
  19389. key:
  19390. description: |-
  19391. A key in the referenced Secret.
  19392. Some instances of this field may be defaulted, in others it may be required.
  19393. maxLength: 253
  19394. minLength: 1
  19395. pattern: ^[-._a-zA-Z0-9]+$
  19396. type: string
  19397. name:
  19398. description: The name of the Secret resource being referred to.
  19399. maxLength: 253
  19400. minLength: 1
  19401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19402. type: string
  19403. namespace:
  19404. description: |-
  19405. The namespace of the Secret resource being referred to.
  19406. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19407. maxLength: 63
  19408. minLength: 1
  19409. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19410. type: string
  19411. type: object
  19412. required:
  19413. - clientCert
  19414. - clientKey
  19415. type: object
  19416. serviceAccount:
  19417. description: points to a service account that should be used for authentication
  19418. properties:
  19419. audiences:
  19420. description: |-
  19421. Audience specifies the `aud` claim for the service account token
  19422. Some providers automatically extend the audience field based on well-known annotations for workload
  19423. identity (e.g. IRSA or GCP Workload Identity)
  19424. items:
  19425. type: string
  19426. type: array
  19427. name:
  19428. description: The name of the ServiceAccount resource being referred to.
  19429. maxLength: 253
  19430. minLength: 1
  19431. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19432. type: string
  19433. namespace:
  19434. description: |-
  19435. Namespace of the resource being referred to.
  19436. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19437. maxLength: 63
  19438. minLength: 1
  19439. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19440. type: string
  19441. required:
  19442. - name
  19443. type: object
  19444. token:
  19445. description: use static token to authenticate with
  19446. properties:
  19447. bearerToken:
  19448. description: |-
  19449. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19450. In some instances, `key` is a required field.
  19451. properties:
  19452. key:
  19453. description: |-
  19454. A key in the referenced Secret.
  19455. Some instances of this field may be defaulted, in others it may be required.
  19456. maxLength: 253
  19457. minLength: 1
  19458. pattern: ^[-._a-zA-Z0-9]+$
  19459. type: string
  19460. name:
  19461. description: The name of the Secret resource being referred to.
  19462. maxLength: 253
  19463. minLength: 1
  19464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19465. type: string
  19466. namespace:
  19467. description: |-
  19468. The namespace of the Secret resource being referred to.
  19469. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19470. maxLength: 63
  19471. minLength: 1
  19472. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19473. type: string
  19474. type: object
  19475. required:
  19476. - bearerToken
  19477. type: object
  19478. type: object
  19479. authRef:
  19480. description: A reference to a secret that contains the auth information.
  19481. properties:
  19482. key:
  19483. description: |-
  19484. A key in the referenced Secret.
  19485. Some instances of this field may be defaulted, in others it may be required.
  19486. maxLength: 253
  19487. minLength: 1
  19488. pattern: ^[-._a-zA-Z0-9]+$
  19489. type: string
  19490. name:
  19491. description: The name of the Secret resource being referred to.
  19492. maxLength: 253
  19493. minLength: 1
  19494. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19495. type: string
  19496. namespace:
  19497. description: |-
  19498. The namespace of the Secret resource being referred to.
  19499. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19500. maxLength: 63
  19501. minLength: 1
  19502. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19503. type: string
  19504. type: object
  19505. remoteNamespace:
  19506. default: default
  19507. description: Remote namespace to fetch the secrets from
  19508. maxLength: 63
  19509. minLength: 1
  19510. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19511. type: string
  19512. server:
  19513. description: configures the Kubernetes server Address.
  19514. properties:
  19515. caBundle:
  19516. description: CABundle is a base64-encoded CA certificate
  19517. format: byte
  19518. type: string
  19519. caProvider:
  19520. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  19521. properties:
  19522. key:
  19523. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19524. maxLength: 253
  19525. minLength: 1
  19526. pattern: ^[-._a-zA-Z0-9]+$
  19527. type: string
  19528. name:
  19529. description: The name of the object located at the provider type.
  19530. maxLength: 253
  19531. minLength: 1
  19532. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19533. type: string
  19534. namespace:
  19535. description: |-
  19536. The namespace the Provider type is in.
  19537. Can only be defined when used in a ClusterSecretStore.
  19538. maxLength: 63
  19539. minLength: 1
  19540. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19541. type: string
  19542. type:
  19543. description: The type of provider to use such as "Secret", or "ConfigMap".
  19544. enum:
  19545. - Secret
  19546. - ConfigMap
  19547. type: string
  19548. required:
  19549. - name
  19550. - type
  19551. type: object
  19552. url:
  19553. default: kubernetes.default
  19554. description: configures the Kubernetes server Address.
  19555. type: string
  19556. type: object
  19557. type: object
  19558. nebiusmysterybox:
  19559. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  19560. properties:
  19561. apiDomain:
  19562. description: NebiusMysterybox API endpoint
  19563. type: string
  19564. auth:
  19565. description: Auth defines parameters to authenticate in MysteryBox
  19566. properties:
  19567. serviceAccountCredsSecretRef:
  19568. description: |-
  19569. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  19570. document with service account credentials used to get an IAM token.
  19571. Expected JSON structure:
  19572. {
  19573. "subject-credentials": {
  19574. "alg": "RS256",
  19575. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  19576. "kid": "<public-key-id>",
  19577. "iss": "<issuer-service-account-id>",
  19578. "sub": "<subject-service-account-id>"
  19579. }
  19580. }
  19581. properties:
  19582. key:
  19583. description: |-
  19584. A key in the referenced Secret.
  19585. Some instances of this field may be defaulted, in others it may be required.
  19586. maxLength: 253
  19587. minLength: 1
  19588. pattern: ^[-._a-zA-Z0-9]+$
  19589. type: string
  19590. name:
  19591. description: The name of the Secret resource being referred to.
  19592. maxLength: 253
  19593. minLength: 1
  19594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19595. type: string
  19596. namespace:
  19597. description: |-
  19598. The namespace of the Secret resource being referred to.
  19599. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19600. maxLength: 63
  19601. minLength: 1
  19602. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19603. type: string
  19604. type: object
  19605. tokenSecretRef:
  19606. description: Token authenticates with Nebius Mysterybox by presenting a token.
  19607. properties:
  19608. key:
  19609. description: |-
  19610. A key in the referenced Secret.
  19611. Some instances of this field may be defaulted, in others it may be required.
  19612. maxLength: 253
  19613. minLength: 1
  19614. pattern: ^[-._a-zA-Z0-9]+$
  19615. type: string
  19616. name:
  19617. description: The name of the Secret resource being referred to.
  19618. maxLength: 253
  19619. minLength: 1
  19620. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19621. type: string
  19622. namespace:
  19623. description: |-
  19624. The namespace of the Secret resource being referred to.
  19625. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19626. maxLength: 63
  19627. minLength: 1
  19628. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19629. type: string
  19630. type: object
  19631. workloadIdentity:
  19632. description: WorkloadIdentity defines configuration for workload identity authentication to Nebius IAM.
  19633. properties:
  19634. iamServiceAccountID:
  19635. description: |-
  19636. IAMServiceAccountID is the Nebius IAM service account identifier that the
  19637. federated Kubernetes service account should impersonate during token exchange.
  19638. example: serviceaccount-e00example
  19639. minLength: 1
  19640. pattern: ^serviceaccount-[a-z][a-z0-9]{2}
  19641. type: string
  19642. serviceAccountRef:
  19643. description: |-
  19644. ServiceAccountRef references a Kubernetes ServiceAccount used to request a
  19645. temporary JWT via the TokenRequest API. The JWT is then exchanged for a
  19646. Nebius IAM token using workload federation.
  19647. properties:
  19648. audiences:
  19649. description: |-
  19650. Audience specifies the `aud` claim for the service account token
  19651. Some providers automatically extend the audience field based on well-known annotations for workload
  19652. identity (e.g. IRSA or GCP Workload Identity)
  19653. items:
  19654. type: string
  19655. type: array
  19656. name:
  19657. description: The name of the ServiceAccount resource being referred to.
  19658. maxLength: 253
  19659. minLength: 1
  19660. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19661. type: string
  19662. namespace:
  19663. description: |-
  19664. Namespace of the resource being referred to.
  19665. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19666. maxLength: 63
  19667. minLength: 1
  19668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19669. type: string
  19670. required:
  19671. - name
  19672. type: object
  19673. required:
  19674. - iamServiceAccountID
  19675. - serviceAccountRef
  19676. type: object
  19677. type: object
  19678. x-kubernetes-validations:
  19679. - message: exactly one of serviceAccountCredsSecretRef, tokenSecretRef, or workloadIdentity must be set
  19680. rule: '(has(self.serviceAccountCredsSecretRef) && has(self.serviceAccountCredsSecretRef.name) && size(self.serviceAccountCredsSecretRef.name) > 0 ? 1 : 0) + (has(self.tokenSecretRef) && has(self.tokenSecretRef.name) && size(self.tokenSecretRef.name) > 0 ? 1 : 0) + (has(self.workloadIdentity) ? 1 : 0) == 1'
  19681. caProvider:
  19682. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  19683. properties:
  19684. certSecretRef:
  19685. description: |-
  19686. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19687. In some instances, `key` is a required field.
  19688. properties:
  19689. key:
  19690. description: |-
  19691. A key in the referenced Secret.
  19692. Some instances of this field may be defaulted, in others it may be required.
  19693. maxLength: 253
  19694. minLength: 1
  19695. pattern: ^[-._a-zA-Z0-9]+$
  19696. type: string
  19697. name:
  19698. description: The name of the Secret resource being referred to.
  19699. maxLength: 253
  19700. minLength: 1
  19701. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19702. type: string
  19703. namespace:
  19704. description: |-
  19705. The namespace of the Secret resource being referred to.
  19706. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19707. maxLength: 63
  19708. minLength: 1
  19709. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19710. type: string
  19711. type: object
  19712. type: object
  19713. required:
  19714. - apiDomain
  19715. - auth
  19716. type: object
  19717. ngrok:
  19718. description: Ngrok configures this store to sync secrets using the ngrok provider.
  19719. properties:
  19720. apiUrl:
  19721. default: https://api.ngrok.com
  19722. description: APIURL is the URL of the ngrok API.
  19723. type: string
  19724. auth:
  19725. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  19726. maxProperties: 1
  19727. minProperties: 1
  19728. properties:
  19729. apiKey:
  19730. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  19731. properties:
  19732. secretRef:
  19733. description: SecretRef is a reference to a secret containing the ngrok API key.
  19734. properties:
  19735. key:
  19736. description: |-
  19737. A key in the referenced Secret.
  19738. Some instances of this field may be defaulted, in others it may be required.
  19739. maxLength: 253
  19740. minLength: 1
  19741. pattern: ^[-._a-zA-Z0-9]+$
  19742. type: string
  19743. name:
  19744. description: The name of the Secret resource being referred to.
  19745. maxLength: 253
  19746. minLength: 1
  19747. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19748. type: string
  19749. namespace:
  19750. description: |-
  19751. The namespace of the Secret resource being referred to.
  19752. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19753. maxLength: 63
  19754. minLength: 1
  19755. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19756. type: string
  19757. type: object
  19758. type: object
  19759. type: object
  19760. vault:
  19761. description: Vault configures the ngrok vault to sync secrets with.
  19762. properties:
  19763. name:
  19764. description: Name is the name of the ngrok vault to sync secrets with.
  19765. type: string
  19766. required:
  19767. - name
  19768. type: object
  19769. required:
  19770. - auth
  19771. - vault
  19772. type: object
  19773. onboardbase:
  19774. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  19775. properties:
  19776. apiHost:
  19777. default: https://public.onboardbase.com/api/v1/
  19778. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  19779. type: string
  19780. auth:
  19781. description: Auth configures how the Operator authenticates with the Onboardbase API
  19782. properties:
  19783. apiKeyRef:
  19784. description: |-
  19785. OnboardbaseAPIKey is the APIKey generated by an admin account.
  19786. It is used to recognize and authorize access to a project and environment within onboardbase
  19787. properties:
  19788. key:
  19789. description: |-
  19790. A key in the referenced Secret.
  19791. Some instances of this field may be defaulted, in others it may be required.
  19792. maxLength: 253
  19793. minLength: 1
  19794. pattern: ^[-._a-zA-Z0-9]+$
  19795. type: string
  19796. name:
  19797. description: The name of the Secret resource being referred to.
  19798. maxLength: 253
  19799. minLength: 1
  19800. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19801. type: string
  19802. namespace:
  19803. description: |-
  19804. The namespace of the Secret resource being referred to.
  19805. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19806. maxLength: 63
  19807. minLength: 1
  19808. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19809. type: string
  19810. type: object
  19811. passcodeRef:
  19812. description: OnboardbasePasscode is the passcode attached to the API Key
  19813. properties:
  19814. key:
  19815. description: |-
  19816. A key in the referenced Secret.
  19817. Some instances of this field may be defaulted, in others it may be required.
  19818. maxLength: 253
  19819. minLength: 1
  19820. pattern: ^[-._a-zA-Z0-9]+$
  19821. type: string
  19822. name:
  19823. description: The name of the Secret resource being referred to.
  19824. maxLength: 253
  19825. minLength: 1
  19826. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19827. type: string
  19828. namespace:
  19829. description: |-
  19830. The namespace of the Secret resource being referred to.
  19831. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19832. maxLength: 63
  19833. minLength: 1
  19834. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19835. type: string
  19836. type: object
  19837. required:
  19838. - apiKeyRef
  19839. - passcodeRef
  19840. type: object
  19841. environment:
  19842. default: development
  19843. description: Environment is the name of an environmnent within a project to pull the secrets from
  19844. type: string
  19845. project:
  19846. default: development
  19847. description: Project is an onboardbase project that the secrets should be pulled from
  19848. type: string
  19849. required:
  19850. - apiHost
  19851. - auth
  19852. - environment
  19853. - project
  19854. type: object
  19855. onepassword:
  19856. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  19857. properties:
  19858. auth:
  19859. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  19860. properties:
  19861. secretRef:
  19862. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  19863. properties:
  19864. connectTokenSecretRef:
  19865. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  19866. properties:
  19867. key:
  19868. description: |-
  19869. A key in the referenced Secret.
  19870. Some instances of this field may be defaulted, in others it may be required.
  19871. maxLength: 253
  19872. minLength: 1
  19873. pattern: ^[-._a-zA-Z0-9]+$
  19874. type: string
  19875. name:
  19876. description: The name of the Secret resource being referred to.
  19877. maxLength: 253
  19878. minLength: 1
  19879. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19880. type: string
  19881. namespace:
  19882. description: |-
  19883. The namespace of the Secret resource being referred to.
  19884. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19885. maxLength: 63
  19886. minLength: 1
  19887. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19888. type: string
  19889. type: object
  19890. required:
  19891. - connectTokenSecretRef
  19892. type: object
  19893. required:
  19894. - secretRef
  19895. type: object
  19896. connectHost:
  19897. description: ConnectHost defines the OnePassword Connect Server to connect to
  19898. type: string
  19899. vaults:
  19900. additionalProperties:
  19901. type: integer
  19902. description: Vaults defines which OnePassword vaults to search in which order
  19903. type: object
  19904. required:
  19905. - auth
  19906. - connectHost
  19907. - vaults
  19908. type: object
  19909. onepasswordSDK:
  19910. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  19911. properties:
  19912. auth:
  19913. description: Auth defines the information necessary to authenticate against OnePassword API.
  19914. properties:
  19915. serviceAccountSecretRef:
  19916. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  19917. properties:
  19918. key:
  19919. description: |-
  19920. A key in the referenced Secret.
  19921. Some instances of this field may be defaulted, in others it may be required.
  19922. maxLength: 253
  19923. minLength: 1
  19924. pattern: ^[-._a-zA-Z0-9]+$
  19925. type: string
  19926. name:
  19927. description: The name of the Secret resource being referred to.
  19928. maxLength: 253
  19929. minLength: 1
  19930. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19931. type: string
  19932. namespace:
  19933. description: |-
  19934. The namespace of the Secret resource being referred to.
  19935. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19936. maxLength: 63
  19937. minLength: 1
  19938. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19939. type: string
  19940. type: object
  19941. required:
  19942. - serviceAccountSecretRef
  19943. type: object
  19944. cache:
  19945. description: |-
  19946. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  19947. When enabled, secrets are cached with the specified TTL.
  19948. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  19949. If omitted, caching is disabled (default).
  19950. cache: {} is a valid option to set.
  19951. properties:
  19952. maxSize:
  19953. default: 100
  19954. description: |-
  19955. MaxSize is the maximum number of secrets to cache.
  19956. When the cache is full, least-recently-used entries are evicted.
  19957. minimum: 1
  19958. type: integer
  19959. ttl:
  19960. default: 5m
  19961. description: |-
  19962. TTL is the time-to-live for cached secrets.
  19963. Format: duration string (e.g., "5m", "1h", "30s")
  19964. type: string
  19965. type: object
  19966. environment:
  19967. description: |-
  19968. Environment defines the 1Password Environment ID to read variables from.
  19969. Environments are read-only: PushSecret, DeleteSecret, and SecretExists return an error when set.
  19970. Mutually exclusive with Vault.
  19971. type: string
  19972. integrationInfo:
  19973. description: |-
  19974. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  19975. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  19976. properties:
  19977. name:
  19978. default: 1Password SDK
  19979. description: Name defaults to "1Password SDK".
  19980. type: string
  19981. version:
  19982. default: v1.0.0
  19983. description: Version defaults to "v1.0.0".
  19984. type: string
  19985. type: object
  19986. vault:
  19987. description: |-
  19988. Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  19989. Mutually exclusive with Environment.
  19990. type: string
  19991. required:
  19992. - auth
  19993. type: object
  19994. x-kubernetes-validations:
  19995. - message: at most one of the fields in [vault environment] may be set
  19996. rule: '[has(self.vault),has(self.environment)].filter(x,x==true).size() <= 1'
  19997. openBao:
  19998. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  19999. properties:
  20000. auth:
  20001. description: Auth configures how secret-manager authenticates with the OpenBao server.
  20002. properties:
  20003. appRole:
  20004. description: |-
  20005. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  20006. with the role and secret stored in a Kubernetes Secret resource.
  20007. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  20008. properties:
  20009. path:
  20010. default: approle
  20011. description: |-
  20012. Path where the App Role authentication backend is mounted
  20013. in OpenBao, e.g: "approle"
  20014. type: string
  20015. roleId:
  20016. description: |-
  20017. RoleID configured in the App Role authentication backend when setting
  20018. up the authentication backend in OpenBao.
  20019. minLength: 1
  20020. type: string
  20021. roleRef:
  20022. description: |-
  20023. Reference to a key in a Secret that contains the App Role ID used
  20024. to authenticate with OpenBao.
  20025. The `key` field must be specified and denotes which entry within the Secret
  20026. resource is used as the app role id.
  20027. properties:
  20028. key:
  20029. description: |-
  20030. A key in the referenced Secret.
  20031. Some instances of this field may be defaulted, in others it may be required.
  20032. maxLength: 253
  20033. minLength: 1
  20034. pattern: ^[-._a-zA-Z0-9]+$
  20035. type: string
  20036. name:
  20037. description: The name of the Secret resource being referred to.
  20038. maxLength: 253
  20039. minLength: 1
  20040. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20041. type: string
  20042. namespace:
  20043. description: |-
  20044. The namespace of the Secret resource being referred to.
  20045. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20046. maxLength: 63
  20047. minLength: 1
  20048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20049. type: string
  20050. type: object
  20051. secretRef:
  20052. description: |-
  20053. Reference to a key in a Secret that contains the App Role secret used
  20054. to authenticate with OpenBao.
  20055. The `key` field must be specified and denotes which entry within the Secret
  20056. resource is used as the app role secret.
  20057. properties:
  20058. key:
  20059. description: |-
  20060. A key in the referenced Secret.
  20061. Some instances of this field may be defaulted, in others it may be required.
  20062. maxLength: 253
  20063. minLength: 1
  20064. pattern: ^[-._a-zA-Z0-9]+$
  20065. type: string
  20066. name:
  20067. description: The name of the Secret resource being referred to.
  20068. maxLength: 253
  20069. minLength: 1
  20070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20071. type: string
  20072. namespace:
  20073. description: |-
  20074. The namespace of the Secret resource being referred to.
  20075. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20076. maxLength: 63
  20077. minLength: 1
  20078. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20079. type: string
  20080. type: object
  20081. required:
  20082. - path
  20083. - secretRef
  20084. type: object
  20085. x-kubernetes-validations:
  20086. - message: exactly one of the fields in [roleId roleRef] must be set
  20087. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  20088. kubernetes:
  20089. description: |-
  20090. Kubernetes authenticates with OpenBao by passing a ServiceAccount
  20091. token to the [Kubernetes auth mechanism].
  20092. [Kubernetes auth mechanism]: https://openbao.org/docs/auth/kubernetes/
  20093. properties:
  20094. path:
  20095. default: kubernetes
  20096. description: |-
  20097. Path where the Kubernetes authentication backend is mounted in OpenBao, e.g:
  20098. "kubernetes"
  20099. type: string
  20100. role:
  20101. description: |-
  20102. A required field containing the OpenBao Role to assume. A Role binds a
  20103. Kubernetes ServiceAccount with a set of OpenBao policies.
  20104. minLength: 1
  20105. type: string
  20106. secretRef:
  20107. description: |-
  20108. Optional secret field containing a Kubernetes ServiceAccount JWT used
  20109. for authenticating with OpenBao. If a name is specified without a key,
  20110. `token` is the default.
  20111. properties:
  20112. key:
  20113. description: |-
  20114. A key in the referenced Secret.
  20115. Some instances of this field may be defaulted, in others it may be required.
  20116. maxLength: 253
  20117. minLength: 1
  20118. pattern: ^[-._a-zA-Z0-9]+$
  20119. type: string
  20120. name:
  20121. description: The name of the Secret resource being referred to.
  20122. maxLength: 253
  20123. minLength: 1
  20124. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20125. type: string
  20126. namespace:
  20127. description: |-
  20128. The namespace of the Secret resource being referred to.
  20129. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20130. maxLength: 63
  20131. minLength: 1
  20132. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20133. type: string
  20134. type: object
  20135. serviceAccountRef:
  20136. description: |-
  20137. Optional service account field containing the name of a Kubernetes ServiceAccount.
  20138. If the service account is specified, a token will be requested from the Kubernetes
  20139. TokenRequest API for authenticating with OpenBao.
  20140. Any configured audiences will be passed to the TokenRequest as-is.
  20141. properties:
  20142. audiences:
  20143. description: |-
  20144. Audience specifies the `aud` claim for the service account token
  20145. Some providers automatically extend the audience field based on well-known annotations for workload
  20146. identity (e.g. IRSA or GCP Workload Identity)
  20147. items:
  20148. type: string
  20149. type: array
  20150. name:
  20151. description: The name of the ServiceAccount resource being referred to.
  20152. maxLength: 253
  20153. minLength: 1
  20154. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20155. type: string
  20156. namespace:
  20157. description: |-
  20158. Namespace of the resource being referred to.
  20159. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20160. maxLength: 63
  20161. minLength: 1
  20162. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20163. type: string
  20164. required:
  20165. - name
  20166. type: object
  20167. required:
  20168. - path
  20169. - role
  20170. type: object
  20171. x-kubernetes-validations:
  20172. - message: exactly one of the fields in [serviceAccountRef secretRef] must be set
  20173. rule: '[has(self.serviceAccountRef),has(self.secretRef)].filter(x,x==true).size() == 1'
  20174. namespace:
  20175. description: |-
  20176. Name of the [OpenBao Namespace] to authenticate to. This can be different
  20177. than the namespace your secret is in. Namespaces is a set of features
  20178. within OpenBao that allows OpenBao environments to support secure
  20179. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  20180. if set, or empty otherwise
  20181. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  20182. type: string
  20183. tokenSecretRef:
  20184. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  20185. properties:
  20186. key:
  20187. description: |-
  20188. A key in the referenced Secret.
  20189. Some instances of this field may be defaulted, in others it may be required.
  20190. maxLength: 253
  20191. minLength: 1
  20192. pattern: ^[-._a-zA-Z0-9]+$
  20193. type: string
  20194. name:
  20195. description: The name of the Secret resource being referred to.
  20196. maxLength: 253
  20197. minLength: 1
  20198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20199. type: string
  20200. namespace:
  20201. description: |-
  20202. The namespace of the Secret resource being referred to.
  20203. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20204. maxLength: 63
  20205. minLength: 1
  20206. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20207. type: string
  20208. type: object
  20209. userPass:
  20210. description: UserPass authenticates with OpenBao by passing a username/password pair
  20211. properties:
  20212. path:
  20213. default: userpass
  20214. description: |-
  20215. Path where the UserPassword authentication backend is mounted
  20216. in OpenBao, e.g: "userpass"
  20217. type: string
  20218. secretRef:
  20219. description: |-
  20220. SecretRef to a key in a Secret resource containing password for the user
  20221. used to authenticate with OpenBao using the [UserPass authentication
  20222. method]
  20223. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  20224. properties:
  20225. key:
  20226. description: |-
  20227. A key in the referenced Secret.
  20228. Some instances of this field may be defaulted, in others it may be required.
  20229. maxLength: 253
  20230. minLength: 1
  20231. pattern: ^[-._a-zA-Z0-9]+$
  20232. type: string
  20233. name:
  20234. description: The name of the Secret resource being referred to.
  20235. maxLength: 253
  20236. minLength: 1
  20237. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20238. type: string
  20239. namespace:
  20240. description: |-
  20241. The namespace of the Secret resource being referred to.
  20242. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20243. maxLength: 63
  20244. minLength: 1
  20245. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20246. type: string
  20247. type: object
  20248. username:
  20249. description: |-
  20250. Username is a username used to authenticate using the [UserPass
  20251. authentication method]
  20252. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  20253. type: string
  20254. required:
  20255. - path
  20256. - username
  20257. type: object
  20258. type: object
  20259. x-kubernetes-validations:
  20260. - message: exactly one of the fields in [appRole tokenSecretRef userPass kubernetes] must be set
  20261. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass),has(self.kubernetes)].filter(x,x==true).size() == 1'
  20262. caBundle:
  20263. description: |-
  20264. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  20265. this and `caProvider` are not set the system root certificates are used
  20266. to validate the TLS connection.
  20267. format: byte
  20268. type: string
  20269. caProvider:
  20270. description: |-
  20271. The provider for the CA bundle to use to validate OpenBao server
  20272. certificate. If this and `caBundle` are not set the system root
  20273. certificates are used to validate the TLS connection.
  20274. properties:
  20275. key:
  20276. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20277. maxLength: 253
  20278. minLength: 1
  20279. pattern: ^[-._a-zA-Z0-9]+$
  20280. type: string
  20281. name:
  20282. description: The name of the object located at the provider type.
  20283. maxLength: 253
  20284. minLength: 1
  20285. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20286. type: string
  20287. namespace:
  20288. description: |-
  20289. The namespace the Provider type is in.
  20290. Can only be defined when used in a ClusterSecretStore.
  20291. maxLength: 63
  20292. minLength: 1
  20293. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20294. type: string
  20295. type:
  20296. description: The type of provider to use such as "Secret", or "ConfigMap".
  20297. enum:
  20298. - Secret
  20299. - ConfigMap
  20300. type: string
  20301. required:
  20302. - name
  20303. - type
  20304. type: object
  20305. namespace:
  20306. description: |-
  20307. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  20308. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  20309. e.g: "ns1".
  20310. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  20311. type: string
  20312. path:
  20313. description: |-
  20314. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  20315. "secret". The v2 KV secret engine version specific "/data" path suffix
  20316. for fetching secrets from OpenBao is optional and will be appended
  20317. if not present in specified path.
  20318. type: string
  20319. server:
  20320. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  20321. type: string
  20322. version:
  20323. default: v2
  20324. description: |-
  20325. Version is the OpenBao KV secret engine version. This can be either "v1" or
  20326. "v2". Version defaults to "v2".
  20327. enum:
  20328. - v1
  20329. - v2
  20330. type: string
  20331. required:
  20332. - server
  20333. type: object
  20334. x-kubernetes-validations:
  20335. - message: at most one of the fields in [caBundle caProvider] may be set
  20336. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  20337. oracle:
  20338. description: Oracle configures this store to sync secrets using Oracle Vault provider
  20339. properties:
  20340. auth:
  20341. description: |-
  20342. Auth configures how secret-manager authenticates with the Oracle Vault.
  20343. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  20344. properties:
  20345. secretRef:
  20346. description: SecretRef to pass through sensitive information.
  20347. properties:
  20348. fingerprint:
  20349. description: Fingerprint is the fingerprint of the API private key.
  20350. properties:
  20351. key:
  20352. description: |-
  20353. A key in the referenced Secret.
  20354. Some instances of this field may be defaulted, in others it may be required.
  20355. maxLength: 253
  20356. minLength: 1
  20357. pattern: ^[-._a-zA-Z0-9]+$
  20358. type: string
  20359. name:
  20360. description: The name of the Secret resource being referred to.
  20361. maxLength: 253
  20362. minLength: 1
  20363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20364. type: string
  20365. namespace:
  20366. description: |-
  20367. The namespace of the Secret resource being referred to.
  20368. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20369. maxLength: 63
  20370. minLength: 1
  20371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20372. type: string
  20373. type: object
  20374. privatekey:
  20375. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  20376. properties:
  20377. key:
  20378. description: |-
  20379. A key in the referenced Secret.
  20380. Some instances of this field may be defaulted, in others it may be required.
  20381. maxLength: 253
  20382. minLength: 1
  20383. pattern: ^[-._a-zA-Z0-9]+$
  20384. type: string
  20385. name:
  20386. description: The name of the Secret resource being referred to.
  20387. maxLength: 253
  20388. minLength: 1
  20389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20390. type: string
  20391. namespace:
  20392. description: |-
  20393. The namespace of the Secret resource being referred to.
  20394. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20395. maxLength: 63
  20396. minLength: 1
  20397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20398. type: string
  20399. type: object
  20400. required:
  20401. - fingerprint
  20402. - privatekey
  20403. type: object
  20404. tenancy:
  20405. description: Tenancy is the tenancy OCID where user is located.
  20406. type: string
  20407. user:
  20408. description: User is an access OCID specific to the account.
  20409. type: string
  20410. required:
  20411. - secretRef
  20412. - tenancy
  20413. - user
  20414. type: object
  20415. compartment:
  20416. description: |-
  20417. Compartment is the vault compartment OCID.
  20418. Required for PushSecret
  20419. type: string
  20420. encryptionKey:
  20421. description: |-
  20422. EncryptionKey is the OCID of the encryption key within the vault.
  20423. Required for PushSecret
  20424. type: string
  20425. principalType:
  20426. description: |-
  20427. The type of principal to use for authentication. If left blank, the Auth struct will
  20428. determine the principal type. This optional field must be specified if using
  20429. workload identity.
  20430. enum:
  20431. - ""
  20432. - UserPrincipal
  20433. - InstancePrincipal
  20434. - Workload
  20435. type: string
  20436. region:
  20437. description: Region is the region where vault is located.
  20438. type: string
  20439. serviceAccountRef:
  20440. description: |-
  20441. ServiceAccountRef specified the service account
  20442. that should be used when authenticating with WorkloadIdentity.
  20443. properties:
  20444. audiences:
  20445. description: |-
  20446. Audience specifies the `aud` claim for the service account token
  20447. Some providers automatically extend the audience field based on well-known annotations for workload
  20448. identity (e.g. IRSA or GCP Workload Identity)
  20449. items:
  20450. type: string
  20451. type: array
  20452. name:
  20453. description: The name of the ServiceAccount resource being referred to.
  20454. maxLength: 253
  20455. minLength: 1
  20456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20457. type: string
  20458. namespace:
  20459. description: |-
  20460. Namespace of the resource being referred to.
  20461. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20462. maxLength: 63
  20463. minLength: 1
  20464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20465. type: string
  20466. required:
  20467. - name
  20468. type: object
  20469. vault:
  20470. description: Vault is the vault's OCID of the specific vault where secret is located.
  20471. type: string
  20472. required:
  20473. - region
  20474. - vault
  20475. type: object
  20476. ovh:
  20477. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  20478. properties:
  20479. auth:
  20480. description: Authentication method (mtls or token).
  20481. properties:
  20482. mtls:
  20483. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  20484. properties:
  20485. caBundle:
  20486. format: byte
  20487. type: string
  20488. caProvider:
  20489. description: |-
  20490. CAProvider provides a custom certificate authority for accessing the provider's store.
  20491. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  20492. properties:
  20493. key:
  20494. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20495. maxLength: 253
  20496. minLength: 1
  20497. pattern: ^[-._a-zA-Z0-9]+$
  20498. type: string
  20499. name:
  20500. description: The name of the object located at the provider type.
  20501. maxLength: 253
  20502. minLength: 1
  20503. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20504. type: string
  20505. namespace:
  20506. description: |-
  20507. The namespace the Provider type is in.
  20508. Can only be defined when used in a ClusterSecretStore.
  20509. maxLength: 63
  20510. minLength: 1
  20511. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20512. type: string
  20513. type:
  20514. description: The type of provider to use such as "Secret", or "ConfigMap".
  20515. enum:
  20516. - Secret
  20517. - ConfigMap
  20518. type: string
  20519. required:
  20520. - name
  20521. - type
  20522. type: object
  20523. certSecretRef:
  20524. description: |-
  20525. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20526. In some instances, `key` is a required field.
  20527. properties:
  20528. key:
  20529. description: |-
  20530. A key in the referenced Secret.
  20531. Some instances of this field may be defaulted, in others it may be required.
  20532. maxLength: 253
  20533. minLength: 1
  20534. pattern: ^[-._a-zA-Z0-9]+$
  20535. type: string
  20536. name:
  20537. description: The name of the Secret resource being referred to.
  20538. maxLength: 253
  20539. minLength: 1
  20540. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20541. type: string
  20542. namespace:
  20543. description: |-
  20544. The namespace of the Secret resource being referred to.
  20545. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20546. maxLength: 63
  20547. minLength: 1
  20548. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20549. type: string
  20550. type: object
  20551. keySecretRef:
  20552. description: |-
  20553. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20554. In some instances, `key` is a required field.
  20555. properties:
  20556. key:
  20557. description: |-
  20558. A key in the referenced Secret.
  20559. Some instances of this field may be defaulted, in others it may be required.
  20560. maxLength: 253
  20561. minLength: 1
  20562. pattern: ^[-._a-zA-Z0-9]+$
  20563. type: string
  20564. name:
  20565. description: The name of the Secret resource being referred to.
  20566. maxLength: 253
  20567. minLength: 1
  20568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20569. type: string
  20570. namespace:
  20571. description: |-
  20572. The namespace of the Secret resource being referred to.
  20573. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20574. maxLength: 63
  20575. minLength: 1
  20576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20577. type: string
  20578. type: object
  20579. required:
  20580. - certSecretRef
  20581. - keySecretRef
  20582. type: object
  20583. token:
  20584. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  20585. properties:
  20586. tokenSecretRef:
  20587. description: |-
  20588. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20589. In some instances, `key` is a required field.
  20590. properties:
  20591. key:
  20592. description: |-
  20593. A key in the referenced Secret.
  20594. Some instances of this field may be defaulted, in others it may be required.
  20595. maxLength: 253
  20596. minLength: 1
  20597. pattern: ^[-._a-zA-Z0-9]+$
  20598. type: string
  20599. name:
  20600. description: The name of the Secret resource being referred to.
  20601. maxLength: 253
  20602. minLength: 1
  20603. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20604. type: string
  20605. namespace:
  20606. description: |-
  20607. The namespace of the Secret resource being referred to.
  20608. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20609. maxLength: 63
  20610. minLength: 1
  20611. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20612. type: string
  20613. type: object
  20614. required:
  20615. - tokenSecretRef
  20616. type: object
  20617. type: object
  20618. casRequired:
  20619. description: 'Enables or disables check-and-set (CAS) (default: false).'
  20620. type: boolean
  20621. okmsTimeout:
  20622. default: 30
  20623. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  20624. format: int32
  20625. minimum: 1
  20626. type: integer
  20627. okmsid:
  20628. description: specifies the OKMS ID.
  20629. type: string
  20630. server:
  20631. description: specifies the OKMS server endpoint.
  20632. type: string
  20633. required:
  20634. - auth
  20635. - okmsid
  20636. - server
  20637. type: object
  20638. passbolt:
  20639. description: |-
  20640. PassboltProvider provides access to Passbolt secrets manager.
  20641. See: https://www.passbolt.com.
  20642. properties:
  20643. auth:
  20644. description: Auth defines the information necessary to authenticate against Passbolt Server
  20645. properties:
  20646. passwordSecretRef:
  20647. description: |-
  20648. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20649. In some instances, `key` is a required field.
  20650. properties:
  20651. key:
  20652. description: |-
  20653. A key in the referenced Secret.
  20654. Some instances of this field may be defaulted, in others it may be required.
  20655. maxLength: 253
  20656. minLength: 1
  20657. pattern: ^[-._a-zA-Z0-9]+$
  20658. type: string
  20659. name:
  20660. description: The name of the Secret resource being referred to.
  20661. maxLength: 253
  20662. minLength: 1
  20663. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20664. type: string
  20665. namespace:
  20666. description: |-
  20667. The namespace of the Secret resource being referred to.
  20668. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20669. maxLength: 63
  20670. minLength: 1
  20671. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20672. type: string
  20673. type: object
  20674. privateKeySecretRef:
  20675. description: |-
  20676. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20677. In some instances, `key` is a required field.
  20678. properties:
  20679. key:
  20680. description: |-
  20681. A key in the referenced Secret.
  20682. Some instances of this field may be defaulted, in others it may be required.
  20683. maxLength: 253
  20684. minLength: 1
  20685. pattern: ^[-._a-zA-Z0-9]+$
  20686. type: string
  20687. name:
  20688. description: The name of the Secret resource being referred to.
  20689. maxLength: 253
  20690. minLength: 1
  20691. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20692. type: string
  20693. namespace:
  20694. description: |-
  20695. The namespace of the Secret resource being referred to.
  20696. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20697. maxLength: 63
  20698. minLength: 1
  20699. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20700. type: string
  20701. type: object
  20702. required:
  20703. - passwordSecretRef
  20704. - privateKeySecretRef
  20705. type: object
  20706. caBundle:
  20707. description: |-
  20708. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  20709. if the Host URL is using HTTPS protocol. If not set the system root certificates
  20710. are used to validate the TLS connection.
  20711. format: byte
  20712. type: string
  20713. caProvider:
  20714. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  20715. properties:
  20716. key:
  20717. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20718. maxLength: 253
  20719. minLength: 1
  20720. pattern: ^[-._a-zA-Z0-9]+$
  20721. type: string
  20722. name:
  20723. description: The name of the object located at the provider type.
  20724. maxLength: 253
  20725. minLength: 1
  20726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20727. type: string
  20728. namespace:
  20729. description: |-
  20730. The namespace the Provider type is in.
  20731. Can only be defined when used in a ClusterSecretStore.
  20732. maxLength: 63
  20733. minLength: 1
  20734. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20735. type: string
  20736. type:
  20737. description: The type of provider to use such as "Secret", or "ConfigMap".
  20738. enum:
  20739. - Secret
  20740. - ConfigMap
  20741. type: string
  20742. required:
  20743. - name
  20744. - type
  20745. type: object
  20746. host:
  20747. description: Host defines the Passbolt Server to connect to
  20748. type: string
  20749. required:
  20750. - auth
  20751. - host
  20752. type: object
  20753. passworddepot:
  20754. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  20755. properties:
  20756. auth:
  20757. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  20758. properties:
  20759. secretRef:
  20760. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  20761. properties:
  20762. credentials:
  20763. description: Username / Password is used for authentication.
  20764. properties:
  20765. key:
  20766. description: |-
  20767. A key in the referenced Secret.
  20768. Some instances of this field may be defaulted, in others it may be required.
  20769. maxLength: 253
  20770. minLength: 1
  20771. pattern: ^[-._a-zA-Z0-9]+$
  20772. type: string
  20773. name:
  20774. description: The name of the Secret resource being referred to.
  20775. maxLength: 253
  20776. minLength: 1
  20777. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20778. type: string
  20779. namespace:
  20780. description: |-
  20781. The namespace of the Secret resource being referred to.
  20782. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20783. maxLength: 63
  20784. minLength: 1
  20785. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20786. type: string
  20787. type: object
  20788. type: object
  20789. required:
  20790. - secretRef
  20791. type: object
  20792. database:
  20793. description: Database to use as source
  20794. type: string
  20795. host:
  20796. description: URL configures the Password Depot instance URL.
  20797. type: string
  20798. required:
  20799. - auth
  20800. - database
  20801. - host
  20802. type: object
  20803. previder:
  20804. description: Previder configures this store to sync secrets using the Previder provider
  20805. properties:
  20806. auth:
  20807. description: PreviderAuth contains a secretRef for credentials.
  20808. properties:
  20809. secretRef:
  20810. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  20811. properties:
  20812. accessToken:
  20813. description: The AccessToken is used for authentication
  20814. properties:
  20815. key:
  20816. description: |-
  20817. A key in the referenced Secret.
  20818. Some instances of this field may be defaulted, in others it may be required.
  20819. maxLength: 253
  20820. minLength: 1
  20821. pattern: ^[-._a-zA-Z0-9]+$
  20822. type: string
  20823. name:
  20824. description: The name of the Secret resource being referred to.
  20825. maxLength: 253
  20826. minLength: 1
  20827. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20828. type: string
  20829. namespace:
  20830. description: |-
  20831. The namespace of the Secret resource being referred to.
  20832. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20833. maxLength: 63
  20834. minLength: 1
  20835. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20836. type: string
  20837. type: object
  20838. required:
  20839. - accessToken
  20840. type: object
  20841. type: object
  20842. baseUri:
  20843. type: string
  20844. required:
  20845. - auth
  20846. type: object
  20847. pulumi:
  20848. description: Pulumi configures this store to sync secrets using the Pulumi provider
  20849. properties:
  20850. accessToken:
  20851. description: |-
  20852. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  20853. Deprecated: Use auth.accessToken instead.
  20854. properties:
  20855. secretRef:
  20856. description: SecretRef is a reference to a secret containing the Pulumi API token.
  20857. properties:
  20858. key:
  20859. description: |-
  20860. A key in the referenced Secret.
  20861. Some instances of this field may be defaulted, in others it may be required.
  20862. maxLength: 253
  20863. minLength: 1
  20864. pattern: ^[-._a-zA-Z0-9]+$
  20865. type: string
  20866. name:
  20867. description: The name of the Secret resource being referred to.
  20868. maxLength: 253
  20869. minLength: 1
  20870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20871. type: string
  20872. namespace:
  20873. description: |-
  20874. The namespace of the Secret resource being referred to.
  20875. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20876. maxLength: 63
  20877. minLength: 1
  20878. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20879. type: string
  20880. type: object
  20881. type: object
  20882. apiUrl:
  20883. default: https://api.pulumi.com/api/esc
  20884. description: APIURL is the URL of the Pulumi API.
  20885. type: string
  20886. auth:
  20887. description: |-
  20888. Auth configures how the Operator authenticates with the Pulumi API.
  20889. Either auth or the deprecated accessToken field must be specified.
  20890. properties:
  20891. accessToken:
  20892. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  20893. properties:
  20894. secretRef:
  20895. description: SecretRef is a reference to a secret containing the Pulumi API token.
  20896. properties:
  20897. key:
  20898. description: |-
  20899. A key in the referenced Secret.
  20900. Some instances of this field may be defaulted, in others it may be required.
  20901. maxLength: 253
  20902. minLength: 1
  20903. pattern: ^[-._a-zA-Z0-9]+$
  20904. type: string
  20905. name:
  20906. description: The name of the Secret resource being referred to.
  20907. maxLength: 253
  20908. minLength: 1
  20909. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20910. type: string
  20911. namespace:
  20912. description: |-
  20913. The namespace of the Secret resource being referred to.
  20914. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20915. maxLength: 63
  20916. minLength: 1
  20917. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20918. type: string
  20919. type: object
  20920. type: object
  20921. oidcConfig:
  20922. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  20923. properties:
  20924. expirationSeconds:
  20925. default: 600
  20926. description: |-
  20927. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  20928. Defaults to 10 minutes.
  20929. format: int64
  20930. minimum: 600
  20931. type: integer
  20932. organization:
  20933. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  20934. type: string
  20935. serviceAccountRef:
  20936. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  20937. properties:
  20938. audiences:
  20939. description: |-
  20940. Audience specifies the `aud` claim for the service account token
  20941. Some providers automatically extend the audience field based on well-known annotations for workload
  20942. identity (e.g. IRSA or GCP Workload Identity)
  20943. items:
  20944. type: string
  20945. type: array
  20946. name:
  20947. description: The name of the ServiceAccount resource being referred to.
  20948. maxLength: 253
  20949. minLength: 1
  20950. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20951. type: string
  20952. namespace:
  20953. description: |-
  20954. Namespace of the resource being referred to.
  20955. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20956. maxLength: 63
  20957. minLength: 1
  20958. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20959. type: string
  20960. required:
  20961. - name
  20962. type: object
  20963. required:
  20964. - organization
  20965. - serviceAccountRef
  20966. type: object
  20967. type: object
  20968. x-kubernetes-validations:
  20969. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  20970. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  20971. environment:
  20972. description: |-
  20973. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  20974. dynamically retrieved values from supported providers including all major clouds,
  20975. and other Pulumi ESC environments.
  20976. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  20977. type: string
  20978. organization:
  20979. description: |-
  20980. Organization are a space to collaborate on shared projects and stacks.
  20981. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  20982. type: string
  20983. project:
  20984. description: Project is the name of the Pulumi ESC project the environment belongs to.
  20985. type: string
  20986. required:
  20987. - environment
  20988. - organization
  20989. - project
  20990. type: object
  20991. x-kubernetes-validations:
  20992. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  20993. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  20994. scaleway:
  20995. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  20996. properties:
  20997. accessKey:
  20998. description: AccessKey is the non-secret part of the api key.
  20999. properties:
  21000. secretRef:
  21001. description: SecretRef references a key in a secret that will be used as value.
  21002. properties:
  21003. key:
  21004. description: |-
  21005. A key in the referenced Secret.
  21006. Some instances of this field may be defaulted, in others it may be required.
  21007. maxLength: 253
  21008. minLength: 1
  21009. pattern: ^[-._a-zA-Z0-9]+$
  21010. type: string
  21011. name:
  21012. description: The name of the Secret resource being referred to.
  21013. maxLength: 253
  21014. minLength: 1
  21015. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21016. type: string
  21017. namespace:
  21018. description: |-
  21019. The namespace of the Secret resource being referred to.
  21020. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21021. maxLength: 63
  21022. minLength: 1
  21023. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21024. type: string
  21025. type: object
  21026. value:
  21027. description: Value can be specified directly to set a value without using a secret.
  21028. type: string
  21029. type: object
  21030. apiUrl:
  21031. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  21032. type: string
  21033. projectId:
  21034. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  21035. type: string
  21036. region:
  21037. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  21038. type: string
  21039. secretKey:
  21040. description: SecretKey is the non-secret part of the api key.
  21041. properties:
  21042. secretRef:
  21043. description: SecretRef references a key in a secret that will be used as value.
  21044. properties:
  21045. key:
  21046. description: |-
  21047. A key in the referenced Secret.
  21048. Some instances of this field may be defaulted, in others it may be required.
  21049. maxLength: 253
  21050. minLength: 1
  21051. pattern: ^[-._a-zA-Z0-9]+$
  21052. type: string
  21053. name:
  21054. description: The name of the Secret resource being referred to.
