bundle.yaml 1.9 MB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117211821192120212121222123212421252126212721282129213021312132213321342135213621372138213921402141214221432144214521462147214821492150215121522153215421552156215721582159216021612162216321642165216621672168216921702171217221732174217521762177217821792180218121822183218421852186218721882189219021912192219321942195219621972198219922002201220222032204220522062207220822092210221122122213221422152216221722182219222022212222222322242225222622272228222922302231223222332234223522362237223822392240224122422243224422452246224722482249225022512252225322542255225622572258225922602261226222632264226522662267226822692270227122722273227422752276227722782279228022812282228322842285228622872288228922902291229222932294229522962297229822992300230123022303230423052306230723082309231023112312231323142315231623172318231923202321232223232324232523262327232823292330233123322333233423352336233723382339234023412342234323442345234623472348234923502351235223532354235523562357235823592360236123622363236423652366236723682369237023712372237323742375237623772378237923802381238223832384238523862387238823892390239123922393239423952396239723982399240024012402240324042405240624072408240924102411241224132414241524162417241824192420242124222423242424252426242724282429243024312432243324342435243624372438243924402441244224432444244524462447244824492450245124522453245424552456245724582459246024612462246324642465246624672468246924702471247224732474247524762477247824792480248124822483248424852486248724882489249024912492249324942495249624972498249925002501250225032504250525062507250825092510251125122513251425152516251725182519252025212522252325242525252625272528252925302531253225332534253525362537253825392540254125422543254425452546254725482549255025512552255325542555255625572558255925602561256225632564256525662567256825692570257125722573257425752576257725782579258025812582258325842585258625872588258925902591259225932594259525962597259825992600260126022603260426052606260726082609261026112612261326142615261626172618261926202621262226232624262526262627262826292630263126322633263426352636263726382639264026412642264326442645264626472648264926502651265226532654265526562657265826592660266126622663266426652666266726682669267026712672267326742675267626772678267926802681268226832684268526862687268826892690269126922693269426952696269726982699270027012702270327042705270627072708270927102711271227132714271527162717271827192720272127222723272427252726272727282729273027312732273327342735273627372738273927402741274227432744274527462747274827492750275127522753275427552756275727582759276027612762276327642765276627672768276927702771277227732774277527762777277827792780278127822783278427852786278727882789279027912792279327942795279627972798279928002801280228032804280528062807280828092810281128122813281428152816281728182819282028212822282328242825282628272828282928302831283228332834283528362837283828392840284128422843284428452846284728482849285028512852285328542855285628572858285928602861286228632864286528662867286828692870287128722873287428752876287728782879288028812882288328842885288628872888288928902891289228932894289528962897289828992900290129022903290429052906290729082909291029112912291329142915291629172918291929202921292229232924292529262927292829292930293129322933293429352936293729382939294029412942294329442945294629472948294929502951295229532954295529562957295829592960296129622963296429652966296729682969297029712972297329742975297629772978297929802981298229832984298529862987298829892990299129922993299429952996299729982999300030013002300330043005300630073008300930103011301230133014301530163017301830193020302130223023302430253026302730283029303030313032303330343035303630373038303930403041304230433044304530463047304830493050305130523053305430553056305730583059306030613062306330643065306630673068306930703071307230733074307530763077307830793080308130823083308430853086308730883089309030913092309330943095309630973098309931003101310231033104310531063107310831093110311131123113311431153116311731183119312031213122312331243125312631273128312931303131313231333134313531363137313831393140314131423143314431453146314731483149315031513152315331543155315631573158315931603161316231633164316531663167316831693170317131723173317431753176317731783179318031813182318331843185318631873188318931903191319231933194319531963197319831993200320132023203320432053206320732083209321032113212321332143215321632173218321932203221322232233224322532263227322832293230323132323233323432353236323732383239324032413242324332443245324632473248324932503251325232533254325532563257325832593260326132623263326432653266326732683269327032713272327332743275327632773278327932803281328232833284328532863287328832893290329132923293329432953296329732983299330033013302330333043305330633073308330933103311331233133314331533163317331833193320332133223323332433253326332733283329333033313332333333343335333633373338333933403341334233433344334533463347334833493350335133523353335433553356335733583359336033613362336333643365336633673368336933703371337233733374337533763377337833793380338133823383338433853386338733883389339033913392339333943395339633973398339934003401340234033404340534063407340834093410341134123413341434153416341734183419342034213422342334243425342634273428342934303431343234333434343534363437343834393440344134423443344434453446344734483449345034513452345334543455345634573458345934603461346234633464346534663467346834693470347134723473347434753476347734783479348034813482348334843485348634873488348934903491349234933494349534963497349834993500350135023503350435053506350735083509351035113512351335143515351635173518351935203521352235233524352535263527352835293530353135323533353435353536353735383539354035413542354335443545354635473548354935503551355235533554355535563557355835593560356135623563356435653566356735683569357035713572357335743575357635773578357935803581358235833584358535863587358835893590359135923593359435953596359735983599360036013602360336043605360636073608360936103611361236133614361536163617361836193620362136223623362436253626362736283629363036313632363336343635363636373638363936403641364236433644364536463647364836493650365136523653365436553656365736583659366036613662366336643665366636673668366936703671367236733674367536763677367836793680368136823683368436853686368736883689369036913692369336943695369636973698369937003701370237033704370537063707370837093710371137123713371437153716371737183719372037213722372337243725372637273728372937303731373237333734373537363737373837393740374137423743374437453746374737483749375037513752375337543755375637573758375937603761376237633764376537663767376837693770377137723773377437753776377737783779378037813782378337843785378637873788378937903791379237933794379537963797379837993800380138023803380438053806380738083809381038113812381338143815381638173818381938203821382238233824382538263827382838293830383138323833383438353836383738383839384038413842384338443845384638473848384938503851385238533854385538563857385838593860386138623863386438653866386738683869387038713872387338743875387638773878387938803881388238833884388538863887388838893890389138923893389438953896389738983899390039013902390339043905390639073908390939103911391239133914391539163917391839193920392139223923392439253926392739283929393039313932393339343935393639373938393939403941394239433944394539463947394839493950395139523953395439553956395739583959396039613962396339643965396639673968396939703971397239733974397539763977397839793980398139823983398439853986398739883989399039913992399339943995399639973998399940004001400240034004400540064007400840094010401140124013401440154016401740184019402040214022402340244025402640274028402940304031403240334034403540364037403840394040404140424043404440454046404740484049405040514052405340544055405640574058405940604061406240634064406540664067406840694070407140724073407440754076407740784079408040814082408340844085408640874088408940904091409240934094409540964097409840994100410141024103410441054106410741084109411041114112411341144115411641174118411941204121412241234124412541264127412841294130413141324133413441354136413741384139414041414142414341444145414641474148414941504151415241534154415541564157415841594160416141624163416441654166416741684169417041714172417341744175417641774178417941804181418241834184418541864187418841894190419141924193419441954196419741984199420042014202420342044205420642074208420942104211421242134214421542164217421842194220422142224223422442254226422742284229423042314232423342344235423642374238423942404241424242434244424542464247424842494250425142524253425442554256425742584259426042614262426342644265426642674268426942704271427242734274427542764277427842794280428142824283428442854286428742884289429042914292429342944295429642974298429943004301430243034304430543064307430843094310431143124313431443154316431743184319432043214322432343244325432643274328432943304331433243334334433543364337433843394340434143424343434443454346434743484349435043514352435343544355435643574358435943604361436243634364436543664367436843694370437143724373437443754376437743784379438043814382438343844385438643874388438943904391439243934394439543964397439843994400440144024403440444054406440744084409441044114412441344144415441644174418441944204421442244234424442544264427442844294430443144324433443444354436443744384439444044414442444344444445444644474448444944504451445244534454445544564457445844594460446144624463446444654466446744684469447044714472447344744475447644774478447944804481448244834484448544864487448844894490449144924493449444954496449744984499450045014502450345044505450645074508450945104511451245134514451545164517451845194520452145224523452445254526452745284529453045314532453345344535453645374538453945404541454245434544454545464547454845494550455145524553455445554556455745584559456045614562456345644565456645674568456945704571457245734574457545764577457845794580458145824583458445854586458745884589459045914592459345944595459645974598459946004601460246034604460546064607460846094610461146124613461446154616461746184619462046214622462346244625462646274628462946304631463246334634463546364637463846394640464146424643464446454646464746484649465046514652465346544655465646574658465946604661466246634664466546664667466846694670467146724673467446754676467746784679468046814682468346844685468646874688468946904691469246934694469546964697469846994700470147024703470447054706470747084709471047114712471347144715471647174718471947204721472247234724472547264727472847294730473147324733473447354736473747384739474047414742474347444745474647474748474947504751475247534754475547564757475847594760476147624763476447654766476747684769477047714772477347744775477647774778477947804781478247834784478547864787478847894790479147924793479447954796479747984799480048014802480348044805480648074808480948104811481248134814481548164817481848194820482148224823482448254826482748284829483048314832483348344835483648374838483948404841484248434844484548464847484848494850485148524853485448554856485748584859486048614862486348644865486648674868486948704871487248734874487548764877487848794880488148824883488448854886488748884889489048914892489348944895489648974898489949004901490249034904490549064907490849094910491149124913491449154916491749184919492049214922492349244925492649274928492949304931493249334934493549364937493849394940494149424943494449454946494749484949495049514952495349544955495649574958495949604961496249634964496549664967496849694970497149724973497449754976497749784979498049814982498349844985498649874988498949904991499249934994499549964997499849995000500150025003500450055006500750085009501050115012501350145015501650175018501950205021502250235024502550265027502850295030503150325033503450355036503750385039504050415042504350445045504650475048504950505051505250535054505550565057505850595060506150625063506450655066506750685069507050715072507350745075507650775078507950805081508250835084508550865087508850895090509150925093509450955096509750985099510051015102510351045105510651075108510951105111511251135114511551165117511851195120512151225123512451255126512751285129513051315132513351345135513651375138513951405141514251435144514551465147514851495150515151525153515451555156515751585159516051615162516351645165516651675168516951705171517251735174517551765177517851795180518151825183518451855186518751885189519051915192519351945195519651975198519952005201520252035204520552065207520852095210521152125213521452155216521752185219522052215222522352245225522652275228522952305231523252335234523552365237523852395240524152425243524452455246524752485249525052515252525352545255525652575258525952605261526252635264526552665267526852695270527152725273527452755276527752785279528052815282528