  21055. maxLength: 253
  21056. minLength: 1
  21057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21058. type: string
  21059. namespace:
  21060. description: |-
  21061. The namespace of the Secret resource being referred to.
  21062. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21063. maxLength: 63
  21064. minLength: 1
  21065. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21066. type: string
  21067. type: object
  21068. value:
  21069. description: Value can be specified directly to set a value without using a secret.
  21070. type: string
  21071. type: object
  21072. required:
  21073. - accessKey
  21074. - projectId
  21075. - region
  21076. - secretKey
  21077. type: object
  21078. secretserver:
  21079. description: |-
  21080. SecretServer configures this store to sync secrets using SecretServer provider
  21081. https://docs.delinea.com/online-help/secret-server/start.htm
  21082. properties:
  21083. caBundle:
  21084. description: |-
  21085. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  21086. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  21087. are used to validate the TLS connection.
  21088. format: byte
  21089. type: string
  21090. caProvider:
  21091. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  21092. properties:
  21093. key:
  21094. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  21095. maxLength: 253
  21096. minLength: 1
  21097. pattern: ^[-._a-zA-Z0-9]+$
  21098. type: string
  21099. name:
  21100. description: The name of the object located at the provider type.
  21101. maxLength: 253
  21102. minLength: 1
  21103. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21104. type: string
  21105. namespace:
  21106. description: |-
  21107. The namespace the Provider type is in.
  21108. Can only be defined when used in a ClusterSecretStore.
  21109. maxLength: 63
  21110. minLength: 1
  21111. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21112. type: string
  21113. type:
  21114. description: The type of provider to use such as "Secret", or "ConfigMap".
  21115. enum:
  21116. - Secret
  21117. - ConfigMap
  21118. type: string
  21119. required:
  21120. - name
  21121. - type
  21122. type: object
  21123. disableSiteIDValidation:
  21124. description: |-
  21125. DisableSiteIDValidation permits a missing site ID for new secrets.
  21126. The provider sends 0 if no site ID is set.
  21127. type: boolean
  21128. domain:
  21129. description: Domain is the secret server domain.
  21130. type: string
  21131. password:
  21132. description: |-
  21133. Password is the secret server account password.
  21134. Required unless Token is set.
  21135. properties:
  21136. secretRef:
  21137. description: SecretRef references a key in a secret that will be used as value.
  21138. properties:
  21139. key:
  21140. description: |-
  21141. A key in the referenced Secret.
  21142. Some instances of this field may be defaulted, in others it may be required.
  21143. maxLength: 253
  21144. minLength: 1
  21145. pattern: ^[-._a-zA-Z0-9]+$
  21146. type: string
  21147. name:
  21148. description: The name of the Secret resource being referred to.
  21149. maxLength: 253
  21150. minLength: 1
  21151. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21152. type: string
  21153. namespace:
  21154. description: |-
  21155. The namespace of the Secret resource being referred to.
  21156. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21157. maxLength: 63
  21158. minLength: 1
  21159. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21160. type: string
  21161. type: object
  21162. value:
  21163. description: Value can be specified directly to set a value without using a secret.
  21164. minLength: 1
  21165. type: string
  21166. type: object
  21167. x-kubernetes-validations:
  21168. - message: exactly one of value or secretRef must be set
  21169. rule: has(self.value) != has(self.secretRef)
  21170. serverURL:
  21171. description: |-
  21172. ServerURL
  21173. URL to your secret server installation
  21174. type: string
  21175. siteId:
  21176. description: |-
  21177. SiteID is the ID of the Secret Server site for new secrets.
  21178. PushSecret metadata can override this value for one secret.
  21179. The provider uses 1 if this field is not set.
  21180. minimum: 1
  21181. type: integer
  21182. token:
  21183. description: |-
  21184. Token is an access token used to authenticate to the secret server,
  21185. as an alternative to Username and Password. When set, Username and
  21186. Password are not required and are ignored.
  21187. properties:
  21188. secretRef:
  21189. description: SecretRef references a key in a secret that will be used as value.
  21190. properties:
  21191. key:
  21192. description: |-
  21193. A key in the referenced Secret.
  21194. Some instances of this field may be defaulted, in others it may be required.
  21195. maxLength: 253
  21196. minLength: 1
  21197. pattern: ^[-._a-zA-Z0-9]+$
  21198. type: string
  21199. name:
  21200. description: The name of the Secret resource being referred to.
  21201. maxLength: 253
  21202. minLength: 1
  21203. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21204. type: string
  21205. namespace:
  21206. description: |-
  21207. The namespace of the Secret resource being referred to.
  21208. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21209. maxLength: 63
  21210. minLength: 1
  21211. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21212. type: string
  21213. type: object
  21214. value:
  21215. description: Value can be specified directly to set a value without using a secret.
  21216. minLength: 1
  21217. type: string
  21218. type: object
  21219. x-kubernetes-validations:
  21220. - message: exactly one of value or secretRef must be set
  21221. rule: has(self.value) != has(self.secretRef)
  21222. username:
  21223. description: |-
  21224. Username is the secret server account username.
  21225. Required unless Token is set.
  21226. properties:
  21227. secretRef:
  21228. description: SecretRef references a key in a secret that will be used as value.
  21229. properties:
  21230. key:
  21231. description: |-
  21232. A key in the referenced Secret.
  21233. Some instances of this field may be defaulted, in others it may be required.
  21234. maxLength: 253
  21235. minLength: 1
  21236. pattern: ^[-._a-zA-Z0-9]+$
  21237. type: string
  21238. name:
  21239. description: The name of the Secret resource being referred to.
  21240. maxLength: 253
  21241. minLength: 1
  21242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21243. type: string
  21244. namespace:
  21245. description: |-
  21246. The namespace of the Secret resource being referred to.
  21247. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21248. maxLength: 63
  21249. minLength: 1
  21250. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21251. type: string
  21252. type: object
  21253. value:
  21254. description: Value can be specified directly to set a value without using a secret.
  21255. minLength: 1
  21256. type: string
  21257. type: object
  21258. x-kubernetes-validations:
  21259. - message: exactly one of value or secretRef must be set
  21260. rule: has(self.value) != has(self.secretRef)
  21261. required:
  21262. - serverURL
  21263. type: object
  21264. x-kubernetes-validations:
  21265. - message: either token, or both username and password, must be set
  21266. rule: has(self.token) || (has(self.username) && has(self.password))
  21267. senhasegura:
  21268. description: Senhasegura configures this store to sync secrets using senhasegura provider
  21269. properties:
  21270. auth:
  21271. description: Auth defines parameters to authenticate in senhasegura
  21272. properties:
  21273. clientId:
  21274. type: string
  21275. clientSecretSecretRef:
  21276. description: |-
  21277. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  21278. In some instances, `key` is a required field.
  21279. properties:
  21280. key:
  21281. description: |-
  21282. A key in the referenced Secret.
  21283. Some instances of this field may be defaulted, in others it may be required.
  21284. maxLength: 253
  21285. minLength: 1
  21286. pattern: ^[-._a-zA-Z0-9]+$
  21287. type: string
  21288. name:
  21289. description: The name of the Secret resource being referred to.
  21290. maxLength: 253
  21291. minLength: 1
  21292. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21293. type: string
  21294. namespace:
  21295. description: |-
  21296. The namespace of the Secret resource being referred to.
  21297. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21298. maxLength: 63
  21299. minLength: 1
  21300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21301. type: string
  21302. type: object
  21303. required:
  21304. - clientId
  21305. - clientSecretSecretRef
  21306. type: object
  21307. ignoreSslCertificate:
  21308. default: false
  21309. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  21310. type: boolean
  21311. module:
  21312. description: Module defines which senhasegura module should be used to get secrets
  21313. type: string
  21314. url:
  21315. description: URL of senhasegura
  21316. type: string
  21317. required:
  21318. - auth
  21319. - module
  21320. - url
  21321. type: object
  21322. vault:
  21323. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  21324. properties:
  21325. auth:
  21326. description: Auth configures how secret-manager authenticates with the Vault server.
  21327. properties:
  21328. appRole:
  21329. description: |-
  21330. AppRole authenticates with Vault using the App Role auth mechanism,
  21331. with the role and secret stored in a Kubernetes Secret resource.
  21332. properties:
  21333. path:
  21334. default: approle
  21335. description: |-
  21336. Path where the App Role authentication backend is mounted
  21337. in Vault, e.g: "approle"
  21338. type: string
  21339. roleId:
  21340. description: |-
  21341. RoleID configured in the App Role authentication backend when setting
  21342. up the authentication backend in Vault.
  21343. type: string
  21344. roleRef:
  21345. description: |-
  21346. Reference to a key in a Secret that contains the App Role ID used
  21347. to authenticate with Vault.
  21348. The `key` field must be specified and denotes which entry within the Secret
  21349. resource is used as the app role id.
  21350. properties:
  21351. key:
  21352. description: |-
  21353. A key in the referenced Secret.
  21354. Some instances of this field may be defaulted, in others it may be required.
  21355. maxLength: 253
  21356. minLength: 1
  21357. pattern: ^[-._a-zA-Z0-9]+$
  21358. type: string
  21359. name:
  21360. description: The name of the Secret resource being referred to.
  21361. maxLength: 253
  21362. minLength: 1
  21363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21364. type: string
  21365. namespace:
  21366. description: |-
  21367. The namespace of the Secret resource being referred to.
  21368. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21369. maxLength: 63
  21370. minLength: 1
  21371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21372. type: string
  21373. type: object
  21374. secretRef:
  21375. description: |-
  21376. Reference to a key in a Secret that contains the App Role secret used
  21377. to authenticate with Vault.
  21378. The `key` field must be specified and denotes which entry within the Secret
  21379. resource is used as the app role secret.
  21380. properties:
  21381. key:
  21382. description: |-
  21383. A key in the referenced Secret.
  21384. Some instances of this field may be defaulted, in others it may be required.
  21385. maxLength: 253
  21386. minLength: 1
  21387. pattern: ^[-._a-zA-Z0-9]+$
  21388. type: string
  21389. name:
  21390. description: The name of the Secret resource being referred to.
  21391. maxLength: 253
  21392. minLength: 1
  21393. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21394. type: string
  21395. namespace:
  21396. description: |-
  21397. The namespace of the Secret resource being referred to.
  21398. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21399. maxLength: 63
  21400. minLength: 1
  21401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21402. type: string
  21403. type: object
  21404. required:
  21405. - path
  21406. - secretRef
  21407. type: object
  21408. cert:
  21409. description: |-
  21410. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  21411. Cert authentication method
  21412. properties:
  21413. clientCert:
  21414. description: |-
  21415. ClientCert is a certificate to authenticate using the Cert Vault
  21416. authentication method
  21417. properties:
  21418. key:
  21419. description: |-
  21420. A key in the referenced Secret.
  21421. Some instances of this field may be defaulted, in others it may be required.
  21422. maxLength: 253
  21423. minLength: 1
  21424. pattern: ^[-._a-zA-Z0-9]+$
  21425. type: string
  21426. name:
  21427. description: The name of the Secret resource being referred to.
  21428. maxLength: 253
  21429. minLength: 1
  21430. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21431. type: string
  21432. namespace:
  21433. description: |-
  21434. The namespace of the Secret resource being referred to.
  21435. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21436. maxLength: 63
  21437. minLength: 1
  21438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21439. type: string
  21440. type: object
  21441. path:
  21442. default: cert
  21443. description: |-
  21444. Path where the Certificate authentication backend is mounted
  21445. in Vault, e.g: "cert"
  21446. type: string
  21447. secretRef:
  21448. description: |-
  21449. SecretRef to a key in a Secret resource containing client private key to
  21450. authenticate with Vault using the Cert authentication method
  21451. properties:
  21452. key:
  21453. description: |-
  21454. A key in the referenced Secret.
  21455. Some instances of this field may be defaulted, in others it may be required.
  21456. maxLength: 253
  21457. minLength: 1
  21458. pattern: ^[-._a-zA-Z0-9]+$
  21459. type: string
  21460. name:
  21461. description: The name of the Secret resource being referred to.
  21462. maxLength: 253
  21463. minLength: 1
  21464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21465. type: string
  21466. namespace:
  21467. description: |-
  21468. The namespace of the Secret resource being referred to.
  21469. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21470. maxLength: 63
  21471. minLength: 1
  21472. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21473. type: string
  21474. type: object
  21475. vaultRole:
  21476. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  21477. type: string
  21478. type: object
  21479. gcp:
  21480. description: |-
  21481. Gcp authenticates with Vault using Google Cloud Platform authentication method
  21482. GCP authentication method
  21483. properties:
  21484. location:
  21485. description: Location optionally defines a location/region for the secret
  21486. type: string
  21487. path:
  21488. default: gcp
  21489. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  21490. type: string
  21491. projectID:
  21492. description: Project ID of the Google Cloud Platform project
  21493. type: string
  21494. role:
  21495. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  21496. type: string
  21497. secretRef:
  21498. description: Specify credentials in a Secret object
  21499. properties:
  21500. secretAccessKeySecretRef:
  21501. description: The SecretAccessKey is used for authentication
  21502. properties:
  21503. key:
  21504. description: |-
  21505. A key in the referenced Secret.
  21506. Some instances of this field may be defaulted, in others it may be required.
  21507. maxLength: 253
  21508. minLength: 1
  21509. pattern: ^[-._a-zA-Z0-9]+$
  21510. type: string
  21511. name:
  21512. description: The name of the Secret resource being referred to.
  21513. maxLength: 253
  21514. minLength: 1
  21515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21516. type: string
  21517. namespace:
  21518. description: |-
  21519. The namespace of the Secret resource being referred to.
  21520. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21521. maxLength: 63
  21522. minLength: 1
  21523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21524. type: string
  21525. type: object
  21526. type: object
  21527. serviceAccountRef:
  21528. description: ServiceAccountRef to a service account for impersonation
  21529. properties:
  21530. audiences:
  21531. description: |-
  21532. Audience specifies the `aud` claim for the service account token
  21533. Some providers automatically extend the audience field based on well-known annotations for workload
  21534. identity (e.g. IRSA or GCP Workload Identity)
  21535. items:
  21536. type: string
  21537. type: array
  21538. name:
  21539. description: The name of the ServiceAccount resource being referred to.
  21540. maxLength: 253
  21541. minLength: 1
  21542. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21543. type: string
  21544. namespace:
  21545. description: |-
  21546. Namespace of the resource being referred to.
  21547. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21548. maxLength: 63
  21549. minLength: 1
  21550. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21551. type: string
  21552. required:
  21553. - name
  21554. type: object
  21555. workloadIdentity:
  21556. description: Specify a service account with Workload Identity
  21557. properties:
  21558. clusterLocation:
  21559. description: |-
  21560. ClusterLocation is the location of the cluster
  21561. If not specified, it fetches information from the metadata server
  21562. type: string
  21563. clusterName:
  21564. description: |-
  21565. ClusterName is the name of the cluster
  21566. If not specified, it fetches information from the metadata server
  21567. type: string
  21568. clusterProjectID:
  21569. description: |-
  21570. ClusterProjectID is the project ID of the cluster
  21571. If not specified, it fetches information from the metadata server
  21572. type: string
  21573. serviceAccountRef:
  21574. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  21575. properties:
  21576. audiences:
  21577. description: |-
  21578. Audience specifies the `aud` claim for the service account token
  21579. Some providers automatically extend the audience field based on well-known annotations for workload
  21580. identity (e.g. IRSA or GCP Workload Identity)
  21581. items:
  21582. type: string
  21583. type: array
  21584. name:
  21585. description: The name of the ServiceAccount resource being referred to.
  21586. maxLength: 253
  21587. minLength: 1
  21588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21589. type: string
  21590. namespace:
  21591. description: |-
  21592. Namespace of the resource being referred to.
  21593. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21594. maxLength: 63
  21595. minLength: 1
  21596. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21597. type: string
  21598. required:
  21599. - name
  21600. type: object
  21601. required:
  21602. - serviceAccountRef
  21603. type: object
  21604. required:
  21605. - role
  21606. type: object
  21607. iam:
  21608. description: |-
  21609. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  21610. AWS IAM authentication method
  21611. properties:
  21612. externalID:
  21613. description: AWS External ID set on assumed IAM roles
  21614. type: string
  21615. jwt:
  21616. description: Specify a service account with IRSA enabled
  21617. properties:
  21618. serviceAccountRef:
  21619. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  21620. properties:
  21621. audiences:
  21622. description: |-
  21623. Audience specifies the `aud` claim for the service account token
  21624. Some providers automatically extend the audience field based on well-known annotations for workload
  21625. identity (e.g. IRSA or GCP Workload Identity)
  21626. items:
  21627. type: string
  21628. type: array
  21629. name:
  21630. description: The name of the ServiceAccount resource being referred to.
  21631. maxLength: 253
  21632. minLength: 1
  21633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21634. type: string
  21635. namespace:
  21636. description: |-
  21637. Namespace of the resource being referred to.
  21638. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21639. maxLength: 63
  21640. minLength: 1
  21641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21642. type: string
  21643. required:
  21644. - name
  21645. type: object
  21646. type: object
  21647. path:
  21648. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  21649. type: string
  21650. region:
  21651. description: AWS region
  21652. type: string
  21653. role:
  21654. description: This is the AWS role to be assumed before talking to vault
  21655. type: string
  21656. secretRef:
  21657. description: Specify credentials in a Secret object
  21658. properties:
  21659. accessKeyIDSecretRef:
  21660. description: The AccessKeyID is used for authentication
  21661. properties:
  21662. key:
  21663. description: |-
  21664. A key in the referenced Secret.
  21665. Some instances of this field may be defaulted, in others it may be required.
  21666. maxLength: 253
  21667. minLength: 1
  21668. pattern: ^[-._a-zA-Z0-9]+$
  21669. type: string
  21670. name:
  21671. description: The name of the Secret resource being referred to.
  21672. maxLength: 253
  21673. minLength: 1
  21674. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21675. type: string
  21676. namespace:
  21677. description: |-
  21678. The namespace of the Secret resource being referred to.
  21679. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21680. maxLength: 63
  21681. minLength: 1
  21682. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21683. type: string
  21684. type: object
  21685. secretAccessKeySecretRef:
  21686. description: The SecretAccessKey is used for authentication
  21687. properties:
  21688. key:
  21689. description: |-
  21690. A key in the referenced Secret.
  21691. Some instances of this field may be defaulted, in others it may be required.
  21692. maxLength: 253
  21693. minLength: 1
  21694. pattern: ^[-._a-zA-Z0-9]+$
  21695. type: string
  21696. name:
  21697. description: The name of the Secret resource being referred to.
  21698. maxLength: 253
  21699. minLength: 1
  21700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21701. type: string
  21702. namespace:
  21703. description: |-
  21704. The namespace of the Secret resource being referred to.
  21705. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21706. maxLength: 63
  21707. minLength: 1
  21708. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21709. type: string
  21710. type: object
  21711. sessionTokenSecretRef:
  21712. description: |-
  21713. The SessionToken used for authentication
  21714. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  21715. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  21716. properties:
  21717. key:
  21718. description: |-
  21719. A key in the referenced Secret.
  21720. Some instances of this field may be defaulted, in others it may be required.
  21721. maxLength: 253
  21722. minLength: 1
  21723. pattern: ^[-._a-zA-Z0-9]+$
  21724. type: string
  21725. name:
  21726. description: The name of the Secret resource being referred to.
  21727. maxLength: 253
  21728. minLength: 1
  21729. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21730. type: string
  21731. namespace:
  21732. description: |-
  21733. The namespace of the Secret resource being referred to.
  21734. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21735. maxLength: 63
  21736. minLength: 1
  21737. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21738. type: string
  21739. type: object
  21740. type: object
  21741. vaultAwsIamServerID:
  21742. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  21743. type: string
  21744. vaultRole:
  21745. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  21746. type: string
  21747. required:
  21748. - vaultRole
  21749. type: object
  21750. jwt:
  21751. description: |-
  21752. Jwt authenticates with Vault by passing role and JWT token using the
  21753. JWT/OIDC authentication method
  21754. properties:
  21755. kubernetesServiceAccountToken:
  21756. description: |-
  21757. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  21758. a token for with the `TokenRequest` API.
  21759. properties:
  21760. audiences:
  21761. description: |-
  21762. Optional audiences field that will be used to request a temporary Kubernetes service
  21763. account token for the service account referenced by `serviceAccountRef`.
  21764. Defaults to a single audience `vault` it not specified.
  21765. Deprecated: use serviceAccountRef.Audiences instead
  21766. items:
  21767. type: string
  21768. type: array
  21769. expirationSeconds:
  21770. description: |-
  21771. Optional expiration time in seconds that will be used to request a temporary
  21772. Kubernetes service account token for the service account referenced by
  21773. `serviceAccountRef`.
  21774. Deprecated: this will be removed in the future.
  21775. Defaults to 10 minutes.
  21776. format: int64
  21777. type: integer
  21778. serviceAccountRef:
  21779. description: Service account field containing the name of a kubernetes ServiceAccount.
  21780. properties:
  21781. audiences:
  21782. description: |-
  21783. Audience specifies the `aud` claim for the service account token
  21784. Some providers automatically extend the audience field based on well-known annotations for workload
  21785. identity (e.g. IRSA or GCP Workload Identity)
  21786. items:
  21787. type: string
  21788. type: array
  21789. name:
  21790. description: The name of the ServiceAccount resource being referred to.
  21791. maxLength: 253
  21792. minLength: 1
  21793. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21794. type: string
  21795. namespace:
  21796. description: |-
  21797. Namespace of the resource being referred to.
  21798. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21799. maxLength: 63
  21800. minLength: 1
  21801. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21802. type: string
  21803. required:
  21804. - name
  21805. type: object
  21806. required:
  21807. - serviceAccountRef
  21808. type: object
  21809. path:
  21810. default: jwt
  21811. description: |-
  21812. Path where the JWT authentication backend is mounted
  21813. in Vault, e.g: "jwt"
  21814. type: string
  21815. role:
  21816. description: |-
  21817. Role is a JWT role to authenticate using the JWT/OIDC Vault
  21818. authentication method
  21819. type: string
  21820. secretRef:
  21821. description: |-
  21822. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  21823. authenticate with Vault using the JWT/OIDC authentication method.
  21824. properties:
  21825. key:
  21826. description: |-
  21827. A key in the referenced Secret.
  21828. Some instances of this field may be defaulted, in others it may be required.
  21829. maxLength: 253
  21830. minLength: 1
  21831. pattern: ^[-._a-zA-Z0-9]+$
  21832. type: string
  21833. name:
  21834. description: The name of the Secret resource being referred to.
  21835. maxLength: 253
  21836. minLength: 1
  21837. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21838. type: string
  21839. namespace:
  21840. description: |-
  21841. The namespace of the Secret resource being referred to.
  21842. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21843. maxLength: 63
  21844. minLength: 1
  21845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21846. type: string
  21847. type: object
  21848. required:
  21849. - path
  21850. type: object
  21851. kubernetes:
  21852. description: |-
  21853. Kubernetes authenticates with Vault by passing the ServiceAccount
  21854. token stored in the named Secret resource to the Vault server.
  21855. properties:
  21856. mountPath:
  21857. default: kubernetes
  21858. description: |-
  21859. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  21860. "kubernetes"
  21861. type: string
  21862. role:
  21863. description: |-
  21864. A required field containing the Vault Role to assume. A Role binds a
  21865. Kubernetes ServiceAccount with a set of Vault policies.
  21866. type: string
  21867. secretRef:
  21868. description: |-
  21869. Optional secret field containing a Kubernetes ServiceAccount JWT used
  21870. for authenticating with Vault. If a name is specified without a key,
  21871. `token` is the default. If one is not specified, the one bound to
  21872. the controller will be used.
  21873. properties:
  21874. key:
  21875. description: |-
  21876. A key in the referenced Secret.
  21877. Some instances of this field may be defaulted, in others it may be required.
  21878. maxLength: 253
  21879. minLength: 1
  21880. pattern: ^[-._a-zA-Z0-9]+$
  21881. type: string
  21882. name:
  21883. description: The name of the Secret resource being referred to.
  21884. maxLength: 253
  21885. minLength: 1
  21886. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21887. type: string
  21888. namespace:
  21889. description: |-
  21890. The namespace of the Secret resource being referred to.
  21891. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21892. maxLength: 63
  21893. minLength: 1
  21894. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21895. type: string
  21896. type: object
  21897. serviceAccountRef:
  21898. description: |-
  21899. Optional service account field containing the name of a kubernetes ServiceAccount.
  21900. If the service account is specified, the service account secret token JWT will be used
  21901. for authenticating with Vault. If the service account selector is not supplied,
  21902. the secretRef will be used instead.
  21903. properties:
  21904. audiences:
  21905. description: |-
  21906. Audience specifies the `aud` claim for the service account token
  21907. Some providers automatically extend the audience field based on well-known annotations for workload
  21908. identity (e.g. IRSA or GCP Workload Identity)
  21909. items:
  21910. type: string
  21911. type: array
  21912. name:
  21913. description: The name of the ServiceAccount resource being referred to.
  21914. maxLength: 253
  21915. minLength: 1
  21916. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21917. type: string
  21918. namespace:
  21919. description: |-
  21920. Namespace of the resource being referred to.
  21921. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21922. maxLength: 63
  21923. minLength: 1
  21924. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21925. type: string
  21926. required:
  21927. - name
  21928. type: object
  21929. required:
  21930. - mountPath
  21931. - role
  21932. type: object
  21933. ldap:
  21934. description: |-
  21935. Ldap authenticates with Vault by passing username/password pair using
  21936. the LDAP authentication method
  21937. properties:
  21938. path:
  21939. default: ldap
  21940. description: |-
  21941. Path where the LDAP authentication backend is mounted
  21942. in Vault, e.g: "ldap"
  21943. type: string
  21944. secretRef:
  21945. description: |-
  21946. SecretRef to a key in a Secret resource containing password for the LDAP
  21947. user used to authenticate with Vault using the LDAP authentication
  21948. method
  21949. properties:
  21950. key:
  21951. description: |-
  21952. A key in the referenced Secret.
  21953. Some instances of this field may be defaulted, in others it may be required.
  21954. maxLength: 253
  21955. minLength: 1
  21956. pattern: ^[-._a-zA-Z0-9]+$
  21957. type: string
  21958. name:
  21959. description: The name of the Secret resource being referred to.
  21960. maxLength: 253
  21961. minLength: 1
  21962. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21963. type: string
  21964. namespace:
  21965. description: |-
  21966. The namespace of the Secret resource being referred to.
  21967. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21968. maxLength: 63
  21969. minLength: 1
  21970. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21971. type: string
  21972. type: object
  21973. username:
  21974. description: |-
  21975. Username is an LDAP username used to authenticate using the LDAP Vault
  21976. authentication method
  21977. type: string
  21978. required:
  21979. - path
  21980. - username
  21981. type: object
  21982. namespace:
  21983. description: |-
  21984. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  21985. Namespaces is a set of features within Vault Enterprise that allows
  21986. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  21987. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  21988. This will default to Vault.Namespace field if set, or empty otherwise
  21989. type: string
  21990. tokenSecretRef:
  21991. description: TokenSecretRef authenticates with Vault by presenting a token.
  21992. properties:
  21993. key:
  21994. description: |-
  21995. A key in the referenced Secret.
  21996. Some instances of this field may be defaulted, in others it may be required.
  21997. maxLength: 253
  21998. minLength: 1
  21999. pattern: ^[-._a-zA-Z0-9]+$
  22000. type: string
  22001. name:
  22002. description: The name of the Secret resource being referred to.
  22003. maxLength: 253
  22004. minLength: 1
  22005. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22006. type: string
  22007. namespace:
  22008. description: |-
  22009. The namespace of the Secret resource being referred to.
  22010. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22011. maxLength: 63
  22012. minLength: 1
  22013. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22014. type: string
  22015. type: object
  22016. userPass:
  22017. description: UserPass authenticates with Vault by passing username/password pair
  22018. properties:
  22019. path:
  22020. default: userpass
  22021. description: |-
  22022. Path where the UserPassword authentication backend is mounted
  22023. in Vault, e.g: "userpass"
  22024. type: string
  22025. secretRef:
  22026. description: |-
  22027. SecretRef to a key in a Secret resource containing password for the
  22028. user used to authenticate with Vault using the UserPass authentication
  22029. method
  22030. properties:
  22031. key:
  22032. description: |-
  22033. A key in the referenced Secret.
  22034. Some instances of this field may be defaulted, in others it may be required.
  22035. maxLength: 253
  22036. minLength: 1
  22037. pattern: ^[-._a-zA-Z0-9]+$
  22038. type: string
  22039. name:
  22040. description: The name of the Secret resource being referred to.
  22041. maxLength: 253
  22042. minLength: 1
  22043. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22044. type: string
  22045. namespace:
  22046. description: |-
  22047. The namespace of the Secret resource being referred to.
  22048. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22049. maxLength: 63
  22050. minLength: 1
  22051. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22052. type: string
  22053. type: object
  22054. username:
  22055. description: |-
  22056. Username is a username used to authenticate using the UserPass Vault
  22057. authentication method
  22058. type: string
  22059. required:
  22060. - path
  22061. - username
  22062. type: object
  22063. type: object
  22064. caBundle:
  22065. description: |-
  22066. PEM encoded CA bundle used to validate Vault server certificate. Only used
  22067. if the Server URL is using HTTPS protocol. This parameter is ignored for
  22068. plain HTTP protocol connection. If not set the system root certificates
  22069. are used to validate the TLS connection.
  22070. format: byte
  22071. type: string
  22072. caProvider:
  22073. description: The provider for the CA bundle to use to validate Vault server certificate.
  22074. properties:
  22075. key:
  22076. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22077. maxLength: 253
  22078. minLength: 1
  22079. pattern: ^[-._a-zA-Z0-9]+$
  22080. type: string
  22081. name:
  22082. description: The name of the object located at the provider type.
  22083. maxLength: 253
  22084. minLength: 1
  22085. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22086. type: string
  22087. namespace:
  22088. description: |-
  22089. The namespace the Provider type is in.
  22090. Can only be defined when used in a ClusterSecretStore.
  22091. maxLength: 63
  22092. minLength: 1
  22093. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22094. type: string
  22095. type:
  22096. description: The type of provider to use such as "Secret", or "ConfigMap".
  22097. enum:
  22098. - Secret
  22099. - ConfigMap
  22100. type: string
  22101. required:
  22102. - name
  22103. - type
  22104. type: object
  22105. checkAndSet:
  22106. description: |-
  22107. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  22108. Only applies to Vault KV v2 stores. When enabled, write operations must include
  22109. the current version of the secret to prevent unintentional overwrites.
  22110. properties:
  22111. required:
  22112. description: |-
  22113. Required when true, all write operations must include a check-and-set parameter.
  22114. This helps prevent unintentional overwrites of secrets.
  22115. type: boolean
  22116. type: object
  22117. forwardInconsistent:
  22118. description: |-
  22119. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  22120. leader instead of simply retrying within a loop. This can increase performance if
  22121. the option is enabled serverside.
  22122. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  22123. type: boolean
  22124. headers:
  22125. additionalProperties:
  22126. type: string
  22127. description: Headers to be added in Vault request
  22128. type: object
  22129. namespace:
  22130. description: |-
  22131. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  22132. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  22133. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  22134. type: string
  22135. path:
  22136. description: |-
  22137. Path is the mount path of the Vault KV backend endpoint, e.g:
  22138. "secret". The v2 KV secret engine version specific "/data" path suffix
  22139. for fetching secrets from Vault is optional and will be appended
  22140. if not present in specified path.
  22141. type: string
  22142. readYourWrites:
  22143. description: |-
  22144. ReadYourWrites ensures isolated read-after-write semantics by
  22145. providing discovered cluster replication states in each request.
  22146. More information about eventual consistency in Vault can be found here
  22147. https://www.vaultproject.io/docs/enterprise/consistency
  22148. type: boolean
  22149. server:
  22150. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  22151. type: string
  22152. tls:
  22153. description: |-
  22154. The configuration used for client side related TLS communication, when the Vault server
  22155. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  22156. This parameter is ignored for plain HTTP protocol connection.
  22157. It's worth noting this configuration is different from the "TLS certificates auth method",
  22158. which is available under the `auth.cert` section.
  22159. properties:
  22160. certSecretRef:
  22161. description: |-
  22162. CertSecretRef is a certificate added to the transport layer
  22163. when communicating with the Vault server.
  22164. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  22165. properties:
  22166. key:
  22167. description: |-
  22168. A key in the referenced Secret.
  22169. Some instances of this field may be defaulted, in others it may be required.
  22170. maxLength: 253
  22171. minLength: 1
  22172. pattern: ^[-._a-zA-Z0-9]+$
  22173. type: string
  22174. name:
  22175. description: The name of the Secret resource being referred to.
  22176. maxLength: 253
  22177. minLength: 1
  22178. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22179. type: string
  22180. namespace:
  22181. description: |-
  22182. The namespace of the Secret resource being referred to.
  22183. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22184. maxLength: 63
  22185. minLength: 1
  22186. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22187. type: string
  22188. type: object
  22189. keySecretRef:
  22190. description: |-
  22191. KeySecretRef to a key in a Secret resource containing client private key
  22192. added to the transport layer when communicating with the Vault server.
  22193. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  22194. properties:
  22195. key:
  22196. description: |-
  22197. A key in the referenced Secret.
  22198. Some instances of this field may be defaulted, in others it may be required.
  22199. maxLength: 253
  22200. minLength: 1
  22201. pattern: ^[-._a-zA-Z0-9]+$
  22202. type: string
  22203. name:
  22204. description: The name of the Secret resource being referred to.
  22205. maxLength: 253
  22206. minLength: 1
  22207. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22208. type: string
  22209. namespace:
  22210. description: |-
  22211. The namespace of the Secret resource being referred to.
  22212. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22213. maxLength: 63
  22214. minLength: 1
  22215. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22216. type: string
  22217. type: object
  22218. type: object
  22219. version:
  22220. default: v2
  22221. description: |-
  22222. Version is the Vault KV secret engine version. This can be either "v1" or
  22223. "v2". Version defaults to "v2".
  22224. enum:
  22225. - v1
  22226. - v2
  22227. type: string
  22228. required:
  22229. - server
  22230. type: object
  22231. volcengine:
  22232. description: Volcengine configures this store to sync secrets using the Volcengine provider
  22233. properties:
  22234. auth:
  22235. description: |-
  22236. Auth defines the authentication method to use.
  22237. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  22238. properties:
  22239. secretRef:
  22240. description: |-
  22241. SecretRef defines the static credentials to use for authentication.
  22242. If not set, IRSA is used.
  22243. properties:
  22244. accessKeyID:
  22245. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  22246. properties:
  22247. key:
  22248. description: |-
  22249. A key in the referenced Secret.
  22250. Some instances of this field may be defaulted, in others it may be required.
  22251. maxLength: 253
  22252. minLength: 1
  22253. pattern: ^[-._a-zA-Z0-9]+$
  22254. type: string
  22255. name:
  22256. description: The name of the Secret resource being referred to.
  22257. maxLength: 253
  22258. minLength: 1
  22259. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22260. type: string
  22261. namespace:
  22262. description: |-
  22263. The namespace of the Secret resource being referred to.
  22264. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22265. maxLength: 63
  22266. minLength: 1
  22267. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22268. type: string
  22269. type: object
  22270. secretAccessKey:
  22271. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  22272. properties:
  22273. key:
  22274. description: |-
  22275. A key in the referenced Secret.
  22276. Some instances of this field may be defaulted, in others it may be required.
  22277. maxLength: 253
  22278. minLength: 1
  22279. pattern: ^[-._a-zA-Z0-9]+$
  22280. type: string
  22281. name:
  22282. description: The name of the Secret resource being referred to.
  22283. maxLength: 253
  22284. minLength: 1
  22285. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22286. type: string
  22287. namespace:
  22288. description: |-
  22289. The namespace of the Secret resource being referred to.
  22290. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22291. maxLength: 63
  22292. minLength: 1
  22293. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22294. type: string
  22295. type: object
  22296. token:
  22297. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  22298. properties:
  22299. key:
  22300. description: |-
  22301. A key in the referenced Secret.
  22302. Some instances of this field may be defaulted, in others it may be required.
  22303. maxLength: 253
  22304. minLength: 1
  22305. pattern: ^[-._a-zA-Z0-9]+$
  22306. type: string
  22307. name:
  22308. description: The name of the Secret resource being referred to.
  22309. maxLength: 253
  22310. minLength: 1
  22311. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22312. type: string
  22313. namespace:
  22314. description: |-
  22315. The namespace of the Secret resource being referred to.
  22316. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22317. maxLength: 63
  22318. minLength: 1
  22319. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22320. type: string
  22321. type: object
  22322. required:
  22323. - accessKeyID
  22324. - secretAccessKey
  22325. type: object
  22326. type: object
  22327. region:
  22328. description: Region specifies the Volcengine region to connect to.
  22329. type: string
  22330. required:
  22331. - region
  22332. type: object
  22333. webhook:
  22334. description: Webhook configures this store to sync secrets using a generic templated webhook
  22335. properties:
  22336. auth:
  22337. description: Auth specifies a authorization protocol. Only one protocol may be set.
  22338. maxProperties: 1
  22339. minProperties: 1
  22340. properties:
  22341. ntlm:
  22342. description: NTLMProtocol configures the store to use NTLM for auth
  22343. properties:
  22344. passwordSecret:
  22345. description: |-
  22346. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22347. In some instances, `key` is a required field.
  22348. properties:
  22349. key:
  22350. description: |-
  22351. A key in the referenced Secret.
  22352. Some instances of this field may be defaulted, in others it may be required.
  22353. maxLength: 253
  22354. minLength: 1
  22355. pattern: ^[-._a-zA-Z0-9]+$
  22356. type: string
  22357. name:
  22358. description: The name of the Secret resource being referred to.
  22359. maxLength: 253
  22360. minLength: 1
  22361. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22362. type: string
  22363. namespace:
  22364. description: |-
  22365. The namespace of the Secret resource being referred to.
  22366. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22367. maxLength: 63
  22368. minLength: 1
  22369. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22370. type: string
  22371. type: object
  22372. usernameSecret:
  22373. description: |-
  22374. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22375. In some instances, `key` is a required field.
  22376. properties:
  22377. key:
  22378. description: |-
  22379. A key in the referenced Secret.
  22380. Some instances of this field may be defaulted, in others it may be required.
  22381. maxLength: 253
  22382. minLength: 1
  22383. pattern: ^[-._a-zA-Z0-9]+$
  22384. type: string
  22385. name:
  22386. description: The name of the Secret resource being referred to.
  22387. maxLength: 253
  22388. minLength: 1
  22389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22390. type: string
  22391. namespace:
  22392. description: |-
  22393. The namespace of the Secret resource being referred to.
  22394. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22395. maxLength: 63
  22396. minLength: 1
  22397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22398. type: string
  22399. type: object
  22400. required:
  22401. - passwordSecret
  22402. - usernameSecret
  22403. type: object
  22404. type: object
  22405. body:
  22406. description: Body
  22407. type: string
  22408. caBundle:
  22409. description: |-
  22410. PEM encoded CA bundle used to validate webhook server certificate. Only used
  22411. if the Server URL is using HTTPS protocol. This parameter is ignored for
  22412. plain HTTP protocol connection. If not set the system root certificates
  22413. are used to validate the TLS connection.
  22414. format: byte
  22415. type: string
  22416. caProvider:
  22417. description: The provider for the CA bundle to use to validate webhook server certificate.
  22418. properties:
  22419. key:
  22420. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22421. maxLength: 253
  22422. minLength: 1
  22423. pattern: ^[-._a-zA-Z0-9]+$
  22424. type: string
  22425. name:
  22426. description: The name of the object located at the provider type.
  22427. maxLength: 253
  22428. minLength: 1
  22429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22430. type: string
  22431. namespace:
  22432. description: The namespace the Provider type is in.
  22433. maxLength: 63
  22434. minLength: 1
  22435. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22436. type: string
  22437. type:
  22438. description: The type of provider to use such as "Secret", or "ConfigMap".
  22439. enum:
  22440. - Secret
  22441. - ConfigMap
  22442. type: string
  22443. required:
  22444. - name
  22445. - type
  22446. type: object
  22447. headers:
  22448. additionalProperties:
  22449. type: string
  22450. description: Headers
  22451. type: object
  22452. method:
  22453. description: Webhook Method
  22454. type: string
  22455. result:
  22456. description: Result formatting
  22457. properties:
  22458. jsonPath:
  22459. description: Json path of return value
  22460. type: string
  22461. type: object
  22462. secrets:
  22463. description: |-
  22464. Secrets to fill in templates
  22465. These secrets will be passed to the templating function as key value pairs under the given name
  22466. items:
  22467. description: WebhookSecret defines a secret that will be passed to the webhook request.
  22468. properties:
  22469. name:
  22470. description: Name of this secret in templates
  22471. type: string
  22472. secretRef:
  22473. description: Secret ref to fill in credentials
  22474. properties:
  22475. key:
  22476. description: |-
  22477. A key in the referenced Secret.
  22478. Some instances of this field may be defaulted, in others it may be required.
  22479. maxLength: 253
  22480. minLength: 1
  22481. pattern: ^[-._a-zA-Z0-9]+$
  22482. type: string
  22483. name:
  22484. description: The name of the Secret resource being referred to.
  22485. maxLength: 253
  22486. minLength: 1
  22487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22488. type: string
  22489. namespace:
  22490. description: |-
  22491. The namespace of the Secret resource being referred to.
  22492. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22493. maxLength: 63
  22494. minLength: 1
  22495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22496. type: string
  22497. type: object
  22498. required:
  22499. - name
  22500. - secretRef
  22501. type: object
  22502. type: array
  22503. timeout:
  22504. description: Timeout
  22505. type: string
  22506. url:
  22507. description: Webhook url to call
  22508. type: string
  22509. required:
  22510. - url
  22511. type: object
  22512. yandexcertificatemanager:
  22513. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  22514. properties:
  22515. apiEndpoint:
  22516. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  22517. type: string
  22518. auth:
  22519. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  22520. properties:
  22521. authorizedKeySecretRef:
  22522. description: The authorized key used for authentication
  22523. properties:
  22524. key:
  22525. description: |-
  22526. A key in the referenced Secret.
  22527. Some instances of this field may be defaulted, in others it may be required.
  22528. maxLength: 253
  22529. minLength: 1
  22530. pattern: ^[-._a-zA-Z0-9]+$
  22531. type: string
  22532. name:
  22533. description: The name of the Secret resource being referred to.
  22534. maxLength: 253
  22535. minLength: 1
  22536. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22537. type: string
  22538. namespace:
  22539. description: |-
  22540. The namespace of the Secret resource being referred to.
  22541. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22542. maxLength: 63
  22543. minLength: 1
  22544. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22545. type: string
  22546. type: object
  22547. type: object
  22548. caProvider:
  22549. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  22550. properties:
  22551. certSecretRef:
  22552. description: |-
  22553. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22554. In some instances, `key` is a required field.
  22555. properties:
  22556. key:
  22557. description: |-
  22558. A key in the referenced Secret.
  22559. Some instances of this field may be defaulted, in others it may be required.
  22560. maxLength: 253
  22561. minLength: 1
  22562. pattern: ^[-._a-zA-Z0-9]+$
  22563. type: string
  22564. name:
  22565. description: The name of the Secret resource being referred to.
  22566. maxLength: 253
  22567. minLength: 1
  22568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22569. type: string
  22570. namespace:
  22571. description: |-
  22572. The namespace of the Secret resource being referred to.
  22573. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22574. maxLength: 63
  22575. minLength: 1
  22576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22577. type: string
  22578. type: object
  22579. type: object
  22580. fetching:
  22581. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  22582. maxProperties: 1
  22583. minProperties: 1
  22584. properties:
  22585. byID:
  22586. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  22587. type: object
  22588. byName:
  22589. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  22590. properties:
  22591. folderID:
  22592. description: The folder to fetch secrets from
  22593. type: string
  22594. required:
  22595. - folderID
  22596. type: object
  22597. type: object
  22598. required:
  22599. - auth
  22600. type: object
  22601. yandexlockbox:
  22602. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  22603. properties:
  22604. apiEndpoint:
  22605. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  22606. type: string
  22607. auth:
  22608. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  22609. properties:
  22610. authorizedKeySecretRef:
  22611. description: The authorized key used for authentication
  22612. properties:
  22613. key:
  22614. description: |-
  22615. A key in the referenced Secret.
  22616. Some instances of this field may be defaulted, in others it may be required.
  22617. maxLength: 253
  22618. minLength: 1
  22619. pattern: ^[-._a-zA-Z0-9]+$
  22620. type: string
  22621. name:
  22622. description: The name of the Secret resource being referred to.
  22623. maxLength: 253
  22624. minLength: 1
  22625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22626. type: string
  22627. namespace:
  22628. description: |-
  22629. The namespace of the Secret resource being referred to.
  22630. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22631. maxLength: 63
  22632. minLength: 1
  22633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22634. type: string
  22635. type: object
  22636. type: object
  22637. caProvider:
  22638. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  22639. properties:
  22640. certSecretRef:
  22641. description: |-
  22642. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22643. In some instances, `key` is a required field.
  22644. properties:
  22645. key:
  22646. description: |-
  22647. A key in the referenced Secret.
  22648. Some instances of this field may be defaulted, in others it may be required.
  22649. maxLength: 253
  22650. minLength: 1
  22651. pattern: ^[-._a-zA-Z0-9]+$
  22652. type: string
  22653. name:
  22654. description: The name of the Secret resource being referred to.
  22655. maxLength: 253
  22656. minLength: 1
  22657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22658. type: string
  22659. namespace:
  22660. description: |-
  22661. The namespace of the Secret resource being referred to.
  22662. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22663. maxLength: 63
  22664. minLength: 1
  22665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22666. type: string
  22667. type: object
  22668. type: object
  22669. fetching:
  22670. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  22671. maxProperties: 1
  22672. minProperties: 1
  22673. properties:
  22674. byID:
  22675. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  22676. type: object
  22677. byName:
  22678. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  22679. properties:
  22680. folderID:
  22681. description: The folder to fetch secrets from
  22682. type: string
  22683. required:
  22684. - folderID
  22685. type: object
  22686. type: object
  22687. required:
  22688. - auth
  22689. type: object
  22690. type: object
  22691. refreshInterval:
  22692. anyOf:
  22693. - type: integer
  22694. - type: string
  22695. description: |-
  22696. Used to configure store refresh interval. Accepts either an integer number
  22697. of seconds (legacy) or a Go duration string such as "1h" or "5m". Empty or
  22698. 0 will default to the controller config.
  22699. x-kubernetes-int-or-string: true
  22700. retrySettings:
  22701. description: Used to configure HTTP retries on failures.
  22702. properties:
  22703. maxRetries:
  22704. format: int32
  22705. type: integer
  22706. retryInterval:
  22707. type: string
  22708. type: object
  22709. required:
  22710. - provider
  22711. type: object
  22712. status:
  22713. description: SecretStoreStatus defines the observed state of the SecretStore.
  22714. properties:
  22715. capabilities:
  22716. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  22717. type: string
  22718. conditions:
  22719. items:
  22720. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  22721. properties:
  22722. lastTransitionTime:
  22723. format: date-time
  22724. type: string
  22725. message:
  22726. type: string
  22727. reason:
  22728. type: string
  22729. status:
  22730. type: string
  22731. type:
  22732. description: SecretStoreConditionType represents the condition of the SecretStore.
  22733. type: string
  22734. required:
  22735. - status
  22736. - type
  22737. type: object
  22738. type: array
  22739. type: object
  22740. type: object
  22741. served: true
  22742. storage: true
  22743. subresources:
  22744. status: {}
  22745. - additionalPrinterColumns:
  22746. - jsonPath: .metadata.creationTimestamp
  22747. name: AGE
  22748. type: date
  22749. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  22750. name: Status
  22751. type: string
  22752. - jsonPath: .status.capabilities
  22753. name: Capabilities
  22754. type: string
  22755. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  22756. name: Ready
  22757. type: string
  22758. deprecated: true
  22759. name: v1beta1
  22760. schema:
  22761. openAPIV3Schema:
  22762. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  22763. properties:
  22764. apiVersion:
  22765. description: |-
  22766. APIVersion defines the versioned schema of this representation of an object.
  22767. Servers should convert recognized schemas to the latest internal value, and
  22768. may reject unrecognized values.