352845285528652875288528952905291529252935294529552965297529852995300530153025303530453055306530753085309531053115312531353145315531653175318531953205321532253235324532553265327532853295330533153325333533453355336533753385339534053415342534353445345534653475348534953505351535253535354535553565357535853595360536153625363536453655366536753685369537053715372537353745375537653775378537953805381538253835384538553865387538853895390539153925393539453955396539753985399540054015402540354045405540654075408540954105411541254135414541554165417541854195420542154225423542454255426542754285429543054315432543354345435543654375438543954405441544254435444544554465447544854495450545154525453545454555456545754585459546054615462546354645465546654675468546954705471547254735474547554765477547854795480548154825483548454855486548754885489549054915492549354945495549654975498549955005501550255035504550555065507550855095510551155125513551455155516551755185519552055215522552355245525552655275528552955305531553255335534553555365537553855395540554155425543554455455546554755485549555055515552555355545555555655575558555955605561556255635564556555665567556855695570557155725573557455755576557755785579558055815582558355845585558655875588558955905591559255935594559555965597559855995600560156025603560456055606560756085609561056115612561356145615561656175618561956205621562256235624562556265627562856295630563156325633563456355636563756385639564056415642564356445645564656475648564956505651565256535654565556565657565856595660566156625663566456655666566756685669567056715672567356745675567656775678567956805681568256835684568556865687568856895690569156925693569456955696569756985699570057015702570357045705570657075708570957105711571257135714571557165717571857195720572157225723572457255726572757285729573057315732573357345735573657375738573957405741574257435744574557465747574857495750575157525753575457555756575757585759576057615762576357645765576657675768576957705771577257735774577557765777577857795780578157825783578457855786578757885789579057915792579357945795579657975798579958005801580258035804580558065807580858095810581158125813581458155816581758185819582058215822582358245825582658275828582958305831583258335834583558365837583858395840584158425843584458455846584758485849585058515852585358545855585658575858585958605861586258635864586558665867586858695870587158725873587458755876587758785879588058815882588358845885588658875888588958905891589258935894589558965897589858995900590159025903590459055906590759085909591059115912591359145915591659175918591959205921592259235924592559265927592859295930593159325933593459355936593759385939594059415942594359445945594659475948594959505951595259535954595559565957595859595960596159625963596459655966596759685969597059715972597359745975597659775978597959805981598259835984598559865987598859895990599159925993599459955996599759985999600060016002600360046005600660076008600960106011601260136014601560166017601860196020602160226023602460256026602760286029603060316032603360346035603660376038603960406041604260436044604560466047604860496050605160526053605460556056605760586059606060616062606360646065606660676068606960706071607260736074607560766077607860796080608160826083608460856086608760886089609060916092609360946095609660976098609961006101610261036104610561066107610861096110611161126113611461156116611761186119612061216122612361246125612661276128612961306131613261336134613561366137613861396140614161426143614461456146614761486149615061516152615361546155615661576158615961606161616261636164616561666167616861696170617161726173617461756176617761786179618061816182618361846185618661876188618961906191619261936194619561966197619861996200620162026203620462056206620762086209621062116212621362146215621662176218621962206221622262236224622562266227622862296230623162326233623462356236623762386239624062416242624362446245624662476248624962506251625262536254625562566257625862596260626162626263626462656266626762686269627062716272627362746275627662776278627962806281628262836284628562866287628862896290629162926293629462956296629762986299630063016302630363046305630663076308630963106311631263136314631563166317631863196320632163226323632463256326632763286329633063316332633363346335633663376338633963406341634263436344634563466347634863496350635163526353635463556356635763586359636063616362636363646365636663676368636963706371637263736374637563766377637863796380638163826383638463856386638763886389639063916392639363946395639663976398639964006401640264036404640564066407640864096410641164126413641464156416641764186419642064216422642364246425642664276428642964306431643264336434643564366437643864396440644164426443644464456446644764486449645064516452645364546455645664576458645964606461646264636464646564666467646864696470647164726473647464756476647764786479648064816482648364846485648664876488648964906491649264936494649564966497649864996500650165026503650465056506650765086509651065116512651365146515651665176518651965206521652265236524652565266527652865296530653165326533653465356536653765386539654065416542654365446545654665476548654965506551655265536554655565566557655865596560656165626563656465656566656765686569657065716572657365746575657665776578657965806581658265836584658565866587658865896590659165926593659465956596659765986599660066016602660366046605660666076608660966106611661266136614661566166617661866196620662166226623662466256626662766286629663066316632663366346635663666376638663966406641664266436644664566466647664866496650665166526653665466556656665766586659666066616662666366646665666666676668666966706671667266736674667566766677667866796680668166826683668466856686668766886689669066916692669366946695669666976698669967006701670267036704670567066707670867096710671167126713671467156716671767186719672067216722672367246725672667276728672967306731673267336734673567366737673867396740674167426743674467456746674767486749675067516752675367546755675667576758675967606761676267636764676567666767676867696770677167726773677467756776677767786779678067816782678367846785678667876788678967906791679267936794679567966797679867996800680168026803680468056806680768086809681068116812681368146815681668176818681968206821682268236824682568266827682868296830683168326833683468356836683768386839684068416842684368446845684668476848684968506851685268536854685568566857685868596860686168626863686468656866686768686869687068716872687368746875687668776878687968806881688268836884688568866887688868896890689168926893689468956896689768986899690069016902690369046905690669076908690969106911691269136914691569166917691869196920692169226923692469256926692769286929693069316932693369346935693669376938693969406941694269436944694569466947694869496950695169526953695469556956695769586959696069616962696369646965696669676968696969706971697269736974697569766977697869796980698169826983698469856986698769886989699069916992699369946995699669976998699970007001700270037004700570067007700870097010701170127013701470157016701770187019702070217022702370247025702670277028702970307031703270337034703570367037703870397040704170427043704470457046704770487049705070517052705370547055705670577058705970607061706270637064706570667067706870697070707170727073707470757076707770787079708070817082708370847085708670877088708970907091709270937094709570967097709870997100710171027103710471057106710771087109711071117112711371147115711671177118711971207121712271237124712571267127712871297130713171327133713471357136713771387139714071417142714371447145714671477148714971507151715271537154715571567157715871597160716171627163716471657166716771687169717071717172717371747175717671777178717971807181718271837184718571867187718871897190719171927193719471957196719771987199720072017202720372047205720672077208720972107211721272137214721572167217721872197220722172227223722472257226722772287229723072317232723372347235723672377238723972407241724272437244724572467247724872497250725172527253725472557256725772587259726072617262726372647265726672677268726972707271727272737274727572767277727872797280728172827283728472857286728772887289729072917292729372947295729672977298729973007301730273037304730573067307730873097310731173127313731473157316731773187319732073217322732373247325732673277328732973307331733273337334733573367337733873397340734173427343734473457346734773487349735073517352735373547355735673577358735973607361736273637364736573667367736873697370737173727373737473757376737773787379738073817382738373847385738673877388738973907391739273937394739573967397739873997400740174027403740474057406740774087409741074117412741374147415741674177418741974207421742274237424742574267427742874297430743174327433743474357436743774387439744074417442744374447445744674477448744974507451745274537454745574567457745874597460746174627463746474657466746774687469747074717472747374747475747674777478747974807481748274837484748574867487748874897490749174927493749474957496749774987499750075017502750375047505750675077508750975107511751275137514751575167517751875197520752175227523752475257526752775287529753075317532753375347535753675377538753975407541754275437544754575467547754875497550755175527553755475557556755775587559756075617562756375647565756675677568756975707571757275737574757575767577757875797580758175827583758475857586758775887589759075917592759375947595759675977598759976007601760276037604760576067607760876097610761176127613761476157616761776187619762076217622762376247625762676277628762976307631763276337634763576367637763876397640764176427643764476457646764776487649765076517652765376547655765676577658765976607661766276637664766576667667766876697670767176727673767476757676767776787679768076817682768376847685768676877688768976907691769276937694769576967697769876997700770177027703770477057706770777087709771077117712771377147715771677177718771977207721772277237724772577267727772877297730773177327733773477357736773777387739774077417742774377447745774677477748774977507751775277537754775577567757775877597760776177627763776477657766776777687769777077717772777377747775777677777778777977807781778277837784778577867787778877897790779177927793779477957796779777987799780078017802780378047805780678077808780978107811781278137814781578167817781878197820782178227823782478257826782778287829783078317832783378347835783678377838783978407841784278437844784578467847784878497850785178527853785478557856785778587859786078617862786378647865786678677868786978707871787278737874787578767877787878797880788178827883788478857886788778887889789078917892789378947895789678977898789979007901790279037904790579067907790879097910791179127913791479157916791779187919792079217922792379247925792679277928792979307931793279337934793579367937793879397940794179427943794479457946794779487949795079517952795379547955795679577958795979607961796279637964796579667967796879697970797179727973797479757976797779787979798079817982798379847985798679877988798979907991799279937994799579967997799879998000800180028003800480058006800780088009801080118012801380148015801680178018801980208021802280238024802580268027802880298030803180328033803480358036803780388039804080418042804380448045804680478048804980508051805280538054805580568057805880598060806180628063806480658066806780688069807080718072807380748075807680778078807980808081808280838084808580868087808880898090809180928093809480958096809780988099810081018102810381048105810681078108810981108111811281138114811581168117811881198120812181228123812481258126812781288129813081318132813381348135813681378138813981408141814281438144814581468147814881498150815181528153815481558156815781588159816081618162816381648165816681678168816981708171817281738174817581768177817881798180818181828183818481858186818781888189819081918192819381948195819681978198819982008201820282038204820582068207820882098210821182128213821482158216821782188219822082218222822382248225822682278228822982308231823282338234823582368237823882398240824182428243824482458246824782488249825082518252825382548255825682578258825982608261826282638264826582668267826882698270827182728273827482758276827782788279828082818282828382848285828682878288828982908291829282938294829582968297829882998300830183028303830483058306830783088309831083118312831383148315831683178318831983208321832283238324832583268327832883298330833183328333833483358336833783388339834083418342834383448345834683478348834983508351835283538354835583568357835883598360836183628363836483658366836783688369837083718372837383748375837683778378837983808381838283838384838583868387838883898390839183928393839483958396839783988399840084018402840384048405840684078408840984108411841284138414841584168417841884198420842184228423842484258426842784288429843084318432843384348435843684378438843984408441844284438444844584468447844884498450845184528453845484558456845784588459846084618462846384648465846684678468846984708471847284738474847584768477847884798480848184828483848484858486848784888489849084918492849384948495849684978498849985008501850285038504850585068507850885098510851185128513851485158516851785188519852085218522852385248525852685278528852985308531853285338534853585368537853885398540854185428543854485458546854785488549855085518552855385548555855685578558855985608561856285638564856585668567856885698570857185728573857485758576857785788579858085818582858385848585858685878588858985908591859285938594859585968597859885998600860186028603860486058606860786088609861086118612861386148615861686178618861986208621862286238624862586268627862886298630863186328633863486358636863786388639864086418642864386448645864686478648864986508651865286538654865586568657865886598660866186628663866486658666866786688669867086718672867386748675867686778678867986808681868286838684868586868687868886898690869186928693869486958696869786988699870087018702870387048705870687078708870987108711871287138714871587168717871887198720872187228723872487258726872787288729873087318732873387348735873687378738873987408741874287438744874587468747874887498750875187528753875487558756875787588759876087618762876387648765876687678768876987708771877287738774877587768777877887798780878187828783878487858786878787888789879087918792879387948795879687978798879988008801880288038804880588068807880888098810881188128813881488158816881788188819882088218822882388248825882688278828882988308831883288338834883588368837883888398840884188428843884488458846884788488849885088518852885388548855885688578858885988608861886288638864886588668867886888698870887188728873887488758876887788788879888088818882888388848885888688878888888988908891889288938894889588968897889888998900890189028903890489058906890789088909891089118912891389148915891689178918891989208921892289238924892589268927892889298930893189328933893489358936893789388939894089418942894389448945894689478948894989508951895289538954895589568957895889598960896189628963896489658966896789688969897089718972897389748975897689778978897989808981898289838984898589868987898889898990899189928993899489958996899789988999900090019002900390049005900690079008900990109011901290139014901590169017901890199020902190229023902490259026902790289029903090319032903390349035903690379038903990409041904290439044904590469047904890499050905190529053905490559056905790589059906090619062906390649065906690679068906990709071907290739074907590769077907890799080908190829083908490859086908790889089909090919092909390949095909690979098909991009101910291039104910591069107910891099110911191129113911491159116911791189119912091219122912391249125912691279128912991309131913291339134913591369137913891399140914191429143914491459146914791489149915091519152915391549155915691579158915991609161916291639164916591669167916891699170917191729173917491759176917791789179918091819182918391849185918691879188918991909191919291939194919591969197919891999200920192029203920492059206920792089209921092119212921392149215921692179218921992209221922292239224922592269227922892299230923192329233923492359236923792389239924092419242924392449245924692479248924992509251925292539254925592569257925892599260926192629263926492659266926792689269927092719272927392749275927692779278927992809281928292839284928592869287928892899290929192929293929492959296929792989299930093019302930393049305930693079308930993109311931293139314931593169317931893199320932193229323932493259326932793289329933093319332933393349335933693379338933993409341934293439344934593469347934893499350935193529353935493559356935793589359936093619362936393649365936693679368936993709371937293739374937593769377937893799380938193829383938493859386938793889389939093919392939393949395939693979398939994009401940294039404940594069407940894099410941194129413941494159416941794189419942094219422942394249425942694279428942994309431943294339434943594369437943894399440944194429443944494459446944794489449945094519452945394549455945694579458945994609461946294639464946594669467946894699470947194729473947494759476947794789479948094819482948394849485948694879488948994909491949294939494949594969497949894999500950195029503950495059506950795089509951095119512951395149515951695179518951995209521952295239524952595269527952895299530953195329533953495359536953795389539954095419542954395449545954695479548954995509551955295539554955595569557955895599560956195629563956495659566956795689569957095719572957395749575957695779578957995809581958295839584958595869587958895899590959195929593959495959596959795989599960096019602960396049605960696079608960996109611961296139614961596169617961896199620962196229623962496259626962796289629963096319632963396349635963696379638963996409641964296439644964596469647964896499650965196529653965496559656965796589659966096619662966396649665966696679668966996709671967296739674967596769677967896799680968196829683968496859686968796889689969096919692969396949695969696979698969997009701970297039704970597069707970897099710971197129713971497159716971797189719972097219722972397249725972697279728972997309731973297339734973597369737973897399740974197429743974497459746974797489749975097519752975397549755975697579758975997609761976297639764976597669767976897699770977197729773977497759776977797789779978097819782978397849785978697879788978997909791979297939794979597969797979897999800980198029803980498059806980798089809981098119812981398149815981698179818981998209821982298239824982598269827982898299830983198329833983498359836983798389839984098419842984398449845984698479848984998509851985298539854985598569857985898599860986198629863986498659866986798689869987098719872987398749875987698779878987998809881988298839884988598869887988898899890989198929893989498959896989798989899990099019902990399049905990699079908990999109911991299139914991599169917991899199920992199229923992499259926992799289929993099319932993399349935993699379938993999409941994299439944994599469947994899499950995199529953995499559956995799589959996099619962996399649965996699679968996999709971997299739974997599769977997899799980998199829983998499859986998799889989999099919992999399949995999699979998999910000100011000210003100041000510006100071000810009100101001110012100131001410015100161001710018100191002010021100221002310024100251002610027100281002910030100311003210033100341003510036100371003810039100401004110042100431004410045100461004710048100491005010051100521005310054100551005610057100581005910060100611006210063100641006510066100671006810069100701007110072100731007410075100761007710078100791008010081100821008310084100851008610087100881008910090100911009210093100941009510096100971009810099101001010110102101031010410105101061010710108101091011010111101121011310114101151011610117101181011910120101211012210123101241012510126101271012810129101301013110132101331013410135101361013710138101391014010141101421014310144101451014610147101481014910150101511015210153101541015510156101571015810159101601016110162101631016410165101661016710168101691017010171101721017310174101751017610177101781017910180101811018210183101841018510186101871018810189101901019110192101931019410195101961019710198101991020010201102021020310204102051020610207102081020910210102111021210213102141021510216102171021810219102201022110222102231022410225102261022710228102291023010231102321023310234102351023610237102381023910240102411024210243102441024510246102471024810249102501025110252102531025410255102561025710258102591026010261102621026310264102651026610267102681026910270102711027210273102741027510276102771027810279102801028110282102831028410285102861028710288102891029010291102921029310294102951029610297102981029910300103011030210303103041030510306103071030810309103101031110312103131031410315103161031710318103191032010321103221032310324103251032610327103281032910330103311033210333103341033510336103371033810339103401034110342103431034410345103461034710348103491035010351103521035310354103551035610357103581035910360103611036210363103641036510366103671036810369103701037110372103731037410375103761037710378103791038010381103821038310384103851038610387103881038910390103911039210393103941039510396103971039810399104001040110402104031040410405104061040710408104091041010411104121041310414104151041610417104181041910420104211042210423104241042510426104271042810429104301043110432104331043410435104361043710438104391044010441104421044310444104451044610447104481044910450104511045210453104541045510456104571045810459104601046110462104631046410465104661046710468104691047010471104721047310474104751047610477104781047910480104811048210483104841048510486104871048810489104901049110492104931049410495104961049710498104991050010501105021050310504105051050610507105081050910510105111051210513105141051510516105171051810519105201052110522105231052410525105261052710528105291053010531105321053310534105351053610537105381053910540105411054210543105441054510546105471054810549105501055110552105531055410555105561055710558105591056010561105621056310564105651056610567105681056910570105711057210573105741057510576105771057810579105801058110582105831058410585105861058710588105891059010591105921059310594105951059610597105981059910600106011060210603106041060510606106071060810609106101061110612106131061410615106161061710618106191062010621106221062310624106251062610627106281062910630106311063210633106341063510636106371063810639106401064110642106431064410645106461064710648106491065010651106521065310654106551065610657106581065910660106611066210663106641066510666106671066810669106701067110672106731067410675106761067710678106791068010681106821068310684106851068610687106881068910690106911069210693106941069510696106971069810699107001070110702107031070410705107061070710708107091071010711107121071310714107151071610717107181071910720107211072210723107241072510726107271072810729107301073110732107331073410735107361073710738107391074010741107421074310744107451074610747107481074910750107511075210753107541075510756107571075810759107601076110762107631076410765107661076710768107691077010771107721077310774107751077610777107781077910780107811078210783107841078510786107871078810789107901079110792107931079410795107961079710798107991080010801108021080310804108051080610807108081080910810108111081210813108141081510816108171081810819108201082110822108231082410825108261082710828108291083010831108321083310834108351083610837108381083910840108411084210843108441084510846108471084810849108501085110852108531085410855108561085710858108591086010861108621086310864108651086610867108681086910870108711087210873108741087510876108771087810879108801088110882108831088410885108861088710888108891089010891108921089310894108951089610897108981089910900109011090210903109041090510906109071090810909109101091110912109131091410915109161091710918109191092010921109221092310924109251092610927109281092910930109311093210933109341093510936109371093810939109401094110942109431094410945109461094710948109491095010951109521095310954109551095610957109581095910960109611096210963109641096510966109671096810969109701097110972109731097410975109761097710978109791098010981109821098310984109851098610987109881098910990109911099210993109941099510996109971099810999110001100111002110031100411005110061100711008110091101011011110121101311014110151101611017110181101911020110211102211023110241102511026110271102811029110301103111032110331103411035110361103711038110391104011041110421104311044110451104611047110481104911050110511105211053110541105511056110571105811059110601106111062110631106411065110661106711068110691107011071110721107311074110751107611077110781107911080110811108211083110841108511086110871108811089110901109111092110931109411095110961109711098110991110011101111021110311104111051110611107111081110911110111111111211113111141111511116111171111811119111201112111122111231112411125111261112711128111291113011131111321113311134111351113611137111381113911140111411114211143111441114511146111471114811149111501115111152111531115411155111561115711158111591116011161111621116311164111651116611167111681116911170111711117211173111741117511176111771117811179111801118111182111831118411185111861118711188111891119011191111921119311194111951119611197111981119911200112011120211203112041120511206112071120811209112101121111212112131121411215112161121711218112191122011221112221122311224112251122611227112281122911230112311123211233112341123511236112371123811239112401124111242112431124411245112461124711248112491125011251112521125311254112551125611257112581125911260112611126211263112641126511266112671126811269112701127111272112731127411275112761127711278112791128011281112821128311284112851128611287112881128911290112911129211293112941129511296112971129811299113001130111302113031130411305113061130711308113091131011311113121131311314113151131611317113181131911320113211