  22769. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  22770. type: string
  22771. kind:
  22772. description: |-
  22773. Kind is a string value representing the REST resource this object represents.
  22774. Servers may infer this from the endpoint the client submits requests to.
  22775. Cannot be updated.
  22776. In CamelCase.
  22777. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  22778. type: string
  22779. metadata:
  22780. type: object
  22781. spec:
  22782. description: SecretStoreSpec defines the desired state of SecretStore.
  22783. properties:
  22784. conditions:
  22785. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  22786. items:
  22787. description: |-
  22788. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  22789. for a ClusterSecretStore instance.
  22790. properties:
  22791. namespaceRegexes:
  22792. description: Choose namespaces by using regex matching
  22793. items:
  22794. type: string
  22795. type: array
  22796. namespaceSelector:
  22797. description: Choose namespace using a labelSelector
  22798. properties:
  22799. matchExpressions:
  22800. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  22801. items:
  22802. description: |-
  22803. A label selector requirement is a selector that contains values, a key, and an operator that
  22804. relates the key and values.
  22805. properties:
  22806. key:
  22807. description: key is the label key that the selector applies to.
  22808. type: string
  22809. operator:
  22810. description: |-
  22811. operator represents a key's relationship to a set of values.
  22812. Valid operators are In, NotIn, Exists and DoesNotExist.
  22813. type: string
  22814. values:
  22815. description: |-
  22816. values is an array of string values. If the operator is In or NotIn,
  22817. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  22818. the values array must be empty. This array is replaced during a strategic
  22819. merge patch.
  22820. items:
  22821. type: string
  22822. type: array
  22823. x-kubernetes-list-type: atomic
  22824. required:
  22825. - key
  22826. - operator
  22827. type: object
  22828. type: array
  22829. x-kubernetes-list-type: atomic
  22830. matchLabels:
  22831. additionalProperties:
  22832. type: string
  22833. description: |-
  22834. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  22835. map is equivalent to an element of matchExpressions, whose key field is "key", the
  22836. operator is "In", and the values array contains only "value". The requirements are ANDed.
  22837. type: object
  22838. type: object
  22839. x-kubernetes-map-type: atomic
  22840. namespaces:
  22841. description: Choose namespaces by name
  22842. items:
  22843. maxLength: 63
  22844. minLength: 1
  22845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22846. type: string
  22847. type: array
  22848. type: object
  22849. type: array
  22850. controller:
  22851. description: |-
  22852. Used to select the correct ESO controller (think: ingress.ingressClassName)
  22853. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  22854. type: string
  22855. provider:
  22856. description: Used to configure the provider. Only one provider may be set
  22857. maxProperties: 1
  22858. minProperties: 1
  22859. properties:
  22860. akeyless:
  22861. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  22862. properties:
  22863. akeylessGWApiURL:
  22864. description: Akeyless GW API Url from which the secrets to be fetched from.
  22865. type: string
  22866. authSecretRef:
  22867. description: Auth configures how the operator authenticates with Akeyless.
  22868. properties:
  22869. kubernetesAuth:
  22870. description: |-
  22871. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  22872. token stored in the named Secret resource.
  22873. properties:
  22874. accessID:
  22875. description: the Akeyless Kubernetes auth-method access-id
  22876. type: string
  22877. k8sConfName:
  22878. description: Kubernetes-auth configuration name in Akeyless-Gateway
  22879. type: string
  22880. secretRef:
  22881. description: |-
  22882. Optional secret field containing a Kubernetes ServiceAccount JWT used
  22883. for authenticating with Akeyless. If a name is specified without a key,
  22884. `token` is the default. If one is not specified, the one bound to
  22885. the controller will be used.
  22886. properties:
  22887. key:
  22888. description: |-
  22889. A key in the referenced Secret.
  22890. Some instances of this field may be defaulted, in others it may be required.
  22891. maxLength: 253
  22892. minLength: 1
  22893. pattern: ^[-._a-zA-Z0-9]+$
  22894. type: string
  22895. name:
  22896. description: The name of the Secret resource being referred to.
  22897. maxLength: 253
  22898. minLength: 1
  22899. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22900. type: string
  22901. namespace:
  22902. description: |-
  22903. The namespace of the Secret resource being referred to.
  22904. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22905. maxLength: 63
  22906. minLength: 1
  22907. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22908. type: string
  22909. type: object
  22910. serviceAccountRef:
  22911. description: |-
  22912. Optional service account field containing the name of a kubernetes ServiceAccount.
  22913. If the service account is specified, the service account secret token JWT will be used
  22914. for authenticating with Akeyless. If the service account selector is not supplied,
  22915. the secretRef will be used instead.
  22916. properties:
  22917. audiences:
  22918. description: |-
  22919. Audience specifies the `aud` claim for the service account token
  22920. Some providers automatically extend the audience field based on well-known annotations for workload
  22921. identity (e.g. IRSA or GCP Workload Identity)
  22922. items:
  22923. type: string
  22924. type: array
  22925. name:
  22926. description: The name of the ServiceAccount resource being referred to.
  22927. maxLength: 253
  22928. minLength: 1
  22929. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22930. type: string
  22931. namespace:
  22932. description: |-
  22933. Namespace of the resource being referred to.
  22934. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22935. maxLength: 63
  22936. minLength: 1
  22937. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22938. type: string
  22939. required:
  22940. - name
  22941. type: object
  22942. required:
  22943. - accessID
  22944. - k8sConfName
  22945. type: object
  22946. secretRef:
  22947. description: |-
  22948. Reference to a Secret that contains the details
  22949. to authenticate with Akeyless.
  22950. properties:
  22951. accessID:
  22952. description: The SecretAccessID is used for authentication
  22953. properties:
  22954. key:
  22955. description: |-
  22956. A key in the referenced Secret.
  22957. Some instances of this field may be defaulted, in others it may be required.
  22958. maxLength: 253
  22959. minLength: 1
  22960. pattern: ^[-._a-zA-Z0-9]+$
  22961. type: string
  22962. name:
  22963. description: The name of the Secret resource being referred to.
  22964. maxLength: 253
  22965. minLength: 1
  22966. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22967. type: string
  22968. namespace:
  22969. description: |-
  22970. The namespace of the Secret resource being referred to.
  22971. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22972. maxLength: 63
  22973. minLength: 1
  22974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22975. type: string
  22976. type: object
  22977. accessType:
  22978. description: |-
  22979. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22980. In some instances, `key` is a required field.
  22981. properties:
  22982. key:
  22983. description: |-
  22984. A key in the referenced Secret.
  22985. Some instances of this field may be defaulted, in others it may be required.
  22986. maxLength: 253
  22987. minLength: 1
  22988. pattern: ^[-._a-zA-Z0-9]+$
  22989. type: string
  22990. name:
  22991. description: The name of the Secret resource being referred to.
  22992. maxLength: 253
  22993. minLength: 1
  22994. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22995. type: string
  22996. namespace:
  22997. description: |-
  22998. The namespace of the Secret resource being referred to.
  22999. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23000. maxLength: 63
  23001. minLength: 1
  23002. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23003. type: string
  23004. type: object
  23005. accessTypeParam:
  23006. description: |-
  23007. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23008. In some instances, `key` is a required field.
  23009. properties:
  23010. key:
  23011. description: |-
  23012. A key in the referenced Secret.
  23013. Some instances of this field may be defaulted, in others it may be required.
  23014. maxLength: 253
  23015. minLength: 1
  23016. pattern: ^[-._a-zA-Z0-9]+$
  23017. type: string
  23018. name:
  23019. description: The name of the Secret resource being referred to.
  23020. maxLength: 253
  23021. minLength: 1
  23022. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23023. type: string
  23024. namespace:
  23025. description: |-
  23026. The namespace of the Secret resource being referred to.
  23027. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23028. maxLength: 63
  23029. minLength: 1
  23030. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23031. type: string
  23032. type: object
  23033. type: object
  23034. type: object
  23035. caBundle:
  23036. description: |-
  23037. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  23038. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  23039. are used to validate the TLS connection.
  23040. format: byte
  23041. type: string
  23042. caProvider:
  23043. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  23044. properties:
  23045. key:
  23046. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23047. maxLength: 253
  23048. minLength: 1
  23049. pattern: ^[-._a-zA-Z0-9]+$
  23050. type: string
  23051. name:
  23052. description: The name of the object located at the provider type.
  23053. maxLength: 253
  23054. minLength: 1
  23055. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23056. type: string
  23057. namespace:
  23058. description: |-
  23059. The namespace the Provider type is in.
  23060. Can only be defined when used in a ClusterSecretStore.
  23061. maxLength: 63
  23062. minLength: 1
  23063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23064. type: string
  23065. type:
  23066. description: The type of provider to use such as "Secret", or "ConfigMap".
  23067. enum:
  23068. - Secret
  23069. - ConfigMap
  23070. type: string
  23071. required:
  23072. - name
  23073. - type
  23074. type: object
  23075. required:
  23076. - akeylessGWApiURL
  23077. - authSecretRef
  23078. type: object
  23079. alibaba:
  23080. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  23081. properties:
  23082. auth:
  23083. description: AlibabaAuth contains a secretRef for credentials.
  23084. properties:
  23085. rrsa:
  23086. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  23087. properties:
  23088. oidcProviderArn:
  23089. type: string
  23090. oidcTokenFilePath:
  23091. type: string
  23092. roleArn:
  23093. type: string
  23094. sessionName:
  23095. type: string
  23096. required:
  23097. - oidcProviderArn
  23098. - oidcTokenFilePath
  23099. - roleArn
  23100. - sessionName
  23101. type: object
  23102. secretRef:
  23103. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  23104. properties:
  23105. accessKeyIDSecretRef:
  23106. description: The AccessKeyID is used for authentication
  23107. properties:
  23108. key:
  23109. description: |-
  23110. A key in the referenced Secret.
  23111. Some instances of this field may be defaulted, in others it may be required.
  23112. maxLength: 253
  23113. minLength: 1
  23114. pattern: ^[-._a-zA-Z0-9]+$
  23115. type: string
  23116. name:
  23117. description: The name of the Secret resource being referred to.
  23118. maxLength: 253
  23119. minLength: 1
  23120. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23121. type: string
  23122. namespace:
  23123. description: |-
  23124. The namespace of the Secret resource being referred to.
  23125. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23126. maxLength: 63
  23127. minLength: 1
  23128. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23129. type: string
  23130. type: object
  23131. accessKeySecretSecretRef:
  23132. description: The AccessKeySecret is used for authentication
  23133. properties:
  23134. key:
  23135. description: |-
  23136. A key in the referenced Secret.
  23137. Some instances of this field may be defaulted, in others it may be required.
  23138. maxLength: 253
  23139. minLength: 1
  23140. pattern: ^[-._a-zA-Z0-9]+$
  23141. type: string
  23142. name:
  23143. description: The name of the Secret resource being referred to.
  23144. maxLength: 253
  23145. minLength: 1
  23146. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23147. type: string
  23148. namespace:
  23149. description: |-
  23150. The namespace of the Secret resource being referred to.
  23151. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23152. maxLength: 63
  23153. minLength: 1
  23154. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23155. type: string
  23156. type: object
  23157. required:
  23158. - accessKeyIDSecretRef
  23159. - accessKeySecretSecretRef
  23160. type: object
  23161. type: object
  23162. regionID:
  23163. description: Alibaba Region to be used for the provider
  23164. type: string
  23165. required:
  23166. - auth
  23167. - regionID
  23168. type: object
  23169. aws:
  23170. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  23171. properties:
  23172. additionalRoles:
  23173. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  23174. items:
  23175. type: string
  23176. type: array
  23177. auth:
  23178. description: |-
  23179. Auth defines the information necessary to authenticate against AWS
  23180. if not set aws sdk will infer credentials from your environment
  23181. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  23182. properties:
  23183. jwt:
  23184. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  23185. properties:
  23186. serviceAccountRef:
  23187. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  23188. properties:
  23189. audiences:
  23190. description: |-
  23191. Audience specifies the `aud` claim for the service account token
  23192. Some providers automatically extend the audience field based on well-known annotations for workload
  23193. identity (e.g. IRSA or GCP Workload Identity)
  23194. items:
  23195. type: string
  23196. type: array
  23197. name:
  23198. description: The name of the ServiceAccount resource being referred to.
  23199. maxLength: 253
  23200. minLength: 1
  23201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23202. type: string
  23203. namespace:
  23204. description: |-
  23205. Namespace of the resource being referred to.
  23206. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23207. maxLength: 63
  23208. minLength: 1
  23209. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23210. type: string
  23211. required:
  23212. - name
  23213. type: object
  23214. type: object
  23215. secretRef:
  23216. description: |-
  23217. AWSAuthSecretRef holds secret references for AWS credentials
  23218. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  23219. properties:
  23220. accessKeyIDSecretRef:
  23221. description: The AccessKeyID is used for authentication
  23222. properties:
  23223. key:
  23224. description: |-
  23225. A key in the referenced Secret.
  23226. Some instances of this field may be defaulted, in others it may be required.
  23227. maxLength: 253
  23228. minLength: 1
  23229. pattern: ^[-._a-zA-Z0-9]+$
  23230. type: string
  23231. name:
  23232. description: The name of the Secret resource being referred to.
  23233. maxLength: 253
  23234. minLength: 1
  23235. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23236. type: string
  23237. namespace:
  23238. description: |-
  23239. The namespace of the Secret resource being referred to.
  23240. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23241. maxLength: 63
  23242. minLength: 1
  23243. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23244. type: string
  23245. type: object
  23246. secretAccessKeySecretRef:
  23247. description: The SecretAccessKey is used for authentication
  23248. properties:
  23249. key:
  23250. description: |-
  23251. A key in the referenced Secret.
  23252. Some instances of this field may be defaulted, in others it may be required.
  23253. maxLength: 253
  23254. minLength: 1
  23255. pattern: ^[-._a-zA-Z0-9]+$
  23256. type: string
  23257. name:
  23258. description: The name of the Secret resource being referred to.
  23259. maxLength: 253
  23260. minLength: 1
  23261. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23262. type: string
  23263. namespace:
  23264. description: |-
  23265. The namespace of the Secret resource being referred to.
  23266. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23267. maxLength: 63
  23268. minLength: 1
  23269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23270. type: string
  23271. type: object
  23272. sessionTokenSecretRef:
  23273. description: |-
  23274. The SessionToken used for authentication
  23275. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  23276. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  23277. properties:
  23278. key:
  23279. description: |-
  23280. A key in the referenced Secret.
  23281. Some instances of this field may be defaulted, in others it may be required.
  23282. maxLength: 253
  23283. minLength: 1
  23284. pattern: ^[-._a-zA-Z0-9]+$
  23285. type: string
  23286. name:
  23287. description: The name of the Secret resource being referred to.
  23288. maxLength: 253
  23289. minLength: 1
  23290. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23291. type: string
  23292. namespace:
  23293. description: |-
  23294. The namespace of the Secret resource being referred to.
  23295. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23296. maxLength: 63
  23297. minLength: 1
  23298. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23299. type: string
  23300. type: object
  23301. type: object
  23302. type: object
  23303. externalID:
  23304. description: AWS External ID set on assumed IAM roles
  23305. type: string
  23306. prefix:
  23307. description: Prefix adds a prefix to all retrieved values.
  23308. type: string
  23309. region:
  23310. description: AWS Region to be used for the provider
  23311. type: string
  23312. role:
  23313. description: Role is a Role ARN which the provider will assume
  23314. type: string
  23315. secretsManager:
  23316. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  23317. properties:
  23318. forceDeleteWithoutRecovery:
  23319. description: |-
  23320. Specifies whether to delete the secret without any recovery window. You
  23321. can't use both this parameter and RecoveryWindowInDays in the same call.
  23322. If you don't use either, then by default Secrets Manager uses a 30 day
  23323. recovery window.
  23324. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  23325. type: boolean
  23326. recoveryWindowInDays:
  23327. description: |-
  23328. The number of days from 7 to 30 that Secrets Manager waits before
  23329. permanently deleting the secret. You can't use both this parameter and
  23330. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  23331. then by default Secrets Manager uses a 30 day recovery window.
  23332. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  23333. format: int64
  23334. type: integer
  23335. type: object
  23336. service:
  23337. description: Service defines which service should be used to fetch the secrets
  23338. enum:
  23339. - SecretsManager
  23340. - ParameterStore
  23341. type: string
  23342. sessionTags:
  23343. description: AWS STS assume role session tags
  23344. items:
  23345. description: Tag defines a tag key and value for AWS resources.
  23346. properties:
  23347. key:
  23348. type: string
  23349. value:
  23350. type: string
  23351. required:
  23352. - key
  23353. - value
  23354. type: object
  23355. type: array
  23356. transitiveTagKeys:
  23357. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  23358. items:
  23359. type: string
  23360. type: array
  23361. required:
  23362. - region
  23363. - service
  23364. type: object
  23365. azurekv:
  23366. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  23367. properties:
  23368. authSecretRef:
  23369. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  23370. properties:
  23371. clientCertificate:
  23372. description: The Azure ClientCertificate of the service principle used for authentication.
  23373. properties:
  23374. key:
  23375. description: |-
  23376. A key in the referenced Secret.
  23377. Some instances of this field may be defaulted, in others it may be required.
  23378. maxLength: 253
  23379. minLength: 1
  23380. pattern: ^[-._a-zA-Z0-9]+$
  23381. type: string
  23382. name:
  23383. description: The name of the Secret resource being referred to.
  23384. maxLength: 253
  23385. minLength: 1
  23386. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23387. type: string
  23388. namespace:
  23389. description: |-
  23390. The namespace of the Secret resource being referred to.
  23391. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23392. maxLength: 63
  23393. minLength: 1
  23394. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23395. type: string
  23396. type: object
  23397. clientId:
  23398. description: The Azure clientId of the service principle or managed identity used for authentication.
  23399. properties:
  23400. key:
  23401. description: |-
  23402. A key in the referenced Secret.
  23403. Some instances of this field may be defaulted, in others it may be required.
  23404. maxLength: 253
  23405. minLength: 1
  23406. pattern: ^[-._a-zA-Z0-9]+$
  23407. type: string
  23408. name:
  23409. description: The name of the Secret resource being referred to.
  23410. maxLength: 253
  23411. minLength: 1
  23412. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23413. type: string
  23414. namespace:
  23415. description: |-
  23416. The namespace of the Secret resource being referred to.
  23417. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23418. maxLength: 63
  23419. minLength: 1
  23420. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23421. type: string
  23422. type: object
  23423. clientSecret:
  23424. description: The Azure ClientSecret of the service principle used for authentication.
  23425. properties:
  23426. key:
  23427. description: |-
  23428. A key in the referenced Secret.
  23429. Some instances of this field may be defaulted, in others it may be required.
  23430. maxLength: 253
  23431. minLength: 1
  23432. pattern: ^[-._a-zA-Z0-9]+$
  23433. type: string
  23434. name:
  23435. description: The name of the Secret resource being referred to.
  23436. maxLength: 253
  23437. minLength: 1
  23438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23439. type: string
  23440. namespace:
  23441. description: |-
  23442. The namespace of the Secret resource being referred to.
  23443. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23444. maxLength: 63
  23445. minLength: 1
  23446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23447. type: string
  23448. type: object
  23449. tenantId:
  23450. description: The Azure tenantId of the managed identity used for authentication.
  23451. properties:
  23452. key:
  23453. description: |-
  23454. A key in the referenced Secret.
  23455. Some instances of this field may be defaulted, in others it may be required.
  23456. maxLength: 253
  23457. minLength: 1
  23458. pattern: ^[-._a-zA-Z0-9]+$
  23459. type: string
  23460. name:
  23461. description: The name of the Secret resource being referred to.
  23462. maxLength: 253
  23463. minLength: 1
  23464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23465. type: string
  23466. namespace:
  23467. description: |-
  23468. The namespace of the Secret resource being referred to.
  23469. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23470. maxLength: 63
  23471. minLength: 1
  23472. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23473. type: string
  23474. type: object
  23475. type: object
  23476. authType:
  23477. default: ServicePrincipal
  23478. description: |-
  23479. Auth type defines how to authenticate to the keyvault service.
  23480. Valid values are:
  23481. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  23482. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  23483. enum:
  23484. - ServicePrincipal
  23485. - ManagedIdentity
  23486. - WorkloadIdentity
  23487. type: string
  23488. environmentType:
  23489. default: PublicCloud
  23490. description: |-
  23491. EnvironmentType specifies the Azure cloud environment endpoints to use for
  23492. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  23493. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  23494. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  23495. enum:
  23496. - PublicCloud
  23497. - USGovernmentCloud
  23498. - ChinaCloud
  23499. - GermanCloud
  23500. type: string
  23501. identityId:
  23502. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  23503. type: string
  23504. serviceAccountRef:
  23505. description: |-
  23506. ServiceAccountRef specified the service account
  23507. that should be used when authenticating with WorkloadIdentity.
  23508. properties:
  23509. audiences:
  23510. description: |-
  23511. Audience specifies the `aud` claim for the service account token
  23512. Some providers automatically extend the audience field based on well-known annotations for workload
  23513. identity (e.g. IRSA or GCP Workload Identity)
  23514. items:
  23515. type: string
  23516. type: array
  23517. name:
  23518. description: The name of the ServiceAccount resource being referred to.
  23519. maxLength: 253
  23520. minLength: 1
  23521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23522. type: string
  23523. namespace:
  23524. description: |-
  23525. Namespace of the resource being referred to.
  23526. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23527. maxLength: 63
  23528. minLength: 1
  23529. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23530. type: string
  23531. required:
  23532. - name
  23533. type: object
  23534. tenantId:
  23535. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  23536. type: string
  23537. vaultUrl:
  23538. description: Vault Url from which the secrets to be fetched from.
  23539. type: string
  23540. required:
  23541. - vaultUrl
  23542. type: object
  23543. beyondtrust:
  23544. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  23545. properties:
  23546. auth:
  23547. description: Auth configures how the operator authenticates with Beyondtrust.
  23548. properties:
  23549. apiKey:
  23550. description: APIKey If not provided then ClientID/ClientSecret become required.
  23551. properties:
  23552. secretRef:
  23553. description: SecretRef references a key in a secret that will be used as value.
  23554. properties:
  23555. key:
  23556. description: |-
  23557. A key in the referenced Secret.
  23558. Some instances of this field may be defaulted, in others it may be required.
  23559. maxLength: 253
  23560. minLength: 1
  23561. pattern: ^[-._a-zA-Z0-9]+$
  23562. type: string
  23563. name:
  23564. description: The name of the Secret resource being referred to.
  23565. maxLength: 253
  23566. minLength: 1
  23567. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23568. type: string
  23569. namespace:
  23570. description: |-
  23571. The namespace of the Secret resource being referred to.
  23572. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23573. maxLength: 63
  23574. minLength: 1
  23575. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23576. type: string
  23577. type: object
  23578. value:
  23579. description: Value can be specified directly to set a value without using a secret.
  23580. type: string
  23581. type: object
  23582. certificate:
  23583. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  23584. properties:
  23585. secretRef:
  23586. description: SecretRef references a key in a secret that will be used as value.
  23587. properties:
  23588. key:
  23589. description: |-
  23590. A key in the referenced Secret.
  23591. Some instances of this field may be defaulted, in others it may be required.
  23592. maxLength: 253
  23593. minLength: 1
  23594. pattern: ^[-._a-zA-Z0-9]+$
  23595. type: string
  23596. name:
  23597. description: The name of the Secret resource being referred to.
  23598. maxLength: 253
  23599. minLength: 1
  23600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23601. type: string
  23602. namespace:
  23603. description: |-
  23604. The namespace of the Secret resource being referred to.
  23605. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23606. maxLength: 63
  23607. minLength: 1
  23608. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23609. type: string
  23610. type: object
  23611. value:
  23612. description: Value can be specified directly to set a value without using a secret.
  23613. type: string
  23614. type: object
  23615. certificateKey:
  23616. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  23617. properties:
  23618. secretRef:
  23619. description: SecretRef references a key in a secret that will be used as value.
  23620. properties:
  23621. key:
  23622. description: |-
  23623. A key in the referenced Secret.
  23624. Some instances of this field may be defaulted, in others it may be required.
  23625. maxLength: 253
  23626. minLength: 1
  23627. pattern: ^[-._a-zA-Z0-9]+$
  23628. type: string
  23629. name:
  23630. description: The name of the Secret resource being referred to.
  23631. maxLength: 253
  23632. minLength: 1
  23633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23634. type: string
  23635. namespace:
  23636. description: |-
  23637. The namespace of the Secret resource being referred to.
  23638. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23639. maxLength: 63
  23640. minLength: 1
  23641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23642. type: string
  23643. type: object
  23644. value:
  23645. description: Value can be specified directly to set a value without using a secret.
  23646. type: string
  23647. type: object
  23648. clientId:
  23649. description: ClientID is the API OAuth Client ID.
  23650. properties:
  23651. secretRef:
  23652. description: SecretRef references a key in a secret that will be used as value.
  23653. properties:
  23654. key:
  23655. description: |-
  23656. A key in the referenced Secret.
  23657. Some instances of this field may be defaulted, in others it may be required.
  23658. maxLength: 253
  23659. minLength: 1
  23660. pattern: ^[-._a-zA-Z0-9]+$
  23661. type: string
  23662. name:
  23663. description: The name of the Secret resource being referred to.
  23664. maxLength: 253
  23665. minLength: 1
  23666. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23667. type: string
  23668. namespace:
  23669. description: |-
  23670. The namespace of the Secret resource being referred to.
  23671. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23672. maxLength: 63
  23673. minLength: 1
  23674. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23675. type: string
  23676. type: object
  23677. value:
  23678. description: Value can be specified directly to set a value without using a secret.
  23679. type: string
  23680. type: object
  23681. clientSecret:
  23682. description: ClientSecret is the API OAuth Client Secret.
  23683. properties:
  23684. secretRef:
  23685. description: SecretRef references a key in a secret that will be used as value.
  23686. properties:
  23687. key:
  23688. description: |-
  23689. A key in the referenced Secret.
  23690. Some instances of this field may be defaulted, in others it may be required.
  23691. maxLength: 253
  23692. minLength: 1
  23693. pattern: ^[-._a-zA-Z0-9]+$
  23694. type: string
  23695. name:
  23696. description: The name of the Secret resource being referred to.
  23697. maxLength: 253
  23698. minLength: 1
  23699. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23700. type: string
  23701. namespace:
  23702. description: |-
  23703. The namespace of the Secret resource being referred to.
  23704. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23705. maxLength: 63
  23706. minLength: 1
  23707. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23708. type: string
  23709. type: object
  23710. value:
  23711. description: Value can be specified directly to set a value without using a secret.
  23712. type: string
  23713. type: object
  23714. type: object
  23715. server:
  23716. description: Auth configures how API server works.
  23717. properties:
  23718. apiUrl:
  23719. type: string
  23720. apiVersion:
  23721. type: string
  23722. clientTimeOutSeconds:
  23723. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  23724. type: integer
  23725. decrypt:
  23726. default: true
  23727. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  23728. type: boolean
  23729. retrievalType:
  23730. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  23731. type: string
  23732. separator:
  23733. description: A character that separates the folder names.
  23734. type: string
  23735. verifyCA:
  23736. type: boolean
  23737. required:
  23738. - apiUrl
  23739. - verifyCA
  23740. type: object
  23741. required:
  23742. - auth
  23743. - server
  23744. type: object
  23745. bitwardensecretsmanager:
  23746. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  23747. properties:
  23748. apiURL:
  23749. type: string
  23750. auth:
  23751. description: |-
  23752. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  23753. Make sure that the token being used has permissions on the given secret.
  23754. properties:
  23755. secretRef:
  23756. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  23757. properties:
  23758. credentials:
  23759. description: AccessToken used for the bitwarden instance.
  23760. properties:
  23761. key:
  23762. description: |-
  23763. A key in the referenced Secret.
  23764. Some instances of this field may be defaulted, in others it may be required.
  23765. maxLength: 253
  23766. minLength: 1
  23767. pattern: ^[-._a-zA-Z0-9]+$
  23768. type: string
  23769. name:
  23770. description: The name of the Secret resource being referred to.
  23771. maxLength: 253
  23772. minLength: 1
  23773. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23774. type: string
  23775. namespace:
  23776. description: |-
  23777. The namespace of the Secret resource being referred to.
  23778. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23779. maxLength: 63
  23780. minLength: 1
  23781. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23782. type: string
  23783. type: object
  23784. required:
  23785. - credentials
  23786. type: object
  23787. required:
  23788. - secretRef
  23789. type: object
  23790. bitwardenServerSDKURL:
  23791. type: string
  23792. caBundle:
  23793. description: |-
  23794. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  23795. can be performed.
  23796. type: string
  23797. caProvider:
  23798. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  23799. properties:
  23800. key:
  23801. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23802. maxLength: 253
  23803. minLength: 1
  23804. pattern: ^[-._a-zA-Z0-9]+$
  23805. type: string
  23806. name:
  23807. description: The name of the object located at the provider type.
  23808. maxLength: 253
  23809. minLength: 1
  23810. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23811. type: string
  23812. namespace:
  23813. description: |-
  23814. The namespace the Provider type is in.
  23815. Can only be defined when used in a ClusterSecretStore.
  23816. maxLength: 63
  23817. minLength: 1
  23818. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23819. type: string
  23820. type:
  23821. description: The type of provider to use such as "Secret", or "ConfigMap".
  23822. enum:
  23823. - Secret
  23824. - ConfigMap
  23825. type: string
  23826. required:
  23827. - name
  23828. - type
  23829. type: object
  23830. identityURL:
  23831. type: string
  23832. organizationID:
  23833. description: OrganizationID determines which organization this secret store manages.
  23834. type: string
  23835. projectID:
  23836. description: ProjectID determines which project this secret store manages.
  23837. type: string
  23838. required:
  23839. - auth
  23840. - organizationID
  23841. - projectID
  23842. type: object
  23843. chef:
  23844. description: Chef configures this store to sync secrets with chef server
  23845. properties:
  23846. auth:
  23847. description: Auth defines the information necessary to authenticate against chef Server
  23848. properties:
  23849. secretRef:
  23850. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  23851. properties:
  23852. privateKeySecretRef:
  23853. description: SecretKey is the Signing Key in PEM format, used for authentication.
  23854. properties:
  23855. key:
  23856. description: |-
  23857. A key in the referenced Secret.
  23858. Some instances of this field may be defaulted, in others it may be required.
  23859. maxLength: 253
  23860. minLength: 1
  23861. pattern: ^[-._a-zA-Z0-9]+$
  23862. type: string
  23863. name:
  23864. description: The name of the Secret resource being referred to.
  23865. maxLength: 253
  23866. minLength: 1
  23867. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23868. type: string
  23869. namespace:
  23870. description: |-
  23871. The namespace of the Secret resource being referred to.
  23872. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23873. maxLength: 63
  23874. minLength: 1
  23875. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23876. type: string
  23877. type: object
  23878. required:
  23879. - privateKeySecretRef
  23880. type: object
  23881. required:
  23882. - secretRef
  23883. type: object
  23884. serverUrl:
  23885. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  23886. type: string
  23887. username:
  23888. description: UserName should be the user ID on the chef server
  23889. type: string
  23890. required:
  23891. - auth
  23892. - serverUrl
  23893. - username
  23894. type: object
  23895. cloudrusm:
  23896. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  23897. properties:
  23898. auth:
  23899. description: CSMAuth contains a secretRef for credentials.
  23900. properties:
  23901. secretRef:
  23902. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  23903. properties:
  23904. accessKeyIDSecretRef:
  23905. description: The AccessKeyID is used for authentication
  23906. properties:
  23907. key:
  23908. description: |-
  23909. A key in the referenced Secret.
  23910. Some instances of this field may be defaulted, in others it may be required.
  23911. maxLength: 253
  23912. minLength: 1
  23913. pattern: ^[-._a-zA-Z0-9]+$
  23914. type: string
  23915. name:
  23916. description: The name of the Secret resource being referred to.
  23917. maxLength: 253
  23918. minLength: 1
  23919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23920. type: string
  23921. namespace:
  23922. description: |-
  23923. The namespace of the Secret resource being referred to.
  23924. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23925. maxLength: 63
  23926. minLength: 1
  23927. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23928. type: string
  23929. type: object
  23930. accessKeySecretSecretRef:
  23931. description: The AccessKeySecret is used for authentication
  23932. properties:
  23933. key:
  23934. description: |-
  23935. A key in the referenced Secret.
  23936. Some instances of this field may be defaulted, in others it may be required.
  23937. maxLength: 253
  23938. minLength: 1
  23939. pattern: ^[-._a-zA-Z0-9]+$
  23940. type: string
  23941. name:
  23942. description: The name of the Secret resource being referred to.
  23943. maxLength: 253
  23944. minLength: 1
  23945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23946. type: string
  23947. namespace:
  23948. description: |-
  23949. The namespace of the Secret resource being referred to.
  23950. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23951. maxLength: 63
  23952. minLength: 1
  23953. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23954. type: string
  23955. type: object
  23956. required:
  23957. - accessKeyIDSecretRef
  23958. - accessKeySecretSecretRef
  23959. type: object
  23960. type: object
  23961. projectID:
  23962. description: ProjectID is the project, which the secrets are stored in.
  23963. type: string
  23964. required:
  23965. - auth
  23966. type: object
  23967. conjur:
  23968. description: Conjur configures this store to sync secrets using conjur provider
  23969. properties:
  23970. auth:
  23971. description: Defines authentication settings for connecting to Conjur.
  23972. properties:
  23973. apikey:
  23974. description: Authenticates with Conjur using an API key.
  23975. properties:
  23976. account:
  23977. description: Account is the Conjur organization account name.
  23978. type: string
  23979. apiKeyRef:
  23980. description: |-
  23981. A reference to a specific 'key' containing the Conjur API key
  23982. within a Secret resource. In some instances, `key` is a required field.
  23983. properties:
  23984. key:
  23985. description: |-
  23986. A key in the referenced Secret.
  23987. Some instances of this field may be defaulted, in others it may be required.
  23988. maxLength: 253
  23989. minLength: 1
  23990. pattern: ^[-._a-zA-Z0-9]+$
  23991. type: string
  23992. name:
  23993. description: The name of the Secret resource being referred to.
  23994. maxLength: 253
  23995. minLength: 1
  23996. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23997. type: string
  23998. namespace:
  23999. description: |-
  24000. The namespace of the Secret resource being referred to.
  24001. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24002. maxLength: 63
  24003. minLength: 1
  24004. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24005. type: string
  24006. type: object
  24007. userRef:
  24008. description: |-
  24009. A reference to a specific 'key' containing the Conjur username
  24010. within a Secret resource. In some instances, `key` is a required field.
  24011. properties:
  24012. key:
  24013. description: |-
  24014. A key in the referenced Secret.
  24015. Some instances of this field may be defaulted, in others it may be required.
  24016. maxLength: 253
  24017. minLength: 1
  24018. pattern: ^[-._a-zA-Z0-9]+$
  24019. type: string
  24020. name:
  24021. description: The name of the Secret resource being referred to.
  24022. maxLength: 253
  24023. minLength: 1
  24024. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24025. type: string
  24026. namespace:
  24027. description: |-
  24028. The namespace of the Secret resource being referred to.
  24029. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24030. maxLength: 63
  24031. minLength: 1
  24032. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24033. type: string
  24034. type: object
  24035. required:
  24036. - account
  24037. - apiKeyRef
  24038. - userRef
  24039. type: object
  24040. jwt:
  24041. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  24042. properties:
  24043. account:
  24044. description: Account is the Conjur organization account name.
  24045. type: string
  24046. hostId:
  24047. description: |-
  24048. Optional HostID for JWT authentication. This may be used depending
  24049. on how the Conjur JWT authenticator policy is configured.
  24050. type: string
  24051. secretRef:
  24052. description: |-
  24053. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  24054. authenticate with Conjur using the JWT authentication method.
  24055. properties:
  24056. key:
  24057. description: |-
  24058. A key in the referenced Secret.
  24059. Some instances of this field may be defaulted, in others it may be required.
  24060. maxLength: 253
  24061. minLength: 1
  24062. pattern: ^[-._a-zA-Z0-9]+$
  24063. type: string
  24064. name:
  24065. description: The name of the Secret resource being referred to.
  24066. maxLength: 253
  24067. minLength: 1
  24068. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24069. type: string
  24070. namespace:
  24071. description: |-
  24072. The namespace of the Secret resource being referred to.
  24073. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24074. maxLength: 63
  24075. minLength: 1
  24076. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24077. type: string
  24078. type: object
  24079. serviceAccountRef:
  24080. description: |-
  24081. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  24082. a token for with the `TokenRequest` API.
  24083. properties:
  24084. audiences:
  24085. description: |-
  24086. Audience specifies the `aud` claim for the service account token
  24087. Some providers automatically extend the audience field based on well-known annotations for workload
  24088. identity (e.g. IRSA or GCP Workload Identity)
  24089. items:
  24090. type: string
  24091. type: array
  24092. name:
  24093. description: The name of the ServiceAccount resource being referred to.
  24094. maxLength: 253
  24095. minLength: 1
  24096. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24097. type: string
  24098. namespace:
  24099. description: |-
  24100. Namespace of the resource being referred to.
  24101. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24102. maxLength: 63
  24103. minLength: 1
  24104. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24105. type: string
  24106. required:
  24107. - name
  24108. type: object
  24109. serviceID:
  24110. description: The conjur authn jwt webservice id
  24111. type: string
  24112. required:
  24113. - account
  24114. - serviceID
  24115. type: object
  24116. type: object
  24117. caBundle:
  24118. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  24119. type: string
  24120. caProvider:
  24121. description: |-
  24122. Used to provide custom certificate authority (CA) certificates
  24123. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  24124. that contains a PEM-encoded certificate.
  24125. properties:
  24126. key:
  24127. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24128. maxLength: 253
  24129. minLength: 1
  24130. pattern: ^[-._a-zA-Z0-9]+$
  24131. type: string
  24132. name:
  24133. description: The name of the object located at the provider type.
  24134. maxLength: 253
  24135. minLength: 1
  24136. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24137. type: string
  24138. namespace:
  24139. description: |-
  24140. The namespace the Provider type is in.
  24141. Can only be defined when used in a ClusterSecretStore.
  24142. maxLength: 63
  24143. minLength: 1
  24144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24145. type: string
  24146. type:
  24147. description: The type of provider to use such as "Secret", or "ConfigMap".
  24148. enum:
  24149. - Secret
  24150. - ConfigMap
  24151. type: string
  24152. required:
  24153. - name
  24154. - type
  24155. type: object
  24156. url:
  24157. description: URL is the endpoint of the Conjur instance.
  24158. type: string
  24159. required:
  24160. - auth
  24161. - url
  24162. type: object
  24163. delinea:
  24164. description: |-
  24165. Delinea DevOps Secrets Vault
  24166. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  24167. properties:
  24168. clientId:
  24169. description: ClientID is the non-secret part of the credential.
  24170. properties:
  24171. secretRef:
  24172. description: SecretRef references a key in a secret that will be used as value.
  24173. properties:
  24174. key:
  24175. description: |-
  24176. A key in the referenced Secret.
  24177. Some instances of this field may be defaulted, in others it may be required.
  24178. maxLength: 253
  24179. minLength: 1
  24180. pattern: ^[-._a-zA-Z0-9]+$
  24181. type: string
  24182. name:
  24183. description: The name of the Secret resource being referred to.
  24184. maxLength: 253
  24185. minLength: 1
  24186. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24187. type: string
  24188. namespace:
  24189. description: |-
  24190. The namespace of the Secret resource being referred to.
  24191. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24192. maxLength: 63
  24193. minLength: 1
  24194. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24195. type: string
  24196. type: object
  24197. value:
  24198. description: Value can be specified directly to set a value without using a secret.
  24199. type: string
  24200. type: object
  24201. clientSecret:
  24202. description: ClientSecret is the secret part of the credential.
  24203. properties:
  24204. secretRef:
  24205. description: SecretRef references a key in a secret that will be used as value.
  24206. properties:
  24207. key:
  24208. description: |-
  24209. A key in the referenced Secret.
  24210. Some instances of this field may be defaulted, in others it may be required.
  24211. maxLength: 253
  24212. minLength: 1
  24213. pattern: ^[-._a-zA-Z0-9]+$
  24214. type: string
  24215. name:
  24216. description: The name of the Secret resource being referred to.
  24217. maxLength: 253
  24218. minLength: 1
  24219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24220. type: string
  24221. namespace:
  24222. description: |-
  24223. The namespace of the Secret resource being referred to.
  24224. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24225. maxLength: 63
  24226. minLength: 1
  24227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24228. type: string
  24229. type: object
  24230. value:
  24231. description: Value can be specified directly to set a value without using a secret.
  24232. type: string
  24233. type: object
  24234. tenant:
  24235. description: Tenant is the chosen hostname / site name.
  24236. type: string
  24237. tld:
  24238. description: |-
  24239. TLD is based on the server location that was chosen during provisioning.
  24240. If unset, defaults to "com".
  24241. type: string
  24242. urlTemplate:
  24243. description: |-
  24244. URLTemplate
  24245. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  24246. type: string
  24247. required:
  24248. - clientId
  24249. - clientSecret
  24250. - tenant
  24251. type: object
  24252. device42:
  24253. description: Device42 configures this store to sync secrets using the Device42 provider
  24254. properties:
  24255. auth:
  24256. description: Auth configures how secret-manager authenticates with a Device42 instance.
  24257. properties:
  24258. secretRef:
  24259. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  24260. properties:
  24261. credentials:
  24262. description: Username / Password is used for authentication.
  24263. properties:
  24264. key:
  24265. description: |-
  24266. A key in the referenced Secret.
  24267. Some instances of this field may be defaulted, in others it may be required.
  24268. maxLength: 253
  24269. minLength: 1
  24270. pattern: ^[-._a-zA-Z0-9]+$
  24271. type: string
  24272. name:
  24273. description: The name of the Secret resource being referred to.
  24274. maxLength: 253
  24275. minLength: 1
  24276. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24277. type: string
  24278. namespace:
  24279. description: |-
  24280. The namespace of the Secret resource being referred to.
  24281. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24282. maxLength: 63
  24283. minLength: 1
  24284. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24285. type: string
  24286. type: object
  24287. type: object
  24288. required:
  24289. - secretRef
  24290. type: object
  24291. host:
  24292. description: URL configures the Device42 instance URL.
  24293. type: string
  24294. required:
  24295. - auth
  24296. - host
  24297. type: object
  24298. doppler:
  24299. description: Doppler configures this store to sync secrets using the Doppler provider
  24300. properties:
  24301. auth:
  24302. description: Auth configures how the Operator authenticates with the Doppler API
  24303. properties:
  24304. secretRef:
  24305. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  24306. properties:
  24307. dopplerToken:
  24308. description: |-
  24309. The DopplerToken is used for authentication.
  24310. See https://docs.doppler.com/reference/api#authentication for auth token types.
  24311. The Key attribute defaults to dopplerToken if not specified.
  24312. properties:
  24313. key:
  24314. description: |-
  24315. A key in the referenced Secret.
  24316. Some instances of this field may be defaulted, in others it may be required.
  24317. maxLength: 253
  24318. minLength: 1
  24319. pattern: ^[-._a-zA-Z0-9]+$
  24320. type: string
  24321. name:
  24322. description: The name of the Secret resource being referred to.
  24323. maxLength: 253
  24324. minLength: 1
  24325. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24326. type: string
  24327. namespace:
  24328. description: |-
  24329. The namespace of the Secret resource being referred to.
  24330. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24331. maxLength: 63
  24332. minLength: 1
  24333. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24334. type: string
  24335. type: object
  24336. required:
  24337. - dopplerToken
  24338. type: object
  24339. required:
  24340. - secretRef
  24341. type: object
  24342. config:
  24343. description: Doppler config (required if not using a Service Token)
  24344. type: string
  24345. format:
  24346. description: Format enables the downloading of secrets as a file (string)
  24347. enum:
  24348. - json
  24349. - dotnet-json
  24350. - env
  24351. - yaml
  24352. - docker
  24353. type: string
  24354. nameTransformer:
  24355. description: Environment variable compatible name transforms that change secret names to a different format
  24356. enum:
  24357. - upper-camel
  24358. - camel
  24359. - lower-snake
  24360. - tf-var
  24361. - dotnet-env
  24362. - lower-kebab
  24363. type: string
  24364. project:
  24365. description: Doppler project (required if not using a Service Token)
  24366. type: string
  24367. required:
  24368. - auth
  24369. type: object
  24370. fake:
  24371. description: Fake configures a store with static key/value pairs
  24372. properties:
  24373. data:
  24374. items:
  24375. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  24376. properties:
  24377. key:
  24378. type: string
  24379. value:
  24380. type: string
  24381. version:
  24382. type: string
  24383. required:
  24384. - key
  24385. - value
  24386. type: object
  24387. type: array
  24388. required:
  24389. - data
  24390. type: object
  24391. fortanix:
  24392. description: Fortanix configures this store to sync secrets using the Fortanix provider
  24393. properties:
  24394. apiKey:
  24395. description: APIKey is the API token to access SDKMS Applications.
  24396. properties:
  24397. secretRef:
  24398. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  24399. properties:
  24400. key:
  24401. description: |-
  24402. A key in the referenced Secret.
  24403. Some instances of this field may be defaulted, in others it may be required.
  24404. maxLength: 253
  24405. minLength: 1
  24406. pattern: ^[-._a-zA-Z0-9]+$
  24407. type: string
  24408. name:
  24409. description: The name of the Secret resource being referred to.
  24410. maxLength: 253
  24411. minLength: 1
  24412. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24413. type: string
  24414. namespace:
  24415. description: |-
  24416. The namespace of the Secret resource being referred to.
  24417. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24418. maxLength: 63
  24419. minLength: 1
  24420. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24421. type: string
  24422. type: object
  24423. type: object
  24424. apiUrl:
  24425. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  24426. type: string
  24427. type: object
  24428. gcpsm:
  24429. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  24430. properties:
  24431. auth:
  24432. description: Auth defines the information necessary to authenticate against GCP
  24433. properties:
  24434. secretRef:
  24435. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  24436. properties:
  24437. secretAccessKeySecretRef:
  24438. description: The SecretAccessKey is used for authentication
  24439. properties:
  24440. key:
  24441. description: |-
  24442. A key in the referenced Secret.
  24443. Some instances of this field may be defaulted, in others it may be required.
  24444. maxLength: 253
  24445. minLength: 1
  24446. pattern: ^[-._a-zA-Z0-9]+$
  24447. type: string
  24448. name:
  24449. description: The name of the Secret resource being referred to.
  24450. maxLength: 253
  24451. minLength: 1
  24452. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24453. type: string
  24454. namespace:
  24455. description: |-
  24456. The namespace of the Secret resource being referred to.
  24457. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24458. maxLength: 63
  24459. minLength: 1
  24460. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24461. type: string
  24462. type: object
  24463. type: object
  24464. workloadIdentity:
  24465. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  24466. properties:
  24467. clusterLocation:
  24468. description: |-
  24469. ClusterLocation is the location of the cluster
  24470. If not specified, it fetches information from the metadata server
  24471. type: string
  24472. clusterName:
  24473. description: |-
  24474. ClusterName is the name of the cluster
  24475. If not specified, it fetches information from the metadata server
  24476. type: string
  24477. clusterProjectID:
  24478. description: |-
  24479. ClusterProjectID is the project ID of the cluster
  24480. If not specified, it fetches information from the metadata server
  24481. type: string
  24482. serviceAccountRef:
  24483. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  24484. properties:
  24485. audiences:
  24486. description: |-
  24487. Audience specifies the `aud` claim for the service account token
  24488. Some providers automatically extend the audience field based on well-known annotations for workload
  24489. identity (e.g. IRSA or GCP Workload Identity)
  24490. items:
  24491. type: string
  24492. type: array
  24493. name:
  24494. description: The name of the ServiceAccount resource being referred to.