132211323113241132511326113271132811329113301133111332113331133411335113361133711338113391134011341113421134311344113451134611347113481134911350113511135211353113541135511356113571135811359113601136111362113631136411365113661136711368113691137011371113721137311374113751137611377113781137911380113811138211383113841138511386113871138811389113901139111392113931139411395113961139711398113991140011401114021140311404114051140611407114081140911410114111141211413114141141511416114171141811419114201142111422114231142411425114261142711428114291143011431114321143311434114351143611437114381143911440114411144211443114441144511446114471144811449114501145111452114531145411455114561145711458114591146011461114621146311464114651146611467114681146911470114711147211473114741147511476114771147811479114801148111482114831148411485114861148711488114891149011491114921149311494114951149611497114981149911500115011150211503115041150511506115071150811509115101151111512115131151411515115161151711518115191152011521115221152311524115251152611527115281152911530115311153211533115341153511536115371153811539115401154111542115431154411545115461154711548115491155011551115521155311554115551155611557115581155911560115611156211563115641156511566115671156811569115701157111572115731157411575115761157711578115791158011581115821158311584115851158611587115881158911590115911159211593115941159511596115971159811599116001160111602116031160411605116061160711608116091161011611116121161311614116151161611617116181161911620116211162211623116241162511626116271162811629116301163111632116331163411635116361163711638116391164011641116421164311644116451164611647116481164911650116511165211653116541165511656116571165811659116601166111662116631166411665116661166711668116691167011671116721167311674116751167611677116781167911680116811168211683116841168511686116871168811689116901169111692116931169411695116961169711698116991170011701117021170311704117051170611707117081170911710117111171211713117141171511716117171171811719117201172111722117231172411725117261172711728117291173011731117321173311734117351173611737117381173911740117411174211743117441174511746117471174811749117501175111752117531175411755117561175711758117591176011761117621176311764117651176611767117681176911770117711177211773117741177511776117771177811779117801178111782117831178411785117861178711788117891179011791117921179311794117951179611797117981179911800118011180211803118041180511806118071180811809118101181111812118131181411815118161181711818118191182011821118221182311824118251182611827118281182911830118311183211833118341183511836118371183811839118401184111842118431184411845118461184711848118491185011851118521185311854118551185611857118581185911860118611186211863118641186511866118671186811869118701187111872118731187411875118761187711878118791188011881118821188311884118851188611887118881188911890118911189211893118941189511896118971189811899119001190111902119031190411905119061190711908119091191011911119121191311914119151191611917119181191911920119211192211923119241192511926119271192811929119301193111932119331193411935119361193711938119391194011941119421194311944119451194611947119481194911950119511195211953119541195511956119571195811959119601196111962119631196411965119661196711968119691197011971119721197311974119751197611977119781197911980119811198211983119841198511986119871198811989119901199111992119931199411995119961199711998119991200012001120021200312004120051200612007120081200912010120111201212013120141201512016120171201812019120201202112022120231202412025120261202712028120291203012031120321203312034120351203612037120381203912040120411204212043120441204512046120471204812049120501205112052120531205412055120561205712058120591206012061120621206312064120651206612067120681206912070120711207212073120741207512076120771207812079120801208112082120831208412085120861208712088120891209012091120921209312094120951209612097120981209912100121011210212103121041210512106121071210812109121101211112112121131211412115121161211712118121191212012121121221212312124121251212612127121281212912130121311213212133121341213512136121371213812139121401214112142121431214412145121461214712148121491215012151121521215312154121551215612157121581215912160121611216212163121641216512166121671216812169121701217112172121731217412175121761217712178121791218012181121821218312184121851218612187121881218912190121911219212193121941219512196121971219812199122001220112202122031220412205122061220712208122091221012211122121221312214122151221612217122181221912220122211222212223122241222512226122271222812229122301223112232122331223412235122361223712238122391224012241122421224312244122451224612247122481224912250122511225212253122541225512256122571225812259122601226112262122631226412265122661226712268122691227012271122721227312274122751227612277122781227912280122811228212283122841228512286122871228812289122901229112292122931229412295122961229712298122991230012301123021230312304123051230612307123081230912310123111231212313123141231512316123171231812319123201232112322123231232412325123261232712328123291233012331123321233312334123351233612337123381233912340123411234212343123441234512346123471234812349123501235112352123531235412355123561235712358123591236012361123621236312364123651236612367123681236912370123711237212373123741237512376123771237812379123801238112382123831238412385123861238712388123891239012391123921239312394123951239612397123981239912400124011240212403124041240512406124071240812409124101241112412124131241412415124161241712418124191242012421124221242312424124251242612427124281242912430124311243212433124341243512436124371243812439124401244112442124431244412445124461244712448124491245012451124521245312454124551245612457124581245912460124611246212463124641246512466124671246812469124701247112472124731247412475124761247712478124791248012481124821248312484124851248612487124881248912490124911249212493124941249512496124971249812499125001250112502125031250412505125061250712508125091251012511125121251312514125151251612517125181251912520125211252212523125241252512526125271252812529125301253112532125331253412535125361253712538125391254012541125421254312544125451254612547125481254912550125511255212553125541255512556125571255812559125601256112562125631256412565125661256712568125691257012571125721257312574125751257612577125781257912580125811258212583125841258512586125871258812589125901259112592125931259412595125961259712598125991260012601126021260312604126051260612607126081260912610126111261212613126141261512616126171261812619126201262112622126231262412625126261262712628126291263012631126321263312634126351263612637126381263912640126411264212643126441264512646126471264812649126501265112652126531265412655126561265712658126591266012661126621266312664126651266612667126681266912670126711267212673126741267512676126771267812679126801268112682126831268412685126861268712688126891269012691126921269312694126951269612697126981269912700127011270212703127041270512706127071270812709127101271112712127131271412715127161271712718127191272012721127221272312724127251272612727127281272912730127311273212733127341273512736127371273812739127401274112742127431274412745127461274712748127491275012751127521275312754127551275612757127581275912760127611276212763127641276512766127671276812769127701277112772127731277412775127761277712778127791278012781127821278312784127851278612787127881278912790127911279212793127941279512796127971279812799128001280112802128031280412805128061280712808128091281012811128121281312814128151281612817128181281912820128211282212823128241282512826128271282812829128301283112832128331283412835128361283712838128391284012841128421284312844128451284612847128481284912850128511285212853128541285512856128571285812859128601286112862128631286412865128661286712868128691287012871128721287312874128751287612877128781287912880128811288212883128841288512886128871288812889128901289112892128931289412895128961289712898128991290012901129021290312904129051290612907129081290912910129111291212913129141291512916129171291812919129201292112922129231292412925129261292712928129291293012931129321293312934129351293612937129381293912940129411294212943129441294512946129471294812949129501295112952129531295412955129561295712958129591296012961129621296312964129651296612967129681296912970129711297212973129741297512976129771297812979129801298112982129831298412985129861298712988129891299012991129921299312994129951299612997129981299913000130011300213003130041300513006130071300813009130101301113012130131301413015130161301713018130191302013021130221302313024130251302613027130281302913030130311303213033130341303513036130371303813039130401304113042130431304413045130461304713048130491305013051130521305313054130551305613057130581305913060130611306213063130641306513066130671306813069130701307113072130731307413075130761307713078130791308013081130821308313084130851308613087130881308913090130911309213093130941309513096130971309813099131001310113102131031310413105131061310713108131091311013111131121311313114131151311613117131181311913120131211312213123131241312513126131271312813129131301313113132131331313413135131361313713138131391314013141131421314313144131451314613147131481314913150131511315213153131541315513156131571315813159131601316113162131631316413165131661316713168131691317013171131721317313174131751317613177131781317913180131811318213183131841318513186131871318813189131901319113192131931319413195131961319713198131991320013201132021320313204132051320613207132081320913210132111321213213132141321513216132171321813219132201322113222132231322413225132261322713228132291323013231132321323313234132351323613237132381323913240132411324213243132441324513246132471324813249132501325113252132531325413255132561325713258132591326013261132621326313264132651326613267132681326913270132711327213273132741327513276132771327813279132801328113282132831328413285132861328713288132891329013291132921329313294132951329613297132981329913300133011330213303133041330513306133071330813309133101331113312133131331413315133161331713318133191332013321133221332313324133251332613327133281332913330133311333213333133341333513336133371333813339133401334113342133431334413345133461334713348133491335013351133521335313354133551335613357133581335913360133611336213363133641336513366133671336813369133701337113372133731337413375133761337713378133791338013381133821338313384133851338613387133881338913390133911339213393133941339513396133971339813399134001340113402134031340413405134061340713408134091341013411134121341313414134151341613417134181341913420134211342213423134241342513426134271342813429134301343113432134331343413435134361343713438134391344013441134421344313444134451344613447134481344913450134511345213453134541345513456134571345813459134601346113462134631346413465134661346713468134691347013471134721347313474134751347613477134781347913480134811348213483134841348513486134871348813489134901349113492134931349413495134961349713498134991350013501135021350313504135051350613507135081350913510135111351213513135141351513516135171351813519135201352113522135231352413525135261352713528135291353013531135321353313534135351353613537135381353913540135411354213543135441354513546135471354813549135501355113552135531355413555135561355713558135591356013561135621356313564135651356613567135681356913570135711357213573135741357513576135771357813579135801358113582135831358413585135861358713588135891359013591135921359313594135951359613597135981359913600136011360213603136041360513606136071360813609136101361113612136131361413615136161361713618136191362013621136221362313624136251362613627136281362913630136311363213633136341363513636136371363813639136401364113642136431364413645136461364713648136491365013651136521365313654136551365613657136581365913660136611366213663136641366513666136671366813669136701367113672136731367413675136761367713678136791368013681136821368313684136851368613687136881368913690136911369213693136941369513696136971369813699137001370113702137031370413705137061370713708137091371013711137121371313714137151371613717137181371913720137211372213723137241372513726137271372813729137301373113732137331373413735137361373713738137391374013741137421374313744137451374613747137481374913750137511375213753137541375513756137571375813759137601376113762137631376413765137661376713768137691377013771137721377313774137751377613777137781377913780137811378213783137841378513786137871378813789137901379113792137931379413795137961379713798137991380013801138021380313804138051380613807138081380913810138111381213813138141381513816138171381813819138201382113822138231382413825138261382713828138291383013831138321383313834138351383613837138381383913840138411384213843138441384513846138471384813849138501385113852138531385413855138561385713858138591386013861138621386313864138651386613867138681386913870138711387213873138741387513876138771387813879138801388113882138831388413885138861388713888138891389013891138921389313894138951389613897138981389913900139011390213903139041390513906139071390813909139101391113912139131391413915139161391713918139191392013921139221392313924139251392613927139281392913930139311393213933139341393513936139371393813939139401394113942139431394413945139461394713948139491395013951139521395313954139551395613957139581395913960139611396213963139641396513966139671396813969139701397113972139731397413975139761397713978139791398013981139821398313984139851398613987139881398913990139911399213993139941399513996139971399813999140001400114002140031400414005140061400714008140091401014011140121401314014140151401614017140181401914020140211402214023140241402514026140271402814029140301403114032140331403414035140361403714038140391404014041140421404314044140451404614047140481404914050140511405214053140541405514056140571405814059140601406114062140631406414065140661406714068140691407014071140721407314074140751407614077140781407914080140811408214083140841408514086140871408814089140901409114092140931409414095140961409714098140991410014101141021410314104141051410614107141081410914110141111411214113141141411514116141171411814119141201412114122141231412414125141261412714128141291413014131141321413314134141351413614137141381413914140141411414214143141441414514146141471414814149141501415114152141531415414155141561415714158141591416014161141621416314164141651416614167141681416914170141711417214173141741417514176141771417814179141801418114182141831418414185141861418714188141891419014191141921419314194141951419614197141981419914200142011420214203142041420514206142071420814209142101421114212142131421414215142161421714218142191422014221142221422314224142251422614227142281422914230142311423214233142341423514236142371423814239142401424114242142431424414245142461424714248142491425014251142521425314254142551425614257142581425914260142611426214263142641426514266142671426814269142701427114272142731427414275142761427714278142791428014281142821428314284142851428614287142881428914290142911429214293142941429514296142971429814299143001430114302143031430414305143061430714308143091431014311143121431314314143151431614317143181431914320143211432214323143241432514326143271432814329143301433114332143331433414335143361433714338143391434014341143421434314344143451434614347143481434914350143511435214353143541435514356143571435814359143601436114362143631436414365143661436714368143691437014371143721437314374143751437614377143781437914380143811438214383143841438514386143871438814389143901439114392143931439414395143961439714398143991440014401144021440314404144051440614407144081440914410144111441214413144141441514416144171441814419144201442114422144231442414425144261442714428144291443014431144321443314434144351443614437144381443914440144411444214443144441444514446144471444814449144501445114452144531445414455144561445714458144591446014461144621446314464144651446614467144681446914470144711447214473144741447514476144771447814479144801448114482144831448414485144861448714488144891449014491144921449314494144951449614497144981449914500145011450214503145041450514506145071450814509145101451114512145131451414515145161451714518145191452014521145221452314524145251452614527145281452914530145311453214533145341453514536145371453814539145401454114542145431454414545145461454714548145491455014551145521455314554145551455614557145581455914560145611456214563145641456514566145671456814569145701457114572145731457414575145761457714578145791458014581145821458314584145851458614587145881458914590145911459214593145941459514596145971459814599146001460114602146031460414605146061460714608146091461014611146121461314614146151461614617146181461914620146211462214623146241462514626146271462814629146301463114632146331463414635146361463714638146391464014641146421464314644146451464614647146481464914650146511465214653146541465514656146571465814659146601466114662146631466414665146661466714668146691467014671146721467314674146751467614677146781467914680146811468214683146841468514686146871468814689146901469114692146931469414695146961469714698146991470014701147021470314704147051470614707147081470914710147111471214713147141471514716147171471814719147201472114722147231472414725147261472714728147291473014731147321473314734147351473614737147381473914740147411474214743147441474514746147471474814749147501475114752147531475414755147561475714758147591476014761147621476314764147651476614767147681476914770147711477214773147741477514776147771477814779147801478114782147831478414785147861478714788147891479014791147921479314794147951479614797147981479914800148011480214803148041480514806148071480814809148101481114812148131481414815148161481714818148191482014821148221482314824148251482614827148281482914830148311483214833148341483514836148371483814839148401484114842148431484414845148461484714848148491485014851148521485314854148551485614857148581485914860148611486214863148641486514866148671486814869148701487114872148731487414875148761487714878148791488014881148821488314884148851488614887148881488914890148911489214893148941489514896148971489814899149001490114902149031490414905149061490714908149091491014911149121491314914149151491614917149181491914920149211492214923149241492514926149271492814929149301493114932149331493414935149361493714938149391494014941149421494314944149451494614947149481494914950149511495214953149541495514956149571495814959149601496114962149631496414965149661496714968149691497014971149721497314974149751497614977149781497914980149811498214983149841498514986149871498814989149901499114992149931499414995149961499714998149991500015001150021500315004150051500615007150081500915010150111501215013150141501515016150171501815019150201502115022150231502415025150261502715028150291503015031150321503315034150351503615037150381503915040150411504215043150441504515046150471504815049150501505115052150531505415055150561505715058150591506015061150621506315064150651506615067150681506915070150711507215073150741507515076150771507815079150801508115082150831508415085150861508715088150891509015091150921509315094150951509615097150981509915100151011510215103151041510515106151071510815109151101511115112151131511415115151161511715118151191512015121151221512315124151251512615127151281512915130151311513215133151341513515136151371513815139151401514115142151431514415145151461514715148151491515015151151521515315154151551515615157151581515915160151611516215163151641516515166151671516815169151701517115172151731517415175151761517715178151791518015181151821518315184151851518615187151881518915190151911519215193151941519515196151971519815199152001520115202152031520415205152061520715208152091521015211152121521315214152151521615217152181521915220152211522215223152241522515226152271522815229152301523115232152331523415235152361523715238152391524015241152421524315244152451524615247152481524915250152511525215253152541525515256152571525815259152601526115262152631526415265152661526715268152691527015271152721527315274152751527615277152781527915280152811528215283152841528515286152871528815289152901529115292152931529415295152961529715298152991530015301153021530315304153051530615307153081530915310153111531215313153141531515316153171531815319153201532115322153231532415325153261532715328153291533015331153321533315334153351533615337153381533915340153411534215343153441534515346153471534815349153501535115352153531535415355153561535715358153591536015361153621536315364153651536615367153681536915370153711537215373153741537515376153771537815379153801538115382153831538415385153861538715388153891539015391153921539315394153951539615397153981539915400154011540215403154041540515406154071540815409154101541115412154131541415415154161541715418154191542015421154221542315424154251542615427154281542915430154311543215433154341543515436154371543815439154401544115442154431544415445154461544715448154491545015451154521545315454154551545615457154581545915460154611546215463154641546515466154671546815469154701547115472154731547415475154761547715478154791548015481154821548315484154851548615487154881548915490154911549215493154941549515496154971549815499155001550115502155031550415505155061550715508155091551015511155121551315514155151551615517155181551915520155211552215523155241552515526155271552815529155301553115532155331553415535155361553715538155391554015541155421554315544155451554615547155481554915550155511555215553155541555515556155571555815559155601556115562155631556415565155661556715568155691557015571155721557315574155751557615577155781557915580155811558215583155841558515586155871558815589155901559115592155931559415595155961559715598155991560015601156021560315604156051560615607156081560915610156111561215613156141561515616156171561815619156201562115622156231562415625156261562715628156291563015631156321563315634156351563615637156381563915640156411564215643156441564515646156471564815649156501565115652156531565415655156561565715658156591566015661156621566315664156651566615667156681566915670156711567215673156741567515676156771567815679156801568115682156831568415685156861568715688156891569015691156921569315694156951569615697156981569915700157011570215703157041570515706157071570815709157101571115712157131571415715157161571715718157191572015721157221572315724157251572615727157281572915730157311573215733157341573515736157371573815739157401574115742157431574415745157461574715748157491575015751157521575315754157551575615757157581575915760157611576215763157641576515766157671576815769157701577115772157731577415775157761577715778157791578015781157821578315784157851578615787157881578915790157911579215793157941579515796157971579815799158001580115802158031580415805158061580715808158091581015811158121581315814158151581615817158181581915820158211582215823158241582515826158271582815829158301583115832158331583415835158361583715838158391584015841158421584315844158451584615847158481584915850158511585215853158541585515856158571585815859158601586115862158631586415865158661586715868158691587015871158721587315874158751587615877158781587915880158811588215883158841588515886158871588815889158901589115892158931589415895158961589715898158991590015901159021590315904159051590615907159081590915910159111591215913159141591515916159171591815919159201592115922159231592415925159261592715928159291593015931159321593315934159351593615937159381593915940159411594215943159441594515946159471594815949159501595115952159531595415955159561595715958159591596015961159621596315964159651596615967159681596915970159711597215973159741597515976159771597815979159801598115982159831598415985159861598715988159891599015991159921599315994159951599615997159981599916000160011600216003160041600516006160071600816009160101601116012160131601416015160161601716018160191602016021160221602316024160251602616027160281602916030160311603216033160341603516036160371603816039160401604116042160431604416045160461604716048160491605016051160521605316054160551605616057160581605916060160611606216063160641606516066160671606816069160701607116072160731607416075160761607716078160791608016081160821608316084160851608616087160881608916090160911609216093160941609516096160971609816099161001610116102161031610416105161061610716108161091611016111161121611316114161151611616117161181611916120161211612216123161241612516126161271612816129161301613116132161331613416135161361613716138161391614016141161421614316144161451614616147161481614916150161511615216153161541615516156161571615816159161601616116162161631616416165161661616716168161691617016171161721617316174161751617616177161781617916180161811618216183161841618516186161871618816189161901619116192161931619416195161961619716198161991620016201162021620316204162051620616207162081620916210162111621216213162141621516216162171621816219162201622116222162231622416225162261622716228162291623016231162321623316234162351623616237162381623916240162411624216243162441624516246162471624816249162501625116252162531625416255162561625716258162591626016261162621626316264162651626616267162681626916270162711627216273162741627516276162771627816279162801628116282162831628416285162861628716288162891629016291162921629316294162951629616297162981629916300163011630216303163041630516306163071630816309163101631116312163131631416315163161631716318163191632016321163221632316324163251632616327163281632916330163311633216333163341633516336163371633816339163401634116342163431634416345163461634716348163491635016351163521635316354163551635616357163581635916360163611636216363163641636516366163671636816369163701637116372163731637416375163761637716378163791638016381163821638316384163851638616387163881638916390163911639216393163941639516396163971639816399164001640116402164031640416405164061640716408164091641016411164121641316414164151641