  24495. maxLength: 253
  24496. minLength: 1
  24497. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24498. type: string
  24499. namespace:
  24500. description: |-
  24501. Namespace of the resource being referred to.
  24502. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24503. maxLength: 63
  24504. minLength: 1
  24505. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24506. type: string
  24507. required:
  24508. - name
  24509. type: object
  24510. required:
  24511. - serviceAccountRef
  24512. type: object
  24513. type: object
  24514. location:
  24515. description: Location optionally defines a location for a secret
  24516. type: string
  24517. projectID:
  24518. description: ProjectID project where secret is located
  24519. type: string
  24520. type: object
  24521. github:
  24522. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  24523. properties:
  24524. appID:
  24525. description: appID specifies the Github APP that will be used to authenticate the client
  24526. format: int64
  24527. type: integer
  24528. auth:
  24529. description: auth configures how secret-manager authenticates with a Github instance.
  24530. properties:
  24531. privateKey:
  24532. description: |-
  24533. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24534. In some instances, `key` is a required field.
  24535. properties:
  24536. key:
  24537. description: |-
  24538. A key in the referenced Secret.
  24539. Some instances of this field may be defaulted, in others it may be required.
  24540. maxLength: 253
  24541. minLength: 1
  24542. pattern: ^[-._a-zA-Z0-9]+$
  24543. type: string
  24544. name:
  24545. description: The name of the Secret resource being referred to.
  24546. maxLength: 253
  24547. minLength: 1
  24548. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24549. type: string
  24550. namespace:
  24551. description: |-
  24552. The namespace of the Secret resource being referred to.
  24553. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24554. maxLength: 63
  24555. minLength: 1
  24556. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24557. type: string
  24558. type: object
  24559. required:
  24560. - privateKey
  24561. type: object
  24562. environment:
  24563. description: environment will be used to fetch secrets from a particular environment within a github repository
  24564. type: string
  24565. installationID:
  24566. description: installationID specifies the Github APP installation that will be used to authenticate the client
  24567. format: int64
  24568. type: integer
  24569. organization:
  24570. description: organization will be used to fetch secrets from the Github organization
  24571. type: string
  24572. repository:
  24573. description: repository will be used to fetch secrets from the Github repository within an organization
  24574. type: string
  24575. uploadURL:
  24576. description: Upload URL for enterprise instances. Default to URL.
  24577. type: string
  24578. url:
  24579. default: https://github.com/
  24580. description: URL configures the Github instance URL. Defaults to https://github.com/.
  24581. type: string
  24582. required:
  24583. - appID
  24584. - auth
  24585. - installationID
  24586. - organization
  24587. type: object
  24588. gitlab:
  24589. description: GitLab configures this store to sync secrets using GitLab Variables provider
  24590. properties:
  24591. auth:
  24592. description: Auth configures how secret-manager authenticates with a GitLab instance.
  24593. properties:
  24594. SecretRef:
  24595. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  24596. properties:
  24597. accessToken:
  24598. description: AccessToken is used for authentication.
  24599. properties:
  24600. key:
  24601. description: |-
  24602. A key in the referenced Secret.
  24603. Some instances of this field may be defaulted, in others it may be required.
  24604. maxLength: 253
  24605. minLength: 1
  24606. pattern: ^[-._a-zA-Z0-9]+$
  24607. type: string
  24608. name:
  24609. description: The name of the Secret resource being referred to.
  24610. maxLength: 253
  24611. minLength: 1
  24612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24613. type: string
  24614. namespace:
  24615. description: |-
  24616. The namespace of the Secret resource being referred to.
  24617. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24618. maxLength: 63
  24619. minLength: 1
  24620. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24621. type: string
  24622. type: object
  24623. type: object
  24624. required:
  24625. - SecretRef
  24626. type: object
  24627. caBundle:
  24628. description: |-
  24629. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  24630. can be performed.
  24631. format: byte
  24632. type: string
  24633. caProvider:
  24634. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  24635. properties:
  24636. key:
  24637. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24638. maxLength: 253
  24639. minLength: 1
  24640. pattern: ^[-._a-zA-Z0-9]+$
  24641. type: string
  24642. name:
  24643. description: The name of the object located at the provider type.
  24644. maxLength: 253
  24645. minLength: 1
  24646. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24647. type: string
  24648. namespace:
  24649. description: |-
  24650. The namespace the Provider type is in.
  24651. Can only be defined when used in a ClusterSecretStore.
  24652. maxLength: 63
  24653. minLength: 1
  24654. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24655. type: string
  24656. type:
  24657. description: The type of provider to use such as "Secret", or "ConfigMap".
  24658. enum:
  24659. - Secret
  24660. - ConfigMap
  24661. type: string
  24662. required:
  24663. - name
  24664. - type
  24665. type: object
  24666. environment:
  24667. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  24668. type: string
  24669. groupIDs:
  24670. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  24671. items:
  24672. type: string
  24673. type: array
  24674. inheritFromGroups:
  24675. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  24676. type: boolean
  24677. projectID:
  24678. description: ProjectID specifies a project where secrets are located.
  24679. type: string
  24680. url:
  24681. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  24682. type: string
  24683. required:
  24684. - auth
  24685. type: object
  24686. ibm:
  24687. description: IBM configures this store to sync secrets using IBM Cloud provider
  24688. properties:
  24689. auth:
  24690. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  24691. maxProperties: 1
  24692. minProperties: 1
  24693. properties:
  24694. containerAuth:
  24695. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  24696. properties:
  24697. iamEndpoint:
  24698. type: string
  24699. profile:
  24700. description: the IBM Trusted Profile
  24701. type: string
  24702. tokenLocation:
  24703. description: Location the token is mounted on the pod
  24704. type: string
  24705. required:
  24706. - profile
  24707. type: object
  24708. secretRef:
  24709. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  24710. properties:
  24711. secretApiKeySecretRef:
  24712. description: The SecretAccessKey is used for authentication
  24713. properties:
  24714. key:
  24715. description: |-
  24716. A key in the referenced Secret.
  24717. Some instances of this field may be defaulted, in others it may be required.
  24718. maxLength: 253
  24719. minLength: 1
  24720. pattern: ^[-._a-zA-Z0-9]+$
  24721. type: string
  24722. name:
  24723. description: The name of the Secret resource being referred to.
  24724. maxLength: 253
  24725. minLength: 1
  24726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24727. type: string
  24728. namespace:
  24729. description: |-
  24730. The namespace of the Secret resource being referred to.
  24731. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24732. maxLength: 63
  24733. minLength: 1
  24734. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24735. type: string
  24736. type: object
  24737. type: object
  24738. type: object
  24739. serviceUrl:
  24740. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  24741. type: string
  24742. required:
  24743. - auth
  24744. type: object
  24745. infisical:
  24746. description: Infisical configures this store to sync secrets using the Infisical provider
  24747. properties:
  24748. auth:
  24749. description: Auth configures how the Operator authenticates with the Infisical API
  24750. properties:
  24751. universalAuthCredentials:
  24752. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  24753. properties:
  24754. clientId:
  24755. description: |-
  24756. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24757. In some instances, `key` is a required field.
  24758. properties:
  24759. key:
  24760. description: |-
  24761. A key in the referenced Secret.
  24762. Some instances of this field may be defaulted, in others it may be required.
  24763. maxLength: 253
  24764. minLength: 1
  24765. pattern: ^[-._a-zA-Z0-9]+$
  24766. type: string
  24767. name:
  24768. description: The name of the Secret resource being referred to.
  24769. maxLength: 253
  24770. minLength: 1
  24771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24772. type: string
  24773. namespace:
  24774. description: |-
  24775. The namespace of the Secret resource being referred to.
  24776. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24777. maxLength: 63
  24778. minLength: 1
  24779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24780. type: string
  24781. type: object
  24782. clientSecret:
  24783. description: |-
  24784. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24785. In some instances, `key` is a required field.
  24786. properties:
  24787. key:
  24788. description: |-
  24789. A key in the referenced Secret.
  24790. Some instances of this field may be defaulted, in others it may be required.
  24791. maxLength: 253
  24792. minLength: 1
  24793. pattern: ^[-._a-zA-Z0-9]+$
  24794. type: string
  24795. name:
  24796. description: The name of the Secret resource being referred to.
  24797. maxLength: 253
  24798. minLength: 1
  24799. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24800. type: string
  24801. namespace:
  24802. description: |-
  24803. The namespace of the Secret resource being referred to.
  24804. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24805. maxLength: 63
  24806. minLength: 1
  24807. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24808. type: string
  24809. type: object
  24810. required:
  24811. - clientId
  24812. - clientSecret
  24813. type: object
  24814. type: object
  24815. hostAPI:
  24816. default: https://app.infisical.com/api
  24817. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  24818. type: string
  24819. secretsScope:
  24820. description: SecretsScope defines the scope of the secrets within the workspace
  24821. properties:
  24822. environmentSlug:
  24823. description: EnvironmentSlug is the required slug identifier for the environment.
  24824. type: string
  24825. expandSecretReferences:
  24826. default: true
  24827. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  24828. type: boolean
  24829. projectSlug:
  24830. description: ProjectSlug is the required slug identifier for the project.
  24831. type: string
  24832. recursive:
  24833. default: false
  24834. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  24835. type: boolean
  24836. secretsPath:
  24837. default: /
  24838. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  24839. type: string
  24840. required:
  24841. - environmentSlug
  24842. - projectSlug
  24843. type: object
  24844. required:
  24845. - auth
  24846. - secretsScope
  24847. type: object
  24848. keepersecurity:
  24849. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  24850. properties:
  24851. authRef:
  24852. description: |-
  24853. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24854. In some instances, `key` is a required field.
  24855. properties:
  24856. key:
  24857. description: |-
  24858. A key in the referenced Secret.
  24859. Some instances of this field may be defaulted, in others it may be required.
  24860. maxLength: 253
  24861. minLength: 1
  24862. pattern: ^[-._a-zA-Z0-9]+$
  24863. type: string
  24864. name:
  24865. description: The name of the Secret resource being referred to.
  24866. maxLength: 253
  24867. minLength: 1
  24868. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24869. type: string
  24870. namespace:
  24871. description: |-
  24872. The namespace of the Secret resource being referred to.
  24873. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24874. maxLength: 63
  24875. minLength: 1
  24876. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24877. type: string
  24878. type: object
  24879. folderID:
  24880. type: string
  24881. required:
  24882. - authRef
  24883. - folderID
  24884. type: object
  24885. kubernetes:
  24886. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  24887. properties:
  24888. auth:
  24889. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  24890. maxProperties: 1
  24891. minProperties: 1
  24892. properties:
  24893. cert:
  24894. description: has both clientCert and clientKey as secretKeySelector
  24895. properties:
  24896. clientCert:
  24897. description: |-
  24898. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24899. In some instances, `key` is a required field.
  24900. properties:
  24901. key:
  24902. description: |-
  24903. A key in the referenced Secret.
  24904. Some instances of this field may be defaulted, in others it may be required.
  24905. maxLength: 253
  24906. minLength: 1
  24907. pattern: ^[-._a-zA-Z0-9]+$
  24908. type: string
  24909. name:
  24910. description: The name of the Secret resource being referred to.
  24911. maxLength: 253
  24912. minLength: 1
  24913. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24914. type: string
  24915. namespace:
  24916. description: |-
  24917. The namespace of the Secret resource being referred to.
  24918. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24919. maxLength: 63
  24920. minLength: 1
  24921. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24922. type: string
  24923. type: object
  24924. clientKey:
  24925. description: |-
  24926. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24927. In some instances, `key` is a required field.
  24928. properties:
  24929. key:
  24930. description: |-
  24931. A key in the referenced Secret.
  24932. Some instances of this field may be defaulted, in others it may be required.
  24933. maxLength: 253
  24934. minLength: 1
  24935. pattern: ^[-._a-zA-Z0-9]+$
  24936. type: string
  24937. name:
  24938. description: The name of the Secret resource being referred to.
  24939. maxLength: 253
  24940. minLength: 1
  24941. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24942. type: string
  24943. namespace:
  24944. description: |-
  24945. The namespace of the Secret resource being referred to.
  24946. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24947. maxLength: 63
  24948. minLength: 1
  24949. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24950. type: string
  24951. type: object
  24952. type: object
  24953. serviceAccount:
  24954. description: points to a service account that should be used for authentication
  24955. properties:
  24956. audiences:
  24957. description: |-
  24958. Audience specifies the `aud` claim for the service account token
  24959. Some providers automatically extend the audience field based on well-known annotations for workload
  24960. identity (e.g. IRSA or GCP Workload Identity)
  24961. items:
  24962. type: string
  24963. type: array
  24964. name:
  24965. description: The name of the ServiceAccount resource being referred to.
  24966. maxLength: 253
  24967. minLength: 1
  24968. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24969. type: string
  24970. namespace:
  24971. description: |-
  24972. Namespace of the resource being referred to.
  24973. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24974. maxLength: 63
  24975. minLength: 1
  24976. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24977. type: string
  24978. required:
  24979. - name
  24980. type: object
  24981. token:
  24982. description: use static token to authenticate with
  24983. properties:
  24984. bearerToken:
  24985. description: |-
  24986. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24987. In some instances, `key` is a required field.
  24988. properties:
  24989. key:
  24990. description: |-
  24991. A key in the referenced Secret.
  24992. Some instances of this field may be defaulted, in others it may be required.
  24993. maxLength: 253
  24994. minLength: 1
  24995. pattern: ^[-._a-zA-Z0-9]+$
  24996. type: string
  24997. name:
  24998. description: The name of the Secret resource being referred to.
  24999. maxLength: 253
  25000. minLength: 1
  25001. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25002. type: string
  25003. namespace:
  25004. description: |-
  25005. The namespace of the Secret resource being referred to.
  25006. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25007. maxLength: 63
  25008. minLength: 1
  25009. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25010. type: string
  25011. type: object
  25012. type: object
  25013. type: object
  25014. authRef:
  25015. description: A reference to a secret that contains the auth information.
  25016. properties:
  25017. key:
  25018. description: |-
  25019. A key in the referenced Secret.
  25020. Some instances of this field may be defaulted, in others it may be required.
  25021. maxLength: 253
  25022. minLength: 1
  25023. pattern: ^[-._a-zA-Z0-9]+$
  25024. type: string
  25025. name:
  25026. description: The name of the Secret resource being referred to.
  25027. maxLength: 253
  25028. minLength: 1
  25029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25030. type: string
  25031. namespace:
  25032. description: |-
  25033. The namespace of the Secret resource being referred to.
  25034. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25035. maxLength: 63
  25036. minLength: 1
  25037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25038. type: string
  25039. type: object
  25040. remoteNamespace:
  25041. default: default
  25042. description: Remote namespace to fetch the secrets from
  25043. maxLength: 63
  25044. minLength: 1
  25045. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25046. type: string
  25047. server:
  25048. description: configures the Kubernetes server Address.
  25049. properties:
  25050. caBundle:
  25051. description: CABundle is a base64-encoded CA certificate
  25052. format: byte
  25053. type: string
  25054. caProvider:
  25055. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  25056. properties:
  25057. key:
  25058. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  25059. maxLength: 253
  25060. minLength: 1
  25061. pattern: ^[-._a-zA-Z0-9]+$
  25062. type: string
  25063. name:
  25064. description: The name of the object located at the provider type.
  25065. maxLength: 253
  25066. minLength: 1
  25067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25068. type: string
  25069. namespace:
  25070. description: |-
  25071. The namespace the Provider type is in.
  25072. Can only be defined when used in a ClusterSecretStore.
  25073. maxLength: 63
  25074. minLength: 1
  25075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25076. type: string
  25077. type:
  25078. description: The type of provider to use such as "Secret", or "ConfigMap".
  25079. enum:
  25080. - Secret
  25081. - ConfigMap
  25082. type: string
  25083. required:
  25084. - name
  25085. - type
  25086. type: object
  25087. url:
  25088. default: kubernetes.default
  25089. description: configures the Kubernetes server Address.
  25090. type: string
  25091. type: object
  25092. type: object
  25093. onboardbase:
  25094. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  25095. properties:
  25096. apiHost:
  25097. default: https://public.onboardbase.com/api/v1/
  25098. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  25099. type: string
  25100. auth:
  25101. description: Auth configures how the Operator authenticates with the Onboardbase API
  25102. properties:
  25103. apiKeyRef:
  25104. description: |-
  25105. OnboardbaseAPIKey is the APIKey generated by an admin account.
  25106. It is used to recognize and authorize access to a project and environment within onboardbase
  25107. properties:
  25108. key:
  25109. description: |-
  25110. A key in the referenced Secret.
  25111. Some instances of this field may be defaulted, in others it may be required.
  25112. maxLength: 253
  25113. minLength: 1
  25114. pattern: ^[-._a-zA-Z0-9]+$
  25115. type: string
  25116. name:
  25117. description: The name of the Secret resource being referred to.
  25118. maxLength: 253
  25119. minLength: 1
  25120. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25121. type: string
  25122. namespace:
  25123. description: |-
  25124. The namespace of the Secret resource being referred to.
  25125. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25126. maxLength: 63
  25127. minLength: 1
  25128. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25129. type: string
  25130. type: object
  25131. passcodeRef:
  25132. description: OnboardbasePasscode is the passcode attached to the API Key
  25133. properties:
  25134. key:
  25135. description: |-
  25136. A key in the referenced Secret.
  25137. Some instances of this field may be defaulted, in others it may be required.
  25138. maxLength: 253
  25139. minLength: 1
  25140. pattern: ^[-._a-zA-Z0-9]+$
  25141. type: string
  25142. name:
  25143. description: The name of the Secret resource being referred to.
  25144. maxLength: 253
  25145. minLength: 1
  25146. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25147. type: string
  25148. namespace:
  25149. description: |-
  25150. The namespace of the Secret resource being referred to.
  25151. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25152. maxLength: 63
  25153. minLength: 1
  25154. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25155. type: string
  25156. type: object
  25157. required:
  25158. - apiKeyRef
  25159. - passcodeRef
  25160. type: object
  25161. environment:
  25162. default: development
  25163. description: Environment is the name of an environmnent within a project to pull the secrets from
  25164. type: string
  25165. project:
  25166. default: development
  25167. description: Project is an onboardbase project that the secrets should be pulled from
  25168. type: string
  25169. required:
  25170. - apiHost
  25171. - auth
  25172. - environment
  25173. - project
  25174. type: object
  25175. onepassword:
  25176. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  25177. properties:
  25178. auth:
  25179. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  25180. properties:
  25181. secretRef:
  25182. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  25183. properties:
  25184. connectTokenSecretRef:
  25185. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  25186. properties:
  25187. key:
  25188. description: |-
  25189. A key in the referenced Secret.
  25190. Some instances of this field may be defaulted, in others it may be required.
  25191. maxLength: 253
  25192. minLength: 1
  25193. pattern: ^[-._a-zA-Z0-9]+$
  25194. type: string
  25195. name:
  25196. description: The name of the Secret resource being referred to.
  25197. maxLength: 253
  25198. minLength: 1
  25199. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25200. type: string
  25201. namespace:
  25202. description: |-
  25203. The namespace of the Secret resource being referred to.
  25204. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25205. maxLength: 63
  25206. minLength: 1
  25207. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25208. type: string
  25209. type: object
  25210. required:
  25211. - connectTokenSecretRef
  25212. type: object
  25213. required:
  25214. - secretRef
  25215. type: object
  25216. connectHost:
  25217. description: ConnectHost defines the OnePassword Connect Server to connect to
  25218. type: string
  25219. vaults:
  25220. additionalProperties:
  25221. type: integer
  25222. description: Vaults defines which OnePassword vaults to search in which order
  25223. type: object
  25224. required:
  25225. - auth
  25226. - connectHost
  25227. - vaults
  25228. type: object
  25229. oracle:
  25230. description: Oracle configures this store to sync secrets using Oracle Vault provider
  25231. properties:
  25232. auth:
  25233. description: |-
  25234. Auth configures how secret-manager authenticates with the Oracle Vault.
  25235. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  25236. properties:
  25237. secretRef:
  25238. description: SecretRef to pass through sensitive information.
  25239. properties:
  25240. fingerprint:
  25241. description: Fingerprint is the fingerprint of the API private key.
  25242. properties:
  25243. key:
  25244. description: |-
  25245. A key in the referenced Secret.
  25246. Some instances of this field may be defaulted, in others it may be required.
  25247. maxLength: 253
  25248. minLength: 1
  25249. pattern: ^[-._a-zA-Z0-9]+$
  25250. type: string
  25251. name:
  25252. description: The name of the Secret resource being referred to.
  25253. maxLength: 253
  25254. minLength: 1
  25255. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25256. type: string
  25257. namespace:
  25258. description: |-
  25259. The namespace of the Secret resource being referred to.
  25260. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25261. maxLength: 63
  25262. minLength: 1
  25263. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25264. type: string
  25265. type: object
  25266. privatekey:
  25267. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  25268. properties:
  25269. key:
  25270. description: |-
  25271. A key in the referenced Secret.
  25272. Some instances of this field may be defaulted, in others it may be required.
  25273. maxLength: 253
  25274. minLength: 1
  25275. pattern: ^[-._a-zA-Z0-9]+$
  25276. type: string
  25277. name:
  25278. description: The name of the Secret resource being referred to.
  25279. maxLength: 253
  25280. minLength: 1
  25281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25282. type: string
  25283. namespace:
  25284. description: |-
  25285. The namespace of the Secret resource being referred to.
  25286. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25287. maxLength: 63
  25288. minLength: 1
  25289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25290. type: string
  25291. type: object
  25292. required:
  25293. - fingerprint
  25294. - privatekey
  25295. type: object
  25296. tenancy:
  25297. description: Tenancy is the tenancy OCID where user is located.
  25298. type: string
  25299. user:
  25300. description: User is an access OCID specific to the account.
  25301. type: string
  25302. required:
  25303. - secretRef
  25304. - tenancy
  25305. - user
  25306. type: object
  25307. compartment:
  25308. description: |-
  25309. Compartment is the vault compartment OCID.
  25310. Required for PushSecret
  25311. type: string
  25312. encryptionKey:
  25313. description: |-
  25314. EncryptionKey is the OCID of the encryption key within the vault.
  25315. Required for PushSecret
  25316. type: string
  25317. principalType:
  25318. description: |-
  25319. The type of principal to use for authentication. If left blank, the Auth struct will
  25320. determine the principal type. This optional field must be specified if using
  25321. workload identity.
  25322. enum:
  25323. - ""
  25324. - UserPrincipal
  25325. - InstancePrincipal
  25326. - Workload
  25327. type: string
  25328. region:
  25329. description: Region is the region where vault is located.
  25330. type: string
  25331. serviceAccountRef:
  25332. description: |-
  25333. ServiceAccountRef specified the service account
  25334. that should be used when authenticating with WorkloadIdentity.
  25335. properties:
  25336. audiences:
  25337. description: |-
  25338. Audience specifies the `aud` claim for the service account token
  25339. Some providers automatically extend the audience field based on well-known annotations for workload
  25340. identity (e.g. IRSA or GCP Workload Identity)
  25341. items:
  25342. type: string
  25343. type: array
  25344. name:
  25345. description: The name of the ServiceAccount resource being referred to.
  25346. maxLength: 253
  25347. minLength: 1
  25348. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25349. type: string
  25350. namespace:
  25351. description: |-
  25352. Namespace of the resource being referred to.
  25353. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25354. maxLength: 63
  25355. minLength: 1
  25356. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25357. type: string
  25358. required:
  25359. - name
  25360. type: object
  25361. vault:
  25362. description: Vault is the vault's OCID of the specific vault where secret is located.
  25363. type: string
  25364. required:
  25365. - region
  25366. - vault
  25367. type: object
  25368. passbolt:
  25369. description: PassboltProvider defines configuration for the Passbolt provider.
  25370. properties:
  25371. auth:
  25372. description: Auth defines the information necessary to authenticate against Passbolt Server
  25373. properties:
  25374. passwordSecretRef:
  25375. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  25376. properties:
  25377. key:
  25378. description: |-
  25379. A key in the referenced Secret.
  25380. Some instances of this field may be defaulted, in others it may be required.
  25381. maxLength: 253
  25382. minLength: 1
  25383. pattern: ^[-._a-zA-Z0-9]+$
  25384. type: string
  25385. name:
  25386. description: The name of the Secret resource being referred to.
  25387. maxLength: 253
  25388. minLength: 1
  25389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25390. type: string
  25391. namespace:
  25392. description: |-
  25393. The namespace of the Secret resource being referred to.
  25394. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25395. maxLength: 63
  25396. minLength: 1
  25397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25398. type: string
  25399. type: object
  25400. privateKeySecretRef:
  25401. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  25402. properties:
  25403. key:
  25404. description: |-
  25405. A key in the referenced Secret.
  25406. Some instances of this field may be defaulted, in others it may be required.
  25407. maxLength: 253
  25408. minLength: 1
  25409. pattern: ^[-._a-zA-Z0-9]+$
  25410. type: string
  25411. name:
  25412. description: The name of the Secret resource being referred to.
  25413. maxLength: 253
  25414. minLength: 1
  25415. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25416. type: string
  25417. namespace:
  25418. description: |-
  25419. The namespace of the Secret resource being referred to.
  25420. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25421. maxLength: 63
  25422. minLength: 1
  25423. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25424. type: string
  25425. type: object
  25426. required:
  25427. - passwordSecretRef
  25428. - privateKeySecretRef
  25429. type: object
  25430. host:
  25431. description: Host defines the Passbolt Server to connect to
  25432. type: string
  25433. required:
  25434. - auth
  25435. - host
  25436. type: object
  25437. passworddepot:
  25438. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  25439. properties:
  25440. auth:
  25441. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  25442. properties:
  25443. secretRef:
  25444. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  25445. properties:
  25446. credentials:
  25447. description: Username / Password is used for authentication.
  25448. properties:
  25449. key:
  25450. description: |-
  25451. A key in the referenced Secret.
  25452. Some instances of this field may be defaulted, in others it may be required.
  25453. maxLength: 253
  25454. minLength: 1
  25455. pattern: ^[-._a-zA-Z0-9]+$
  25456. type: string
  25457. name:
  25458. description: The name of the Secret resource being referred to.
  25459. maxLength: 253
  25460. minLength: 1
  25461. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25462. type: string
  25463. namespace:
  25464. description: |-
  25465. The namespace of the Secret resource being referred to.
  25466. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25467. maxLength: 63
  25468. minLength: 1
  25469. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25470. type: string
  25471. type: object
  25472. type: object
  25473. required:
  25474. - secretRef
  25475. type: object
  25476. database:
  25477. description: Database to use as source
  25478. type: string
  25479. host:
  25480. description: URL configures the Password Depot instance URL.
  25481. type: string
  25482. required:
  25483. - auth
  25484. - database
  25485. - host
  25486. type: object
  25487. previder:
  25488. description: Previder configures this store to sync secrets using the Previder provider
  25489. properties:
  25490. auth:
  25491. description: PreviderAuth contains a secretRef for credentials.
  25492. properties:
  25493. secretRef:
  25494. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  25495. properties:
  25496. accessToken:
  25497. description: The AccessToken is used for authentication
  25498. properties:
  25499. key:
  25500. description: |-
  25501. A key in the referenced Secret.
  25502. Some instances of this field may be defaulted, in others it may be required.
  25503. maxLength: 253
  25504. minLength: 1
  25505. pattern: ^[-._a-zA-Z0-9]+$
  25506. type: string
  25507. name:
  25508. description: The name of the Secret resource being referred to.
  25509. maxLength: 253
  25510. minLength: 1
  25511. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25512. type: string
  25513. namespace:
  25514. description: |-
  25515. The namespace of the Secret resource being referred to.
  25516. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25517. maxLength: 63
  25518. minLength: 1
  25519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25520. type: string
  25521. type: object
  25522. required:
  25523. - accessToken
  25524. type: object
  25525. type: object
  25526. baseUri:
  25527. type: string
  25528. required:
  25529. - auth
  25530. type: object
  25531. pulumi:
  25532. description: Pulumi configures this store to sync secrets using the Pulumi provider
  25533. properties:
  25534. accessToken:
  25535. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  25536. properties:
  25537. secretRef:
  25538. description: SecretRef is a reference to a secret containing the Pulumi API token.
  25539. properties:
  25540. key:
  25541. description: |-
  25542. A key in the referenced Secret.
  25543. Some instances of this field may be defaulted, in others it may be required.
  25544. maxLength: 253
  25545. minLength: 1
  25546. pattern: ^[-._a-zA-Z0-9]+$
  25547. type: string
  25548. name:
  25549. description: The name of the Secret resource being referred to.
  25550. maxLength: 253
  25551. minLength: 1
  25552. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25553. type: string
  25554. namespace:
  25555. description: |-
  25556. The namespace of the Secret resource being referred to.
  25557. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25558. maxLength: 63
  25559. minLength: 1
  25560. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25561. type: string
  25562. type: object
  25563. type: object
  25564. apiUrl:
  25565. default: https://api.pulumi.com/api/esc
  25566. description: APIURL is the URL of the Pulumi API.
  25567. type: string
  25568. environment:
  25569. description: |-
  25570. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  25571. dynamically retrieved values from supported providers including all major clouds,
  25572. and other Pulumi ESC environments.
  25573. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  25574. type: string
  25575. organization:
  25576. description: |-
  25577. Organization are a space to collaborate on shared projects and stacks.
  25578. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  25579. type: string
  25580. project:
  25581. description: Project is the name of the Pulumi ESC project the environment belongs to.
  25582. type: string
  25583. required:
  25584. - accessToken
  25585. - environment
  25586. - organization
  25587. - project
  25588. type: object
  25589. scaleway:
  25590. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  25591. properties:
  25592. accessKey:
  25593. description: AccessKey is the non-secret part of the api key.
  25594. properties:
  25595. secretRef:
  25596. description: SecretRef references a key in a secret that will be used as value.
  25597. properties:
  25598. key:
  25599. description: |-
  25600. A key in the referenced Secret.
  25601. Some instances of this field may be defaulted, in others it may be required.
  25602. maxLength: 253
  25603. minLength: 1
  25604. pattern: ^[-._a-zA-Z0-9]+$
  25605. type: string
  25606. name:
  25607. description: The name of the Secret resource being referred to.
  25608. maxLength: 253
  25609. minLength: 1
  25610. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25611. type: string
  25612. namespace:
  25613. description: |-
  25614. The namespace of the Secret resource being referred to.
  25615. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25616. maxLength: 63
  25617. minLength: 1
  25618. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25619. type: string
  25620. type: object
  25621. value:
  25622. description: Value can be specified directly to set a value without using a secret.
  25623. type: string
  25624. type: object
  25625. apiUrl:
  25626. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  25627. type: string
  25628. projectId:
  25629. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  25630. type: string
  25631. region:
  25632. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  25633. type: string
  25634. secretKey:
  25635. description: SecretKey is the non-secret part of the api key.
  25636. properties:
  25637. secretRef:
  25638. description: SecretRef references a key in a secret that will be used as value.
  25639. properties:
  25640. key:
  25641. description: |-
  25642. A key in the referenced Secret.
  25643. Some instances of this field may be defaulted, in others it may be required.
  25644. maxLength: 253
  25645. minLength: 1
  25646. pattern: ^[-._a-zA-Z0-9]+$
  25647. type: string
  25648. name:
  25649. description: The name of the Secret resource being referred to.
  25650. maxLength: 253
  25651. minLength: 1
  25652. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25653. type: string
  25654. namespace:
  25655. description: |-
  25656. The namespace of the Secret resource being referred to.
  25657. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25658. maxLength: 63
  25659. minLength: 1
  25660. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25661. type: string
  25662. type: object
  25663. value:
  25664. description: Value can be specified directly to set a value without using a secret.
  25665. type: string
  25666. type: object
  25667. required:
  25668. - accessKey
  25669. - projectId
  25670. - region
  25671. - secretKey
  25672. type: object
  25673. secretserver:
  25674. description: |-
  25675. SecretServer configures this store to sync secrets using SecretServer provider
  25676. https://docs.delinea.com/online-help/secret-server/start.htm
  25677. properties:
  25678. password:
  25679. description: Password is the secret server account password.
  25680. properties:
  25681. secretRef:
  25682. description: SecretRef references a key in a secret that will be used as value.
  25683. properties:
  25684. key:
  25685. description: |-
  25686. A key in the referenced Secret.
  25687. Some instances of this field may be defaulted, in others it may be required.
  25688. maxLength: 253
  25689. minLength: 1
  25690. pattern: ^[-._a-zA-Z0-9]+$
  25691. type: string
  25692. name:
  25693. description: The name of the Secret resource being referred to.
  25694. maxLength: 253
  25695. minLength: 1
  25696. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25697. type: string
  25698. namespace:
  25699. description: |-
  25700. The namespace of the Secret resource being referred to.
  25701. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25702. maxLength: 63
  25703. minLength: 1
  25704. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25705. type: string
  25706. type: object
  25707. value:
  25708. description: Value can be specified directly to set a value without using a secret.
  25709. type: string
  25710. type: object
  25711. serverURL:
  25712. description: |-
  25713. ServerURL
  25714. URL to your secret server installation
  25715. type: string
  25716. username:
  25717. description: Username is the secret server account username.
  25718. properties:
  25719. secretRef:
  25720. description: SecretRef references a key in a secret that will be used as value.
  25721. properties:
  25722. key:
  25723. description: |-
  25724. A key in the referenced Secret.
  25725. Some instances of this field may be defaulted, in others it may be required.
  25726. maxLength: 253
  25727. minLength: 1
  25728. pattern: ^[-._a-zA-Z0-9]+$
  25729. type: string
  25730. name:
  25731. description: The name of the Secret resource being referred to.
  25732. maxLength: 253
  25733. minLength: 1
  25734. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25735. type: string
  25736. namespace:
  25737. description: |-
  25738. The namespace of the Secret resource being referred to.
  25739. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25740. maxLength: 63
  25741. minLength: 1
  25742. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25743. type: string
  25744. type: object
  25745. value:
  25746. description: Value can be specified directly to set a value without using a secret.
  25747. type: string
  25748. type: object
  25749. required:
  25750. - password
  25751. - serverURL
  25752. - username
  25753. type: object
  25754. senhasegura:
  25755. description: Senhasegura configures this store to sync secrets using senhasegura provider
  25756. properties:
  25757. auth:
  25758. description: Auth defines parameters to authenticate in senhasegura
  25759. properties:
  25760. clientId:
  25761. type: string
  25762. clientSecretSecretRef:
  25763. description: |-
  25764. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25765. In some instances, `key` is a required field.
  25766. properties:
  25767. key:
  25768. description: |-
  25769. A key in the referenced Secret.
  25770. Some instances of this field may be defaulted, in others it may be required.
  25771. maxLength: 253
  25772. minLength: 1
  25773. pattern: ^[-._a-zA-Z0-9]+$
  25774. type: string
  25775. name:
  25776. description: The name of the Secret resource being referred to.
  25777. maxLength: 253
  25778. minLength: 1
  25779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25780. type: string
  25781. namespace:
  25782. description: |-
  25783. The namespace of the Secret resource being referred to.
  25784. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25785. maxLength: 63
  25786. minLength: 1
  25787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25788. type: string
  25789. type: object
  25790. required:
  25791. - clientId
  25792. - clientSecretSecretRef
  25793. type: object
  25794. ignoreSslCertificate:
  25795. default: false
  25796. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  25797. type: boolean
  25798. module:
  25799. description: Module defines which senhasegura module should be used to get secrets
  25800. type: string
  25801. url:
  25802. description: URL of senhasegura
  25803. type: string
  25804. required:
  25805. - auth
  25806. - module
  25807. - url
  25808. type: object
  25809. vault:
  25810. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  25811. properties:
  25812. auth:
  25813. description: Auth configures how secret-manager authenticates with the Vault server.
  25814. properties:
  25815. appRole:
  25816. description: |-
  25817. AppRole authenticates with Vault using the App Role auth mechanism,
  25818. with the role and secret stored in a Kubernetes Secret resource.
  25819. properties:
  25820. path:
  25821. default: approle
  25822. description: |-
  25823. Path where the App Role authentication backend is mounted
  25824. in Vault, e.g: "approle"
  25825. type: string
  25826. roleId:
  25827. description: |-
  25828. RoleID configured in the App Role authentication backend when setting
  25829. up the authentication backend in Vault.
  25830. type: string
  25831. roleRef:
  25832. description: |-
  25833. Reference to a key in a Secret that contains the App Role ID used
  25834. to authenticate with Vault.
  25835. The `key` field must be specified and denotes which entry within the Secret
  25836. resource is used as the app role id.
  25837. properties:
  25838. key:
  25839. description: |-
  25840. A key in the referenced Secret.
  25841. Some instances of this field may be defaulted, in others it may be required.
  25842. maxLength: 253
  25843. minLength: 1
  25844. pattern: ^[-._a-zA-Z0-9]+$
  25845. type: string
  25846. name:
  25847. description: The name of the Secret resource being referred to.
  25848. maxLength: 253
  25849. minLength: 1
  25850. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25851. type: string
  25852. namespace:
  25853. description: |-
  25854. The namespace of the Secret resource being referred to.
  25855. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25856. maxLength: 63
  25857. minLength: 1
  25858. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25859. type: string
  25860. type: object
  25861. secretRef:
  25862. description: |-
  25863. Reference to a key in a Secret that contains the App Role secret used
  25864. to authenticate with Vault.
  25865. The `key` field must be specified and denotes which entry within the Secret
  25866. resource is used as the app role secret.
  25867. properties:
  25868. key:
  25869. description: |-
  25870. A key in the referenced Secret.
  25871. Some instances of this field may be defaulted, in others it may be required.
  25872. maxLength: 253
  25873. minLength: 1
  25874. pattern: ^[-._a-zA-Z0-9]+$
  25875. type: string
  25876. name:
  25877. description: The name of the Secret resource being referred to.
  25878. maxLength: 253
  25879. minLength: 1
  25880. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25881. type: string
  25882. namespace:
  25883. description: |-
  25884. The namespace of the Secret resource being referred to.
  25885. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25886. maxLength: 63
  25887. minLength: 1
  25888. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25889. type: string
  25890. type: object
  25891. required:
  25892. - path
  25893. - secretRef
  25894. type: object
  25895. cert:
  25896. description: |-
  25897. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  25898. Cert authentication method
  25899. properties:
  25900. clientCert:
  25901. description: |-
  25902. ClientCert is a certificate to authenticate using the Cert Vault
  25903. authentication method
  25904. properties:
  25905. key:
  25906. description: |-
  25907. A key in the referenced Secret.
  25908. Some instances of this field may be defaulted, in others it may be required.
  25909. maxLength: 253
  25910. minLength: 1
  25911. pattern: ^[-._a-zA-Z0-9]+$
  25912. type: string
  25913. name:
  25914. description: The name of the Secret resource being referred to.
  25915. maxLength: 253
  25916. minLength: 1
  25917. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25918. type: string
  25919. namespace:
  25920. description: |-
  25921. The namespace of the Secret resource being referred to.
  25922. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25923. maxLength: 63
  25924. minLength: 1
  25925. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25926. type: string
  25927. type: object
  25928. secretRef:
  25929. description: |-
  25930. SecretRef to a key in a Secret resource containing client private key to
  25931. authenticate with Vault using the Cert authentication method
  25932. properties:
  25933. key:
  25934. description: |-
  25935. A key in the referenced Secret.
  25936. Some instances of this field may be defaulted, in others it may be required.
  25937. maxLength: 253
  25938. minLength: 1
  25939. pattern: ^[-._a-zA-Z0-9]+$
  25940. type: string
  25941. name:
  25942. description: The name of the Secret resource being referred to.
  25943. maxLength: 253
  25944. minLength: 1
  25945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25946. type: string
  25947. namespace:
  25948. description: |-
  25949. The namespace of the Secret resource being referred to.
  25950. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25951. maxLength: 63
  25952. minLength: 1
  25953. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25954. type: string
  25955. type: object
  25956. type: object
  25957. iam:
  25958. description: |-
  25959. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  25960. AWS IAM authentication method
  25961. properties:
  25962. externalID:
  25963. description: AWS External ID set on assumed IAM roles
  25964. type: string
  25965. jwt:
  25966. description: Specify a service account with IRSA enabled
  25967. properties:
  25968. serviceAccountRef:
  25969. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  25970. properties:
  25971. audiences:
  25972. description: |-
  25973. Audience specifies the `aud` claim for the service account token
  25974. Some providers automatically extend the audience field based on well-known annotations for workload
  25975. identity (e.g. IRSA or GCP Workload Identity)
  25976. items:
  25977. type: string
  25978. type: array
  25979. name:
  25980. description: The name of the ServiceAccount resource being referred to.
  25981. maxLength: 253
  25982. minLength: 1
  25983. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25984. type: string
  25985. namespace:
  25986. description: |-
  25987. Namespace of the resource being referred to.
  25988. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25989. maxLength: 63
  25990. minLength: 1
  25991. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25992. type: string
  25993. required:
  25994. - name
  25995. type: object
  25996. type: object
  25997. path:
  25998. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  25999. type: string
  26000. region:
  26001. description: AWS region
  26002. type: string
  26003. role:
  26004. description: This is the AWS role to be assumed before talking to vault
  26005. type: string
  26006. secretRef:
  26007. description: Specify credentials in a Secret object
  26008. properties:
  26009. accessKeyIDSecretRef:
  26010. description: The AccessKeyID is used for authentication
  26011. properties:
  26012. key:
  26013. description: |-
  26014. A key in the referenced Secret.
  26015. Some instances of this field may be defaulted, in others it may be required.
  26016. maxLength: 253
  26017. minLength: 1
  26018. pattern: ^[-._a-zA-Z0-9]+$
  26019. type: string
  26020. name:
  26021. description: The name of the Secret resource being referred to.
  26022. maxLength: 253
  26023. minLength: 1
  26024. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26025. type: string
  26026. namespace:
  26027. description: |-
  26028. The namespace of the Secret resource being referred to.
  26029. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26030. maxLength: 63
  26031. minLength: 1
  26032. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26033. type: string
  26034. type: object
  26035. secretAccessKeySecretRef:
  26036. description: The SecretAccessKey is used for authentication
  26037. properties:
  26038. key:
  26039. description: |-
  26040. A key in the referenced Secret.
  26041. Some instances of this field may be defaulted, in others it may be required.
  26042. maxLength: 253
  26043. minLength: 1
  26044. pattern: ^[-._a-zA-Z0-9]+$
  26045. type: string
  26046. name:
  26047. description: The name of the Secret resource being referred to.
  26048. maxLength: 253
  26049. minLength: 1
  26050. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26051. type: string
  26052. namespace:
  26053. description: |-
  26054. The namespace of the Secret resource being referred to.
  26055. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26056. maxLength: 63
  26057. minLength: 1
  26058. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26059. type: string
  26060. type: object
  26061. sessionTokenSecretRef:
  26062. description: |-
  26063. The SessionToken used for authentication
  26064. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  26065. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  26066. properties:
  26067. key:
  26068. description: |-
  26069. A key in the referenced Secret.
  26070. Some instances of this field may be defaulted, in others it may be required.
  26071. maxLength: 253
  26072. minLength: 1
  26073. pattern: ^[-._a-zA-Z0-9]+$
  26074. type: string
  26075. name:
  26076. description: The name of the Secret resource being referred to.
  26077. maxLength: 253
  26078. minLength: 1
  26079. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26080. type: string
  26081. namespace:
  26082. description: |-
  26083. The namespace of the Secret resource being referred to.
  26084. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26085. maxLength: 63
  26086. minLength: 1
  26087. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26088. type: string
  26089. type: object
  26090. type: object
  26091. vaultAwsIamServerID:
  26092. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  26093. type: string
  26094. vaultRole:
  26095. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  26096. type: string
  26097. required:
  26098. - vaultRole
  26099. type: object
  26100. jwt:
  26101. description: |-
  26102. Jwt authenticates with Vault by passing role and JWT token using the
  26103. JWT/OIDC authentication method
  26104. properties:
  26105. kubernetesServiceAccountToken:
  26106. description: |-
  26107. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  26108. a token for with the `TokenRequest` API.
  26109. properties:
  26110. audiences:
  26111. description: |-
  26112. Optional audiences field that will be used to request a temporary Kubernetes service
  26113. account token for the service account referenced by `serviceAccountRef`.
  26114. Defaults to a single audience `vault` it not specified.
  26115. Deprecated: use serviceAccountRef.Audiences instead
  26116. items:
  26117. type: string
  26118. type: array
  26119. expirationSeconds:
  26120. description: |-
  26121. Optional expiration time in seconds that will be used to request a temporary
  26122. Kubernetes service account token for the service account referenced by
  26123. `serviceAccountRef`.
  26124. Deprecated: this will be removed in the future.
  26125. Defaults to 10 minutes.
  26126. format: int64
  26127. type: integer
  26128. serviceAccountRef:
  26129. description: Service account field containing the name of a kubernetes ServiceAccount.
  26130. properties:
  26131. audiences:
  26132. description: |-
  26133. Audience specifies the `aud` claim for the service account token
  26134. Some providers automatically extend the audience field based on well-known annotations for workload
  26135. identity (e.g. IRSA or GCP Workload Identity)
  26136. items:
  26137. type: string
  26138. type: array
  26139. name:
  26140. description: The name of the ServiceAccount resource being referred to.
  26141. maxLength: 253
  26142. minLength: 1
  26143. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26144. type: string
  26145. namespace:
  26146. description: |-
  26147. Namespace of the resource being referred to.
  26148. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26149. maxLength: 63
  26150. minLength: 1
  26151. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26152. type: string
  26153. required:
  26154. - name
  26155. type: object
  26156. required:
  26157. - serviceAccountRef
  26158. type: object
  26159. path:
  26160. default: jwt
  26161. description: |-
  26162. Path where the JWT authentication backend is mounted
  26163. in Vault, e.g: "jwt"
  26164. type: string
  26165. role:
  26166. description: |-
  26167. Role is a JWT role to authenticate using the JWT/OIDC Vault
  26168. authentication method
  26169. type: string
  26170. secretRef:
  26171. description: |-
  26172. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  26173. authenticate with Vault using the JWT/OIDC authentication method.
  26174. properties:
  26175. key:
  26176. description: |-
  26177. A key in the referenced Secret.
  26178. Some instances of this field may be defaulted, in others it may be required.
  26179. maxLength: 253
  26180. minLength: 1
  26181. pattern: ^[-._a-zA-Z0-9]+$
  26182. type: string
  26183. name:
  26184. description: The name of the Secret resource being referred to.
  26185. maxLength: 253
  26186. minLength: 1
  26187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26188. type: string
  26189. namespace:
  26190. description: |-
  26191. The namespace of the Secret resource being referred to.
  26192. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26193. maxLength: 63
  26194. minLength: 1
  26195. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26196. type: string
  26197. type: object
  26198. required:
  26199. - path
  26200. type: object
  26201. kubernetes:
  26202. description: |-
  26203. Kubernetes authenticates with Vault by passing the ServiceAccount
  26204. token stored in the named Secret resource to the Vault server.
  26205. properties:
  26206. mountPath:
  26207. default: kubernetes
  26208. description: |-
  26209. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  26210. "kubernetes"
  26211. type: string
  26212. role:
  26213. description: |-
  26214. A required field containing the Vault Role to assume. A Role binds a
  26215. Kubernetes ServiceAccount with a set of Vault policies.
  26216. type: string
  26217. secretRef:
  26218. description: |-
  26219. Optional secret field containing a Kubernetes ServiceAccount JWT used
  26220. for authenticating with Vault. If a name is specified without a key,
  26221. `token` is the default. If one is not specified, the one bound to
  26222. the controller will be used.
  26223. properties:
  26224. key:
  26225. description: |-
  26226. A key in the referenced Secret.
  26227. Some instances of this field may be defaulted, in others it may be required.
  26228. maxLength: 253
  26229. minLength: 1
  26230. pattern: ^[-._a-zA-Z0-9]+$
  26231. type: string
  26232. name:
  26233. description: The name of the Secret resource being referred to.
  26234. maxLength: 253
  26235. minLength: 1
  26236. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26237. type: string
  26238. namespace:
  26239. description: |-
  26240. The namespace of the Secret resource being referred to.
  26241. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26242. maxLength: 63
  26243. minLength: 1
  26244. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26245. type: string
  26246. type: object
  26247. serviceAccountRef:
  26248. description: |-
  26249. Optional service account field containing the name of a kubernetes ServiceAccount.
  26250. If the service account is specified, the service account secret token JWT will be used
  26251. for authenticating with Vault. If the service account selector is not supplied,
  26252. the secretRef will be used instead.
  26253. properties:
  26254. audiences:
  26255. description: |-
  26256. Audience specifies the `aud` claim for the service account token
  26257. Some providers automatically extend the audience field based on well-known annotations for workload
  26258. identity (e.g. IRSA or GCP Workload Identity)
  26259. items:
  26260. type: string
  26261. type: array
  26262. name:
  26263. description: The name of the ServiceAccount resource being referred to.
  26264. maxLength: 253
  26265. minLength: 1
  26266. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26267. type: string
  26268. namespace:
  26269. description: |-
  26270. Namespace of the resource being referred to.
  26271. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26272. maxLength: 63
  26273. minLength: 1
  26274. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26275. type: string
  26276. required:
  26277. - name
  26278. type: object
  26279. required:
  26280. - mountPath
  26281. - role
  26282. type: object
  26283. ldap:
  26284. description: |-
  26285. Ldap authenticates with Vault by passing username/password pair using
  26286. the LDAP authentication method
  26287. properties:
  26288. path:
  26289. default: ldap
  26290. description: |-
  26291. Path where the LDAP authentication backend is mounted
  26292. in Vault, e.g: "ldap"
  26293. type: string
  26294. secretRef:
  26295. description: |-
  26296. SecretRef to a key in a Secret resource containing password for the LDAP
  26297. user used to authenticate with Vault using the LDAP authentication
  26298. method
  26299. properties:
  26300. key:
  26301. description: |-
  26302. A key in the referenced Secret.
  26303. Some instances of this field may be defaulted, in others it may be required.
  26304. maxLength: 253
  26305. minLength: 1
  26306. pattern: ^[-._a-zA-Z0-9]+$
  26307. type: string
  26308. name:
  26309. description: The name of the Secret resource being referred to.
  26310. maxLength: 253
  26311. minLength: 1
  26312. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26313. type: string
  26314. namespace:
  26315. description: |-
  26316. The namespace of the Secret resource being referred to.
  26317. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26318. maxLength: 63
  26319. minLength: 1
  26320. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26321. type: string
  26322. type: object
  26323. username:
  26324. description: |-
  26325. Username is an LDAP username used to authenticate using the LDAP Vault
  26326. authentication method
  26327. type: string
  26328. required:
  26329. - path
  26330. - username
  26331. type: object
  26332. namespace:
  26333. description: |-
  26334. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  26335. Namespaces is a set of features within Vault Enterprise that allows
  26336. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  26337. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  26338. This will default to Vault.Namespace field if set, or empty otherwise
  26339. type: string
  26340. tokenSecretRef:
  26341. description: TokenSecretRef authenticates with Vault by presenting a token.
  26342. properties:
  26343. key:
  26344. description: |-
  26345. A key in the referenced Secret.
  26346. Some instances of this field may be defaulted, in others it may be required.
  26347. maxLength: 253
  26348. minLength: 1
  26349. pattern: ^[-._a-zA-Z0-9]+$
  26350. type: string
  26351. name:
  26352. description: The name of the Secret resource being referred to.
  26353. maxLength: 253
  26354. minLength: 1
  26355. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26356. type: string
  26357. namespace:
  26358. description: |-
  26359. The namespace of the Secret resource being referred to.
  26360. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26361. maxLength: 63
  26362. minLength: 1
  26363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26364. type: string
  26365. type: object
  26366. userPass:
  26367. description: UserPass authenticates with Vault by passing username/password pair
  26368. properties:
  26369. path:
  26370. default: userpass
  26371. description: |-
  26372. Path where the UserPassword authentication backend is mounted
  26373. in Vault, e.g: "userpass"
  26374. type: string
  26375. secretRef:
  26376. description: |-
  26377. SecretRef to a key in a Secret resource containing password for the
  26378. user used to authenticate with Vault using the UserPass authentication
  26379. method
  26380. properties:
  26381. key:
  26382. description: |-
  26383. A key in the referenced Secret.
  26384. Some instances of this field may be defaulted, in others it may be required.
  26385. maxLength: 253
  26386. minLength: 1
  26387. pattern: ^[-._a-zA-Z0-9]+$
  26388. type: string
  26389. name:
  26390. description: The name of the Secret resource being referred to.
  26391. maxLength: 253
  26392. minLength: 1
  26393. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26394. type: string
  26395. namespace:
  26396. description: |-
  26397. The namespace of the Secret resource being referred to.
  26398. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26399. maxLength: 63
  26400. minLength: 1
  26401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26402. type: string
  26403. type: object
  26404. username:
  26405. description: |-
  26406. Username is a username used to authenticate using the UserPass Vault
  26407. authentication method
  26408. type: string
  26409. required:
  26410. - path
  26411. - username
  26412. type: object
  26413. type: object
  26414. caBundle:
  26415. description: |-
  26416. PEM encoded CA bundle used to validate Vault server certificate. Only used
  26417. if the Server URL is using HTTPS protocol. This parameter is ignored for
  26418. plain HTTP protocol connection. If not set the system root certificates
  26419. are used to validate the TLS connection.
  26420. format: byte
  26421. type: string
  26422. caProvider:
  26423. description: The provider for the CA bundle to use to validate Vault server certificate.
  26424. properties:
  26425. key:
  26426. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26427. maxLength: 253
  26428. minLength: 1
  26429. pattern: ^[-._a-zA-Z0-9]+$
  26430. type: string
  26431. name:
  26432. description: The name of the object located at the provider type.
  26433. maxLength: 253
  26434. minLength: 1
  26435. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26436. type: string
  26437. namespace:
  26438. description: |-
  26439. The namespace the Provider type is in.
  26440. Can only be defined when used in a ClusterSecretStore.
  26441. maxLength: 63
  26442. minLength: 1
  26443. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26444. type: string
  26445. type:
  26446. description: The type of provider to use such as "Secret", or "ConfigMap".
  26447. enum:
  26448. - Secret
  26449. - ConfigMap
  26450. type: string
  26451. required:
  26452. - name
  26453. - type
  26454. type: object
  26455. forwardInconsistent:
  26456. description: |-
  26457. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  26458. leader instead of simply retrying within a loop. This can increase performance if
  26459. the option is enabled serverside.
  26460. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  26461. type: boolean
  26462. headers:
  26463. additionalProperties:
  26464. type: string
  26465. description: Headers to be added in Vault request
  26466. type: object
  26467. namespace:
  26468. description: |-
  26469. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  26470. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  26471. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  26472. type: string
  26473. path:
  26474. description: |-
  26475. Path is the mount path of the Vault KV backend endpoint, e.g:
  26476. "secret". The v2 KV secret engine version specific "/data" path suffix
  26477. for fetching secrets from Vault is optional and will be appended
  26478. if not present in specified path.
  26479. type: string
  26480. readYourWrites:
  26481. description: |-
  26482. ReadYourWrites ensures isolated read-after-write semantics by
  26483. providing discovered cluster replication states in each request.
  26484. More information about eventual consistency in Vault can be found here
  26485. https://www.vaultproject.io/docs/enterprise/consistency
  26486. type: boolean
  26487. server:
  26488. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  26489. type: string
  26490. tls:
  26491. description: |-
  26492. The configuration used for client side related TLS communication, when the Vault server
  26493. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  26494. This parameter is ignored for plain HTTP protocol connection.
  26495. It's worth noting this configuration is different from the "TLS certificates auth method",
  26496. which is available under the `auth.cert` section.
  26497. properties:
  26498. certSecretRef:
  26499. description: |-
  26500. CertSecretRef is a certificate added to the transport layer
  26501. when communicating with the Vault server.
  26502. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  26503. properties:
  26504. key:
  26505. description: |-
  26506. A key in the referenced Secret.
  26507. Some instances of this field may be defaulted, in others it may be required.
  26508. maxLength: 253
  26509. minLength: 1
  26510. pattern: ^[-._a-zA-Z0-9]+$
  26511. type: string
  26512. name:
  26513. description: The name of the Secret resource being referred to.
  26514. maxLength: 253
  26515. minLength: 1
  26516. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26517. type: string
  26518. namespace:
  26519. description: |-
  26520. The namespace of the Secret resource being referred to.
  26521. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26522. maxLength: 63
  26523. minLength: 1
  26524. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26525. type: string
  26526. type: object
  26527. keySecretRef:
  26528. description: |-
  26529. KeySecretRef to a key in a Secret resource containing client private key
  26530. added to the transport layer when communicating with the Vault server.
  26531. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  26532. properties:
  26533. key:
  26534. description: |-
  26535. A key in the referenced Secret.
  26536. Some instances of this field may be defaulted, in others it may be required.
  26537. maxLength: 253
  26538. minLength: 1
  26539. pattern: ^[-._a-zA-Z0-9]+$
  26540. type: string
  26541. name:
  26542. description: The name of the Secret resource being referred to.
  26543. maxLength: 253
  26544. minLength: 1
  26545. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26546. type: string
  26547. namespace:
  26548. description: |-
  26549. The namespace of the Secret resource being referred to.
  26550. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26551. maxLength: 63
  26552. minLength: 1
  26553. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26554. type: string
  26555. type: object
  26556. type: object
  26557. version:
  26558. default: v2
  26559. description: |-
  26560. Version is the Vault KV secret engine version. This can be either "v1" or
  26561. "v2". Version defaults to "v2".
  26562. enum:
  26563. - v1
  26564. - v2
  26565. type: string
  26566. required:
  26567. - server
  26568. type: object
  26569. webhook:
  26570. description: Webhook configures this store to sync secrets using a generic templated webhook
  26571. properties:
  26572. auth:
  26573. description: Auth specifies a authorization protocol. Only one protocol may be set.
  26574. maxProperties: 1
  26575. minProperties: 1
  26576. properties:
  26577. ntlm:
  26578. description: NTLMProtocol configures the store to use NTLM for auth
  26579. properties:
  26580. passwordSecret:
  26581. description: |-
  26582. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26583. In some instances, `key` is a required field.
  26584. properties:
  26585. key:
  26586. description: |-
  26587. A key in the referenced Secret.
  26588. Some instances of this field may be defaulted, in others it may be required.
  26589. maxLength: 253
  26590. minLength: 1
  26591. pattern: ^[-._a-zA-Z0-9]+$
  26592. type: string
  26593. name:
  26594. description: The name of the Secret resource being referred to.
  26595. maxLength: 253
  26596. minLength: 1
  26597. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26598. type: string
  26599. namespace:
  26600. description: |-
  26601. The namespace of the Secret resource being referred to.
  26602. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26603. maxLength: 63
  26604. minLength: 1
  26605. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26606. type: string
  26607. type: object
  26608. usernameSecret:
  26609. description: |-
  26610. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26611. In some instances, `key` is a required field.
  26612. properties:
  26613. key:
  26614. description: |-
  26615. A key in the referenced Secret.
  26616. Some instances of this field may be defaulted, in others it may be required.
  26617. maxLength: 253
  26618. minLength: 1
  26619. pattern: ^[-._a-zA-Z0-9]+$
  26620. type: string
  26621. name:
  26622. description: The name of the Secret resource being referred to.
  26623. maxLength: 253
  26624. minLength: 1
  26625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26626. type: string
  26627. namespace:
  26628. description: |-
  26629. The namespace of the Secret resource being referred to.
  26630. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26631. maxLength: 63
  26632. minLength: 1
  26633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26634. type: string
  26635. type: object
  26636. required:
  26637. - passwordSecret
  26638. - usernameSecret
  26639. type: object
  26640. type: object
  26641. body:
  26642. description: Body
  26643. type: string
  26644. caBundle:
  26645. description: |-
  26646. PEM encoded CA bundle used to validate webhook server certificate. Only used
  26647. if the Server URL is using HTTPS protocol. This parameter is ignored for
  26648. plain HTTP protocol connection. If not set the system root certificates
  26649. are used to validate the TLS connection.
  26650. format: byte
  26651. type: string
  26652. caProvider:
  26653. description: The provider for the CA bundle to use to validate webhook server certificate.
  26654. properties:
  26655. key:
  26656. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26657. maxLength: 253
  26658. minLength: 1
  26659. pattern: ^[-._a-zA-Z0-9]+$
  26660. type: string
  26661. name:
  26662. description: The name of the object located at the provider type.
  26663. maxLength: 253
  26664. minLength: 1
  26665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26666. type: string
  26667. namespace:
  26668. description: The namespace the Provider type is in.
  26669. maxLength: 63
  26670. minLength: 1
  26671. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26672. type: string
  26673. type:
  26674. description: The type of provider to use such as "Secret", or "ConfigMap".
  26675. enum:
  26676. - Secret
  26677. - ConfigMap
  26678. type: string
  26679. required:
  26680. - name
  26681. - type
  26682. type: object
  26683. headers:
  26684. additionalProperties:
  26685. type: string
  26686. description: Headers
  26687. type: object
  26688. method:
  26689. description: Webhook Method
  26690. type: string
  26691. result:
  26692. description: Result formatting
  26693. properties:
  26694. jsonPath:
  26695. description: Json path of return value
  26696. type: string
  26697. type: object
  26698. secrets:
  26699. description: |-
  26700. Secrets to fill in templates
  26701. These secrets will be passed to the templating function as key value pairs under the given name
  26702. items:
  26703. description: WebhookSecret defines a secret to be used in webhook templates.
  26704. properties:
  26705. name:
  26706. description: Name of this secret in templates
  26707. type: string
  26708. secretRef:
  26709. description: Secret ref to fill in credentials
  26710. properties:
  26711. key:
  26712. description: |-
  26713. A key in the referenced Secret.
  26714. Some instances of this field may be defaulted, in others it may be required.
  26715. maxLength: 253
  26716. minLength: 1
  26717. pattern: ^[-._a-zA-Z0-9]+$
  26718. type: string
  26719. name:
  26720. description: The name of the Secret resource being referred to.
  26721. maxLength: 253
  26722. minLength: 1
  26723. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26724. type: string
  26725. namespace:
  26726. description: |-
  26727. The namespace of the Secret resource being referred to.
  26728. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26729. maxLength: 63
  26730. minLength: 1
  26731. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26732. type: string
  26733. type: object
  26734. required:
  26735. - name
  26736. - secretRef
  26737. type: object
  26738. type: array
  26739. timeout:
  26740. description: Timeout
  26741. type: string
  26742. url:
  26743. description: Webhook url to call
  26744. type: string
  26745. required:
  26746. - result
  26747. - url
  26748. type: object
  26749. yandexcertificatemanager:
  26750. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  26751. properties:
  26752. apiEndpoint:
  26753. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  26754. type: string
  26755. auth:
  26756. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  26757. properties:
  26758. authorizedKeySecretRef:
  26759. description: The authorized key used for authentication
  26760. properties:
  26761. key:
  26762. description: |-
  26763. A key in the referenced Secret.
  26764. Some instances of this field may be defaulted, in others it may be required.
  26765. maxLength: 253
  26766. minLength: 1
  26767. pattern: ^[-._a-zA-Z0-9]+$
  26768. type: string
  26769. name:
  26770. description: The name of the Secret resource being referred to.
  26771. maxLength: 253
  26772. minLength: 1
  26773. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26774. type: string
  26775. namespace:
  26776. description: |-
  26777. The namespace of the Secret resource being referred to.
  26778. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26779. maxLength: 63
  26780. minLength: 1
  26781. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26782. type: string
  26783. type: object
  26784. type: object
  26785. caProvider:
  26786. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  26787. properties:
  26788. certSecretRef:
  26789. description: |-
  26790. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26791. In some instances, `key` is a required field.
  26792. properties:
  26793. key:
  26794. description: |-
  26795. A key in the referenced Secret.
  26796. Some instances of this field may be defaulted, in others it may be required.
  26797. maxLength: 253
  26798. minLength: 1
  26799. pattern: ^[-._a-zA-Z0-9]+$
  26800. type: string
  26801. name:
  26802. description: The name of the Secret resource being referred to.
  26803. maxLength: 253
  26804. minLength: 1
  26805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26806. type: string
  26807. namespace:
  26808. description: |-
  26809. The namespace of the Secret resource being referred to.
  26810. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26811. maxLength: 63
  26812. minLength: 1
  26813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26814. type: string
  26815. type: object
  26816. type: object
  26817. required:
  26818. - auth
  26819. type: object
  26820. yandexlockbox:
  26821. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  26822. properties:
  26823. apiEndpoint:
  26824. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  26825. type: string
  26826. auth:
  26827. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  26828. properties:
  26829. authorizedKeySecretRef:
  26830. description: The authorized key used for authentication
  26831. properties:
  26832. key:
  26833. description: |-
  26834. A key in the referenced Secret.
  26835. Some instances of this field may be defaulted, in others it may be required.
  26836. maxLength: 253
  26837. minLength: 1
  26838. pattern: ^[-._a-zA-Z0-9]+$
  26839. type: string
  26840. name:
  26841. description: The name of the Secret resource being referred to.
  26842. maxLength: 253
  26843. minLength: 1
  26844. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26845. type: string
  26846. namespace:
  26847. description: |-
  26848. The namespace of the Secret resource being referred to.
  26849. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26850. maxLength: 63
  26851. minLength: 1
  26852. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26853. type: string
  26854. type: object
  26855. type: object
  26856. caProvider:
  26857. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  26858. properties:
  26859. certSecretRef:
  26860. description: |-
  26861. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26862. In some instances, `key` is a required field.
  26863. properties:
  26864. key:
  26865. description: |-
  26866. A key in the referenced Secret.
  26867. Some instances of this field may be defaulted, in others it may be required.
  26868. maxLength: 253
  26869. minLength: 1
  26870. pattern: ^[-._a-zA-Z0-9]+$
  26871. type: string
  26872. name:
  26873. description: The name of the Secret resource being referred to.
  26874. maxLength: 253
  26875. minLength: 1
  26876. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26877. type: string
  26878. namespace:
  26879. description: |-
  26880. The namespace of the Secret resource being referred to.
  26881. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26882. maxLength: 63
  26883. minLength: 1
  26884. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26885. type: string
  26886. type: object
  26887. type: object
  26888. required:
  26889. - auth
  26890. type: object
  26891. type: object
  26892. refreshInterval:
  26893. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  26894. type: integer
  26895. retrySettings:
  26896. description: Used to configure HTTP retries on failures.
  26897. properties:
  26898. maxRetries:
  26899. description: MaxRetries is the maximum number of retry attempts.
  26900. format: int32
  26901. type: integer
  26902. retryInterval:
  26903. description: RetryInterval is the interval between retry attempts.
  26904. type: string
  26905. type: object
  26906. required:
  26907. - provider
  26908. type: object
  26909. status:
  26910. description: SecretStoreStatus defines the observed state of the SecretStore.
  26911. properties:
  26912. capabilities:
  26913. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  26914. type: string
  26915. conditions:
  26916. items:
  26917. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  26918. properties:
  26919. lastTransitionTime:
  26920. format: date-time
  26921. type: string
  26922. message:
  26923. type: string
  26924. reason:
  26925. type: string
  26926. status:
  26927. type: string
  26928. type:
  26929. description: SecretStoreConditionType represents the condition type of the SecretStore.
  26930. type: string
  26931. required:
  26932. - status
  26933. - type
  26934. type: object
  26935. type: array
  26936. type: object
  26937. type: object
  26938. served: false
  26939. storage: false
  26940. subresources:
  26941. status: {}
  26942. ---
  26943. apiVersion: apiextensions.k8s.io/v1
  26944. kind: CustomResourceDefinition
  26945. metadata:
  26946. annotations:
  26947. controller-gen.kubebuilder.io/version: v0.19.0
  26948. labels:
  26949. external-secrets.io/component: controller
  26950. name: acraccesstokens.generators.external-secrets.io
  26951. spec:
  26952. group: generators.external-secrets.io
  26953. names:
  26954. categories:
  26955. - external-secrets
  26956. - external-secrets-generators
  26957. kind: ACRAccessToken
  26958. listKind: ACRAccessTokenList
  26959. plural: acraccesstokens
  26960. singular: acraccesstoken
  26961. scope: Namespaced
  26962. versions:
  26963. - name: v1alpha1
  26964. schema:
  26965. openAPIV3Schema:
  26966. description: |-
  26967. ACRAccessToken returns an Azure Container Registry token
  26968. that can be used for pushing/pulling images.
  26969. Note: by default it will return an ACR Refresh Token with full access
  26970. (depending on the identity).
  26971. This can be scoped down to the repository level using .spec.scope.
  26972. In case scope is defined it will return an ACR Access Token.
  26973. See docs: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md
  26974. properties:
  26975. apiVersion:
  26976. description: |-
  26977. APIVersion defines the versioned schema of this representation of an object.
  26978. Servers should convert recognized schemas to the latest internal value, and
  26979. may reject unrecognized values.
  26980. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  26981. type: string
  26982. kind:
  26983. description: |-
  26984. Kind is a string value representing the REST resource this object represents.
  26985. Servers may infer this from the endpoint the client submits requests to.
  26986. Cannot be updated.
  26987. In CamelCase.
  26988. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  26989. type: string
  26990. metadata:
  26991. type: object
  26992. spec:
  26993. description: |-
  26994. ACRAccessTokenSpec defines how to generate the access token
  26995. e.g. how to authenticate and which registry to use.
  26996. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  26997. properties:
  26998. auth:
  26999. description: ACRAuth defines the authentication methods for Azure Container Registry.
  27000. properties:
  27001. managedIdentity:
  27002. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  27003. properties:
  27004. identityId:
  27005. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  27006. type: string
  27007. type: object
  27008. servicePrincipal:
  27009. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  27010. properties:
  27011. secretRef:
  27012. description: |-
  27013. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  27014. It uses static credentials stored in a Kind=Secret.
  27015. properties:
  27016. clientId:
  27017. description: The Azure clientId of the service principle used for authentication.
  27018. properties:
  27019. key:
  27020. description: |-
  27021. A key in the referenced Secret.
  27022. Some instances of this field may be defaulted, in others it may be required.
  27023. maxLength: 253
  27024. minLength: 1
  27025. pattern: ^[-._a-zA-Z0-9]+$
  27026. type: string
  27027. name:
  27028. description: The name of the Secret resource being referred to.
  27029. maxLength: 253
  27030. minLength: 1
  27031. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27032. type: string
  27033. namespace:
  27034. description: |-
  27035. The namespace of the Secret resource being referred to.
  27036. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27037. maxLength: 63
  27038. minLength: 1
  27039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27040. type: string
  27041. type: object
  27042. clientSecret:
  27043. description: The Azure ClientSecret of the service principle used for authentication.
  27044. properties:
  27045. key:
  27046. description: |-
  27047. A key in the referenced Secret.
  27048. Some instances of this field may be defaulted, in others it may be required.
  27049. maxLength: 253
  27050. minLength: 1
  27051. pattern: ^[-._a-zA-Z0-9]+$
  27052. type: string
  27053. name:
  27054. description: The name of the Secret resource being referred to.
  27055. maxLength: 253
  27056. minLength: 1
  27057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27058. type: string
  27059. namespace:
  27060. description: |-
  27061. The namespace of the Secret resource being referred to.
  27062. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27063. maxLength: 63
  27064. minLength: 1
  27065. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27066. type: string
  27067. type: object
  27068. type: object
  27069. required:
  27070. - secretRef
  27071. type: object
  27072. workloadIdentity:
  27073. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  27074. properties:
  27075. serviceAccountRef:
  27076. description: |-
  27077. ServiceAccountRef specified the service account
  27078. that should be used when authenticating with WorkloadIdentity.
  27079. properties:
  27080. audiences:
  27081. description: |-
  27082. Audience specifies the `aud` claim for the service account token
  27083. Some providers automatically extend the audience field based on well-known annotations for workload
  27084. identity (e.g. IRSA or GCP Workload Identity)
  27085. items:
  27086. type: string
  27087. type: array
  27088. name:
  27089. description: The name of the ServiceAccount resource being referred to.
  27090. maxLength: 253
  27091. minLength: 1
  27092. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27093. type: string
  27094. namespace:
  27095. description: |-
  27096. Namespace of the resource being referred to.
  27097. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27098. maxLength: 63
  27099. minLength: 1
  27100. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27101. type: string
  27102. required:
  27103. - name
  27104. type: object
  27105. type: object
  27106. type: object
  27107. environmentType:
  27108. default: PublicCloud
  27109. description: |-
  27110. EnvironmentType specifies the Azure cloud environment endpoints to use for
  27111. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  27112. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  27113. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  27114. enum:
  27115. - PublicCloud
  27116. - USGovernmentCloud
  27117. - ChinaCloud
  27118. - GermanCloud
  27119. - AzureStackCloud
  27120. type: string
  27121. registry:
  27122. description: |-
  27123. the domain name of the ACR registry
  27124. e.g. foobarexample.azurecr.io
  27125. type: string
  27126. scope:
  27127. description: |-
  27128. Define the scope for the access token, e.g. pull/push access for a repository.
  27129. if not provided it will return a refresh token that has full scope.
  27130. Note: you need to pin it down to the repository level, there is no wildcard available.
  27131. examples:
  27132. repository:my-repository:pull,push
  27133. repository:my-repository:pull
  27134. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  27135. type: string
  27136. tenantId:
  27137. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  27138. type: string
  27139. required:
  27140. - auth
  27141. - registry
  27142. type: object
  27143. type: object
  27144. served: true
  27145. storage: true
  27146. subresources:
  27147. status: {}
  27148. ---
  27149. apiVersion: apiextensions.k8s.io/v1
  27150. kind: CustomResourceDefinition
  27151. metadata:
  27152. annotations:
  27153. controller-gen.kubebuilder.io/version: v0.19.0
  27154. labels:
  27155. external-secrets.io/component: controller
  27156. name: beyondtrustworkloadcredentialsdynamicsecrets.generators.external-secrets.io
  27157. spec:
  27158. group: generators.external-secrets.io
  27159. names:
  27160. categories:
  27161. - external-secrets
  27162. - external-secrets-generators
  27163. kind: BeyondtrustWorkloadCredentialsDynamicSecret
  27164. listKind: BeyondtrustWorkloadCredentialsDynamicSecretList
  27165. plural: beyondtrustworkloadcredentialsdynamicsecrets
  27166. singular: beyondtrustworkloadcredentialsdynamicsecret
  27167. scope: Namespaced
  27168. versions:
  27169. - name: v1alpha1
  27170. schema:
  27171. openAPIV3Schema:
  27172. description: |-
  27173. BeyondtrustWorkloadCredentialsDynamicSecret represents a generator that requests dynamic credentials from BeyondTrust Workload Credentials.
  27174. This generator calls the BeyondTrust Workload Credentials API to generate fresh, temporary credentials
  27175. (such as AWS STS credentials) each time an ExternalSecret is refreshed.
  27176. Dynamic secret definitions must be created in BeyondTrust Workload Credentials before they can be referenced.
  27177. For complete documentation, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27178. properties:
  27179. apiVersion:
  27180. description: |-
  27181. APIVersion defines the versioned schema of this representation of an object.
  27182. Servers should convert recognized schemas to the latest internal value, and
  27183. may reject unrecognized values.
  27184. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27185. type: string
  27186. kind:
  27187. description: |-
  27188. Kind is a string value representing the REST resource this object represents.
  27189. Servers may infer this from the endpoint the client submits requests to.
  27190. Cannot be updated.
  27191. In CamelCase.
  27192. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27193. type: string
  27194. metadata:
  27195. type: object
  27196. spec:
  27197. description: |-
  27198. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  27199. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  27200. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27201. properties:
  27202. controller:
  27203. description: |-
  27204. Controller selects the controller that should handle this generator.
  27205. Leave empty to use the default controller.
  27206. type: string
  27207. provider:
  27208. description: |-
  27209. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  27210. server connection details, and the folder path to the dynamic secret definition.
  27211. The folderPath should point to a dynamic secret definition that has been created in
  27212. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  27213. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27214. properties:
  27215. auth:
  27216. description: |-
  27217. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  27218. Currently supports API key authentication via Kubernetes secret reference.
  27219. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27220. properties:
  27221. apikey:
  27222. description: |-
  27223. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  27224. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  27225. properties:
  27226. token:
  27227. description: |-
  27228. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  27229. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  27230. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  27231. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27232. properties:
  27233. key:
  27234. description: |-
  27235. A key in the referenced Secret.
  27236. Some instances of this field may be defaulted, in others it may be required.
  27237. maxLength: 253
  27238. minLength: 1
  27239. pattern: ^[-._a-zA-Z0-9]+$
  27240. type: string
  27241. name:
  27242. description: The name of the Secret resource being referred to.
  27243. maxLength: 253
  27244. minLength: 1
  27245. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27246. type: string
  27247. namespace:
  27248. description: |-
  27249. The namespace of the Secret resource being referred to.
  27250. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27251. maxLength: 63
  27252. minLength: 1
  27253. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27254. type: string
  27255. type: object
  27256. required:
  27257. - token
  27258. type: object
  27259. required:
  27260. - apikey
  27261. type: object
  27262. caBundle:
  27263. description: |-
  27264. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27265. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  27266. If not set, the system's trusted root certificates are used.
  27267. format: byte
  27268. type: string
  27269. caProvider:
  27270. description: |-
  27271. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  27272. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27273. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  27274. properties:
  27275. key:
  27276. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  27277. maxLength: 253
  27278. minLength: 1
  27279. pattern: ^[-._a-zA-Z0-9]+$
  27280. type: string
  27281. name:
  27282. description: The name of the object located at the provider type.
  27283. maxLength: 253
  27284. minLength: 1
  27285. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27286. type: string
  27287. namespace:
  27288. description: |-
  27289. The namespace the Provider type is in.
  27290. Can only be defined when used in a ClusterSecretStore.
  27291. maxLength: 63
  27292. minLength: 1
  27293. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27294. type: string
  27295. type:
  27296. description: The type of provider to use such as "Secret", or "ConfigMap".
  27297. enum:
  27298. - Secret
  27299. - ConfigMap
  27300. type: string
  27301. required:
  27302. - name
  27303. - type
  27304. type: object
  27305. folderPath:
  27306. description: |-
  27307. FolderPath specifies the default folder path for secret retrieval.
  27308. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  27309. Example: "production/database" or "dev/api-keys"
  27310. Leave empty to retrieve secrets from the root folder.
  27311. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  27312. type: string
  27313. server:
  27314. description: |-
  27315. Server configures the BeyondTrust Workload Credentials server connection details.
  27316. Includes the API URL and Site ID for your BeyondTrust instance.
  27317. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27318. properties:
  27319. apiUrl:
  27320. description: |-
  27321. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  27322. This should be the full URL to your BeyondTrust instance.
  27323. Example: https://api.beyondtrust.io/siie
  27324. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  27325. type: string
  27326. siteId:
  27327. description: |-
  27328. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  27329. This identifier is unique to your BeyondTrust Workload Credentials instance.
  27330. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  27331. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  27332. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27333. type: string
  27334. required:
  27335. - apiUrl
  27336. - siteId
  27337. type: object
  27338. required:
  27339. - auth
  27340. - server
  27341. type: object
  27342. retrySettings:
  27343. description: |-
  27344. RetrySettings configures exponential backoff for failed API requests.
  27345. If not specified, uses the default retry settings.
  27346. properties:
  27347. maxRetries:
  27348. format: int32
  27349. type: integer
  27350. retryInterval:
  27351. type: string
  27352. type: object
  27353. required:
  27354. - provider
  27355. type: object
  27356. type: object
  27357. served: true
  27358. storage: true
  27359. subresources:
  27360. status: {}
  27361. ---
  27362. apiVersion: apiextensions.k8s.io/v1
  27363. kind: CustomResourceDefinition
  27364. metadata:
  27365. annotations:
  27366. controller-gen.kubebuilder.io/version: v0.19.0
  27367. labels:
  27368. external-secrets.io/component: controller
  27369. name: cloudsmithaccesstokens.generators.external-secrets.io
  27370. spec:
  27371. group: generators.external-secrets.io
  27372. names:
  27373. categories:
  27374. - external-secrets
  27375. - external-secrets-generators
  27376. kind: CloudsmithAccessToken
  27377. listKind: CloudsmithAccessTokenList
  27378. plural: cloudsmithaccesstokens
  27379. singular: cloudsmithaccesstoken
  27380. scope: Namespaced
  27381. versions:
  27382. - name: v1alpha1
  27383. schema:
  27384. openAPIV3Schema:
  27385. description: CloudsmithAccessToken generates Cloudsmith access token using OIDC authentication
  27386. properties:
  27387. apiVersion:
  27388. description: |-
  27389. APIVersion defines the versioned schema of this representation of an object.
  27390. Servers should convert recognized schemas to the latest internal value, and
  27391. may reject unrecognized values.
  27392. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27393. type: string
  27394. kind:
  27395. description: |-
  27396. Kind is a string value representing the REST resource this object represents.
  27397. Servers may infer this from the endpoint the client submits requests to.
  27398. Cannot be updated.
  27399. In CamelCase.
  27400. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27401. type: string
  27402. metadata:
  27403. type: object
  27404. spec:
  27405. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  27406. properties:
  27407. apiUrl:
  27408. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  27409. type: string
  27410. orgSlug:
  27411. description: OrgSlug is the organization slug in Cloudsmith
  27412. type: string
  27413. serviceAccountRef:
  27414. description: Name of the service account you are federating with
  27415. properties:
  27416. audiences:
  27417. description: |-
  27418. Audience specifies the `aud` claim for the service account token
  27419. Some providers automatically extend the audience field based on well-known annotations for workload
  27420. identity (e.g. IRSA or GCP Workload Identity)
  27421. items:
  27422. type: string
  27423. type: array
  27424. name:
  27425. description: The name of the ServiceAccount resource being referred to.
  27426. maxLength: 253
  27427. minLength: 1
  27428. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27429. type: string
  27430. namespace:
  27431. description: |-
  27432. Namespace of the resource being referred to.
  27433. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27434. maxLength: 63
  27435. minLength: 1
  27436. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27437. type: string
  27438. required:
  27439. - name
  27440. type: object
  27441. serviceSlug:
  27442. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  27443. type: string
  27444. required:
  27445. - orgSlug
  27446. - serviceAccountRef
  27447. - serviceSlug
  27448. type: object
  27449. type: object
  27450. served: true
  27451. storage: true
  27452. subresources:
  27453. status: {}
  27454. ---
  27455. apiVersion: apiextensions.k8s.io/v1
  27456. kind: CustomResourceDefinition
  27457. metadata:
  27458. annotations:
  27459. controller-gen.kubebuilder.io/version: v0.19.0
  27460. labels:
  27461. external-secrets.io/component: controller
  27462. name: clustergenerators.generators.external-secrets.io
  27463. spec:
  27464. group: generators.external-secrets.io
  27465. names:
  27466. categories:
  27467. - external-secrets
  27468. - external-secrets-generators
  27469. kind: ClusterGenerator
  27470. listKind: ClusterGeneratorList
  27471. plural: clustergenerators
  27472. singular: clustergenerator
  27473. scope: Cluster
  27474. versions:
  27475. - name: v1alpha1
  27476. schema:
  27477. openAPIV3Schema:
  27478. description: ClusterGenerator represents a cluster-wide generator which can be referenced as part of `generatorRef` fields.
  27479. properties:
  27480. apiVersion:
  27481. description: |-
  27482. APIVersion defines the versioned schema of this representation of an object.
  27483. Servers should convert recognized schemas to the latest internal value, and
  27484. may reject unrecognized values.
  27485. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27486. type: string
  27487. kind:
  27488. description: |-
  27489. Kind is a string value representing the REST resource this object represents.
  27490. Servers may infer this from the endpoint the client submits requests to.
  27491. Cannot be updated.
  27492. In CamelCase.
  27493. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27494. type: string
  27495. metadata:
  27496. type: object
  27497. spec:
  27498. description: ClusterGeneratorSpec defines the desired state of a ClusterGenerator.
  27499. properties:
  27500. generator:
  27501. description: Generator the spec for this generator, must match the kind.
  27502. maxProperties: 1
  27503. minProperties: 1
  27504. properties:
  27505. acrAccessTokenSpec:
  27506. description: |-
  27507. ACRAccessTokenSpec defines how to generate the access token
  27508. e.g. how to authenticate and which registry to use.
  27509. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  27510. properties:
  27511. auth:
  27512. description: ACRAuth defines the authentication methods for Azure Container Registry.
  27513. properties:
  27514. managedIdentity:
  27515. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  27516. properties:
  27517. identityId:
  27518. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  27519. type: string
  27520. type: object
  27521. servicePrincipal:
  27522. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  27523. properties:
  27524. secretRef:
  27525. description: |-
  27526. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  27527. It uses static credentials stored in a Kind=Secret.
  27528. properties:
  27529. clientId:
  27530. description: The Azure clientId of the service principle used for authentication.
  27531. properties:
  27532. key:
  27533. description: |-
  27534. A key in the referenced Secret.
  27535. Some instances of this field may be defaulted, in others it may be required.
  27536. maxLength: 253
  27537. minLength: 1
  27538. pattern: ^[-._a-zA-Z0-9]+$
  27539. type: string
  27540. name:
  27541. description: The name of the Secret resource being referred to.
  27542. maxLength: 253
  27543. minLength: 1
  27544. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27545. type: string
  27546. namespace:
  27547. description: |-
  27548. The namespace of the Secret resource being referred to.
  27549. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27550. maxLength: 63
  27551. minLength: 1
  27552. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27553. type: string
  27554. type: object
  27555. clientSecret:
  27556. description: The Azure ClientSecret of the service principle used for authentication.
  27557. properties:
  27558. key:
  27559. description: |-
  27560. A key in the referenced Secret.
  27561. Some instances of this field may be defaulted, in others it may be required.
  27562. maxLength: 253
  27563. minLength: 1
  27564. pattern: ^[-._a-zA-Z0-9]+$
  27565. type: string
  27566. name:
  27567. description: The name of the Secret resource being referred to.
  27568. maxLength: 253
  27569. minLength: 1
  27570. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27571. type: string
  27572. namespace:
  27573. description: |-
  27574. The namespace of the Secret resource being referred to.
  27575. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27576. maxLength: 63
  27577. minLength: 1
  27578. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27579. type: string
  27580. type: object
  27581. type: object
  27582. required:
  27583. - secretRef
  27584. type: object
  27585. workloadIdentity:
  27586. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  27587. properties:
  27588. serviceAccountRef:
  27589. description: |-
  27590. ServiceAccountRef specified the service account
  27591. that should be used when authenticating with WorkloadIdentity.
  27592. properties:
  27593. audiences:
  27594. description: |-
  27595. Audience specifies the `aud` claim for the service account token
  27596. Some providers automatically extend the audience field based on well-known annotations for workload
  27597. identity (e.g. IRSA or GCP Workload Identity)
  27598. items:
  27599. type: string
  27600. type: array
  27601. name:
  27602. description: The name of the ServiceAccount resource being referred to.
  27603. maxLength: 253
  27604. minLength: 1
  27605. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27606. type: string
  27607. namespace:
  27608. description: |-
  27609. Namespace of the resource being referred to.
  27610. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27611. maxLength: 63
  27612. minLength: 1
  27613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27614. type: string
  27615. required:
  27616. - name
  27617. type: object
  27618. type: object
  27619. type: object
  27620. environmentType:
  27621. default: PublicCloud
  27622. description: |-
  27623. EnvironmentType specifies the Azure cloud environment endpoints to use for
  27624. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  27625. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  27626. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  27627. enum:
  27628. - PublicCloud
  27629. - USGovernmentCloud
  27630. - ChinaCloud
  27631. - GermanCloud
  27632. - AzureStackCloud
  27633. type: string
  27634. registry:
  27635. description: |-
  27636. the domain name of the ACR registry
  27637. e.g. foobarexample.azurecr.io
  27638. type: string
  27639. scope:
  27640. description: |-
  27641. Define the scope for the access token, e.g. pull/push access for a repository.
  27642. if not provided it will return a refresh token that has full scope.
  27643. Note: you need to pin it down to the repository level, there is no wildcard available.
  27644. examples:
  27645. repository:my-repository:pull,push
  27646. repository:my-repository:pull
  27647. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  27648. type: string
  27649. tenantId:
  27650. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  27651. type: string
  27652. required:
  27653. - auth
  27654. - registry
  27655. type: object
  27656. beyondtrustWorkloadCredentialsDynamicSecretSpec:
  27657. description: |-
  27658. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  27659. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  27660. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27661. properties:
  27662. controller:
  27663. description: |-
  27664. Controller selects the controller that should handle this generator.
  27665. Leave empty to use the default controller.
  27666. type: string
  27667. provider:
  27668. description: |-
  27669. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  27670. server connection details, and the folder path to the dynamic secret definition.
  27671. The folderPath should point to a dynamic secret definition that has been created in
  27672. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  27673. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27674. properties:
  27675. auth:
  27676. description: |-
  27677. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  27678. Currently supports API key authentication via Kubernetes secret reference.
  27679. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27680. properties:
  27681. apikey:
  27682. description: |-
  27683. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  27684. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  27685. properties:
  27686. token:
  27687. description: |-
  27688. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  27689. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  27690. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  27691. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27692. properties:
  27693. key:
  27694. description: |-
  27695. A key in the referenced Secret.
  27696. Some instances of this field may be defaulted, in others it may be required.
  27697. maxLength: 253
  27698. minLength: 1
  27699. pattern: ^[-._a-zA-Z0-9]+$
  27700. type: string
  27701. name:
  27702. description: The name of the Secret resource being referred to.
  27703. maxLength: 253
  27704. minLength: 1
  27705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27706. type: string
  27707. namespace:
  27708. description: |-
  27709. The namespace of the Secret resource being referred to.
  27710. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27711. maxLength: 63
  27712. minLength: 1
  27713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27714. type: string
  27715. type: object
  27716. required:
  27717. - token
  27718. type: object
  27719. required:
  27720. - apikey
  27721. type: object
  27722. caBundle:
  27723. description: |-
  27724. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27725. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  27726. If not set, the system's trusted root certificates are used.
  27727. format: byte
  27728. type: string
  27729. caProvider:
  27730. description: |-
  27731. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  27732. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27733. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  27734. properties:
  27735. key:
  27736. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  27737. maxLength: 253
  27738. minLength: 1
  27739. pattern: ^[-._a-zA-Z0-9]+$
  27740. type: string
  27741. name:
  27742. description: The name of the object located at the provider type.
  27743. maxLength: 253
  27744. minLength: 1
  27745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27746. type: string
  27747. namespace:
  27748. description: |-
  27749. The namespace the Provider type is in.
  27750. Can only be defined when used in a ClusterSecretStore.
  27751. maxLength: 63
  27752. minLength: 1
  27753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27754. type: string
  27755. type:
  27756. description: The type of provider to use such as "Secret", or "ConfigMap".
  27757. enum:
  27758. - Secret
  27759. - ConfigMap
  27760. type: string
  27761. required:
  27762. - name
  27763. - type
  27764. type: object
  27765. folderPath:
  27766. description: |-
  27767. FolderPath specifies the default folder path for secret retrieval.
  27768. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  27769. Example: "production/database" or "dev/api-keys"
  27770. Leave empty to retrieve secrets from the root folder.
  27771. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  27772. type: string
  27773. server:
  27774. description: |-
  27775. Server configures the BeyondTrust Workload Credentials server connection details.
  27776. Includes the API URL and Site ID for your BeyondTrust instance.
  27777. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27778. properties:
  27779. apiUrl:
  27780. description: |-
  27781. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  27782. This should be the full URL to your BeyondTrust instance.
  27783. Example: https://api.beyondtrust.io/siie
  27784. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  27785. type: string
  27786. siteId:
  27787. description: |-
  27788. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  27789. This identifier is unique to your BeyondTrust Workload Credentials instance.
  27790. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  27791. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  27792. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27793. type: string
  27794. required:
  27795. - apiUrl
  27796. - siteId
  27797. type: object
  27798. required:
  27799. - auth
  27800. - server
  27801. type: object
  27802. retrySettings:
  27803. description: |-
  27804. RetrySettings configures exponential backoff for failed API requests.
  27805. If not specified, uses the default retry settings.
  27806. properties:
  27807. maxRetries:
  27808. format: int32
  27809. type: integer
  27810. retryInterval:
  27811. type: string
  27812. type: object
  27813. required:
  27814. - provider
  27815. type: object
  27816. cloudsmithAccessTokenSpec:
  27817. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  27818. properties:
  27819. apiUrl:
  27820. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  27821. type: string
  27822. orgSlug:
  27823. description: OrgSlug is the organization slug in Cloudsmith
  27824. type: string
  27825. serviceAccountRef:
  27826. description: Name of the service account you are federating with
  27827. properties:
  27828. audiences:
  27829. description: |-
  27830. Audience specifies the `aud` claim for the service account token
  27831. Some providers automatically extend the audience field based on well-known annotations for workload
  27832. identity (e.g. IRSA or GCP Workload Identity)
  27833. items:
  27834. type: string
  27835. type: array
  27836. name:
  27837. description: The name of the ServiceAccount resource being referred to.
  27838. maxLength: 253
  27839. minLength: 1
  27840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27841. type: string
  27842. namespace:
  27843. description: |-
  27844. Namespace of the resource being referred to.
  27845. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27846. maxLength: 63
  27847. minLength: 1
  27848. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27849. type: string
  27850. required:
  27851. - name
  27852. type: object
  27853. serviceSlug:
  27854. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  27855. type: string
  27856. required:
  27857. - orgSlug
  27858. - serviceAccountRef
  27859. - serviceSlug
  27860. type: object
  27861. ecrAuthorizationTokenSpec:
  27862. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  27863. properties:
  27864. auth:
  27865. description: Auth defines how to authenticate with AWS
  27866. properties:
  27867. jwt:
  27868. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  27869. properties:
  27870. serviceAccountRef:
  27871. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  27872. properties:
  27873. audiences:
  27874. description: |-
  27875. Audience specifies the `aud` claim for the service account token
  27876. Some providers automatically extend the audience field based on well-known annotations for workload
  27877. identity (e.g. IRSA or GCP Workload Identity)
  27878. items:
  27879. type: string
  27880. type: array
  27881. name:
  27882. description: The name of the ServiceAccount resource being referred to.
  27883. maxLength: 253
  27884. minLength: 1
  27885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27886. type: string
  27887. namespace:
  27888. description: |-
  27889. Namespace of the resource being referred to.
  27890. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27891. maxLength: 63
  27892. minLength: 1
  27893. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27894. type: string
  27895. required:
  27896. - name
  27897. type: object
  27898. type: object
  27899. secretRef:
  27900. description: |-
  27901. AWSAuthSecretRef holds secret references for AWS credentials
  27902. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  27903. properties:
  27904. accessKeyIDSecretRef:
  27905. description: The AccessKeyID is used for authentication
  27906. properties:
  27907. key:
  27908. description: |-
  27909. A key in the referenced Secret.
  27910. Some instances of this field may be defaulted, in others it may be required.
  27911. maxLength: 253
  27912. minLength: 1
  27913. pattern: ^[-._a-zA-Z0-9]+$
  27914. type: string
  27915. name:
  27916. description: The name of the Secret resource being referred to.