616417164181641916420164211642216423164241642516426164271642816429164301643116432164331643416435164361643716438164391644016441164421644316444164451644616447164481644916450164511645216453164541645516456164571645816459164601646116462164631646416465164661646716468164691647016471164721647316474164751647616477164781647916480164811648216483164841648516486164871648816489164901649116492164931649416495164961649716498164991650016501165021650316504165051650616507165081650916510165111651216513165141651516516165171651816519165201652116522165231652416525165261652716528165291653016531165321653316534165351653616537165381653916540165411654216543165441654516546165471654816549165501655116552165531655416555165561655716558165591656016561165621656316564165651656616567165681656916570165711657216573165741657516576165771657816579165801658116582165831658416585165861658716588165891659016591165921659316594165951659616597165981659916600166011660216603166041660516606166071660816609166101661116612166131661416615166161661716618166191662016621166221662316624166251662616627166281662916630166311663216633166341663516636166371663816639166401664116642166431664416645166461664716648166491665016651166521665316654166551665616657166581665916660166611666216663166641666516666166671666816669166701667116672166731667416675166761667716678166791668016681166821668316684166851668616687166881668916690166911669216693166941669516696166971669816699167001670116702167031670416705167061670716708167091671016711167121671316714167151671616717167181671916720167211672216723167241672516726167271672816729167301673116732167331673416735167361673716738167391674016741167421674316744167451674616747167481674916750167511675216753167541675516756167571675816759167601676116762167631676416765167661676716768167691677016771167721677316774167751677616777167781677916780167811678216783167841678516786167871678816789167901679116792167931679416795167961679716798167991680016801168021680316804168051680616807168081680916810168111681216813168141681516816168171681816819168201682116822168231682416825168261682716828168291683016831168321683316834168351683616837168381683916840168411684216843168441684516846168471684816849168501685116852168531685416855168561685716858168591686016861168621686316864168651686616867168681686916870168711687216873168741687516876168771687816879168801688116882168831688416885168861688716888168891689016891168921689316894168951689616897168981689916900169011690216903169041690516906169071690816909169101691116912169131691416915169161691716918169191692016921169221692316924169251692616927169281692916930169311693216933169341693516936169371693816939169401694116942169431694416945169461694716948169491695016951169521695316954169551695616957169581695916960169611696216963169641696516966169671696816969169701697116972169731697416975169761697716978169791698016981169821698316984169851698616987169881698916990169911699216993169941699516996169971699816999170001700117002170031700417005170061700717008170091701017011170121701317014170151701617017170181701917020170211702217023170241702517026170271702817029170301703117032170331703417035170361703717038170391704017041170421704317044170451704617047170481704917050170511705217053170541705517056170571705817059170601706117062170631706417065170661706717068170691707017071170721707317074170751707617077170781707917080170811708217083170841708517086170871708817089170901709117092170931709417095170961709717098170991710017101171021710317104171051710617107171081710917110171111711217113171141711517116171171711817119171201712117122171231712417125171261712717128171291713017131171321713317134171351713617137171381713917140171411714217143171441714517146171471714817149171501715117152171531715417155171561715717158171591716017161171621716317164171651716617167171681716917170171711717217173171741717517176171771717817179171801718117182171831718417185171861718717188171891719017191171921719317194171951719617197171981719917200172011720217203172041720517206172071720817209172101721117212172131721417215172161721717218172191722017221172221722317224172251722617227172281722917230172311723217233172341723517236172371723817239172401724117242172431724417245172461724717248172491725017251172521725317254172551725617257172581725917260172611726217263172641726517266172671726817269172701727117272172731727417275172761727717278172791728017281172821728317284172851728617287172881728917290172911729217293172941729517296172971729817299173001730117302173031730417305173061730717308173091731017311173121731317314173151731617317173181731917320173211732217323173241732517326173271732817329173301733117332173331733417335173361733717338173391734017341173421734317344173451734617347173481734917350173511735217353173541735517356173571735817359173601736117362173631736417365173661736717368173691737017371173721737317374173751737617377173781737917380173811738217383173841738517386173871738817389173901739117392173931739417395173961739717398173991740017401174021740317404174051740617407174081740917410174111741217413174141741517416174171741817419174201742117422174231742417425174261742717428174291743017431174321743317434174351743617437174381743917440174411744217443174441744517446174471744817449174501745117452174531745417455174561745717458174591746017461174621746317464174651746617467174681746917470174711747217473174741747517476174771747817479174801748117482174831748417485174861748717488174891749017491174921749317494174951749617497174981749917500175011750217503175041750517506175071750817509175101751117512175131751417515175161751717518175191752017521175221752317524175251752617527175281752917530175311753217533175341753517536175371753817539175401754117542175431754417545175461754717548175491755017551175521755317554175551755617557175581755917560175611756217563175641756517566175671756817569175701757117572175731757417575175761757717578175791758017581175821758317584175851758617587175881758917590175911759217593175941759517596175971759817599176001760117602176031760417605176061760717608176091761017611176121761317614176151761617617176181761917620176211762217623176241762517626176271762817629176301763117632176331763417635176361763717638176391764017641176421764317644176451764617647176481764917650176511765217653176541765517656176571765817659176601766117662176631766417665176661766717668176691767017671176721767317674176751767617677176781767917680176811768217683176841768517686176871768817689176901769117692176931769417695176961769717698176991770017701177021770317704177051770617707177081770917710177111771217713177141771517716177171771817719177201772117722177231772417725177261772717728177291773017731177321773317734177351773617737177381773917740177411774217743177441774517746177471774817749177501775117752177531775417755177561775717758177591776017761177621776317764177651776617767177681776917770177711777217773177741777517776177771777817779177801778117782177831778417785177861778717788177891779017791177921779317794177951779617797177981779917800178011780217803178041780517806178071780817809178101781117812178131781417815178161781717818178191782017821178221782317824178251782617827178281782917830178311783217833178341783517836178371783817839178401784117842178431784417845178461784717848178491785017851178521785317854178551785617857178581785917860178611786217863178641786517866178671786817869178701787117872178731787417875178761787717878178791788017881178821788317884178851788617887178881788917890178911789217893178941789517896178971789817899179001790117902179031790417905179061790717908179091791017911179121791317914179151791617917179181791917920179211792217923179241792517926179271792817929179301793117932179331793417935179361793717938179391794017941179421794317944179451794617947179481794917950179511795217953179541795517956179571795817959179601796117962179631796417965179661796717968179691797017971179721797317974179751797617977179781797917980179811798217983179841798517986179871798817989179901799117992179931799417995179961799717998179991800018001180021800318004180051800618007180081800918010180111801218013180141801518016180171801818019180201802118022180231802418025180261802718028180291803018031180321803318034180351803618037180381803918040180411804218043180441804518046180471804818049180501805118052180531805418055180561805718058180591806018061180621806318064180651806618067180681806918070180711807218073180741807518076180771807818079180801808118082180831808418085180861808718088180891809018091180921809318094180951809618097180981809918100181011810218103181041810518106181071810818109181101811118112181131811418115181161811718118181191812018121181221812318124181251812618127181281812918130181311813218133181341813518136181371813818139181401814118142181431814418145181461814718148181491815018151181521815318154181551815618157181581815918160181611816218163181641816518166181671816818169181701817118172181731817418175181761817718178181791818018181181821818318184181851818618187181881818918190181911819218193181941819518196181971819818199182001820118202182031820418205182061820718208182091821018211182121821318214182151821618217182181821918220182211822218223182241822518226182271822818229182301823118232182331823418235182361823718238182391824018241182421824318244182451824618247182481824918250182511825218253182541825518256182571825818259182601826118262182631826418265182661826718268182691827018271182721827318274182751827618277182781827918280182811828218283182841828518286182871828818289182901829118292182931829418295182961829718298182991830018301183021830318304183051830618307183081830918310183111831218313183141831518316183171831818319183201832118322183231832418325183261832718328183291833018331183321833318334183351833618337183381833918340183411834218343183441834518346183471834818349183501835118352183531835418355183561835718358183591836018361183621836318364183651836618367183681836918370183711837218373183741837518376183771837818379183801838118382183831838418385183861838718388183891839018391183921839318394183951839618397183981839918400184011840218403184041840518406184071840818409184101841118412184131841418415184161841718418184191842018421184221842318424184251842618427184281842918430184311843218433184341843518436184371843818439184401844118442184431844418445184461844718448184491845018451184521845318454184551845618457184581845918460184611846218463184641846518466184671846818469184701847118472184731847418475184761847718478184791848018481184821848318484184851848618487184881848918490184911849218493184941849518496184971849818499185001850118502185031850418505185061850718508185091851018511185121851318514185151851618517185181851918520185211852218523185241852518526185271852818529185301853118532185331853418535185361853718538185391854018541185421854318544185451854618547185481854918550185511855218553185541855518556185571855818559185601856118562185631856418565185661856718568185691857018571185721857318574185751857618577185781857918580185811858218583185841858518586185871858818589185901859118592185931859418595185961859718598185991860018601186021860318604186051860618607186081860918610186111861218613186141861518616186171861818619186201862118622186231862418625186261862718628186291863018631186321863318634186351863618637186381863918640186411864218643186441864518646186471864818649186501865118652186531865418655186561865718658186591866018661186621866318664186651866618667186681866918670186711867218673186741867518676186771867818679186801868118682186831868418685186861868718688186891869018691186921869318694186951869618697186981869918700187011870218703187041870518706187071870818709187101871118712187131871418715187161871718718187191872018721187221872318724187251872618727187281872918730187311873218733187341873518736187371873818739187401874118742187431874418745187461874718748187491875018751187521875318754187551875618757187581875918760187611876218763187641876518766187671876818769187701877118772187731877418775187761877718778187791878018781187821878318784187851878618787187881878918790187911879218793187941879518796187971879818799188001880118802188031880418805188061880718808188091881018811188121881318814188151881618817188181881918820188211882218823188241882518826188271882818829188301883118832188331883418835188361883718838188391884018841188421884318844188451884618847188481884918850188511885218853188541885518856188571885818859188601886118862188631886418865188661886718868188691887018871188721887318874188751887618877188781887918880188811888218883188841888518886188871888818889188901889118892188931889418895188961889718898188991890018901189021890318904189051890618907189081890918910189111891218913189141891518916189171891818919189201892118922189231892418925189261892718928189291893018931189321893318934189351893618937189381893918940189411894218943189441894518946189471894818949189501895118952189531895418955189561895718958189591896018961189621896318964189651896618967189681896918970189711897218973189741897518976189771897818979189801898118982189831898418985189861898718988189891899018991189921899318994189951899618997189981899919000190011900219003190041900519006190071900819009190101901119012190131901419015190161901719018190191902019021190221902319024190251902619027190281902919030190311903219033190341903519036190371903819039190401904119042190431904419045190461904719048190491905019051190521905319054190551905619057190581905919060190611906219063190641906519066190671906819069190701907119072190731907419075190761907719078190791908019081190821908319084190851908619087190881908919090190911909219093190941909519096190971909819099191001910119102191031910419105191061910719108191091911019111191121911319114191151911619117191181911919120191211912219123191241912519126191271912819129191301913119132191331913419135191361913719138191391914019141191421914319144191451914619147191481914919150191511915219153191541915519156191571915819159191601916119162191631916419165191661916719168191691917019171191721917319174191751917619177191781917919180191811918219183191841918519186191871918819189191901919119192191931919419195191961919719198191991920019201192021920319204192051920619207192081920919210192111921219213192141921519216192171921819219192201922119222192231922419225192261922719228192291923019231192321923319234192351923619237192381923919240192411924219243192441924519246192471924819249192501925119252192531925419255192561925719258192591926019261192621926319264192651926619267192681926919270192711927219273192741927519276192771927819279192801928119282192831928419285192861928719288192891929019291192921929319294192951929619297192981929919300193011930219303193041930519306193071930819309193101931119312193131931419315193161931719318193191932019321193221932319324193251932619327193281932919330193311933219333193341933519336193371933819339193401934119342193431934419345193461934719348193491935019351193521935319354193551935619357193581935919360193611936219363193641936519366193671936819369193701937119372193731937419375193761937719378193791938019381193821938319384193851938619387193881938919390193911939219393193941939519396193971939819399194001940119402194031940419405194061940719408194091941019411194121941319414194151941619417194181941919420194211942219423194241942519426194271942819429194301943119432194331943419435194361943719438194391944019441194421944319444194451944619447194481944919450194511945219453194541945519456194571945819459194601946119462194631946419465194661946719468194691947019471194721947319474194751947619477194781947919480194811948219483194841948519486194871948819489194901949119492194931949419495194961949719498194991950019501195021950319504195051950619507195081950919510195111951219513195141951519516195171951819519195201952119522195231952419525195261952719528195291953019531195321953319534195351953619537195381953919540195411954219543195441954519546195471954819549195501955119552195531955419555195561955719558195591956019561195621956319564195651956619567195681956919570195711957219573195741957519576195771957819579195801958119582195831958419585195861958719588195891959019591195921959319594195951959619597195981959919600196011960219603196041960519606196071960819609196101961119612196131961419615196161961719618196191962019621196221962319624196251962619627196281962919630196311963219633196341963519636196371963819639196401964119642196431964419645196461964719648196491965019651196521965319654196551965619657196581965919660196611966219663196641966519666196671966819669196701967119672196731967419675196761967719678196791968019681196821968319684196851968619687196881968919690196911969219693196941969519696196971969819699197001970119702197031970419705197061970719708197091971019711197121971319714197151971619717197181971919720197211972219723197241972519726197271972819729197301973119732197331973419735197361973719738197391974019741197421974319744197451974619747197481974919750197511975219753197541975519756197571975819759197601976119762197631976419765197661976719768197691977019771197721977319774197751977619777197781977919780197811978219783197841978519786197871978819789197901979119792197931979419795197961979719798197991980019801198021980319804198051980619807198081980919810198111981219813198141981519816198171981819819198201982119822198231982419825198261982719828198291983019831198321983319834198351983619837198381983919840198411984219843198441984519846198471984819849198501985119852198531985419855198561985719858198591986019861198621986319864198651986619867198681986919870198711987219873198741987519876198771987819879198801988119882198831988419885198861988719888198891989019891198921989319894198951989619897198981989919900199011990219903199041990519906199071990819909199101991119912199131991419915199161991719918199191992019921199221992319924199251992619927199281992919930199311993219933199341993519936199371993819939199401994119942199431994419945199461994719948199491995019951199521995319954199551995619957199581995919960199611996219963199641996519966199671996819969199701997119972199731997419975199761997719978199791998019981199821998319984199851998619987199881998919990199911999219993199941999519996199971999819999200002000120002200032000420005200062000720008200092001020011200122001320014200152001620017200182001920020200212002220023200242002520026200272002820029200302003120032200332003420035200362003720038200392004020041200422004320044200452004620047200482004920050200512005220053200542005520056200572005820059200602006120062200632006420065200662006720068200692007020071200722007320074200752007620077200782007920080200812008220083200842008520086200872008820089200902009120092200932009420095200962009720098200992010020101201022010320104201052010620107201082010920110201112011220113201142011520116201172011820119201202012120122201232012420125201262012720128201292013020131201322013320134201352013620137201382013920140201412014220143201442014520146201472014820149201502015120152201532015420155201562015720158201592016020161201622016320164201652016620167201682016920170201712017220173201742017520176201772017820179201802018120182201832018420185201862018720188201892019020191201922019320194201952019620197201982019920200202012020220203202042020520206202072020820209202102021120212202132021420215202162021720218202192022020221202222022320224202252022620227202282022920230202312023220233202342023520236202372023820239202402024120242202432024420245202462024720248202492025020251202522025320254202552025620257202582025920260202612026220263202642026520266202672026820269202702027120272202732027420275202762027720278202792028020281202822028320284202852028620287202882028920290202912029220293202942029520296202972029820299203002030120302203032030420305203062030720308203092031020311203122031320314203152031620317203182031920320203212032220323203242032520326203272032820329203302033120332203332033420335203362033720338203392034020341203422034320344203452034620347203482034920350203512035220353203542035520356203572035820359203602036120362203632036420365203662036720368203692037020371203722037320374203752037620377203782037920380203812038220383203842038520386203872038820389203902039120392203932039420395203962039720398203992040020401204022040320404204052040620407204082040920410204112041220413204142041520416204172041820419204202042120422204232042420425204262042720428204292043020431204322043320434204352043620437204382043920440204412044220443204442044520446204472044820449204502045120452204532045420455204562045720458204592046020461204622046320464204652046620467204682046920470204712047220473204742047520476204772047820479204802048120482204832048420485204862048720488204892049020491204922049320494204952049620497204982049920500205012050220503205042050520506205072050820509205102051120512205132051420515205162051720518205192052020521205222052320524205252052620527205282052920530205312053220533205342053520536205372053820539205402054120542205432054420545205462054720548205492055020551205522055320554205552055620557205582055920560205612056220563205642056520566205672056820569205702057120572205732057420575205762057720578205792058020581205822058320584205852058620587205882058920590205912059220593205942059520596205972059820599206002060120602206032060420605206062060720608206092061020611206122061320614206152061620617206182061920620206212062220623206242062520626206272062820629206302063120632206332063420635206362063720638206392064020641206422064320644206452064620647206482064920650206512065220653206542065520656206572065820659206602066120662206632066420665206662066720668206692067020671206722067320674206752067620677206782067920680206812068220683206842068520686206872068820689206902069120692206932069420695206962069720698206992070020701207022070320704207052070620707207082070920710207112071220713207142071520716207172071820719207202072120722207232072420725207262072720728207292073020731207322073320734207352073620737207382073920740207412074220743207442074520746207472074820749207502075120752207532075420755207562075720758207592076020761207622076320764207652076620767207682076920770207712077220773207742077520776207772077820779207802078120782207832078420785207862078720788207892079020791207922079320794207952079620797207982079920800208012080220803208042080520806208072080820809208102081120812208132081420815208162081720818208192082020821208222082320824208252082620827208282082920830208312083220833208342083520836208372083820839208402084120842208432084420845208462084720848208492085020851208522085320854208552085620857208582085920860208612086220863208642086520866208672086820869208702087120872208732087420875208762087720878208792088020881208822088320884208852088620887208882088920890208912089220893208942089520896208972089820899209002090120902209032090420905209062090720908209092091020911209122091320914209152091620917209182091920920209212092220923209242092520926209272092820929209302093120932209332093420935209362093720938209392094020941209422094320944209452094620947209482094920950209512095220953209542095520956209572095820959209602096120962209632096420965209662096720968209692097020971209722097320974209752097620977209782097920980209812098220983209842098520986209872098820989209902099120992209932099420995209962099720998209992100021001210022100321004210052100621007210082100921010210112101221013210142101521016210172101821019210202102121022210232102421025210262102721028210292103021031210322103321034210352103621037210382103921040210412104221043210442104521046210472104821049210502105121052210532105421055210562105721058210592106021061210622106321064210652106621067210682106921070210712107221073210742107521076210772107821079210802108121082210832108421085210862108721088210892109021091210922109321094210952109621097210982109921100211012110221103211042110521106211072110821109211102111121112211132111421115211162111721118211192112021121211222112321124211252112621127211282112921130211312113221133211342113521136211372113821139211402114121142211432114421145211462114721148211492115021151211522115321154211552115621157211582115921160211612116221163211642116521166211672116821169211702117121172211732117421175211762117721178211792118021181211822118321184211852118621187211882118921190211912119221193211942119521196211972119821199212002120121202212032120421205212062120721208212092121021211212122121321214212152121621217212182121921220212212122221223212242122521226212272122821229212302123121232212332123421235212362123721238212392124021241212422124321244212452124621247212482124921250212512125221253212542125521256212572125821259212602126121262212632126421265212662126721268212692127021271212722127321274212752127621277212782127921280212812128221283212842128521286212872128821289212902129121292212932129421295212962129721298212992130021301213022130321304213052130621307213082130921310213112131221313213142131521316213172131821319213202132121322213232132421325213262132721328213292133021331213322133321334213352133621337213382133921340213412134221343213442134521346213472134821349213502135121352213532135421355213562135721358213592136021361213622136321364213652136621367213682136921370213712137221373213742137521376213772137821379213802138121382213832138421385213862138721388213892139021391213922139321394213952139621397213982139921400214012140221403214042140521406214072140821409214102141121412214132141421415214162141721418214192142021421214222142321424214252142621427214282142921430214312143221433214342143521436214372143821439214402144121442214432144421445214462144721448214492145021451214522145321454214552145621457214582145921460214612146221463214642146521466214672146821469214702147121472214732147421475214762147721478214792148021481214822148321484214852148621487214882148921490214912149221493214942149521496214972149821499215002150121502215032150421505215062150721508215092151021511