  27917. maxLength: 253
  27918. minLength: 1
  27919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27920. type: string
  27921. namespace:
  27922. description: |-
  27923. The namespace of the Secret resource being referred to.
  27924. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27925. maxLength: 63
  27926. minLength: 1
  27927. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27928. type: string
  27929. type: object
  27930. secretAccessKeySecretRef:
  27931. description: The SecretAccessKey is used for authentication
  27932. properties:
  27933. key:
  27934. description: |-
  27935. A key in the referenced Secret.
  27936. Some instances of this field may be defaulted, in others it may be required.
  27937. maxLength: 253
  27938. minLength: 1
  27939. pattern: ^[-._a-zA-Z0-9]+$
  27940. type: string
  27941. name:
  27942. description: The name of the Secret resource being referred to.
  27943. maxLength: 253
  27944. minLength: 1
  27945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27946. type: string
  27947. namespace:
  27948. description: |-
  27949. The namespace of the Secret resource being referred to.
  27950. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27951. maxLength: 63
  27952. minLength: 1
  27953. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27954. type: string
  27955. type: object
  27956. sessionTokenSecretRef:
  27957. description: |-
  27958. The SessionToken used for authentication
  27959. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  27960. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  27961. properties:
  27962. key:
  27963. description: |-
  27964. A key in the referenced Secret.
  27965. Some instances of this field may be defaulted, in others it may be required.
  27966. maxLength: 253
  27967. minLength: 1
  27968. pattern: ^[-._a-zA-Z0-9]+$
  27969. type: string
  27970. name:
  27971. description: The name of the Secret resource being referred to.
  27972. maxLength: 253
  27973. minLength: 1
  27974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27975. type: string
  27976. namespace:
  27977. description: |-
  27978. The namespace of the Secret resource being referred to.
  27979. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27980. maxLength: 63
  27981. minLength: 1
  27982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27983. type: string
  27984. type: object
  27985. type: object
  27986. type: object
  27987. region:
  27988. description: Region specifies the region to operate in.
  27989. type: string
  27990. role:
  27991. description: |-
  27992. You can assume a role before making calls to the
  27993. desired AWS service.
  27994. type: string
  27995. scope:
  27996. description: |-
  27997. Scope specifies the ECR service scope.
  27998. Valid options are private and public.
  27999. type: string
  28000. required:
  28001. - region
  28002. type: object
  28003. fakeSpec:
  28004. description: FakeSpec contains the static data.
  28005. properties:
  28006. controller:
  28007. description: |-
  28008. Used to select the correct ESO controller (think: ingress.ingressClassName)
  28009. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  28010. type: string
  28011. data:
  28012. additionalProperties:
  28013. type: string
  28014. description: |-
  28015. Data defines the static data returned
  28016. by this generator.
  28017. type: object
  28018. type: object
  28019. gcrAccessTokenSpec:
  28020. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  28021. properties:
  28022. auth:
  28023. description: Auth defines the means for authenticating with GCP
  28024. properties:
  28025. secretRef:
  28026. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  28027. properties:
  28028. secretAccessKeySecretRef:
  28029. description: The SecretAccessKey is used for authentication
  28030. properties:
  28031. key:
  28032. description: |-
  28033. A key in the referenced Secret.
  28034. Some instances of this field may be defaulted, in others it may be required.
  28035. maxLength: 253
  28036. minLength: 1
  28037. pattern: ^[-._a-zA-Z0-9]+$
  28038. type: string
  28039. name:
  28040. description: The name of the Secret resource being referred to.
  28041. maxLength: 253
  28042. minLength: 1
  28043. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28044. type: string
  28045. namespace:
  28046. description: |-
  28047. The namespace of the Secret resource being referred to.
  28048. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28049. maxLength: 63
  28050. minLength: 1
  28051. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28052. type: string
  28053. type: object
  28054. type: object
  28055. workloadIdentity:
  28056. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  28057. properties:
  28058. clusterLocation:
  28059. type: string
  28060. clusterName:
  28061. type: string
  28062. clusterProjectID:
  28063. type: string
  28064. serviceAccountRef:
  28065. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28066. properties:
  28067. audiences:
  28068. description: |-
  28069. Audience specifies the `aud` claim for the service account token
  28070. Some providers automatically extend the audience field based on well-known annotations for workload
  28071. identity (e.g. IRSA or GCP Workload Identity)
  28072. items:
  28073. type: string
  28074. type: array
  28075. name:
  28076. description: The name of the ServiceAccount resource being referred to.
  28077. maxLength: 253
  28078. minLength: 1
  28079. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28080. type: string
  28081. namespace:
  28082. description: |-
  28083. Namespace of the resource being referred to.
  28084. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28085. maxLength: 63
  28086. minLength: 1
  28087. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28088. type: string
  28089. required:
  28090. - name
  28091. type: object
  28092. required:
  28093. - clusterLocation
  28094. - clusterName
  28095. - serviceAccountRef
  28096. type: object
  28097. workloadIdentityFederation:
  28098. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  28099. properties:
  28100. audience:
  28101. description: |-
  28102. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  28103. If specified, Audience found in the external account credential config will be overridden with the configured value.
  28104. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  28105. type: string
  28106. awsSecurityCredentials:
  28107. description: |-
  28108. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  28109. when using the AWS metadata server is not an option.
  28110. properties:
  28111. awsCredentialsSecretRef:
  28112. description: |-
  28113. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  28114. Secret should be created with below names for keys
  28115. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  28116. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  28117. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  28118. properties:
  28119. name:
  28120. description: name of the secret.
  28121. maxLength: 253
  28122. minLength: 1
  28123. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28124. type: string
  28125. namespace:
  28126. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  28127. maxLength: 63
  28128. minLength: 1
  28129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28130. type: string
  28131. required:
  28132. - name
  28133. type: object
  28134. region:
  28135. description: region is for configuring the AWS region to be used.
  28136. example: ap-south-1
  28137. maxLength: 50
  28138. minLength: 1
  28139. pattern: ^[a-z0-9-]+$
  28140. type: string
  28141. required:
  28142. - awsCredentialsSecretRef
  28143. - region
  28144. type: object
  28145. credConfig:
  28146. description: |-
  28147. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  28148. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  28149. serviceAccountRef must be used by providing operators service account details.
  28150. properties:
  28151. key:
  28152. description: key name holding the external account credential config.
  28153. maxLength: 253
  28154. minLength: 1
  28155. pattern: ^[-._a-zA-Z0-9]+$
  28156. type: string
  28157. name:
  28158. description: name of the configmap.
  28159. maxLength: 253
  28160. minLength: 1
  28161. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28162. type: string
  28163. namespace:
  28164. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  28165. maxLength: 63
  28166. minLength: 1
  28167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28168. type: string
  28169. required:
  28170. - key
  28171. - name
  28172. type: object
  28173. externalTokenEndpoint:
  28174. description: |-
  28175. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  28176. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  28177. URL is having the expected value.
  28178. type: string
  28179. gcpServiceAccountEmail:
  28180. description: |-
  28181. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  28182. after Workload Identity Federation. Use this to grant access through the service account's
  28183. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  28184. service_account_impersonation_url in the external account JSON from credConfig;
  28185. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  28186. on that ServiceAccount.
  28187. example: my-gsa@my-project.iam.gserviceaccount.com
  28188. minLength: 1
  28189. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  28190. type: string
  28191. serviceAccountRef:
  28192. description: |-
  28193. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  28194. when Kubernetes is configured as provider in workload identity pool.
  28195. properties:
  28196. audiences:
  28197. description: |-
  28198. Audience specifies the `aud` claim for the service account token
  28199. Some providers automatically extend the audience field based on well-known annotations for workload
  28200. identity (e.g. IRSA or GCP Workload Identity)
  28201. items:
  28202. type: string
  28203. type: array
  28204. name:
  28205. description: The name of the ServiceAccount resource being referred to.
  28206. maxLength: 253
  28207. minLength: 1
  28208. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28209. type: string
  28210. namespace:
  28211. description: |-
  28212. Namespace of the resource being referred to.
  28213. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28214. maxLength: 63
  28215. minLength: 1
  28216. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28217. type: string
  28218. required:
  28219. - name
  28220. type: object
  28221. type: object
  28222. type: object
  28223. projectID:
  28224. description: ProjectID defines which project to use to authenticate with
  28225. type: string
  28226. required:
  28227. - auth
  28228. - projectID
  28229. type: object
  28230. githubAccessTokenSpec:
  28231. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  28232. properties:
  28233. appID:
  28234. type: string
  28235. auth:
  28236. description: Auth configures how ESO authenticates with a Github instance.
  28237. properties:
  28238. privateKey:
  28239. description: GithubSecretRef references a secret containing GitHub credentials.
  28240. properties:
  28241. secretRef:
  28242. description: |-
  28243. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28244. In some instances, `key` is a required field.
  28245. properties:
  28246. key:
  28247. description: |-
  28248. A key in the referenced Secret.
  28249. Some instances of this field may be defaulted, in others it may be required.
  28250. maxLength: 253
  28251. minLength: 1
  28252. pattern: ^[-._a-zA-Z0-9]+$
  28253. type: string
  28254. name:
  28255. description: The name of the Secret resource being referred to.
  28256. maxLength: 253
  28257. minLength: 1
  28258. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28259. type: string
  28260. namespace:
  28261. description: |-
  28262. The namespace of the Secret resource being referred to.
  28263. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28264. maxLength: 63
  28265. minLength: 1
  28266. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28267. type: string
  28268. type: object
  28269. required:
  28270. - secretRef
  28271. type: object
  28272. required:
  28273. - privateKey
  28274. type: object
  28275. installID:
  28276. type: string
  28277. permissions:
  28278. additionalProperties:
  28279. type: string
  28280. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  28281. type: object
  28282. repositories:
  28283. description: |-
  28284. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  28285. is installed to.
  28286. items:
  28287. type: string
  28288. type: array
  28289. url:
  28290. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  28291. type: string
  28292. required:
  28293. - appID
  28294. - auth
  28295. - installID
  28296. type: object
  28297. gitlabDeployTokenSpec:
  28298. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  28299. properties:
  28300. auth:
  28301. description: Auth configures how ESO authenticates with the GitLab API.
  28302. properties:
  28303. token:
  28304. description: |-
  28305. Token references a secret containing a GitLab access token (personal, group, or
  28306. project) with the api scope and at least the Maintainer role on the target.
  28307. properties:
  28308. secretRef:
  28309. description: |-
  28310. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28311. In some instances, `key` is a required field.
  28312. properties:
  28313. key:
  28314. description: |-
  28315. A key in the referenced Secret.
  28316. Some instances of this field may be defaulted, in others it may be required.
  28317. maxLength: 253
  28318. minLength: 1
  28319. pattern: ^[-._a-zA-Z0-9]+$
  28320. type: string
  28321. name:
  28322. description: The name of the Secret resource being referred to.
  28323. maxLength: 253
  28324. minLength: 1
  28325. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28326. type: string
  28327. namespace:
  28328. description: |-
  28329. The namespace of the Secret resource being referred to.
  28330. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28331. maxLength: 63
  28332. minLength: 1
  28333. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28334. type: string
  28335. type: object
  28336. required:
  28337. - secretRef
  28338. type: object
  28339. required:
  28340. - token
  28341. type: object
  28342. expiresAt:
  28343. description: |-
  28344. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  28345. not expire on the GitLab side and is revoked only when the generator state is
  28346. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  28347. format: date-time
  28348. type: string
  28349. groupID:
  28350. description: |-
  28351. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  28352. create the deploy token in. The generator URL-escapes paths before calling the
  28353. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  28354. minLength: 1
  28355. type: string
  28356. name:
  28357. description: Name of the deploy token.
  28358. minLength: 1
  28359. type: string
  28360. projectID:
  28361. description: |-
  28362. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  28363. project to create the deploy token in. The generator URL-escapes paths before
  28364. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  28365. minLength: 1
  28366. type: string
  28367. scopes:
  28368. description: Scopes granted to the deploy token. At least one scope is required.
  28369. items:
  28370. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  28371. enum:
  28372. - read_repository
  28373. - read_registry
  28374. - write_registry
  28375. - read_package_registry
  28376. - write_package_registry
  28377. - read_virtual_registry
  28378. - write_virtual_registry
  28379. type: string
  28380. minItems: 1
  28381. type: array
  28382. url:
  28383. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  28384. type: string
  28385. username:
  28386. description: |-
  28387. Username is an optional username for the deploy token. GitLab defaults it to
  28388. gitlab+deploy-token-{n} when omitted.
  28389. type: string
  28390. required:
  28391. - auth
  28392. - name
  28393. - scopes
  28394. type: object
  28395. x-kubernetes-validations:
  28396. - message: exactly one of projectID or groupID must be set
  28397. rule: has(self.projectID) != has(self.groupID)
  28398. grafanaSpec:
  28399. description: GrafanaSpec controls the behavior of the grafana generator.
  28400. properties:
  28401. auth:
  28402. description: |-
  28403. Auth is the authentication configuration to authenticate
  28404. against the Grafana instance.
  28405. properties:
  28406. basic:
  28407. description: |-
  28408. Basic auth credentials used to authenticate against the Grafana instance.
  28409. Note: you need a token which has elevated permissions to create service accounts.
  28410. See here for the documentation on basic roles offered by Grafana:
  28411. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28412. properties:
  28413. password:
  28414. description: A basic auth password used to authenticate against the Grafana instance.
  28415. properties:
  28416. key:
  28417. description: The key where the token is found.
  28418. maxLength: 253
  28419. minLength: 1
  28420. pattern: ^[-._a-zA-Z0-9]+$
  28421. type: string
  28422. name:
  28423. description: The name of the Secret resource being referred to.
  28424. maxLength: 253
  28425. minLength: 1
  28426. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28427. type: string
  28428. type: object
  28429. username:
  28430. description: A basic auth username used to authenticate against the Grafana instance.
  28431. type: string
  28432. required:
  28433. - password
  28434. - username
  28435. type: object
  28436. token:
  28437. description: |-
  28438. A service account token used to authenticate against the Grafana instance.
  28439. Note: you need a token which has elevated permissions to create service accounts.
  28440. See here for the documentation on basic roles offered by Grafana:
  28441. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28442. properties:
  28443. key:
  28444. description: The key where the token is found.
  28445. maxLength: 253
  28446. minLength: 1
  28447. pattern: ^[-._a-zA-Z0-9]+$
  28448. type: string
  28449. name:
  28450. description: The name of the Secret resource being referred to.
  28451. maxLength: 253
  28452. minLength: 1
  28453. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28454. type: string
  28455. type: object
  28456. type: object
  28457. serviceAccount:
  28458. description: |-
  28459. ServiceAccount is the configuration for the service account that
  28460. is supposed to be generated by the generator.
  28461. properties:
  28462. name:
  28463. description: Name is the name of the service account that will be created by ESO.
  28464. type: string
  28465. role:
  28466. description: |-
  28467. Role is the role of the service account.
  28468. See here for the documentation on basic roles offered by Grafana:
  28469. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28470. type: string
  28471. secondsToLive:
  28472. description: |-
  28473. SecondsToLive is the number of seconds before the generated service account token will expire.
  28474. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  28475. format: int64
  28476. minimum: 1
  28477. type: integer
  28478. required:
  28479. - name
  28480. - role
  28481. type: object
  28482. url:
  28483. description: URL is the URL of the Grafana instance.
  28484. type: string
  28485. required:
  28486. - auth
  28487. - serviceAccount
  28488. - url
  28489. type: object
  28490. mfaSpec:
  28491. description: MFASpec controls the behavior of the mfa generator.
  28492. properties:
  28493. algorithm:
  28494. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  28495. type: string
  28496. length:
  28497. description: Length defines the token length. Defaults to 6 characters.
  28498. type: integer
  28499. secret:
  28500. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  28501. properties:
  28502. key:
  28503. description: |-
  28504. A key in the referenced Secret.
  28505. Some instances of this field may be defaulted, in others it may be required.
  28506. maxLength: 253
  28507. minLength: 1
  28508. pattern: ^[-._a-zA-Z0-9]+$
  28509. type: string
  28510. name:
  28511. description: The name of the Secret resource being referred to.
  28512. maxLength: 253
  28513. minLength: 1
  28514. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28515. type: string
  28516. namespace:
  28517. description: |-
  28518. The namespace of the Secret resource being referred to.
  28519. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28520. maxLength: 63
  28521. minLength: 1
  28522. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28523. type: string
  28524. type: object
  28525. timePeriod:
  28526. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  28527. type: integer
  28528. when:
  28529. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  28530. format: date-time
  28531. type: string
  28532. required:
  28533. - secret
  28534. type: object
  28535. passwordSpec:
  28536. description: PasswordSpec controls the behavior of the password generator.
  28537. properties:
  28538. allowRepeat:
  28539. default: false
  28540. description: set AllowRepeat to true to allow repeating characters.
  28541. type: boolean
  28542. digits:
  28543. description: |-
  28544. Digits specifies the number of digits in the generated
  28545. password. If omitted it defaults to 25% of the length of the password
  28546. type: integer
  28547. encoding:
  28548. default: raw
  28549. description: |-
  28550. Encoding specifies the encoding of the generated password.
  28551. Valid values are:
  28552. - "raw" (default): no encoding
  28553. - "base64": standard base64 encoding
  28554. - "base64url": base64url encoding
  28555. - "base32": base32 encoding
  28556. - "hex": hexadecimal encoding
  28557. enum:
  28558. - base64
  28559. - base64url
  28560. - base32
  28561. - hex
  28562. - raw
  28563. type: string
  28564. length:
  28565. default: 24
  28566. description: |-
  28567. Length of the password to be generated.
  28568. Defaults to 24
  28569. type: integer
  28570. noUpper:
  28571. default: false
  28572. description: Set NoUpper to disable uppercase characters
  28573. type: boolean
  28574. secretKeys:
  28575. description: |-
  28576. SecretKeys defines the keys that will be populated with generated passwords.
  28577. Defaults to "password" when not set.
  28578. items:
  28579. type: string
  28580. minItems: 1
  28581. type: array
  28582. symbolCharacters:
  28583. description: |-
  28584. SymbolCharacters specifies the special characters that should be used
  28585. in the generated password.
  28586. type: string
  28587. symbols:
  28588. description: |-
  28589. Symbols specifies the number of symbol characters in the generated
  28590. password. If omitted it defaults to 25% of the length of the password
  28591. type: integer
  28592. required:
  28593. - allowRepeat
  28594. - length
  28595. - noUpper
  28596. type: object
  28597. quayAccessTokenSpec:
  28598. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  28599. properties:
  28600. robotAccount:
  28601. description: Name of the robot account you are federating with
  28602. type: string
  28603. serviceAccountRef:
  28604. description: Name of the service account you are federating with
  28605. properties:
  28606. audiences:
  28607. description: |-
  28608. Audience specifies the `aud` claim for the service account token
  28609. Some providers automatically extend the audience field based on well-known annotations for workload
  28610. identity (e.g. IRSA or GCP Workload Identity)
  28611. items:
  28612. type: string
  28613. type: array
  28614. name:
  28615. description: The name of the ServiceAccount resource being referred to.
  28616. maxLength: 253
  28617. minLength: 1
  28618. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28619. type: string
  28620. namespace:
  28621. description: |-
  28622. Namespace of the resource being referred to.
  28623. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28624. maxLength: 63
  28625. minLength: 1
  28626. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28627. type: string
  28628. required:
  28629. - name
  28630. type: object
  28631. url:
  28632. description: URL configures the Quay instance URL. Defaults to quay.io.
  28633. type: string
  28634. required:
  28635. - robotAccount
  28636. - serviceAccountRef
  28637. type: object
  28638. sshKeySpec:
  28639. description: SSHKeySpec controls the behavior of the ssh key generator.
  28640. properties:
  28641. comment:
  28642. description: Comment specifies an optional comment for the SSH key
  28643. type: string
  28644. keySize:
  28645. description: |-
  28646. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  28647. For RSA keys: 2048, 3072, 4096
  28648. For ECDSA keys: 256, 384, 521
  28649. Ignored for ed25519 keys
  28650. maximum: 8192
  28651. minimum: 256
  28652. type: integer
  28653. keyType:
  28654. default: rsa
  28655. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  28656. enum:
  28657. - rsa
  28658. - ecdsa
  28659. - ed25519
  28660. type: string
  28661. type: object
  28662. stsSessionTokenSpec:
  28663. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  28664. properties:
  28665. auth:
  28666. description: Auth defines how to authenticate with AWS
  28667. properties:
  28668. jwt:
  28669. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  28670. properties:
  28671. serviceAccountRef:
  28672. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28673. properties:
  28674. audiences:
  28675. description: |-
  28676. Audience specifies the `aud` claim for the service account token
  28677. Some providers automatically extend the audience field based on well-known annotations for workload
  28678. identity (e.g. IRSA or GCP Workload Identity)
  28679. items:
  28680. type: string
  28681. type: array
  28682. name:
  28683. description: The name of the ServiceAccount resource being referred to.
  28684. maxLength: 253
  28685. minLength: 1
  28686. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28687. type: string
  28688. namespace:
  28689. description: |-
  28690. Namespace of the resource being referred to.
  28691. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28692. maxLength: 63
  28693. minLength: 1
  28694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28695. type: string
  28696. required:
  28697. - name
  28698. type: object
  28699. type: object
  28700. secretRef:
  28701. description: |-
  28702. AWSAuthSecretRef holds secret references for AWS credentials
  28703. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  28704. properties:
  28705. accessKeyIDSecretRef:
  28706. description: The AccessKeyID is used for authentication
  28707. properties:
  28708. key:
  28709. description: |-
  28710. A key in the referenced Secret.
  28711. Some instances of this field may be defaulted, in others it may be required.
  28712. maxLength: 253
  28713. minLength: 1
  28714. pattern: ^[-._a-zA-Z0-9]+$
  28715. type: string
  28716. name:
  28717. description: The name of the Secret resource being referred to.
  28718. maxLength: 253
  28719. minLength: 1
  28720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28721. type: string
  28722. namespace:
  28723. description: |-
  28724. The namespace of the Secret resource being referred to.
  28725. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28726. maxLength: 63
  28727. minLength: 1
  28728. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28729. type: string
  28730. type: object
  28731. secretAccessKeySecretRef:
  28732. description: The SecretAccessKey is used for authentication
  28733. properties:
  28734. key:
  28735. description: |-
  28736. A key in the referenced Secret.
  28737. Some instances of this field may be defaulted, in others it may be required.
  28738. maxLength: 253
  28739. minLength: 1
  28740. pattern: ^[-._a-zA-Z0-9]+$
  28741. type: string
  28742. name:
  28743. description: The name of the Secret resource being referred to.
  28744. maxLength: 253
  28745. minLength: 1
  28746. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28747. type: string
  28748. namespace:
  28749. description: |-
  28750. The namespace of the Secret resource being referred to.
  28751. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28752. maxLength: 63
  28753. minLength: 1
  28754. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28755. type: string
  28756. type: object
  28757. sessionTokenSecretRef:
  28758. description: |-
  28759. The SessionToken used for authentication
  28760. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28761. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28762. properties:
  28763. key:
  28764. description: |-
  28765. A key in the referenced Secret.
  28766. Some instances of this field may be defaulted, in others it may be required.
  28767. maxLength: 253
  28768. minLength: 1
  28769. pattern: ^[-._a-zA-Z0-9]+$
  28770. type: string
  28771. name:
  28772. description: The name of the Secret resource being referred to.
  28773. maxLength: 253
  28774. minLength: 1
  28775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28776. type: string
  28777. namespace:
  28778. description: |-
  28779. The namespace of the Secret resource being referred to.
  28780. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28781. maxLength: 63
  28782. minLength: 1
  28783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28784. type: string
  28785. type: object
  28786. type: object
  28787. type: object
  28788. region:
  28789. description: Region specifies the region to operate in.
  28790. type: string
  28791. requestParameters:
  28792. description: RequestParameters contains parameters that can be passed to the STS service.
  28793. properties:
  28794. serialNumber:
  28795. description: |-
  28796. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  28797. the GetSessionToken call.
  28798. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  28799. (such as arn:aws:iam::123456789012:mfa/user)
  28800. type: string
  28801. sessionDuration:
  28802. format: int32
  28803. type: integer
  28804. tokenCode:
  28805. description: TokenCode is the value provided by the MFA device, if MFA is required.
  28806. type: string
  28807. type: object
  28808. role:
  28809. description: |-
  28810. You can assume a role before making calls to the
  28811. desired AWS service.
  28812. type: string
  28813. required:
  28814. - region
  28815. type: object
  28816. uuidSpec:
  28817. description: UUIDSpec controls the behavior of the uuid generator.
  28818. type: object
  28819. vaultDynamicSecretSpec:
  28820. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  28821. properties:
  28822. allowEmptyResponse:
  28823. default: false
  28824. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  28825. type: boolean
  28826. controller:
  28827. description: |-
  28828. Used to select the correct ESO controller (think: ingress.ingressClassName)
  28829. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  28830. type: string
  28831. getParameters:
  28832. additionalProperties:
  28833. items:
  28834. type: string
  28835. type: array
  28836. description: |-
  28837. GetParameters are query-string parameters passed to Vault on GET calls.
  28838. Each key may map to multiple values, matching HTTP query-string semantics.
  28839. Ignored for non-GET methods; use Parameters for write bodies.
  28840. type: object
  28841. method:
  28842. description: Vault API method to use (GET/POST/other)
  28843. type: string
  28844. parameters:
  28845. description: Parameters to pass to Vault write (for non-GET methods)
  28846. x-kubernetes-preserve-unknown-fields: true
  28847. path:
  28848. description: Vault path to obtain the dynamic secret from
  28849. type: string
  28850. provider:
  28851. description: Vault provider common spec
  28852. properties:
  28853. auth:
  28854. description: Auth configures how secret-manager authenticates with the Vault server.
  28855. properties:
  28856. appRole:
  28857. description: |-
  28858. AppRole authenticates with Vault using the App Role auth mechanism,
  28859. with the role and secret stored in a Kubernetes Secret resource.
  28860. properties:
  28861. path:
  28862. default: approle
  28863. description: |-
  28864. Path where the App Role authentication backend is mounted
  28865. in Vault, e.g: "approle"
  28866. type: string
  28867. roleId:
  28868. description: |-
  28869. RoleID configured in the App Role authentication backend when setting
  28870. up the authentication backend in Vault.
  28871. type: string
  28872. roleRef:
  28873. description: |-
  28874. Reference to a key in a Secret that contains the App Role ID used
  28875. to authenticate with Vault.
  28876. The `key` field must be specified and denotes which entry within the Secret
  28877. resource is used as the app role id.
  28878. properties:
  28879. key:
  28880. description: |-
  28881. A key in the referenced Secret.
  28882. Some instances of this field may be defaulted, in others it may be required.
  28883. maxLength: 253
  28884. minLength: 1
  28885. pattern: ^[-._a-zA-Z0-9]+$
  28886. type: string
  28887. name:
  28888. description: The name of the Secret resource being referred to.
  28889. maxLength: 253
  28890. minLength: 1
  28891. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28892. type: string
  28893. namespace:
  28894. description: |-
  28895. The namespace of the Secret resource being referred to.
  28896. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28897. maxLength: 63
  28898. minLength: 1
  28899. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28900. type: string
  28901. type: object
  28902. secretRef:
  28903. description: |-
  28904. Reference to a key in a Secret that contains the App Role secret used
  28905. to authenticate with Vault.
  28906. The `key` field must be specified and denotes which entry within the Secret
  28907. resource is used as the app role secret.
  28908. properties:
  28909. key:
  28910. description: |-
  28911. A key in the referenced Secret.
  28912. Some instances of this field may be defaulted, in others it may be required.
  28913. maxLength: 253
  28914. minLength: 1
  28915. pattern: ^[-._a-zA-Z0-9]+$
  28916. type: string
  28917. name:
  28918. description: The name of the Secret resource being referred to.
  28919. maxLength: 253
  28920. minLength: 1
  28921. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28922. type: string
  28923. namespace:
  28924. description: |-
  28925. The namespace of the Secret resource being referred to.
  28926. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28927. maxLength: 63
  28928. minLength: 1
  28929. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28930. type: string
  28931. type: object
  28932. required:
  28933. - path
  28934. - secretRef
  28935. type: object
  28936. cert:
  28937. description: |-
  28938. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  28939. Cert authentication method
  28940. properties:
  28941. clientCert:
  28942. description: |-
  28943. ClientCert is a certificate to authenticate using the Cert Vault
  28944. authentication method
  28945. properties:
  28946. key:
  28947. description: |-
  28948. A key in the referenced Secret.
  28949. Some instances of this field may be defaulted, in others it may be required.
  28950. maxLength: 253
  28951. minLength: 1
  28952. pattern: ^[-._a-zA-Z0-9]+$
  28953. type: string
  28954. name:
  28955. description: The name of the Secret resource being referred to.
  28956. maxLength: 253
  28957. minLength: 1
  28958. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28959. type: string
  28960. namespace:
  28961. description: |-
  28962. The namespace of the Secret resource being referred to.
  28963. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28964. maxLength: 63
  28965. minLength: 1
  28966. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28967. type: string
  28968. type: object
  28969. path:
  28970. default: cert
  28971. description: |-
  28972. Path where the Certificate authentication backend is mounted
  28973. in Vault, e.g: "cert"
  28974. type: string
  28975. secretRef:
  28976. description: |-
  28977. SecretRef to a key in a Secret resource containing client private key to
  28978. authenticate with Vault using the Cert authentication method
  28979. properties:
  28980. key:
  28981. description: |-
  28982. A key in the referenced Secret.
  28983. Some instances of this field may be defaulted, in others it may be required.
  28984. maxLength: 253
  28985. minLength: 1
  28986. pattern: ^[-._a-zA-Z0-9]+$
  28987. type: string
  28988. name:
  28989. description: The name of the Secret resource being referred to.
  28990. maxLength: 253
  28991. minLength: 1
  28992. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28993. type: string
  28994. namespace:
  28995. description: |-
  28996. The namespace of the Secret resource being referred to.
  28997. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28998. maxLength: 63
  28999. minLength: 1
  29000. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29001. type: string
  29002. type: object
  29003. vaultRole:
  29004. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  29005. type: string
  29006. type: object
  29007. gcp:
  29008. description: |-
  29009. Gcp authenticates with Vault using Google Cloud Platform authentication method
  29010. GCP authentication method
  29011. properties:
  29012. location:
  29013. description: Location optionally defines a location/region for the secret
  29014. type: string
  29015. path:
  29016. default: gcp
  29017. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  29018. type: string
  29019. projectID:
  29020. description: Project ID of the Google Cloud Platform project
  29021. type: string
  29022. role:
  29023. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  29024. type: string
  29025. secretRef:
  29026. description: Specify credentials in a Secret object
  29027. properties:
  29028. secretAccessKeySecretRef:
  29029. description: The SecretAccessKey is used for authentication
  29030. properties:
  29031. key:
  29032. description: |-
  29033. A key in the referenced Secret.
  29034. Some instances of this field may be defaulted, in others it may be required.
  29035. maxLength: 253
  29036. minLength: 1
  29037. pattern: ^[-._a-zA-Z0-9]+$
  29038. type: string
  29039. name:
  29040. description: The name of the Secret resource being referred to.
  29041. maxLength: 253
  29042. minLength: 1
  29043. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29044. type: string
  29045. namespace:
  29046. description: |-
  29047. The namespace of the Secret resource being referred to.
  29048. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29049. maxLength: 63
  29050. minLength: 1
  29051. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29052. type: string
  29053. type: object
  29054. type: object
  29055. serviceAccountRef:
  29056. description: ServiceAccountRef to a service account for impersonation
  29057. properties:
  29058. audiences:
  29059. description: |-
  29060. Audience specifies the `aud` claim for the service account token
  29061. Some providers automatically extend the audience field based on well-known annotations for workload
  29062. identity (e.g. IRSA or GCP Workload Identity)
  29063. items:
  29064. type: string
  29065. type: array
  29066. name:
  29067. description: The name of the ServiceAccount resource being referred to.
  29068. maxLength: 253
  29069. minLength: 1
  29070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29071. type: string
  29072. namespace:
  29073. description: |-
  29074. Namespace of the resource being referred to.
  29075. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29076. maxLength: 63
  29077. minLength: 1
  29078. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29079. type: string
  29080. required:
  29081. - name
  29082. type: object
  29083. workloadIdentity:
  29084. description: Specify a service account with Workload Identity
  29085. properties:
  29086. clusterLocation:
  29087. description: |-
  29088. ClusterLocation is the location of the cluster
  29089. If not specified, it fetches information from the metadata server
  29090. type: string
  29091. clusterName:
  29092. description: |-
  29093. ClusterName is the name of the cluster
  29094. If not specified, it fetches information from the metadata server
  29095. type: string
  29096. clusterProjectID:
  29097. description: |-
  29098. ClusterProjectID is the project ID of the cluster
  29099. If not specified, it fetches information from the metadata server
  29100. type: string
  29101. serviceAccountRef:
  29102. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29103. properties:
  29104. audiences:
  29105. description: |-
  29106. Audience specifies the `aud` claim for the service account token
  29107. Some providers automatically extend the audience field based on well-known annotations for workload
  29108. identity (e.g. IRSA or GCP Workload Identity)
  29109. items:
  29110. type: string
  29111. type: array
  29112. name:
  29113. description: The name of the ServiceAccount resource being referred to.
  29114. maxLength: 253
  29115. minLength: 1
  29116. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29117. type: string
  29118. namespace:
  29119. description: |-
  29120. Namespace of the resource being referred to.
  29121. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29122. maxLength: 63
  29123. minLength: 1
  29124. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29125. type: string
  29126. required:
  29127. - name
  29128. type: object
  29129. required:
  29130. - serviceAccountRef
  29131. type: object
  29132. required:
  29133. - role
  29134. type: object
  29135. iam:
  29136. description: |-
  29137. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  29138. AWS IAM authentication method
  29139. properties:
  29140. externalID:
  29141. description: AWS External ID set on assumed IAM roles
  29142. type: string
  29143. jwt:
  29144. description: Specify a service account with IRSA enabled
  29145. properties:
  29146. serviceAccountRef:
  29147. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29148. properties:
  29149. audiences:
  29150. description: |-
  29151. Audience specifies the `aud` claim for the service account token
  29152. Some providers automatically extend the audience field based on well-known annotations for workload
  29153. identity (e.g. IRSA or GCP Workload Identity)
  29154. items:
  29155. type: string
  29156. type: array
  29157. name:
  29158. description: The name of the ServiceAccount resource being referred to.
  29159. maxLength: 253
  29160. minLength: 1
  29161. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29162. type: string
  29163. namespace:
  29164. description: |-
  29165. Namespace of the resource being referred to.
  29166. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29167. maxLength: 63
  29168. minLength: 1
  29169. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29170. type: string
  29171. required:
  29172. - name
  29173. type: object
  29174. type: object
  29175. path:
  29176. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  29177. type: string
  29178. region:
  29179. description: AWS region
  29180. type: string
  29181. role:
  29182. description: This is the AWS role to be assumed before talking to vault
  29183. type: string
  29184. secretRef:
  29185. description: Specify credentials in a Secret object
  29186. properties:
  29187. accessKeyIDSecretRef:
  29188. description: The AccessKeyID is used for authentication
  29189. properties:
  29190. key:
  29191. description: |-
  29192. A key in the referenced Secret.
  29193. Some instances of this field may be defaulted, in others it may be required.
  29194. maxLength: 253
  29195. minLength: 1
  29196. pattern: ^[-._a-zA-Z0-9]+$
  29197. type: string
  29198. name:
  29199. description: The name of the Secret resource being referred to.
  29200. maxLength: 253
  29201. minLength: 1
  29202. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29203. type: string
  29204. namespace:
  29205. description: |-
  29206. The namespace of the Secret resource being referred to.
  29207. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29208. maxLength: 63
  29209. minLength: 1
  29210. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29211. type: string
  29212. type: object
  29213. secretAccessKeySecretRef:
  29214. description: The SecretAccessKey is used for authentication
  29215. properties:
  29216. key:
  29217. description: |-
  29218. A key in the referenced Secret.
  29219. Some instances of this field may be defaulted, in others it may be required.
  29220. maxLength: 253
  29221. minLength: 1
  29222. pattern: ^[-._a-zA-Z0-9]+$
  29223. type: string
  29224. name:
  29225. description: The name of the Secret resource being referred to.
  29226. maxLength: 253
  29227. minLength: 1
  29228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29229. type: string
  29230. namespace:
  29231. description: |-
  29232. The namespace of the Secret resource being referred to.
  29233. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29234. maxLength: 63
  29235. minLength: 1
  29236. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29237. type: string
  29238. type: object
  29239. sessionTokenSecretRef:
  29240. description: |-
  29241. The SessionToken used for authentication
  29242. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  29243. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  29244. properties:
  29245. key:
  29246. description: |-
  29247. A key in the referenced Secret.
  29248. Some instances of this field may be defaulted, in others it may be required.
  29249. maxLength: 253
  29250. minLength: 1
  29251. pattern: ^[-._a-zA-Z0-9]+$
  29252. type: string
  29253. name:
  29254. description: The name of the Secret resource being referred to.
  29255. maxLength: 253
  29256. minLength: 1
  29257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29258. type: string
  29259. namespace:
  29260. description: |-
  29261. The namespace of the Secret resource being referred to.
  29262. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29263. maxLength: 63
  29264. minLength: 1
  29265. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29266. type: string
  29267. type: object
  29268. type: object
  29269. vaultAwsIamServerID:
  29270. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  29271. type: string
  29272. vaultRole:
  29273. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  29274. type: string
  29275. required:
  29276. - vaultRole
  29277. type: object
  29278. jwt:
  29279. description: |-
  29280. Jwt authenticates with Vault by passing role and JWT token using the
  29281. JWT/OIDC authentication method
  29282. properties:
  29283. kubernetesServiceAccountToken:
  29284. description: |-
  29285. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  29286. a token for with the `TokenRequest` API.
  29287. properties:
  29288. audiences:
  29289. description: |-
  29290. Optional audiences field that will be used to request a temporary Kubernetes service
  29291. account token for the service account referenced by `serviceAccountRef`.
  29292. Defaults to a single audience `vault` it not specified.
  29293. Deprecated: use serviceAccountRef.Audiences instead
  29294. items:
  29295. type: string
  29296. type: array
  29297. expirationSeconds:
  29298. description: |-
  29299. Optional expiration time in seconds that will be used to request a temporary
  29300. Kubernetes service account token for the service account referenced by
  29301. `serviceAccountRef`.
  29302. Deprecated: this will be removed in the future.
  29303. Defaults to 10 minutes.
  29304. format: int64
  29305. type: integer
  29306. serviceAccountRef:
  29307. description: Service account field containing the name of a kubernetes ServiceAccount.
  29308. properties:
  29309. audiences:
  29310. description: |-
  29311. Audience specifies the `aud` claim for the service account token
  29312. Some providers automatically extend the audience field based on well-known annotations for workload
  29313. identity (e.g. IRSA or GCP Workload Identity)
  29314. items:
  29315. type: string
  29316. type: array
  29317. name:
  29318. description: The name of the ServiceAccount resource being referred to.
  29319. maxLength: 253
  29320. minLength: 1
  29321. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29322. type: string
  29323. namespace:
  29324. description: |-
  29325. Namespace of the resource being referred to.
  29326. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29327. maxLength: 63
  29328. minLength: 1
  29329. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29330. type: string
  29331. required:
  29332. - name
  29333. type: object
  29334. required:
  29335. - serviceAccountRef
  29336. type: object
  29337. path:
  29338. default: jwt
  29339. description: |-
  29340. Path where the JWT authentication backend is mounted
  29341. in Vault, e.g: "jwt"
  29342. type: string
  29343. role:
  29344. description: |-
  29345. Role is a JWT role to authenticate using the JWT/OIDC Vault
  29346. authentication method
  29347. type: string
  29348. secretRef:
  29349. description: |-
  29350. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  29351. authenticate with Vault using the JWT/OIDC authentication method.
  29352. properties:
  29353. key:
  29354. description: |-
  29355. A key in the referenced Secret.
  29356. Some instances of this field may be defaulted, in others it may be required.
  29357. maxLength: 253
  29358. minLength: 1
  29359. pattern: ^[-._a-zA-Z0-9]+$
  29360. type: string
  29361. name:
  29362. description: The name of the Secret resource being referred to.
  29363. maxLength: 253
  29364. minLength: 1
  29365. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29366. type: string
  29367. namespace:
  29368. description: |-
  29369. The namespace of the Secret resource being referred to.
  29370. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29371. maxLength: 63
  29372. minLength: 1
  29373. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29374. type: string
  29375. type: object
  29376. required:
  29377. - path
  29378. type: object
  29379. kubernetes:
  29380. description: |-
  29381. Kubernetes authenticates with Vault by passing the ServiceAccount
  29382. token stored in the named Secret resource to the Vault server.
  29383. properties:
  29384. mountPath:
  29385. default: kubernetes
  29386. description: |-
  29387. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  29388. "kubernetes"
  29389. type: string
  29390. role:
  29391. description: |-
  29392. A required field containing the Vault Role to assume. A Role binds a
  29393. Kubernetes ServiceAccount with a set of Vault policies.
  29394. type: string
  29395. secretRef:
  29396. description: |-
  29397. Optional secret field containing a Kubernetes ServiceAccount JWT used
  29398. for authenticating with Vault. If a name is specified without a key,
  29399. `token` is the default. If one is not specified, the one bound to
  29400. the controller will be used.
  29401. properties:
  29402. key:
  29403. description: |-
  29404. A key in the referenced Secret.
  29405. Some instances of this field may be defaulted, in others it may be required.
  29406. maxLength: 253
  29407. minLength: 1
  29408. pattern: ^[-._a-zA-Z0-9]+$
  29409. type: string
  29410. name:
  29411. description: The name of the Secret resource being referred to.
  29412. maxLength: 253
  29413. minLength: 1
  29414. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29415. type: string
  29416. namespace:
  29417. description: |-
  29418. The namespace of the Secret resource being referred to.
  29419. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29420. maxLength: 63
  29421. minLength: 1
  29422. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29423. type: string
  29424. type: object
  29425. serviceAccountRef:
  29426. description: |-
  29427. Optional service account field containing the name of a kubernetes ServiceAccount.
  29428. If the service account is specified, the service account secret token JWT will be used
  29429. for authenticating with Vault. If the service account selector is not supplied,
  29430. the secretRef will be used instead.
  29431. properties:
  29432. audiences:
  29433. description: |-
  29434. Audience specifies the `aud` claim for the service account token
  29435. Some providers automatically extend the audience field based on well-known annotations for workload
  29436. identity (e.g. IRSA or GCP Workload Identity)
  29437. items:
  29438. type: string
  29439. type: array
  29440. name:
  29441. description: The name of the ServiceAccount resource being referred to.
  29442. maxLength: 253
  29443. minLength: 1
  29444. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29445. type: string
  29446. namespace:
  29447. description: |-
  29448. Namespace of the resource being referred to.
  29449. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29450. maxLength: 63
  29451. minLength: 1
  29452. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29453. type: string
  29454. required:
  29455. - name
  29456. type: object
  29457. required:
  29458. - mountPath
  29459. - role
  29460. type: object
  29461. ldap:
  29462. description: |-
  29463. Ldap authenticates with Vault by passing username/password pair using
  29464. the LDAP authentication method
  29465. properties:
  29466. path:
  29467. default: ldap
  29468. description: |-
  29469. Path where the LDAP authentication backend is mounted
  29470. in Vault, e.g: "ldap"
  29471. type: string
  29472. secretRef:
  29473. description: |-
  29474. SecretRef to a key in a Secret resource containing password for the LDAP
  29475. user used to authenticate with Vault using the LDAP authentication
  29476. method
  29477. properties:
  29478. key:
  29479. description: |-
  29480. A key in the referenced Secret.
  29481. Some instances of this field may be defaulted, in others it may be required.
  29482. maxLength: 253
  29483. minLength: 1
  29484. pattern: ^[-._a-zA-Z0-9]+$
  29485. type: string
  29486. name:
  29487. description: The name of the Secret resource being referred to.
  29488. maxLength: 253
  29489. minLength: 1
  29490. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29491. type: string
  29492. namespace:
  29493. description: |-
  29494. The namespace of the Secret resource being referred to.
  29495. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29496. maxLength: 63
  29497. minLength: 1
  29498. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29499. type: string
  29500. type: object
  29501. username:
  29502. description: |-
  29503. Username is an LDAP username used to authenticate using the LDAP Vault
  29504. authentication method
  29505. type: string
  29506. required:
  29507. - path
  29508. - username
  29509. type: object
  29510. namespace:
  29511. description: |-
  29512. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  29513. Namespaces is a set of features within Vault Enterprise that allows
  29514. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  29515. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  29516. This will default to Vault.Namespace field if set, or empty otherwise
  29517. type: string
  29518. tokenSecretRef:
  29519. description: TokenSecretRef authenticates with Vault by presenting a token.
  29520. properties:
  29521. key:
  29522. description: |-
  29523. A key in the referenced Secret.
  29524. Some instances of this field may be defaulted, in others it may be required.
  29525. maxLength: 253
  29526. minLength: 1
  29527. pattern: ^[-._a-zA-Z0-9]+$
  29528. type: string
  29529. name:
  29530. description: The name of the Secret resource being referred to.
  29531. maxLength: 253
  29532. minLength: 1
  29533. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29534. type: string
  29535. namespace:
  29536. description: |-
  29537. The namespace of the Secret resource being referred to.
  29538. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29539. maxLength: 63
  29540. minLength: 1
  29541. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29542. type: string
  29543. type: object
  29544. userPass:
  29545. description: UserPass authenticates with Vault by passing username/password pair
  29546. properties:
  29547. path:
  29548. default: userpass
  29549. description: |-
  29550. Path where the UserPassword authentication backend is mounted
  29551. in Vault, e.g: "userpass"
  29552. type: string
  29553. secretRef:
  29554. description: |-
  29555. SecretRef to a key in a Secret resource containing password for the
  29556. user used to authenticate with Vault using the UserPass authentication
  29557. method
  29558. properties:
  29559. key:
  29560. description: |-
  29561. A key in the referenced Secret.
  29562. Some instances of this field may be defaulted, in others it may be required.
  29563. maxLength: 253
  29564. minLength: 1
  29565. pattern: ^[-._a-zA-Z0-9]+$
  29566. type: string
  29567. name:
  29568. description: The name of the Secret resource being referred to.
  29569. maxLength: 253
  29570. minLength: 1
  29571. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29572. type: string
  29573. namespace:
  29574. description: |-
  29575. The namespace of the Secret resource being referred to.
  29576. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29577. maxLength: 63
  29578. minLength: 1
  29579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29580. type: string
  29581. type: object
  29582. username:
  29583. description: |-
  29584. Username is a username used to authenticate using the UserPass Vault
  29585. authentication method
  29586. type: string
  29587. required:
  29588. - path
  29589. - username
  29590. type: object
  29591. type: object
  29592. caBundle:
  29593. description: |-
  29594. PEM encoded CA bundle used to validate Vault server certificate. Only used
  29595. if the Server URL is using HTTPS protocol. This parameter is ignored for
  29596. plain HTTP protocol connection. If not set the system root certificates
  29597. are used to validate the TLS connection.
  29598. format: byte
  29599. type: string
  29600. caProvider:
  29601. description: The provider for the CA bundle to use to validate Vault server certificate.
  29602. properties:
  29603. key:
  29604. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  29605. maxLength: 253
  29606. minLength: 1
  29607. pattern: ^[-._a-zA-Z0-9]+$
  29608. type: string
  29609. name:
  29610. description: The name of the object located at the provider type.
  29611. maxLength: 253
  29612. minLength: 1
  29613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29614. type: string
  29615. namespace:
  29616. description: |-
  29617. The namespace the Provider type is in.
  29618. Can only be defined when used in a ClusterSecretStore.
  29619. maxLength: 63
  29620. minLength: 1
  29621. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29622. type: string
  29623. type:
  29624. description: The type of provider to use such as "Secret", or "ConfigMap".
  29625. enum:
  29626. - Secret
  29627. - ConfigMap
  29628. type: string
  29629. required:
  29630. - name
  29631. - type
  29632. type: object
  29633. checkAndSet:
  29634. description: |-
  29635. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  29636. Only applies to Vault KV v2 stores. When enabled, write operations must include
  29637. the current version of the secret to prevent unintentional overwrites.
  29638. properties:
  29639. required:
  29640. description: |-
  29641. Required when true, all write operations must include a check-and-set parameter.
  29642. This helps prevent unintentional overwrites of secrets.
  29643. type: boolean
  29644. type: object
  29645. forwardInconsistent:
  29646. description: |-
  29647. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  29648. leader instead of simply retrying within a loop. This can increase performance if
  29649. the option is enabled serverside.
  29650. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  29651. type: boolean
  29652. headers:
  29653. additionalProperties:
  29654. type: string
  29655. description: Headers to be added in Vault request
  29656. type: object
  29657. namespace:
  29658. description: |-
  29659. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  29660. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  29661. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  29662. type: string
  29663. path:
  29664. description: |-
  29665. Path is the mount path of the Vault KV backend endpoint, e.g:
  29666. "secret". The v2 KV secret engine version specific "/data" path suffix
  29667. for fetching secrets from Vault is optional and will be appended
  29668. if not present in specified path.
  29669. type: string
  29670. readYourWrites:
  29671. description: |-
  29672. ReadYourWrites ensures isolated read-after-write semantics by
  29673. providing discovered cluster replication states in each request.
  29674. More information about eventual consistency in Vault can be found here
  29675. https://www.vaultproject.io/docs/enterprise/consistency
  29676. type: boolean
  29677. server:
  29678. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  29679. type: string
  29680. tls:
  29681. description: |-
  29682. The configuration used for client side related TLS communication, when the Vault server
  29683. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  29684. This parameter is ignored for plain HTTP protocol connection.
  29685. It's worth noting this configuration is different from the "TLS certificates auth method",
  29686. which is available under the `auth.cert` section.
  29687. properties:
  29688. certSecretRef:
  29689. description: |-
  29690. CertSecretRef is a certificate added to the transport layer
  29691. when communicating with the Vault server.
  29692. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  29693. properties:
  29694. key:
  29695. description: |-
  29696. A key in the referenced Secret.
  29697. Some instances of this field may be defaulted, in others it may be required.
  29698. maxLength: 253
  29699. minLength: 1
  29700. pattern: ^[-._a-zA-Z0-9]+$
  29701. type: string
  29702. name:
  29703. description: The name of the Secret resource being referred to.
  29704. maxLength: 253
  29705. minLength: 1
  29706. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29707. type: string
  29708. namespace:
  29709. description: |-
  29710. The namespace of the Secret resource being referred to.
  29711. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29712. maxLength: 63
  29713. minLength: 1
  29714. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29715. type: string
  29716. type: object
  29717. keySecretRef:
  29718. description: |-
  29719. KeySecretRef to a key in a Secret resource containing client private key
  29720. added to the transport layer when communicating with the Vault server.
  29721. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  29722. properties:
  29723. key:
  29724. description: |-
  29725. A key in the referenced Secret.
  29726. Some instances of this field may be defaulted, in others it may be required.
  29727. maxLength: 253
  29728. minLength: 1
  29729. pattern: ^[-._a-zA-Z0-9]+$
  29730. type: string
  29731. name:
  29732. description: The name of the Secret resource being referred to.
  29733. maxLength: 253
  29734. minLength: 1
  29735. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29736. type: string
  29737. namespace:
  29738. description: |-
  29739. The namespace of the Secret resource being referred to.
  29740. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29741. maxLength: 63
  29742. minLength: 1
  29743. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29744. type: string
  29745. type: object
  29746. type: object
  29747. version:
  29748. default: v2
  29749. description: |-
  29750. Version is the Vault KV secret engine version. This can be either "v1" or
  29751. "v2". Version defaults to "v2".
  29752. enum:
  29753. - v1
  29754. - v2
  29755. type: string
  29756. required:
  29757. - server
  29758. type: object
  29759. resultType:
  29760. default: Data
  29761. description: |-
  29762. Result type defines which data is returned from the generator.
  29763. By default, it is the "data" section of the Vault API response.
  29764. When using e.g. /auth/token/create the "data" section is empty but
  29765. the "auth" section contains the generated token.
  29766. Please refer to the vault docs regarding the result data structure.
  29767. Additionally, accessing the raw response is possibly by using "Raw" result type.
  29768. enum:
  29769. - Data
  29770. - Auth
  29771. - Raw
  29772. type: string
  29773. retrySettings:
  29774. description: Used to configure http retries if failed
  29775. properties:
  29776. maxRetries:
  29777. format: int32
  29778. type: integer
  29779. retryInterval:
  29780. type: string
  29781. type: object
  29782. required:
  29783. - path
  29784. - provider
  29785. type: object
  29786. webhookSpec:
  29787. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  29788. properties:
  29789. auth:
  29790. description: Auth specifies a authorization protocol. Only one protocol may be set.
  29791. maxProperties: 1
  29792. minProperties: 1
  29793. properties:
  29794. ntlm:
  29795. description: NTLMProtocol configures the store to use NTLM for auth
  29796. properties:
  29797. passwordSecret:
  29798. description: |-
  29799. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  29800. In some instances, `key` is a required field.
  29801. properties:
  29802. key:
  29803. description: |-
  29804. A key in the referenced Secret.
  29805. Some instances of this field may be defaulted, in others it may be required.
  29806. maxLength: 253
  29807. minLength: 1
  29808. pattern: ^[-._a-zA-Z0-9]+$
  29809. type: string
  29810. name:
  29811. description: The name of the Secret resource being referred to.
  29812. maxLength: 253
  29813. minLength: 1
  29814. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29815. type: string
  29816. namespace:
  29817. description: |-
  29818. The namespace of the Secret resource being referred to.
  29819. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29820. maxLength: 63
  29821. minLength: 1
  29822. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29823. type: string
  29824. type: object
  29825. usernameSecret:
  29826. description: |-
  29827. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  29828. In some instances, `key` is a required field.
  29829. properties:
  29830. key:
  29831. description: |-
  29832. A key in the referenced Secret.
  29833. Some instances of this field may be defaulted, in others it may be required.
  29834. maxLength: 253
  29835. minLength: 1
  29836. pattern: ^[-._a-zA-Z0-9]+$
  29837. type: string
  29838. name:
  29839. description: The name of the Secret resource being referred to.
  29840. maxLength: 253
  29841. minLength: 1
  29842. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29843. type: string
  29844. namespace:
  29845. description: |-
  29846. The namespace of the Secret resource being referred to.
  29847. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29848. maxLength: 63
  29849. minLength: 1
  29850. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29851. type: string
  29852. type: object
  29853. required:
  29854. - passwordSecret
  29855. - usernameSecret
  29856. type: object
  29857. type: object
  29858. body:
  29859. description: Body
  29860. type: string
  29861. caBundle:
  29862. description: |-
  29863. PEM encoded CA bundle used to validate webhook server certificate. Only used
  29864. if the Server URL is using HTTPS protocol. This parameter is ignored for
  29865. plain HTTP protocol connection. If not set the system root certificates
  29866. are used to validate the TLS connection.
  29867. format: byte
  29868. type: string
  29869. caProvider:
  29870. description: The provider for the CA bundle to use to validate webhook server certificate.
  29871. properties:
  29872. key:
  29873. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  29874. maxLength: 253
  29875. minLength: 1
  29876. pattern: ^[-._a-zA-Z0-9]+$
  29877. type: string
  29878. name:
  29879. description: The name of the object located at the provider type.
  29880. maxLength: 253
  29881. minLength: 1
  29882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29883. type: string
  29884. namespace:
  29885. description: The namespace the Provider type is in.
  29886. maxLength: 63
  29887. minLength: 1
  29888. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29889. type: string
  29890. type:
  29891. description: The type of provider to use such as "Secret", or "ConfigMap".
  29892. enum:
  29893. - Secret
  29894. - ConfigMap
  29895. type: string
  29896. required:
  29897. - name
  29898. - type
  29899. type: object
  29900. headers:
  29901. additionalProperties:
  29902. type: string
  29903. description: Headers
  29904. type: object
  29905. method:
  29906. description: Webhook Method
  29907. type: string
  29908. result:
  29909. description: Result formatting
  29910. properties:
  29911. jsonPath:
  29912. description: Json path of return value
  29913. type: string
  29914. type: object
  29915. secrets:
  29916. description: |-
  29917. Secrets to fill in templates
  29918. These secrets will be passed to the templating function as key value pairs under the given name
  29919. items:
  29920. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  29921. properties:
  29922. name:
  29923. description: Name of this secret in templates
  29924. type: string
  29925. secretRef:
  29926. description: Secret ref to fill in credentials
  29927. properties:
  29928. key:
  29929. description: The key where the token is found.
  29930. maxLength: 253
  29931. minLength: 1
  29932. pattern: ^[-._a-zA-Z0-9]+$
  29933. type: string
  29934. name:
  29935. description: The name of the Secret resource being referred to.
  29936. maxLength: 253
  29937. minLength: 1
  29938. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29939. type: string
  29940. type: object
  29941. required:
  29942. - name
  29943. - secretRef
  29944. type: object
  29945. type: array
  29946. timeout:
  29947. description: Timeout
  29948. type: string
  29949. url:
  29950. description: Webhook url to call
  29951. type: string
  29952. required:
  29953. - result
  29954. - url
  29955. type: object
  29956. type: object
  29957. kind:
  29958. description: Kind the kind of this generator.
  29959. enum:
  29960. - ACRAccessToken
  29961. - BeyondtrustWorkloadCredentialsDynamicSecret
  29962. - CloudsmithAccessToken
  29963. - ECRAuthorizationToken
  29964. - Fake
  29965. - GCRAccessToken
  29966. - GithubAccessToken
  29967. - GitlabDeployToken
  29968. - QuayAccessToken
  29969. - Password
  29970. - SSHKey
  29971. - STSSessionToken
  29972. - UUID
  29973. - VaultDynamicSecret
  29974. - Webhook
  29975. - Grafana
  29976. - MFA
  29977. type: string
  29978. required:
  29979. - generator
  29980. - kind
  29981. type: object
  29982. type: object
  29983. served: true
  29984. storage: true
  29985. subresources:
  29986. status: {}
  29987. ---
  29988. apiVersion: apiextensions.k8s.io/v1
  29989. kind: CustomResourceDefinition
  29990. metadata:
  29991. annotations:
  29992. controller-gen.kubebuilder.io/version: v0.19.0
  29993. labels:
  29994. external-secrets.io/component: controller
  29995. name: ecrauthorizationtokens.generators.external-secrets.io
  29996. spec:
  29997. group: generators.external-secrets.io
  29998. names:
  29999. categories:
  30000. - external-secrets
  30001. - external-secrets-generators
  30002. kind: ECRAuthorizationToken
  30003. listKind: ECRAuthorizationTokenList
  30004. plural: ecrauthorizationtokens
  30005. singular: ecrauthorizationtoken
  30006. scope: Namespaced
  30007. versions:
  30008. - name: v1alpha1
  30009. schema:
  30010. openAPIV3Schema:
  30011. description: |-
  30012. ECRAuthorizationToken uses the GetAuthorizationToken API to retrieve an authorization token.
  30013. The authorization token is valid for 12 hours.
  30014. The authorizationToken returned is a base64 encoded string that can be decoded
  30015. and used in a docker login command to authenticate to a registry.
  30016. For more information, see Registry authentication (https://docs.aws.amazon.com/AmazonECR/latest/userguide/Registries.html#registry_auth) in the Amazon Elastic Container Registry User Guide.
  30017. properties:
  30018. apiVersion:
  30019. description: |-
  30020. APIVersion defines the versioned schema of this representation of an object.
  30021. Servers should convert recognized schemas to the latest internal value, and
  30022. may reject unrecognized values.
  30023. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30024. type: string
  30025. kind:
  30026. description: |-
  30027. Kind is a string value representing the REST resource this object represents.
  30028. Servers may infer this from the endpoint the client submits requests to.
  30029. Cannot be updated.
  30030. In CamelCase.
  30031. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30032. type: string
  30033. metadata:
  30034. type: object
  30035. spec:
  30036. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  30037. properties:
  30038. auth:
  30039. description: Auth defines how to authenticate with AWS
  30040. properties:
  30041. jwt:
  30042. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  30043. properties:
  30044. serviceAccountRef:
  30045. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  30046. properties:
  30047. audiences:
  30048. description: |-
  30049. Audience specifies the `aud` claim for the service account token
  30050. Some providers automatically extend the audience field based on well-known annotations for workload
  30051. identity (e.g. IRSA or GCP Workload Identity)
  30052. items:
  30053. type: string
  30054. type: array
  30055. name:
  30056. description: The name of the ServiceAccount resource being referred to.
  30057. maxLength: 253
  30058. minLength: 1
  30059. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30060. type: string
  30061. namespace:
  30062. description: |-
  30063. Namespace of the resource being referred to.
  30064. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30065. maxLength: 63
  30066. minLength: 1
  30067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30068. type: string
  30069. required:
  30070. - name
  30071. type: object
  30072. type: object
  30073. secretRef:
  30074. description: |-
  30075. AWSAuthSecretRef holds secret references for AWS credentials
  30076. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  30077. properties:
  30078. accessKeyIDSecretRef:
  30079. description: The AccessKeyID is used for authentication
  30080. properties:
  30081. key:
  30082. description: |-
  30083. A key in the referenced Secret.
  30084. Some instances of this field may be defaulted, in others it may be required.
  30085. maxLength: 253
  30086. minLength: 1
  30087. pattern: ^[-._a-zA-Z0-9]+$
  30088. type: string
  30089. name:
  30090. description: The name of the Secret resource being referred to.
  30091. maxLength: 253
  30092. minLength: 1
  30093. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30094. type: string
  30095. namespace:
  30096. description: |-
  30097. The namespace of the Secret resource being referred to.
  30098. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30099. maxLength: 63
  30100. minLength: 1
  30101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30102. type: string
  30103. type: object
  30104. secretAccessKeySecretRef:
  30105. description: The SecretAccessKey is used for authentication
  30106. properties:
  30107. key:
  30108. description: |-
  30109. A key in the referenced Secret.
  30110. Some instances of this field may be defaulted, in others it may be required.
  30111. maxLength: 253
  30112. minLength: 1
  30113. pattern: ^[-._a-zA-Z0-9]+$
  30114. type: string
  30115. name:
  30116. description: The name of the Secret resource being referred to.
  30117. maxLength: 253
  30118. minLength: 1
  30119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30120. type: string
  30121. namespace:
  30122. description: |-
  30123. The namespace of the Secret resource being referred to.
  30124. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30125. maxLength: 63
  30126. minLength: 1
  30127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30128. type: string
  30129. type: object
  30130. sessionTokenSecretRef:
  30131. description: |-
  30132. The SessionToken used for authentication
  30133. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  30134. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  30135. properties:
  30136. key:
  30137. description: |-
  30138. A key in the referenced Secret.
  30139. Some instances of this field may be defaulted, in others it may be required.
  30140. maxLength: 253
  30141. minLength: 1
  30142. pattern: ^[-._a-zA-Z0-9]+$
  30143. type: string
  30144. name:
  30145. description: The name of the Secret resource being referred to.
  30146. maxLength: 253
  30147. minLength: 1
  30148. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30149. type: string
  30150. namespace:
  30151. description: |-
  30152. The namespace of the Secret resource being referred to.
  30153. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30154. maxLength: 63
  30155. minLength: 1
  30156. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30157. type: string
  30158. type: object
  30159. type: object
  30160. type: object
  30161. region:
  30162. description: Region specifies the region to operate in.
  30163. type: string
  30164. role:
  30165. description: |-
  30166. You can assume a role before making calls to the
  30167. desired AWS service.
  30168. type: string
  30169. scope:
  30170. description: |-
  30171. Scope specifies the ECR service scope.
  30172. Valid options are private and public.
  30173. type: string
  30174. required:
  30175. - region
  30176. type: object
  30177. type: object
  30178. served: true
  30179. storage: true
  30180. subresources:
  30181. status: {}
  30182. ---
  30183. apiVersion: apiextensions.k8s.io/v1
  30184. kind: CustomResourceDefinition
  30185. metadata:
  30186. annotations:
  30187. controller-gen.kubebuilder.io/version: v0.19.0
  30188. labels:
  30189. external-secrets.io/component: controller
  30190. name: fakes.generators.external-secrets.io
  30191. spec:
  30192. group: generators.external-secrets.io
  30193. names:
  30194. categories:
  30195. - external-secrets
  30196. - external-secrets-generators
  30197. kind: Fake
  30198. listKind: FakeList
  30199. plural: fakes
  30200. singular: fake
  30201. scope: Namespaced
  30202. versions:
  30203. - name: v1alpha1
  30204. schema:
  30205. openAPIV3Schema:
  30206. description: |-
  30207. Fake generator is used for testing. It lets you define
  30208. a static set of credentials that is always returned.
  30209. properties:
  30210. apiVersion:
  30211. description: |-
  30212. APIVersion defines the versioned schema of this representation of an object.
  30213. Servers should convert recognized schemas to the latest internal value, and
  30214. may reject unrecognized values.
  30215. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30216. type: string
  30217. kind:
  30218. description: |-
  30219. Kind is a string value representing the REST resource this object represents.
  30220. Servers may infer this from the endpoint the client submits requests to.
  30221. Cannot be updated.
  30222. In CamelCase.
  30223. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30224. type: string
  30225. metadata:
  30226. type: object
  30227. spec:
  30228. description: FakeSpec contains the static data.
  30229. properties:
  30230. controller:
  30231. description: |-
  30232. Used to select the correct ESO controller (think: ingress.ingressClassName)
  30233. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  30234. type: string
  30235. data:
  30236. additionalProperties:
  30237. type: string
  30238. description: |-
  30239. Data defines the static data returned
  30240. by this generator.
  30241. type: object
  30242. type: object
  30243. type: object
  30244. served: true
  30245. storage: true
  30246. subresources:
  30247. status: {}
  30248. ---
  30249. apiVersion: apiextensions.k8s.io/v1
  30250. kind: CustomResourceDefinition
  30251. metadata:
  30252. annotations:
  30253. controller-gen.kubebuilder.io/version: v0.19.0
  30254. labels:
  30255. external-secrets.io/component: controller
  30256. name: gcraccesstokens.generators.external-secrets.io
  30257. spec:
  30258. group: generators.external-secrets.io
  30259. names:
  30260. categories:
  30261. - external-secrets
  30262. - external-secrets-generators
  30263. kind: GCRAccessToken
  30264. listKind: GCRAccessTokenList
  30265. plural: gcraccesstokens
  30266. singular: gcraccesstoken
  30267. scope: Namespaced
  30268. versions:
  30269. - name: v1alpha1
  30270. schema:
  30271. openAPIV3Schema:
  30272. description: |-
  30273. GCRAccessToken generates an GCP access token
  30274. that can be used to authenticate with GCR.
  30275. properties:
  30276. apiVersion:
  30277. description: |-
  30278. APIVersion defines the versioned schema of this representation of an object.
  30279. Servers should convert recognized schemas to the latest internal value, and
  30280. may reject unrecognized values.
  30281. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30282. type: string
  30283. kind:
  30284. description: |-
  30285. Kind is a string value representing the REST resource this object represents.
  30286. Servers may infer this from the endpoint the client submits requests to.
  30287. Cannot be updated.
  30288. In CamelCase.
  30289. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30290. type: string
  30291. metadata:
  30292. type: object
  30293. spec:
  30294. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  30295. properties:
  30296. auth:
  30297. description: Auth defines the means for authenticating with GCP
  30298. properties:
  30299. secretRef:
  30300. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  30301. properties:
  30302. secretAccessKeySecretRef:
  30303. description: The SecretAccessKey is used for authentication
  30304. properties:
  30305. key:
  30306. description: |-
  30307. A key in the referenced Secret.
  30308. Some instances of this field may be defaulted, in others it may be required.
  30309. maxLength: 253
  30310. minLength: 1
  30311. pattern: ^[-._a-zA-Z0-9]+$
  30312. type: string
  30313. name:
  30314. description: The name of the Secret resource being referred to.
  30315. maxLength: 253
  30316. minLength: 1
  30317. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30318. type: string
  30319. namespace:
  30320. description: |-
  30321. The namespace of the Secret resource being referred to.
  30322. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30323. maxLength: 63
  30324. minLength: 1
  30325. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30326. type: string
  30327. type: object
  30328. type: object
  30329. workloadIdentity:
  30330. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  30331. properties:
  30332. clusterLocation:
  30333. type: string
  30334. clusterName:
  30335. type: string
  30336. clusterProjectID:
  30337. type: string
  30338. serviceAccountRef:
  30339. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  30340. properties:
  30341. audiences:
  30342. description: |-
  30343. Audience specifies the `aud` claim for the service account token
  30344. Some providers automatically extend the audience field based on well-known annotations for workload
  30345. identity (e.g. IRSA or GCP Workload Identity)
  30346. items:
  30347. type: string
  30348. type: array
  30349. name:
  30350. description: The name of the ServiceAccount resource being referred to.
  30351. maxLength: 253
  30352. minLength: 1
  30353. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30354. type: string
  30355. namespace:
  30356. description: |-
  30357. Namespace of the resource being referred to.
  30358. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30359. maxLength: 63
  30360. minLength: 1
  30361. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30362. type: string
  30363. required:
  30364. - name
  30365. type: object
  30366. required:
  30367. - clusterLocation
  30368. - clusterName
  30369. - serviceAccountRef
  30370. type: object
  30371. workloadIdentityFederation:
  30372. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  30373. properties:
  30374. audience:
  30375. description: |-
  30376. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  30377. If specified, Audience found in the external account credential config will be overridden with the configured value.
  30378. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  30379. type: string
  30380. awsSecurityCredentials:
  30381. description: |-
  30382. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  30383. when using the AWS metadata server is not an option.
  30384. properties:
  30385. awsCredentialsSecretRef:
  30386. description: |-
  30387. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  30388. Secret should be created with below names for keys
  30389. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  30390. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  30391. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  30392. properties:
  30393. name:
  30394. description: name of the secret.
  30395. maxLength: 253
  30396. minLength: 1
  30397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30398. type: string
  30399. namespace:
  30400. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  30401. maxLength: 63
  30402. minLength: 1
  30403. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30404. type: string
  30405. required:
  30406. - name
  30407. type: object
  30408. region:
  30409. description: region is for configuring the AWS region to be used.
  30410. example: ap-south-1
  30411. maxLength: 50
  30412. minLength: 1
  30413. pattern: ^[a-z0-9-]+$
  30414. type: string
  30415. required:
  30416. - awsCredentialsSecretRef
  30417. - region
  30418. type: object
  30419. credConfig:
  30420. description: |-
  30421. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  30422. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  30423. serviceAccountRef must be used by providing operators service account details.
  30424. properties:
  30425. key:
  30426. description: key name holding the external account credential config.
  30427. maxLength: 253
  30428. minLength: 1
  30429. pattern: ^[-._a-zA-Z0-9]+$
  30430. type: string
  30431. name:
  30432. description: name of the configmap.
  30433. maxLength: 253
  30434. minLength: 1
  30435. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30436. type: string
  30437. namespace:
  30438. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  30439. maxLength: 63
  30440. minLength: 1
  30441. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30442. type: string
  30443. required:
  30444. - key
  30445. - name
  30446. type: object
  30447. externalTokenEndpoint:
  30448. description: |-
  30449. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  30450. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  30451. URL is having the expected value.
  30452. type: string
  30453. gcpServiceAccountEmail:
  30454. description: |-
  30455. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  30456. after Workload Identity Federation. Use this to grant access through the service account's
  30457. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  30458. service_account_impersonation_url in the external account JSON from credConfig;
  30459. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  30460. on that ServiceAccount.
  30461. example: my-gsa@my-project.iam.gserviceaccount.com
  30462. minLength: 1
  30463. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  30464. type: string
  30465. serviceAccountRef:
  30466. description: |-
  30467. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  30468. when Kubernetes is configured as provider in workload identity pool.
  30469. properties:
  30470. audiences:
  30471. description: |-
  30472. Audience specifies the `aud` claim for the service account token
  30473. Some providers automatically extend the audience field based on well-known annotations for workload
  30474. identity (e.g. IRSA or GCP Workload Identity)
  30475. items:
  30476. type: string
  30477. type: array
  30478. name:
  30479. description: The name of the ServiceAccount resource being referred to.
  30480. maxLength: 253
  30481. minLength: 1
  30482. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30483. type: string
  30484. namespace:
  30485. description: |-
  30486. Namespace of the resource being referred to.
  30487. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30488. maxLength: 63
  30489. minLength: 1
  30490. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30491. type: string
  30492. required:
  30493. - name
  30494. type: object
  30495. type: object
  30496. type: object
  30497. projectID:
  30498. description: ProjectID defines which project to use to authenticate with
  30499. type: string
  30500. required:
  30501. - auth
  30502. - projectID
  30503. type: object
  30504. type: object
  30505. served: true
  30506. storage: true
  30507. subresources:
  30508. status: {}
  30509. ---
  30510. apiVersion: apiextensions.k8s.io/v1
  30511. kind: CustomResourceDefinition
  30512. metadata:
  30513. annotations:
  30514. controller-gen.kubebuilder.io/version: v0.19.0
  30515. labels:
  30516. external-secrets.io/component: controller
  30517. name: generatorstates.generators.external-secrets.io
  30518. spec:
  30519. group: generators.external-secrets.io
  30520. names:
  30521. categories:
  30522. - external-secrets
  30523. - external-secrets-generators
  30524. kind: GeneratorState
  30525. listKind: GeneratorStateList
  30526. plural: generatorstates
  30527. shortNames:
  30528. - gs
  30529. singular: generatorstate
  30530. scope: Namespaced
  30531. versions:
  30532. - additionalPrinterColumns:
  30533. - jsonPath: .spec.garbageCollectionDeadline
  30534. name: GC Deadline
  30535. type: string
  30536. - jsonPath: .metadata.creationTimestamp
  30537. name: Age
  30538. type: date
  30539. name: v1alpha1
  30540. schema:
  30541. openAPIV3Schema:
  30542. description: GeneratorState represents the state created and managed by a generator resource.
  30543. properties:
  30544. apiVersion:
  30545. description: |-
  30546. APIVersion defines the versioned schema of this representation of an object.
  30547. Servers should convert recognized schemas to the latest internal value, and
  30548. may reject unrecognized values.
  30549. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30550. type: string
  30551. kind:
  30552. description: |-
  30553. Kind is a string value representing the REST resource this object represents.
  30554. Servers may infer this from the endpoint the client submits requests to.
  30555. Cannot be updated.
  30556. In CamelCase.
  30557. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30558. type: string
  30559. metadata:
  30560. type: object
  30561. spec:
  30562. description: GeneratorStateSpec defines the desired state of a generator state resource.
  30563. properties:
  30564. garbageCollectionDeadline:
  30565. description: |-
  30566. GarbageCollectionDeadline is the time after which the generator state
  30567. will be deleted.
  30568. It is set by the controller which creates the generator state and
  30569. can be set configured by the user.
  30570. If the garbage collection deadline is not set the generator state will not be deleted.
  30571. format: date-time
  30572. type: string
  30573. resource:
  30574. description: |-
  30575. Resource is the generator manifest that produced the state.
  30576. It is a snapshot of the generator manifest at the time the state was produced.
  30577. This manifest will be used to delete the resource. Any configuration that is referenced
  30578. in the manifest should be available at the time of garbage collection. If that is not the case deletion will
  30579. be blocked by a finalizer.
  30580. x-kubernetes-preserve-unknown-fields: true
  30581. state:
  30582. description: State is the state that was produced by the generator implementation.
  30583. x-kubernetes-preserve-unknown-fields: true
  30584. required:
  30585. - resource
  30586. - state
  30587. type: object
  30588. status:
  30589. description: GeneratorStateStatus defines the observed state of a generator state resource.
  30590. properties:
  30591. conditions:
  30592. items:
  30593. description: GeneratorStateStatusCondition represents the observed condition of a generator state.
  30594. properties:
  30595. lastTransitionTime:
  30596. format: date-time
  30597. type: string
  30598. message:
  30599. type: string
  30600. reason:
  30601. type: string
  30602. status:
  30603. type: string
  30604. type:
  30605. description: GeneratorStateConditionType represents the type of condition for a generator state.
  30606. type: string
  30607. required:
  30608. - status
  30609. - type
  30610. type: object
  30611. type: array
  30612. type: object
  30613. type: object
  30614. served: true
  30615. storage: true
  30616. subresources: {}
  30617. ---
  30618. apiVersion: apiextensions.k8s.io/v1
  30619. kind: CustomResourceDefinition
  30620. metadata:
  30621. annotations:
  30622. controller-gen.kubebuilder.io/version: v0.19.0
  30623. labels:
  30624. external-secrets.io/component: controller
  30625. name: githubaccesstokens.generators.external-secrets.io
  30626. spec:
  30627. group: generators.external-secrets.io
  30628. names:
  30629. categories:
  30630. - external-secrets
  30631. - external-secrets-generators
  30632. kind: GithubAccessToken
  30633. listKind: GithubAccessTokenList
  30634. plural: githubaccesstokens
  30635. singular: githubaccesstoken
  30636. scope: Namespaced
  30637. versions:
  30638. - name: v1alpha1
  30639. schema:
  30640. openAPIV3Schema:
  30641. description: GithubAccessToken generates ghs_ accessToken
  30642. properties:
  30643. apiVersion:
  30644. description: |-
  30645. APIVersion defines the versioned schema of this representation of an object.
  30646. Servers should convert recognized schemas to the latest internal value, and
  30647. may reject unrecognized values.
  30648. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30649. type: string
  30650. kind:
  30651. description: |-
  30652. Kind is a string value representing the REST resource this object represents.
  30653. Servers may infer this from the endpoint the client submits requests to.
  30654. Cannot be updated.
  30655. In CamelCase.
  30656. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30657. type: string
  30658. metadata:
  30659. type: object
  30660. spec:
  30661. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  30662. properties:
  30663. appID:
  30664. type: string
  30665. auth:
  30666. description: Auth configures how ESO authenticates with a Github instance.
  30667. properties:
  30668. privateKey:
  30669. description: GithubSecretRef references a secret containing GitHub credentials.
  30670. properties:
  30671. secretRef:
  30672. description: |-
  30673. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30674. In some instances, `key` is a required field.
  30675. properties:
  30676. key:
  30677. description: |-
  30678. A key in the referenced Secret.
  30679. Some instances of this field may be defaulted, in others it may be required.
  30680. maxLength: 253
  30681. minLength: 1
  30682. pattern: ^[-._a-zA-Z0-9]+$
  30683. type: string
  30684. name:
  30685. description: The name of the Secret resource being referred to.
  30686. maxLength: 253
  30687. minLength: 1
  30688. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30689. type: string
  30690. namespace:
  30691. description: |-
  30692. The namespace of the Secret resource being referred to.
  30693. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30694. maxLength: 63
  30695. minLength: 1
  30696. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30697. type: string
  30698. type: object
  30699. required:
  30700. - secretRef
  30701. type: object
  30702. required:
  30703. - privateKey
  30704. type: object
  30705. installID:
  30706. type: string
  30707. permissions:
  30708. additionalProperties:
  30709. type: string
  30710. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  30711. type: object
  30712. repositories:
  30713. description: |-
  30714. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  30715. is installed to.
  30716. items:
  30717. type: string
  30718. type: array
  30719. url:
  30720. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  30721. type: string
  30722. required:
  30723. - appID
  30724. - auth
  30725. - installID
  30726. type: object
  30727. type: object
  30728. served: true
  30729. storage: true
  30730. subresources:
  30731. status: {}
  30732. ---
  30733. apiVersion: apiextensions.k8s.io/v1
  30734. kind: CustomResourceDefinition
  30735. metadata:
  30736. annotations:
  30737. controller-gen.kubebuilder.io/version: v0.19.0
  30738. labels:
  30739. external-secrets.io/component: controller
  30740. name: gitlabdeploytokens.generators.external-secrets.io
  30741. spec:
  30742. group: generators.external-secrets.io
  30743. names:
  30744. categories:
  30745. - external-secrets
  30746. - external-secrets-generators
  30747. kind: GitlabDeployToken
  30748. listKind: GitlabDeployTokenList
  30749. plural: gitlabdeploytokens
  30750. singular: gitlabdeploytoken
  30751. scope: Namespaced
  30752. versions:
  30753. - name: v1alpha1
  30754. schema:
  30755. openAPIV3Schema:
  30756. description: GitlabDeployToken generates a GitLab deploy token.
  30757. properties:
  30758. apiVersion:
  30759. description: |-
  30760. APIVersion defines the versioned schema of this representation of an object.
  30761. Servers should convert recognized schemas to the latest internal value, and
  30762. may reject unrecognized values.
  30763. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30764. type: string
  30765. kind:
  30766. description: |-
  30767. Kind is a string value representing the REST resource this object represents.
  30768. Servers may infer this from the endpoint the client submits requests to.
  30769. Cannot be updated.
  30770. In CamelCase.
  30771. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30772. type: string
  30773. metadata:
  30774. type: object
  30775. spec:
  30776. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  30777. properties:
  30778. auth:
  30779. description: Auth configures how ESO authenticates with the GitLab API.
  30780. properties:
  30781. token:
  30782. description: |-
  30783. Token references a secret containing a GitLab access token (personal, group, or
  30784. project) with the api scope and at least the Maintainer role on the target.
  30785. properties:
  30786. secretRef:
  30787. description: |-
  30788. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30789. In some instances, `key` is a required field.
  30790. properties:
  30791. key:
  30792. description: |-
  30793. A key in the referenced Secret.
  30794. Some instances of this field may be defaulted, in others it may be required.
  30795. maxLength: 253
  30796. minLength: 1
  30797. pattern: ^[-._a-zA-Z0-9]+$
  30798. type: string
  30799. name:
  30800. description: The name of the Secret resource being referred to.
  30801. maxLength: 253
  30802. minLength: 1
  30803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30804. type: string
  30805. namespace:
  30806. description: |-
  30807. The namespace of the Secret resource being referred to.
  30808. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30809. maxLength: 63
  30810. minLength: 1
  30811. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30812. type: string
  30813. type: object
  30814. required:
  30815. - secretRef
  30816. type: object
  30817. required:
  30818. - token
  30819. type: object
  30820. expiresAt:
  30821. description: |-
  30822. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  30823. not expire on the GitLab side and is revoked only when the generator state is
  30824. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  30825. format: date-time
  30826. type: string
  30827. groupID:
  30828. description: |-
  30829. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  30830. create the deploy token in. The generator URL-escapes paths before calling the
  30831. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  30832. minLength: 1
  30833. type: string
  30834. name:
  30835. description: Name of the deploy token.
  30836. minLength: 1
  30837. type: string
  30838. projectID:
  30839. description: |-
  30840. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  30841. project to create the deploy token in. The generator URL-escapes paths before
  30842. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  30843. minLength: 1
  30844. type: string
  30845. scopes:
  30846. description: Scopes granted to the deploy token. At least one scope is required.
  30847. items:
  30848. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  30849. enum:
  30850. - read_repository
  30851. - read_registry
  30852. - write_registry
  30853. - read_package_registry
  30854. - write_package_registry
  30855. - read_virtual_registry
  30856. - write_virtual_registry
  30857. type: string
  30858. minItems: 1
  30859. type: array
  30860. url:
  30861. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  30862. type: string
  30863. username:
  30864. description: |-
  30865. Username is an optional username for the deploy token. GitLab defaults it to
  30866. gitlab+deploy-token-{n} when omitted.
  30867. type: string
  30868. required:
  30869. - auth
  30870. - name
  30871. - scopes
  30872. type: object
  30873. x-kubernetes-validations:
  30874. - message: exactly one of projectID or groupID must be set
  30875. rule: has(self.projectID) != has(self.groupID)
  30876. type: object
  30877. served: true
  30878. storage: true
  30879. subresources:
  30880. status: {}
  30881. ---
  30882. apiVersion: apiextensions.k8s.io/v1
  30883. kind: CustomResourceDefinition
  30884. metadata:
  30885. annotations:
  30886. controller-gen.kubebuilder.io/version: v0.19.0
  30887. labels:
  30888. external-secrets.io/component: controller
  30889. name: grafanas.generators.external-secrets.io
  30890. spec:
  30891. group: generators.external-secrets.io
  30892. names:
  30893. categories:
  30894. - external-secrets
  30895. - external-secrets-generators
  30896. kind: Grafana
  30897. listKind: GrafanaList
  30898. plural: grafanas
  30899. singular: grafana
  30900. scope: Namespaced
  30901. versions:
  30902. - name: v1alpha1
  30903. schema:
  30904. openAPIV3Schema:
  30905. description: Grafana represents a generator for Grafana service account tokens.
  30906. properties:
  30907. apiVersion:
  30908. description: |-
  30909. APIVersion defines the versioned schema of this representation of an object.
  30910. Servers should convert recognized schemas to the latest internal value, and
  30911. may reject unrecognized values.
  30912. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30913. type: string
  30914. kind:
  30915. description: |-
  30916. Kind is a string value representing the REST resource this object represents.
  30917. Servers may infer this from the endpoint the client submits requests to.
  30918. Cannot be updated.
  30919. In CamelCase.
  30920. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30921. type: string
  30922. metadata:
  30923. type: object
  30924. spec:
  30925. description: GrafanaSpec controls the behavior of the grafana generator.
  30926. properties:
  30927. auth:
  30928. description: |-
  30929. Auth is the authentication configuration to authenticate
  30930. against the Grafana instance.
  30931. properties:
  30932. basic:
  30933. description: |-
  30934. Basic auth credentials used to authenticate against the Grafana instance.
  30935. Note: you need a token which has elevated permissions to create service accounts.
  30936. See here for the documentation on basic roles offered by Grafana:
  30937. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30938. properties:
  30939. password:
  30940. description: A basic auth password used to authenticate against the Grafana instance.
  30941. properties:
  30942. key:
  30943. description: The key where the token is found.
  30944. maxLength: 253
  30945. minLength: 1
  30946. pattern: ^[-._a-zA-Z0-9]+$
  30947. type: string
  30948. name:
  30949. description: The name of the Secret resource being referred to.
  30950. maxLength: 253
  30951. minLength: 1
  30952. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30953. type: string
  30954. type: object
  30955. username:
  30956. description: A basic auth username used to authenticate against the Grafana instance.
  30957. type: string
  30958. required:
  30959. - password
  30960. - username
  30961. type: object
  30962. token:
  30963. description: |-
  30964. A service account token used to authenticate against the Grafana instance.
  30965. Note: you need a token which has elevated permissions to create service accounts.
  30966. See here for the documentation on basic roles offered by Grafana:
  30967. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30968. properties:
  30969. key:
  30970. description: The key where the token is found.
  30971. maxLength: 253
  30972. minLength: 1
  30973. pattern: ^[-._a-zA-Z0-9]+$
  30974. type: string
  30975. name:
  30976. description: The name of the Secret resource being referred to.
  30977. maxLength: 253
  30978. minLength: 1
  30979. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30980. type: string
  30981. type: object
  30982. type: object
  30983. serviceAccount:
  30984. description: |-
  30985. ServiceAccount is the configuration for the service account that
  30986. is supposed to be generated by the generator.
  30987. properties:
  30988. name:
  30989. description: Name is the name of the service account that will be created by ESO.
  30990. type: string
  30991. role:
  30992. description: |-
  30993. Role is the role of the service account.
  30994. See here for the documentation on basic roles offered by Grafana:
  30995. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30996. type: string
  30997. secondsToLive:
  30998. description: |-
  30999. SecondsToLive is the number of seconds before the generated service account token will expire.
  31000. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  31001. format: int64
  31002. minimum: 1
  31003. type: integer
  31004. required:
  31005. - name
  31006. - role
  31007. type: object
  31008. url:
  31009. description: URL is the URL of the Grafana instance.
  31010. type: string
  31011. required:
  31012. - auth
  31013. - serviceAccount
  31014. - url
  31015. type: object
  31016. type: object
  31017. served: true
  31018. storage: true
  31019. subresources:
  31020. status: {}
  31021. ---
  31022. apiVersion: apiextensions.k8s.io/v1
  31023. kind: CustomResourceDefinition
  31024. metadata:
  31025. annotations:
  31026. controller-gen.kubebuilder.io/version: v0.19.0
  31027. labels:
  31028. external-secrets.io/component: controller
  31029. name: mfas.generators.external-secrets.io
  31030. spec:
  31031. group: generators.external-secrets.io
  31032. names:
  31033. categories:
  31034. - external-secrets
  31035. - external-secrets-generators
  31036. kind: MFA
  31037. listKind: MFAList
  31038. plural: mfas
  31039. singular: mfa
  31040. scope: Namespaced
  31041. versions:
  31042. - name: v1alpha1
  31043. schema:
  31044. openAPIV3Schema:
  31045. description: MFA generates a new TOTP token that is compliant with RFC 6238.
  31046. properties:
  31047. apiVersion:
  31048. description: |-
  31049. APIVersion defines the versioned schema of this representation of an object.
  31050. Servers should convert recognized schemas to the latest internal value, and
  31051. may reject unrecognized values.
  31052. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31053. type: string
  31054. kind:
  31055. description: |-
  31056. Kind is a string value representing the REST resource this object represents.
  31057. Servers may infer this from the endpoint the client submits requests to.
  31058. Cannot be updated.
  31059. In CamelCase.
  31060. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31061. type: string
  31062. metadata:
  31063. type: object
  31064. spec:
  31065. description: MFASpec controls the behavior of the mfa generator.
  31066. properties:
  31067. algorithm:
  31068. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  31069. type: string
  31070. length:
  31071. description: Length defines the token length. Defaults to 6 characters.
  31072. type: integer
  31073. secret:
  31074. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  31075. properties:
  31076. key:
  31077. description: |-
  31078. A key in the referenced Secret.
  31079. Some instances of this field may be defaulted, in others it may be required.
  31080. maxLength: 253
  31081. minLength: 1
  31082. pattern: ^[-._a-zA-Z0-9]+$
  31083. type: string
  31084. name:
  31085. description: The name of the Secret resource being referred to.
  31086. maxLength: 253
  31087. minLength: 1
  31088. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31089. type: string
  31090. namespace:
  31091. description: |-
  31092. The namespace of the Secret resource being referred to.
  31093. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31094. maxLength: 63
  31095. minLength: 1
  31096. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31097. type: string
  31098. type: object
  31099. timePeriod:
  31100. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  31101. type: integer
  31102. when:
  31103. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  31104. format: date-time
  31105. type: string
  31106. required:
  31107. - secret
  31108. type: object
  31109. type: object
  31110. served: true
  31111. storage: true
  31112. subresources:
  31113. status: {}
  31114. ---
  31115. apiVersion: apiextensions.k8s.io/v1
  31116. kind: CustomResourceDefinition
  31117. metadata:
  31118. annotations:
  31119. controller-gen.kubebuilder.io/version: v0.19.0
  31120. labels:
  31121. external-secrets.io/component: controller
  31122. name: passwords.generators.external-secrets.io
  31123. spec:
  31124. group: generators.external-secrets.io
  31125. names:
  31126. categories:
  31127. - external-secrets
  31128. - external-secrets-generators
  31129. kind: Password
  31130. listKind: PasswordList
  31131. plural: passwords
  31132. singular: password
  31133. scope: Namespaced
  31134. versions:
  31135. - name: v1alpha1
  31136. schema:
  31137. openAPIV3Schema:
  31138. description: |-
  31139. Password generates a random password based on the
  31140. configuration parameters in spec.
  31141. You can specify the length, characterset and other attributes.
  31142. properties:
  31143. apiVersion:
  31144. description: |-
  31145. APIVersion defines the versioned schema of this representation of an object.
  31146. Servers should convert recognized schemas to the latest internal value, and
  31147. may reject unrecognized values.
  31148. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31149. type: string
  31150. kind:
  31151. description: |-
  31152. Kind is a string value representing the REST resource this object represents.
  31153. Servers may infer this from the endpoint the client submits requests to.
  31154. Cannot be updated.
  31155. In CamelCase.
  31156. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31157. type: string
  31158. metadata:
  31159. type: object
  31160. spec:
  31161. description: PasswordSpec controls the behavior of the password generator.
  31162. properties:
  31163. allowRepeat:
  31164. default: false
  31165. description: set AllowRepeat to true to allow repeating characters.
  31166. type: boolean
  31167. digits:
  31168. description: |-
  31169. Digits specifies the number of digits in the generated
  31170. password. If omitted it defaults to 25% of the length of the password
  31171. type: integer
  31172. encoding:
  31173. default: raw
  31174. description: |-
  31175. Encoding specifies the encoding of the generated password.
  31176. Valid values are:
  31177. - "raw" (default): no encoding
  31178. - "base64": standard base64 encoding
  31179. - "base64url": base64url encoding
  31180. - "base32": base32 encoding
  31181. - "hex": hexadecimal encoding
  31182. enum:
  31183. - base64
  31184. - base64url
  31185. - base32
  31186. - hex
  31187. - raw
  31188. type: string
  31189. length:
  31190. default: 24
  31191. description: |-
  31192. Length of the password to be generated.
  31193. Defaults to 24
  31194. type: integer
  31195. noUpper:
  31196. default: false
  31197. description: Set NoUpper to disable uppercase characters
  31198. type: boolean
  31199. secretKeys:
  31200. description: |-
  31201. SecretKeys defines the keys that will be populated with generated passwords.
  31202. Defaults to "password" when not set.
  31203. items:
  31204. type: string
  31205. minItems: 1
  31206. type: array
  31207. symbolCharacters:
  31208. description: |-
  31209. SymbolCharacters specifies the special characters that should be used
  31210. in the generated password.
  31211. type: string
  31212. symbols:
  31213. description: |-
  31214. Symbols specifies the number of symbol characters in the generated
  31215. password. If omitted it defaults to 25% of the length of the password
  31216. type: integer
  31217. required:
  31218. - allowRepeat
  31219. - length
  31220. - noUpper
  31221. type: object
  31222. type: object
  31223. served: true
  31224. storage: true
  31225. subresources:
  31226. status: {}
  31227. ---
  31228. apiVersion: apiextensions.k8s.io/v1
  31229. kind: CustomResourceDefinition
  31230. metadata:
  31231. annotations:
  31232. controller-gen.kubebuilder.io/version: v0.19.0
  31233. labels:
  31234. external-secrets.io/component: controller
  31235. name: quayaccesstokens.generators.external-secrets.io
  31236. spec:
  31237. group: generators.external-secrets.io
  31238. names:
  31239. categories:
  31240. - external-secrets
  31241. - external-secrets-generators
  31242. kind: QuayAccessToken
  31243. listKind: QuayAccessTokenList
  31244. plural: quayaccesstokens
  31245. singular: quayaccesstoken
  31246. scope: Namespaced
  31247. versions:
  31248. - name: v1alpha1
  31249. schema:
  31250. openAPIV3Schema:
  31251. description: QuayAccessToken generates Quay oauth token for pulling/pushing images
  31252. properties:
  31253. apiVersion:
  31254. description: |-
  31255. APIVersion defines the versioned schema of this representation of an object.
  31256. Servers should convert recognized schemas to the latest internal value, and
  31257. may reject unrecognized values.
  31258. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31259. type: string
  31260. kind:
  31261. description: |-
  31262. Kind is a string value representing the REST resource this object represents.
  31263. Servers may infer this from the endpoint the client submits requests to.
  31264. Cannot be updated.
  31265. In CamelCase.
  31266. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31267. type: string
  31268. metadata:
  31269. type: object
  31270. spec:
  31271. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  31272. properties:
  31273. robotAccount:
  31274. description: Name of the robot account you are federating with
  31275. type: string
  31276. serviceAccountRef:
  31277. description: Name of the service account you are federating with
  31278. properties:
  31279. audiences:
  31280. description: |-
  31281. Audience specifies the `aud` claim for the service account token
  31282. Some providers automatically extend the audience field based on well-known annotations for workload
  31283. identity (e.g. IRSA or GCP Workload Identity)
  31284. items:
  31285. type: string
  31286. type: array
  31287. name:
  31288. description: The name of the ServiceAccount resource being referred to.
  31289. maxLength: 253
  31290. minLength: 1
  31291. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31292. type: string
  31293. namespace:
  31294. description: |-
  31295. Namespace of the resource being referred to.
  31296. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31297. maxLength: 63
  31298. minLength: 1
  31299. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31300. type: string
  31301. required:
  31302. - name
  31303. type: object
  31304. url:
  31305. description: URL configures the Quay instance URL. Defaults to quay.io.
  31306. type: string
  31307. required:
  31308. - robotAccount
  31309. - serviceAccountRef
  31310. type: object
  31311. type: object
  31312. served: true
  31313. storage: true
  31314. subresources:
  31315. status: {}
  31316. ---
  31317. apiVersion: apiextensions.k8s.io/v1
  31318. kind: CustomResourceDefinition
  31319. metadata:
  31320. annotations:
  31321. controller-gen.kubebuilder.io/version: v0.19.0
  31322. labels:
  31323. external-secrets.io/component: controller
  31324. name: sshkeys.generators.external-secrets.io
  31325. spec:
  31326. group: generators.external-secrets.io
  31327. names:
  31328. categories:
  31329. - external-secrets
  31330. - external-secrets-generators
  31331. kind: SSHKey
  31332. listKind: SSHKeyList
  31333. plural: sshkeys
  31334. singular: sshkey
  31335. scope: Namespaced
  31336. versions:
  31337. - name: v1alpha1
  31338. schema:
  31339. openAPIV3Schema:
  31340. description: SSHKey generates SSH key pairs.
  31341. properties:
  31342. apiVersion:
  31343. description: |-
  31344. APIVersion defines the versioned schema of this representation of an object.
  31345. Servers should convert recognized schemas to the latest internal value, and
  31346. may reject unrecognized values.
  31347. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31348. type: string
  31349. kind:
  31350. description: |-
  31351. Kind is a string value representing the REST resource this object represents.
  31352. Servers may infer this from the endpoint the client submits requests to.
  31353. Cannot be updated.
  31354. In CamelCase.
  31355. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31356. type: string
  31357. metadata:
  31358. type: object
  31359. spec:
  31360. description: SSHKeySpec controls the behavior of the ssh key generator.
  31361. properties:
  31362. comment:
  31363. description: Comment specifies an optional comment for the SSH key
  31364. type: string
  31365. keySize:
  31366. description: |-
  31367. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  31368. For RSA keys: 2048, 3072, 4096
  31369. For ECDSA keys: 256, 384, 521
  31370. Ignored for ed25519 keys
  31371. maximum: 8192
  31372. minimum: 256
  31373. type: integer
  31374. keyType:
  31375. default: rsa
  31376. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  31377. enum:
  31378. - rsa
  31379. - ecdsa
  31380. - ed25519
  31381. type: string
  31382. type: object
  31383. type: object
  31384. served: true
  31385. storage: true
  31386. subresources:
  31387. status: {}
  31388. ---
  31389. apiVersion: apiextensions.k8s.io/v1
  31390. kind: CustomResourceDefinition
  31391. metadata:
  31392. annotations:
  31393. controller-gen.kubebuilder.io/version: v0.19.0
  31394. labels:
  31395. external-secrets.io/component: controller
  31396. name: stssessiontokens.generators.external-secrets.io
  31397. spec:
  31398. group: generators.external-secrets.io
  31399. names:
  31400. categories:
  31401. - external-secrets
  31402. - external-secrets-generators
  31403. kind: STSSessionToken
  31404. listKind: STSSessionTokenList
  31405. plural: stssessiontokens
  31406. singular: stssessiontoken
  31407. scope: Namespaced
  31408. versions:
  31409. - name: v1alpha1
  31410. schema:
  31411. openAPIV3Schema:
  31412. description: |-
  31413. STSSessionToken uses the GetSessionToken API to retrieve an authorization token.
  31414. The authorization token is valid for 12 hours.
  31415. The authorizationToken returned is a base64 encoded string that can be decoded.
  31416. For more information, see GetSessionToken (https://docs.aws.amazon.com/STS/latest/APIReference/API_GetSessionToken.html).
  31417. properties:
  31418. apiVersion:
  31419. description: |-
  31420. APIVersion defines the versioned schema of this representation of an object.
  31421. Servers should convert recognized schemas to the latest internal value, and
  31422. may reject unrecognized values.
  31423. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31424. type: string
  31425. kind:
  31426. description: |-
  31427. Kind is a string value representing the REST resource this object represents.
  31428. Servers may infer this from the endpoint the client submits requests to.
  31429. Cannot be updated.
  31430. In CamelCase.
  31431. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31432. type: string
  31433. metadata:
  31434. type: object
  31435. spec:
  31436. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  31437. properties:
  31438. auth:
  31439. description: Auth defines how to authenticate with AWS
  31440. properties:
  31441. jwt:
  31442. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  31443. properties:
  31444. serviceAccountRef:
  31445. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31446. properties:
  31447. audiences:
  31448. description: |-
  31449. Audience specifies the `aud` claim for the service account token
  31450. Some providers automatically extend the audience field based on well-known annotations for workload
  31451. identity (e.g. IRSA or GCP Workload Identity)
  31452. items:
  31453. type: string
  31454. type: array
  31455. name:
  31456. description: The name of the ServiceAccount resource being referred to.
  31457. maxLength: 253
  31458. minLength: 1
  31459. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31460. type: string
  31461. namespace:
  31462. description: |-
  31463. Namespace of the resource being referred to.
  31464. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31465. maxLength: 63
  31466. minLength: 1
  31467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31468. type: string
  31469. required:
  31470. - name
  31471. type: object
  31472. type: object
  31473. secretRef:
  31474. description: |-
  31475. AWSAuthSecretRef holds secret references for AWS credentials
  31476. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  31477. properties:
  31478. accessKeyIDSecretRef:
  31479. description: The AccessKeyID is used for authentication
  31480. properties:
  31481. key:
  31482. description: |-
  31483. A key in the referenced Secret.
  31484. Some instances of this field may be defaulted, in others it may be required.
  31485. maxLength: 253
  31486. minLength: 1
  31487. pattern: ^[-._a-zA-Z0-9]+$
  31488. type: string
  31489. name:
  31490. description: The name of the Secret resource being referred to.
  31491. maxLength: 253
  31492. minLength: 1
  31493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31494. type: string
  31495. namespace:
  31496. description: |-
  31497. The namespace of the Secret resource being referred to.
  31498. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31499. maxLength: 63
  31500. minLength: 1
  31501. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31502. type: string
  31503. type: object
  31504. secretAccessKeySecretRef:
  31505. description: The SecretAccessKey is used for authentication
  31506. properties:
  31507. key:
  31508. description: |-
  31509. A key in the referenced Secret.
  31510. Some instances of this field may be defaulted, in others it may be required.
  31511. maxLength: 253
  31512. minLength: 1
  31513. pattern: ^[-._a-zA-Z0-9]+$
  31514. type: string
  31515. name:
  31516. description: The name of the Secret resource being referred to.
  31517. maxLength: 253
  31518. minLength: 1
  31519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31520. type: string
  31521. namespace:
  31522. description: |-
  31523. The namespace of the Secret resource being referred to.
  31524. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31525. maxLength: 63
  31526. minLength: 1
  31527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31528. type: string
  31529. type: object
  31530. sessionTokenSecretRef:
  31531. description: |-
  31532. The SessionToken used for authentication
  31533. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  31534. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  31535. properties:
  31536. key:
  31537. description: |-
  31538. A key in the referenced Secret.
  31539. Some instances of this field may be defaulted, in others it may be required.
  31540. maxLength: 253
  31541. minLength: 1
  31542. pattern: ^[-._a-zA-Z0-9]+$
  31543. type: string
  31544. name:
  31545. description: The name of the Secret resource being referred to.
  31546. maxLength: 253
  31547. minLength: 1
  31548. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31549. type: string
  31550. namespace:
  31551. description: |-
  31552. The namespace of the Secret resource being referred to.
  31553. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31554. maxLength: 63
  31555. minLength: 1
  31556. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31557. type: string
  31558. type: object
  31559. type: object
  31560. type: object
  31561. region:
  31562. description: Region specifies the region to operate in.
  31563. type: string
  31564. requestParameters:
  31565. description: RequestParameters contains parameters that can be passed to the STS service.
  31566. properties:
  31567. serialNumber:
  31568. description: |-
  31569. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  31570. the GetSessionToken call.
  31571. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  31572. (such as arn:aws:iam::123456789012:mfa/user)
  31573. type: string
  31574. sessionDuration:
  31575. format: int32
  31576. type: integer
  31577. tokenCode:
  31578. description: TokenCode is the value provided by the MFA device, if MFA is required.
  31579. type: string
  31580. type: object
  31581. role:
  31582. description: |-
  31583. You can assume a role before making calls to the
  31584. desired AWS service.
  31585. type: string
  31586. required:
  31587. - region
  31588. type: object
  31589. type: object
  31590. served: true
  31591. storage: true
  31592. subresources:
  31593. status: {}
  31594. ---
  31595. apiVersion: apiextensions.k8s.io/v1
  31596. kind: CustomResourceDefinition
  31597. metadata:
  31598. annotations:
  31599. controller-gen.kubebuilder.io/version: v0.19.0
  31600. labels:
  31601. external-secrets.io/component: controller
  31602. name: uuids.generators.external-secrets.io
  31603. spec:
  31604. group: generators.external-secrets.io
  31605. names:
  31606. categories:
  31607. - external-secrets
  31608. - external-secrets-generators
  31609. kind: UUID
  31610. listKind: UUIDList
  31611. plural: uuids
  31612. singular: uuid
  31613. scope: Namespaced
  31614. versions:
  31615. - name: v1alpha1
  31616. schema:
  31617. openAPIV3Schema:
  31618. description: UUID generates a version 1 UUID (e56657e3-764f-11ef-a397-65231a88c216).
  31619. properties:
  31620. apiVersion:
  31621. description: |-
  31622. APIVersion defines the versioned schema of this representation of an object.
  31623. Servers should convert recognized schemas to the latest internal value, and
  31624. may reject unrecognized values.
  31625. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31626. type: string
  31627. kind:
  31628. description: |-
  31629. Kind is a string value representing the REST resource this object represents.
  31630. Servers may infer this from the endpoint the client submits requests to.
  31631. Cannot be updated.
  31632. In CamelCase.
  31633. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31634. type: string
  31635. metadata:
  31636. type: object
  31637. spec:
  31638. description: UUIDSpec controls the behavior of the uuid generator.
  31639. type: object
  31640. type: object
  31641. served: true
  31642. storage: true
  31643. subresources:
  31644. status: {}
  31645. ---
  31646. apiVersion: apiextensions.k8s.io/v1
  31647. kind: CustomResourceDefinition
  31648. metadata:
  31649. annotations:
  31650. controller-gen.kubebuilder.io/version: v0.19.0
  31651. labels:
  31652. external-secrets.io/component: controller
  31653. name: vaultdynamicsecrets.generators.external-secrets.io
  31654. spec:
  31655. group: generators.external-secrets.io
  31656. names:
  31657. categories:
  31658. - external-secrets
  31659. - external-secrets-generators
  31660. kind: VaultDynamicSecret
  31661. listKind: VaultDynamicSecretList
  31662. plural: vaultdynamicsecrets
  31663. singular: vaultdynamicsecret
  31664. scope: Namespaced
  31665. versions:
  31666. - name: v1alpha1
  31667. schema:
  31668. openAPIV3Schema:
  31669. description: VaultDynamicSecret represents a generator that can create dynamic secrets from HashiCorp Vault.
  31670. properties:
  31671. apiVersion:
  31672. description: |-
  31673. APIVersion defines the versioned schema of this representation of an object.
  31674. Servers should convert recognized schemas to the latest internal value, and
  31675. may reject unrecognized values.
  31676. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31677. type: string
  31678. kind:
  31679. description: |-
  31680. Kind is a string value representing the REST resource this object represents.
  31681. Servers may infer this from the endpoint the client submits requests to.
  31682. Cannot be updated.
  31683. In CamelCase.
  31684. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31685. type: string
  31686. metadata:
  31687. type: object
  31688. spec:
  31689. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  31690. properties:
  31691. allowEmptyResponse:
  31692. default: false
  31693. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  31694. type: boolean
  31695. controller:
  31696. description: |-
  31697. Used to select the correct ESO controller (think: ingress.ingressClassName)
  31698. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  31699. type: string
  31700. getParameters:
  31701. additionalProperties:
  31702. items:
  31703. type: string
  31704. type: array
  31705. description: |-
  31706. GetParameters are query-string parameters passed to Vault on GET calls.
  31707. Each key may map to multiple values, matching HTTP query-string semantics.
  31708. Ignored for non-GET methods; use Parameters for write bodies.
  31709. type: object
  31710. method:
  31711. description: Vault API method to use (GET/POST/other)
  31712. type: string
  31713. parameters:
  31714. description: Parameters to pass to Vault write (for non-GET methods)
  31715. x-kubernetes-preserve-unknown-fields: true
  31716. path:
  31717. description: Vault path to obtain the dynamic secret from
  31718. type: string
  31719. provider:
  31720. description: Vault provider common spec
  31721. properties:
  31722. auth:
  31723. description: Auth configures how secret-manager authenticates with the Vault server.
  31724. properties:
  31725. appRole:
  31726. description: |-
  31727. AppRole authenticates with Vault using the App Role auth mechanism,
  31728. with the role and secret stored in a Kubernetes Secret resource.
  31729. properties:
  31730. path:
  31731. default: approle
  31732. description: |-
  31733. Path where the App Role authentication backend is mounted
  31734. in Vault, e.g: "approle"
  31735. type: string
  31736. roleId:
  31737. description: |-
  31738. RoleID configured in the App Role authentication backend when setting
  31739. up the authentication backend in Vault.
  31740. type: string
  31741. roleRef:
  31742. description: |-
  31743. Reference to a key in a Secret that contains the App Role ID used
  31744. to authenticate with Vault.
  31745. The `key` field must be specified and denotes which entry within the Secret
  31746. resource is used as the app role id.
  31747. properties:
  31748. key:
  31749. description: |-
  31750. A key in the referenced Secret.
  31751. Some instances of this field may be defaulted, in others it may be required.
  31752. maxLength: 253
  31753. minLength: 1
  31754. pattern: ^[-._a-zA-Z0-9]+$
  31755. type: string
  31756. name:
  31757. description: The name of the Secret resource being referred to.
  31758. maxLength: 253
  31759. minLength: 1
  31760. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31761. type: string
  31762. namespace:
  31763. description: |-
  31764. The namespace of the Secret resource being referred to.
  31765. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31766. maxLength: 63
  31767. minLength: 1
  31768. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31769. type: string
  31770. type: object
  31771. secretRef:
  31772. description: |-
  31773. Reference to a key in a Secret that contains the App Role secret used
  31774. to authenticate with Vault.
  31775. The `key` field must be specified and denotes which entry within the Secret
  31776. resource is used as the app role secret.
  31777. properties:
  31778. key:
  31779. description: |-
  31780. A key in the referenced Secret.
  31781. Some instances of this field may be defaulted, in others it may be required.
  31782. maxLength: 253
  31783. minLength: 1
  31784. pattern: ^[-._a-zA-Z0-9]+$
  31785. type: string
  31786. name:
  31787. description: The name of the Secret resource being referred to.
  31788. maxLength: 253
  31789. minLength: 1
  31790. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31791. type: string
  31792. namespace:
  31793. description: |-
  31794. The namespace of the Secret resource being referred to.
  31795. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31796. maxLength: 63
  31797. minLength: 1
  31798. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31799. type: string
  31800. type: object
  31801. required:
  31802. - path
  31803. - secretRef
  31804. type: object
  31805. cert:
  31806. description: |-
  31807. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  31808. Cert authentication method
  31809. properties:
  31810. clientCert:
  31811. description: |-
  31812. ClientCert is a certificate to authenticate using the Cert Vault
  31813. authentication method
  31814. properties:
  31815. key:
  31816. description: |-
  31817. A key in the referenced Secret.
  31818. Some instances of this field may be defaulted, in others it may be required.
  31819. maxLength: 253
  31820. minLength: 1
  31821. pattern: ^[-._a-zA-Z0-9]+$
  31822. type: string
  31823. name:
  31824. description: The name of the Secret resource being referred to.
  31825. maxLength: 253
  31826. minLength: 1
  31827. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31828. type: string
  31829. namespace:
  31830. description: |-
  31831. The namespace of the Secret resource being referred to.
  31832. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31833. maxLength: 63
  31834. minLength: 1
  31835. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31836. type: string
  31837. type: object
  31838. path:
  31839. default: cert
  31840. description: |-
  31841. Path where the Certificate authentication backend is mounted
  31842. in Vault, e.g: "cert"
  31843. type: string
  31844. secretRef:
  31845. description: |-
  31846. SecretRef to a key in a Secret resource containing client private key to
  31847. authenticate with Vault using the Cert authentication method
  31848. properties:
  31849. key:
  31850. description: |-
  31851. A key in the referenced Secret.
  31852. Some instances of this field may be defaulted, in others it may be required.
  31853. maxLength: 253
  31854. minLength: 1
  31855. pattern: ^[-._a-zA-Z0-9]+$
  31856. type: string
  31857. name:
  31858. description: The name of the Secret resource being referred to.
  31859. maxLength: 253
  31860. minLength: 1
  31861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31862. type: string
  31863. namespace:
  31864. description: |-
  31865. The namespace of the Secret resource being referred to.
  31866. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31867. maxLength: 63
  31868. minLength: 1
  31869. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31870. type: string
  31871. type: object
  31872. vaultRole:
  31873. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  31874. type: string
  31875. type: object
  31876. gcp:
  31877. description: |-
  31878. Gcp authenticates with Vault using Google Cloud Platform authentication method
  31879. GCP authentication method
  31880. properties:
  31881. location:
  31882. description: Location optionally defines a location/region for the secret
  31883. type: string
  31884. path:
  31885. default: gcp
  31886. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  31887. type: string
  31888. projectID:
  31889. description: Project ID of the Google Cloud Platform project
  31890. type: string
  31891. role:
  31892. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  31893. type: string
  31894. secretRef:
  31895. description: Specify credentials in a Secret object
  31896. properties:
  31897. secretAccessKeySecretRef:
  31898. description: The SecretAccessKey is used for authentication
  31899. properties:
  31900. key:
  31901. description: |-
  31902. A key in the referenced Secret.
  31903. Some instances of this field may be defaulted, in others it may be required.
  31904. maxLength: 253
  31905. minLength: 1
  31906. pattern: ^[-._a-zA-Z0-9]+$
  31907. type: string
  31908. name:
  31909. description: The name of the Secret resource being referred to.
  31910. maxLength: 253
  31911. minLength: 1
  31912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31913. type: string
  31914. namespace:
  31915. description: |-
  31916. The namespace of the Secret resource being referred to.
  31917. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31918. maxLength: 63
  31919. minLength: 1
  31920. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31921. type: string
  31922. type: object
  31923. type: object
  31924. serviceAccountRef:
  31925. description: ServiceAccountRef to a service account for impersonation
  31926. properties:
  31927. audiences:
  31928. description: |-
  31929. Audience specifies the `aud` claim for the service account token
  31930. Some providers automatically extend the audience field based on well-known annotations for workload
  31931. identity (e.g. IRSA or GCP Workload Identity)
  31932. items:
  31933. type: string
  31934. type: array
  31935. name:
  31936. description: The name of the ServiceAccount resource being referred to.
  31937. maxLength: 253
  31938. minLength: 1
  31939. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31940. type: string
  31941. namespace:
  31942. description: |-
  31943. Namespace of the resource being referred to.
  31944. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31945. maxLength: 63
  31946. minLength: 1
  31947. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31948. type: string
  31949. required:
  31950. - name
  31951. type: object
  31952. workloadIdentity:
  31953. description: Specify a service account with Workload Identity
  31954. properties:
  31955. clusterLocation:
  31956. description: |-
  31957. ClusterLocation is the location of the cluster
  31958. If not specified, it fetches information from the metadata server
  31959. type: string
  31960. clusterName:
  31961. description: |-
  31962. ClusterName is the name of the cluster
  31963. If not specified, it fetches information from the metadata server
  31964. type: string
  31965. clusterProjectID:
  31966. description: |-
  31967. ClusterProjectID is the project ID of the cluster
  31968. If not specified, it fetches information from the metadata server
  31969. type: string
  31970. serviceAccountRef:
  31971. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31972. properties:
  31973. audiences:
  31974. description: |-
  31975. Audience specifies the `aud` claim for the service account token
  31976. Some providers automatically extend the audience field based on well-known annotations for workload
  31977. identity (e.g. IRSA or GCP Workload Identity)
  31978. items:
  31979. type: string
  31980. type: array
  31981. name:
  31982. description: The name of the ServiceAccount resource being referred to.
  31983. maxLength: 253
  31984. minLength: 1
  31985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31986. type: string
  31987. namespace:
  31988. description: |-
  31989. Namespace of the resource being referred to.
  31990. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31991. maxLength: 63
  31992. minLength: 1
  31993. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31994. type: string
  31995. required:
  31996. - name
  31997. type: object
  31998. required:
  31999. - serviceAccountRef
  32000. type: object
  32001. required:
  32002. - role
  32003. type: object
  32004. iam:
  32005. description: |-
  32006. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  32007. AWS IAM authentication method
  32008. properties:
  32009. externalID:
  32010. description: AWS External ID set on assumed IAM roles
  32011. type: string
  32012. jwt:
  32013. description: Specify a service account with IRSA enabled
  32014. properties:
  32015. serviceAccountRef:
  32016. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  32017. properties:
  32018. audiences:
  32019. description: |-
  32020. Audience specifies the `aud` claim for the service account token
  32021. Some providers automatically extend the audience field based on well-known annotations for workload
  32022. identity (e.g. IRSA or GCP Workload Identity)
  32023. items:
  32024. type: string
  32025. type: array
  32026. name:
  32027. description: The name of the ServiceAccount resource being referred to.
  32028. maxLength: 253
  32029. minLength: 1
  32030. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32031. type: string
  32032. namespace:
  32033. description: |-
  32034. Namespace of the resource being referred to.
  32035. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32036. maxLength: 63
  32037. minLength: 1
  32038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32039. type: string
  32040. required:
  32041. - name
  32042. type: object
  32043. type: object
  32044. path:
  32045. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  32046. type: string
  32047. region:
  32048. description: AWS region
  32049. type: string
  32050. role:
  32051. description: This is the AWS role to be assumed before talking to vault
  32052. type: string
  32053. secretRef:
  32054. description: Specify credentials in a Secret object
  32055. properties:
  32056. accessKeyIDSecretRef:
  32057. description: The AccessKeyID is used for authentication
  32058. properties:
  32059. key:
  32060. description: |-
  32061. A key in the referenced Secret.
  32062. Some instances of this field may be defaulted, in others it may be required.
  32063. maxLength: 253
  32064. minLength: 1
  32065. pattern: ^[-._a-zA-Z0-9]+$
  32066. type: string
  32067. name:
  32068. description: The name of the Secret resource being referred to.
  32069. maxLength: 253
  32070. minLength: 1
  32071. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32072. type: string
  32073. namespace:
  32074. description: |-
  32075. The namespace of the Secret resource being referred to.
  32076. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32077. maxLength: 63
  32078. minLength: 1
  32079. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32080. type: string
  32081. type: object
  32082. secretAccessKeySecretRef:
  32083. description: The SecretAccessKey is used for authentication
  32084. properties:
  32085. key:
  32086. description: |-
  32087. A key in the referenced Secret.
  32088. Some instances of this field may be defaulted, in others it may be required.
  32089. maxLength: 253
  32090. minLength: 1
  32091. pattern: ^[-._a-zA-Z0-9]+$
  32092. type: string
  32093. name:
  32094. description: The name of the Secret resource being referred to.
  32095. maxLength: 253
  32096. minLength: 1
  32097. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32098. type: string
  32099. namespace:
  32100. description: |-
  32101. The namespace of the Secret resource being referred to.
  32102. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32103. maxLength: 63
  32104. minLength: 1
  32105. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32106. type: string
  32107. type: object
  32108. sessionTokenSecretRef:
  32109. description: |-
  32110. The SessionToken used for authentication
  32111. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  32112. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  32113. properties:
  32114. key:
  32115. description: |-
  32116. A key in the referenced Secret.
  32117. Some instances of this field may be defaulted, in others it may be required.
  32118. maxLength: 253
  32119. minLength: 1
  32120. pattern: ^[-._a-zA-Z0-9]+$
  32121. type: string
  32122. name:
  32123. description: The name of the Secret resource being referred to.
  32124. maxLength: 253
  32125. minLength: 1
  32126. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32127. type: string
  32128. namespace:
  32129. description: |-
  32130. The namespace of the Secret resource being referred to.
  32131. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32132. maxLength: 63
  32133. minLength: 1
  32134. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32135. type: string
  32136. type: object
  32137. type: object
  32138. vaultAwsIamServerID:
  32139. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  32140. type: string
  32141. vaultRole:
  32142. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  32143. type: string
  32144. required:
  32145. - vaultRole
  32146. type: object
  32147. jwt:
  32148. description: |-
  32149. Jwt authenticates with Vault by passing role and JWT token using the
  32150. JWT/OIDC authentication method
  32151. properties:
  32152. kubernetesServiceAccountToken:
  32153. description: |-
  32154. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  32155. a token for with the `TokenRequest` API.
  32156. properties:
  32157. audiences:
  32158. description: |-
  32159. Optional audiences field that will be used to request a temporary Kubernetes service
  32160. account token for the service account referenced by `serviceAccountRef`.
  32161. Defaults to a single audience `vault` it not specified.
  32162. Deprecated: use serviceAccountRef.Audiences instead
  32163. items:
  32164. type: string
  32165. type: array
  32166. expirationSeconds:
  32167. description: |-
  32168. Optional expiration time in seconds that will be used to request a temporary
  32169. Kubernetes service account token for the service account referenced by
  32170. `serviceAccountRef`.
  32171. Deprecated: this will be removed in the future.
  32172. Defaults to 10 minutes.
  32173. format: int64
  32174. type: integer
  32175. serviceAccountRef:
  32176. description: Service account field containing the name of a kubernetes ServiceAccount.
  32177. properties:
  32178. audiences:
  32179. description: |-
  32180. Audience specifies the `aud` claim for the service account token
  32181. Some providers automatically extend the audience field based on well-known annotations for workload
  32182. identity (e.g. IRSA or GCP Workload Identity)
  32183. items:
  32184. type: string
  32185. type: array
  32186. name:
  32187. description: The name of the ServiceAccount resource being referred to.
  32188. maxLength: 253
  32189. minLength: 1
  32190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32191. type: string
  32192. namespace:
  32193. description: |-
  32194. Namespace of the resource being referred to.
  32195. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32196. maxLength: 63
  32197. minLength: 1
  32198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32199. type: string
  32200. required:
  32201. - name
  32202. type: object
  32203. required:
  32204. - serviceAccountRef
  32205. type: object
  32206. path:
  32207. default: jwt
  32208. description: |-
  32209. Path where the JWT authentication backend is mounted
  32210. in Vault, e.g: "jwt"
  32211. type: string
  32212. role:
  32213. description: |-
  32214. Role is a JWT role to authenticate using the JWT/OIDC Vault
  32215. authentication method
  32216. type: string
  32217. secretRef:
  32218. description: |-
  32219. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  32220. authenticate with Vault using the JWT/OIDC authentication method.
  32221. properties:
  32222. key:
  32223. description: |-
  32224. A key in the referenced Secret.
  32225. Some instances of this field may be defaulted, in others it may be required.
  32226. maxLength: 253
  32227. minLength: 1
  32228. pattern: ^[-._a-zA-Z0-9]+$
  32229. type: string
  32230. name:
  32231. description: The name of the Secret resource being referred to.
  32232. maxLength: 253
  32233. minLength: 1
  32234. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32235. type: string
  32236. namespace:
  32237. description: |-
  32238. The namespace of the Secret resource being referred to.
  32239. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32240. maxLength: 63
  32241. minLength: 1
  32242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32243. type: string
  32244. type: object
  32245. required:
  32246. - path
  32247. type: object
  32248. kubernetes:
  32249. description: |-
  32250. Kubernetes authenticates with Vault by passing the ServiceAccount
  32251. token stored in the named Secret resource to the Vault server.
  32252. properties:
  32253. mountPath:
  32254. default: kubernetes
  32255. description: |-
  32256. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  32257. "kubernetes"
  32258. type: string
  32259. role:
  32260. description: |-
  32261. A required field containing the Vault Role to assume. A Role binds a
  32262. Kubernetes ServiceAccount with a set of Vault policies.
  32263. type: string
  32264. secretRef:
  32265. description: |-
  32266. Optional secret field containing a Kubernetes ServiceAccount JWT used
  32267. for authenticating with Vault. If a name is specified without a key,
  32268. `token` is the default. If one is not specified, the one bound to
  32269. the controller will be used.
  32270. properties:
  32271. key:
  32272. description: |-
  32273. A key in the referenced Secret.
  32274. Some instances of this field may be defaulted, in others it may be required.
  32275. maxLength: 253
  32276. minLength: 1
  32277. pattern: ^[-._a-zA-Z0-9]+$
  32278. type: string
  32279. name:
  32280. description: The name of the Secret resource being referred to.
  32281. maxLength: 253
  32282. minLength: 1
  32283. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32284. type: string
  32285. namespace:
  32286. description: |-
  32287. The namespace of the Secret resource being referred to.
  32288. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32289. maxLength: 63
  32290. minLength: 1
  32291. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32292. type: string
  32293. type: object
  32294. serviceAccountRef:
  32295. description: |-
  32296. Optional service account field containing the name of a kubernetes ServiceAccount.
  32297. If the service account is specified, the service account secret token JWT will be used
  32298. for authenticating with Vault. If the service account selector is not supplied,
  32299. the secretRef will be used instead.
  32300. properties:
  32301. audiences:
  32302. description: |-
  32303. Audience specifies the `aud` claim for the service account token
  32304. Some providers automatically extend the audience field based on well-known annotations for workload
  32305. identity (e.g. IRSA or GCP Workload Identity)
  32306. items:
  32307. type: string
  32308. type: array
  32309. name:
  32310. description: The name of the ServiceAccount resource being referred to.
  32311. maxLength: 253
  32312. minLength: 1
  32313. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32314. type: string
  32315. namespace:
  32316. description: |-
  32317. Namespace of the resource being referred to.
  32318. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32319. maxLength: 63
  32320. minLength: 1
  32321. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32322. type: string
  32323. required:
  32324. - name
  32325. type: object
  32326. required:
  32327. - mountPath
  32328. - role
  32329. type: object
  32330. ldap:
  32331. description: |-
  32332. Ldap authenticates with Vault by passing username/password pair using
  32333. the LDAP authentication method
  32334. properties:
  32335. path:
  32336. default: ldap
  32337. description: |-
  32338. Path where the LDAP authentication backend is mounted
  32339. in Vault, e.g: "ldap"
  32340. type: string
  32341. secretRef:
  32342. description: |-
  32343. SecretRef to a key in a Secret resource containing password for the LDAP
  32344. user used to authenticate with Vault using the LDAP authentication
  32345. method
  32346. properties:
  32347. key:
  32348. description: |-
  32349. A key in the referenced Secret.
  32350. Some instances of this field may be defaulted, in others it may be required.
  32351. maxLength: 253
  32352. minLength: 1
  32353. pattern: ^[-._a-zA-Z0-9]+$
  32354. type: string
  32355. name:
  32356. description: The name of the Secret resource being referred to.
  32357. maxLength: 253
  32358. minLength: 1
  32359. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32360. type: string
  32361. namespace:
  32362. description: |-
  32363. The namespace of the Secret resource being referred to.
  32364. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32365. maxLength: 63
  32366. minLength: 1
  32367. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32368. type: string
  32369. type: object
  32370. username:
  32371. description: |-
  32372. Username is an LDAP username used to authenticate using the LDAP Vault
  32373. authentication method
  32374. type: string
  32375. required:
  32376. - path
  32377. - username
  32378. type: object
  32379. namespace:
  32380. description: |-
  32381. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  32382. Namespaces is a set of features within Vault Enterprise that allows
  32383. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  32384. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  32385. This will default to Vault.Namespace field if set, or empty otherwise
  32386. type: string
  32387. tokenSecretRef:
  32388. description: TokenSecretRef authenticates with Vault by presenting a token.
  32389. properties:
  32390. key:
  32391. description: |-
  32392. A key in the referenced Secret.
  32393. Some instances of this field may be defaulted, in others it may be required.
  32394. maxLength: 253
  32395. minLength: 1
  32396. pattern: ^[-._a-zA-Z0-9]+$
  32397. type: string
  32398. name:
  32399. description: The name of the Secret resource being referred to.
  32400. maxLength: 253
  32401. minLength: 1
  32402. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32403. type: string
  32404. namespace:
  32405. description: |-
  32406. The namespace of the Secret resource being referred to.
  32407. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32408. maxLength: 63
  32409. minLength: 1
  32410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32411. type: string
  32412. type: object
  32413. userPass:
  32414. description: UserPass authenticates with Vault by passing username/password pair
  32415. properties:
  32416. path:
  32417. default: userpass
  32418. description: |-
  32419. Path where the UserPassword authentication backend is mounted
  32420. in Vault, e.g: "userpass"
  32421. type: string
  32422. secretRef:
  32423. description: |-
  32424. SecretRef to a key in a Secret resource containing password for the
  32425. user used to authenticate with Vault using the UserPass authentication
  32426. method
  32427. properties:
  32428. key:
  32429. description: |-
  32430. A key in the referenced Secret.
  32431. Some instances of this field may be defaulted, in others it may be required.
  32432. maxLength: 253
  32433. minLength: 1
  32434. pattern: ^[-._a-zA-Z0-9]+$
  32435. type: string
  32436. name:
  32437. description: The name of the Secret resource being referred to.
  32438. maxLength: 253
  32439. minLength: 1
  32440. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32441. type: string
  32442. namespace:
  32443. description: |-
  32444. The namespace of the Secret resource being referred to.
  32445. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32446. maxLength: 63
  32447. minLength: 1
  32448. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32449. type: string
  32450. type: object
  32451. username:
  32452. description: |-
  32453. Username is a username used to authenticate using the UserPass Vault
  32454. authentication method
  32455. type: string
  32456. required:
  32457. - path
  32458. - username
  32459. type: object
  32460. type: object
  32461. caBundle:
  32462. description: |-
  32463. PEM encoded CA bundle used to validate Vault server certificate. Only used
  32464. if the Server URL is using HTTPS protocol. This parameter is ignored for
  32465. plain HTTP protocol connection. If not set the system root certificates
  32466. are used to validate the TLS connection.
  32467. format: byte
  32468. type: string
  32469. caProvider:
  32470. description: The provider for the CA bundle to use to validate Vault server certificate.
  32471. properties:
  32472. key:
  32473. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  32474. maxLength: 253
  32475. minLength: 1
  32476. pattern: ^[-._a-zA-Z0-9]+$
  32477. type: string
  32478. name:
  32479. description: The name of the object located at the provider type.
  32480. maxLength: 253
  32481. minLength: 1
  32482. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32483. type: string
  32484. namespace:
  32485. description: |-
  32486. The namespace the Provider type is in.
  32487. Can only be defined when used in a ClusterSecretStore.
  32488. maxLength: 63
  32489. minLength: 1
  32490. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32491. type: string
  32492. type:
  32493. description: The type of provider to use such as "Secret", or "ConfigMap".
  32494. enum:
  32495. - Secret
  32496. - ConfigMap
  32497. type: string
  32498. required:
  32499. - name
  32500. - type
  32501. type: object
  32502. checkAndSet:
  32503. description: |-
  32504. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  32505. Only applies to Vault KV v2 stores. When enabled, write operations must include
  32506. the current version of the secret to prevent unintentional overwrites.
  32507. properties:
  32508. required:
  32509. description: |-
  32510. Required when true, all write operations must include a check-and-set parameter.
  32511. This helps prevent unintentional overwrites of secrets.
  32512. type: boolean
  32513. type: object
  32514. forwardInconsistent:
  32515. description: |-
  32516. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  32517. leader instead of simply retrying within a loop. This can increase performance if
  32518. the option is enabled serverside.
  32519. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  32520. type: boolean
  32521. headers:
  32522. additionalProperties:
  32523. type: string
  32524. description: Headers to be added in Vault request
  32525. type: object
  32526. namespace:
  32527. description: |-
  32528. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  32529. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  32530. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  32531. type: string
  32532. path:
  32533. description: |-
  32534. Path is the mount path of the Vault KV backend endpoint, e.g:
  32535. "secret". The v2 KV secret engine version specific "/data" path suffix
  32536. for fetching secrets from Vault is optional and will be appended
  32537. if not present in specified path.
  32538. type: string
  32539. readYourWrites:
  32540. description: |-
  32541. ReadYourWrites ensures isolated read-after-write semantics by
  32542. providing discovered cluster replication states in each request.
  32543. More information about eventual consistency in Vault can be found here
  32544. https://www.vaultproject.io/docs/enterprise/consistency
  32545. type: boolean
  32546. server:
  32547. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  32548. type: string
  32549. tls:
  32550. description: |-
  32551. The configuration used for client side related TLS communication, when the Vault server
  32552. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  32553. This parameter is ignored for plain HTTP protocol connection.
  32554. It's worth noting this configuration is different from the "TLS certificates auth method",
  32555. which is available under the `auth.cert` section.
  32556. properties:
  32557. certSecretRef:
  32558. description: |-
  32559. CertSecretRef is a certificate added to the transport layer
  32560. when communicating with the Vault server.
  32561. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  32562. properties:
  32563. key:
  32564. description: |-
  32565. A key in the referenced Secret.
  32566. Some instances of this field may be defaulted, in others it may be required.
  32567. maxLength: 253
  32568. minLength: 1
  32569. pattern: ^[-._a-zA-Z0-9]+$
  32570. type: string
  32571. name:
  32572. description: The name of the Secret resource being referred to.
  32573. maxLength: 253
  32574. minLength: 1
  32575. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32576. type: string
  32577. namespace:
  32578. description: |-
  32579. The namespace of the Secret resource being referred to.
  32580. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32581. maxLength: 63
  32582. minLength: 1
  32583. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32584. type: string
  32585. type: object
  32586. keySecretRef:
  32587. description: |-
  32588. KeySecretRef to a key in a Secret resource containing client private key
  32589. added to the transport layer when communicating with the Vault server.
  32590. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  32591. properties:
  32592. key:
  32593. description: |-
  32594. A key in the referenced Secret.
  32595. Some instances of this field may be defaulted, in others it may be required.
  32596. maxLength: 253
  32597. minLength: 1
  32598. pattern: ^[-._a-zA-Z0-9]+$
  32599. type: string
  32600. name:
  32601. description: The name of the Secret resource being referred to.
  32602. maxLength: 253
  32603. minLength: 1
  32604. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32605. type: string
  32606. namespace:
  32607. description: |-
  32608. The namespace of the Secret resource being referred to.
  32609. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32610. maxLength: 63
  32611. minLength: 1
  32612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32613. type: string
  32614. type: object
  32615. type: object
  32616. version:
  32617. default: v2
  32618. description: |-
  32619. Version is the Vault KV secret engine version. This can be either "v1" or
  32620. "v2". Version defaults to "v2".
  32621. enum:
  32622. - v1
  32623. - v2
  32624. type: string
  32625. required:
  32626. - server
  32627. type: object
  32628. resultType:
  32629. default: Data
  32630. description: |-
  32631. Result type defines which data is returned from the generator.
  32632. By default, it is the "data" section of the Vault API response.
  32633. When using e.g. /auth/token/create the "data" section is empty but
  32634. the "auth" section contains the generated token.
  32635. Please refer to the vault docs regarding the result data structure.
  32636. Additionally, accessing the raw response is possibly by using "Raw" result type.
  32637. enum:
  32638. - Data
  32639. - Auth
  32640. - Raw
  32641. type: string
  32642. retrySettings:
  32643. description: Used to configure http retries if failed
  32644. properties:
  32645. maxRetries:
  32646. format: int32
  32647. type: integer
  32648. retryInterval:
  32649. type: string
  32650. type: object
  32651. required:
  32652. - path
  32653. - provider
  32654. type: object
  32655. type: object
  32656. served: true
  32657. storage: true
  32658. subresources:
  32659. status: {}
  32660. ---
  32661. apiVersion: apiextensions.k8s.io/v1
  32662. kind: CustomResourceDefinition
  32663. metadata:
  32664. annotations:
  32665. controller-gen.kubebuilder.io/version: v0.19.0
  32666. labels:
  32667. external-secrets.io/component: controller
  32668. name: webhooks.generators.external-secrets.io
  32669. spec:
  32670. group: generators.external-secrets.io
  32671. names:
  32672. categories:
  32673. - external-secrets
  32674. - external-secrets-generators
  32675. kind: Webhook
  32676. listKind: WebhookList
  32677. plural: webhooks
  32678. singular: webhook
  32679. scope: Namespaced
  32680. versions:
  32681. - name: v1alpha1
  32682. schema:
  32683. openAPIV3Schema:
  32684. description: |-
  32685. Webhook connects to a third party API server to handle the secrets generation
  32686. configuration parameters in spec.
  32687. You can specify the server, the token, and additional body parameters.
  32688. See documentation for the full API specification for requests and responses.
  32689. properties:
  32690. apiVersion:
  32691. description: |-
  32692. APIVersion defines the versioned schema of this representation of an object.
  32693. Servers should convert recognized schemas to the latest internal value, and
  32694. may reject unrecognized values.
  32695. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  32696. type: string
  32697. kind:
  32698. description: |-
  32699. Kind is a string value representing the REST resource this object represents.
  32700. Servers may infer this from the endpoint the client submits requests to.
  32701. Cannot be updated.
  32702. In CamelCase.
  32703. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  32704. type: string
  32705. metadata:
  32706. type: object
  32707. spec:
  32708. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  32709. properties:
  32710. auth:
  32711. description: Auth specifies a authorization protocol. Only one protocol may be set.
  32712. maxProperties: 1
  32713. minProperties: 1
  32714. properties:
  32715. ntlm:
  32716. description: NTLMProtocol configures the store to use NTLM for auth
  32717. properties:
  32718. passwordSecret:
  32719. description: |-
  32720. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  32721. In some instances, `key` is a required field.
  32722. properties:
  32723. key:
  32724. description: |-
  32725. A key in the referenced Secret.
  32726. Some instances of this field may be defaulted, in others it may be required.
  32727. maxLength: 253
  32728. minLength: 1
  32729. pattern: ^[-._a-zA-Z0-9]+$
  32730. type: string
  32731. name:
  32732. description: The name of the Secret resource being referred to.
  32733. maxLength: 253
  32734. minLength: 1
  32735. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32736. type: string
  32737. namespace:
  32738. description: |-
  32739. The namespace of the Secret resource being referred to.
  32740. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32741. maxLength: 63
  32742. minLength: 1
  32743. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32744. type: string
  32745. type: object
  32746. usernameSecret:
  32747. description: |-
  32748. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  32749. In some instances, `key` is a required field.
  32750. properties:
  32751. key:
  32752. description: |-
  32753. A key in the referenced Secret.
  32754. Some instances of this field may be defaulted, in others it may be required.
  32755. maxLength: 253
  32756. minLength: 1
  32757. pattern: ^[-._a-zA-Z0-9]+$
  32758. type: string
  32759. name:
  32760. description: The name of the Secret resource being referred to.
  32761. maxLength: 253
  32762. minLength: 1
  32763. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32764. type: string
  32765. namespace:
  32766. description: |-
  32767. The namespace of the Secret resource being referred to.
  32768. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32769. maxLength: 63
  32770. minLength: 1
  32771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32772. type: string
  32773. type: object
  32774. required:
  32775. - passwordSecret
  32776. - usernameSecret
  32777. type: object
  32778. type: object
  32779. body:
  32780. description: Body
  32781. type: string
  32782. caBundle:
  32783. description: |-
  32784. PEM encoded CA bundle used to validate webhook server certificate. Only used
  32785. if the Server URL is using HTTPS protocol. This parameter is ignored for
  32786. plain HTTP protocol connection. If not set the system root certificates
  32787. are used to validate the TLS connection.
  32788. format: byte
  32789. type: string
  32790. caProvider:
  32791. description: The provider for the CA bundle to use to validate webhook server certificate.
  32792. properties:
  32793. key:
  32794. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  32795. maxLength: 253
  32796. minLength: 1
  32797. pattern: ^[-._a-zA-Z0-9]+$
  32798. type: string
  32799. name:
  32800. description: The name of the object located at the provider type.
  32801. maxLength: 253
  32802. minLength: 1
  32803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32804. type: string
  32805. namespace:
  32806. description: The namespace the Provider type is in.
  32807. maxLength: 63
  32808. minLength: 1
  32809. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32810. type: string
  32811. type:
  32812. description: The type of provider to use such as "Secret", or "ConfigMap".
  32813. enum:
  32814. - Secret
  32815. - ConfigMap
  32816. type: string
  32817. required:
  32818. - name
  32819. - type
  32820. type: object
  32821. headers:
  32822. additionalProperties:
  32823. type: string
  32824. description: Headers
  32825. type: object
  32826. method:
  32827. description: Webhook Method
  32828. type: string
  32829. result:
  32830. description: Result formatting
  32831. properties:
  32832. jsonPath:
  32833. description: Json path of return value
  32834. type: string
  32835. type: object
  32836. secrets:
  32837. description: |-
  32838. Secrets to fill in templates
  32839. These secrets will be passed to the templating function as key value pairs under the given name
  32840. items:
  32841. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  32842. properties:
  32843. name:
  32844. description: Name of this secret in templates
  32845. type: string
  32846. secretRef:
  32847. description: Secret ref to fill in credentials
  32848. properties:
  32849. key:
  32850. description: The key where the token is found.
  32851. maxLength: 253
  32852. minLength: 1
  32853. pattern: ^[-._a-zA-Z0-9]+$
  32854. type: string
  32855. name:
  32856. description: The name of the Secret resource being referred to.
  32857. maxLength: 253
  32858. minLength: 1
  32859. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32860. type: string
  32861. type: object
  32862. required:
  32863. - name
  32864. - secretRef
  32865. type: object
  32866. type: array
  32867. timeout:
  32868. description: Timeout
  32869. type: string
  32870. url:
  32871. description: Webhook url to call
  32872. type: string
  32873. required:
  32874. - result
  32875. - url
  32876. type: object
  32877. type: object
  32878. served: true
  32879. storage: true
  32880. subresources:
  32881. status: {}