215122151321514215152151621517215182151921520215212152221523215242152521526215272152821529215302153121532215332153421535215362153721538215392154021541215422154321544215452154621547215482154921550215512155221553215542155521556215572155821559215602156121562215632156421565215662156721568215692157021571215722157321574215752157621577215782157921580215812158221583215842158521586215872158821589215902159121592215932159421595215962159721598215992160021601216022160321604216052160621607216082160921610216112161221613216142161521616216172161821619216202162121622216232162421625216262162721628216292163021631216322163321634216352163621637216382163921640216412164221643216442164521646216472164821649216502165121652216532165421655216562165721658216592166021661216622166321664216652166621667216682166921670216712167221673216742167521676216772167821679216802168121682216832168421685216862168721688216892169021691216922169321694216952169621697216982169921700217012170221703217042170521706217072170821709217102171121712217132171421715217162171721718217192172021721217222172321724217252172621727217282172921730217312173221733217342173521736217372173821739217402174121742217432174421745217462174721748217492175021751217522175321754217552175621757217582175921760217612176221763217642176521766217672176821769217702177121772217732177421775217762177721778217792178021781217822178321784217852178621787217882178921790217912179221793217942179521796217972179821799218002180121802218032180421805218062180721808218092181021811218122181321814218152181621817218182181921820218212182221823218242182521826218272182821829218302183121832218332183421835218362183721838218392184021841218422184321844218452184621847218482184921850218512185221853218542185521856218572185821859218602186121862218632186421865218662186721868218692187021871218722187321874218752187621877218782187921880218812188221883218842188521886218872188821889218902189121892218932189421895218962189721898218992190021901219022190321904219052190621907219082190921910219112191221913219142191521916219172191821919219202192121922219232192421925219262192721928219292193021931219322193321934219352193621937219382193921940219412194221943219442194521946219472194821949219502195121952219532195421955219562195721958219592196021961219622196321964219652196621967219682196921970219712197221973219742197521976219772197821979219802198121982219832198421985219862198721988219892199021991219922199321994219952199621997219982199922000220012200222003220042200522006220072200822009220102201122012220132201422015220162201722018220192202022021220222202322024220252202622027220282202922030220312203222033220342203522036220372203822039220402204122042220432204422045220462204722048220492205022051220522205322054220552205622057220582205922060220612206222063220642206522066220672206822069220702207122072220732207422075220762207722078220792208022081220822208322084220852208622087220882208922090220912209222093220942209522096220972209822099221002210122102221032210422105221062210722108221092211022111221122211322114221152211622117221182211922120221212212222123221242212522126221272212822129221302213122132221332213422135221362213722138221392214022141221422214322144221452214622147221482214922150221512215222153221542215522156221572215822159221602216122162221632216422165221662216722168221692217022171221722217322174221752217622177221782217922180221812218222183221842218522186221872218822189221902219122192221932219422195221962219722198221992220022201222022220322204222052220622207222082220922210222112221222213222142221522216222172221822219222202222122222222232222422225222262222722228222292223022231222322223322234222352223622237222382223922240222412224222243222442224522246222472224822249222502225122252222532225422255222562225722258222592226022261222622226322264222652226622267222682226922270222712227222273222742227522276222772227822279222802228122282222832228422285222862228722288222892229022291222922229322294222952229622297222982229922300223012230222303223042230522306223072230822309223102231122312223132231422315223162231722318223192232022321223222232322324223252232622327223282232922330223312233222333223342233522336223372233822339223402234122342223432234422345223462234722348223492235022351223522235322354223552235622357223582235922360223612236222363223642236522366223672236822369223702237122372223732237422375223762237722378223792238022381223822238322384223852238622387223882238922390223912239222393223942239522396223972239822399224002240122402224032240422405224062240722408224092241022411224122241322414224152241622417224182241922420224212242222423224242242522426224272242822429224302243122432224332243422435224362243722438224392244022441224422244322444224452244622447224482244922450224512245222453224542245522456224572245822459224602246122462224632246422465224662246722468224692247022471224722247322474224752247622477224782247922480224812248222483224842248522486224872248822489224902249122492224932249422495224962249722498224992250022501225022250322504225052250622507225082250922510225112251222513225142251522516225172251822519225202252122522225232252422525225262252722528225292253022531225322253322534225352253622537225382253922540225412254222543225442254522546225472254822549225502255122552225532255422555225562255722558225592256022561225622256322564225652256622567225682256922570225712257222573225742257522576225772257822579225802258122582225832258422585225862258722588225892259022591225922259322594225952259622597225982259922600226012260222603226042260522606226072260822609226102261122612226132261422615226162261722618226192262022621226222262322624226252262622627226282262922630226312263222633226342263522636226372263822639226402264122642226432264422645226462264722648226492265022651226522265322654226552265622657226582265922660226612266222663226642266522666226672266822669226702267122672226732267422675226762267722678226792268022681226822268322684226852268622687226882268922690226912269222693226942269522696226972269822699227002270122702227032270422705227062270722708227092271022711227122271322714227152271622717227182271922720227212272222723227242272522726227272272822729227302273122732227332273422735227362273722738227392274022741227422274322744227452274622747227482274922750227512275222753227542275522756227572275822759227602276122762227632276422765227662276722768227692277022771227722277322774227752277622777227782277922780227812278222783227842278522786227872278822789227902279122792227932279422795227962279722798227992280022801228022280322804228052280622807228082280922810228112281222813228142281522816228172281822819228202282122822228232282422825228262282722828228292283022831228322283322834228352283622837228382283922840228412284222843228442284522846228472284822849228502285122852228532285422855228562285722858228592286022861228622286322864228652286622867228682286922870228712287222873228742287522876228772287822879228802288122882228832288422885228862288722888228892289022891228922289322894228952289622897228982289922900229012290222903229042290522906229072290822909229102291122912229132291422915229162291722918229192292022921229222292322924229252292622927229282292922930229312293222933229342293522936229372293822939229402294122942229432294422945229462294722948229492295022951229522295322954229552295622957229582295922960229612296222963229642296522966229672296822969229702297122972229732297422975229762297722978229792298022981229822298322984229852298622987229882298922990229912299222993229942299522996229972299822999230002300123002230032300423005230062300723008230092301023011230122301323014230152301623017230182301923020230212302223023230242302523026230272302823029230302303123032230332303423035230362303723038230392304023041230422304323044230452304623047230482304923050230512305223053230542305523056230572305823059230602306123062230632306423065230662306723068230692307023071230722307323074230752307623077230782307923080230812308223083230842308523086230872308823089230902309123092230932309423095230962309723098230992310023101231022310323104231052310623107231082310923110231112311223113231142311523116231172311823119231202312123122231232312423125231262312723128231292313023131231322313323134231352313623137231382313923140231412314223143231442314523146231472314823149231502315123152231532315423155231562315723158231592316023161231622316323164231652316623167231682316923170231712317223173231742317523176231772317823179231802318123182231832318423185231862318723188231892319023191231922319323194231952319623197231982319923200232012320223203232042320523206232072320823209232102321123212232132321423215232162321723218232192322023221232222322323224232252322623227232282322923230232312323223233232342323523236232372323823239232402324123242232432324423245232462324723248232492325023251232522325323254232552325623257232582325923260232612326223263232642326523266232672326823269232702327123272232732327423275232762327723278232792328023281232822328323284232852328623287232882328923290232912329223293232942329523296232972329823299233002330123302233032330423305233062330723308233092331023311233122331323314233152331623317233182331923320233212332223323233242332523326233272332823329233302333123332233332333423335233362333723338233392334023341233422334323344233452334623347233482334923350233512335223353233542335523356233572335823359233602336123362233632336423365233662336723368233692337023371233722337323374233752337623377233782337923380233812338223383233842338523386233872338823389233902339123392233932339423395233962339723398233992340023401234022340323404234052340623407234082340923410234112341223413234142341523416234172341823419234202342123422234232342423425234262342723428234292343023431234322343323434234352343623437234382343923440234412344223443234442344523446234472344823449234502345123452234532345423455234562345723458234592346023461234622346323464234652346623467234682346923470234712347223473234742347523476234772347823479234802348123482234832348423485234862348723488234892349023491234922349323494234952349623497234982349923500235012350223503235042350523506235072350823509235102351123512235132351423515235162351723518235192352023521235222352323524235252352623527235282352923530235312353223533235342353523536235372353823539235402354123542235432354423545235462354723548235492355023551235522355323554235552355623557235582355923560235612356223563235642356523566235672356823569235702357123572235732357423575235762357723578235792358023581235822358323584235852358623587235882358923590235912359223593235942359523596235972359823599236002360123602236032360423605236062360723608236092361023611236122361323614236152361623617236182361923620236212362223623236242362523626236272362823629236302363123632236332363423635236362363723638236392364023641236422364323644236452364623647236482364923650236512365223653236542365523656236572365823659236602366123662236632366423665236662366723668236692367023671236722367323674236752367623677236782367923680236812368223683236842368523686236872368823689236902369123692236932369423695236962369723698236992370023701237022370323704237052370623707237082370923710237112371223713237142371523716237172371823719237202372123722237232372423725237262372723728237292373023731237322373323734237352373623737237382373923740237412374223743237442374523746237472374823749237502375123752237532375423755237562375723758237592376023761237622376323764237652376623767237682376923770237712377223773237742377523776237772377823779237802378123782237832378423785237862378723788237892379023791237922379323794237952379623797237982379923800238012380223803238042380523806238072380823809238102381123812238132381423815238162381723818238192382023821238222382323824238252382623827238282382923830238312383223833238342383523836238372383823839238402384123842238432384423845238462384723848238492385023851238522385323854238552385623857238582385923860238612386223863238642386523866238672386823869238702387123872238732387423875238762387723878238792388023881238822388323884238852388623887238882388923890238912389223893238942389523896238972389823899239002390123902239032390423905239062390723908239092391023911239122391323914239152391623917239182391923920239212392223923239242392523926239272392823929239302393123932239332393423935239362393723938239392394023941239422394323944239452394623947239482394923950239512395223953239542395523956239572395823959239602396123962239632396423965239662396723968239692397023971239722397323974239752397623977239782397923980239812398223983239842398523986239872398823989239902399123992239932399423995239962399723998239992400024001240022400324004240052400624007240082400924010240112401224013240142401524016240172401824019240202402124022240232402424025240262402724028240292403024031240322403324034240352403624037240382403924040240412404224043240442404524046240472404824049240502405124052240532405424055240562405724058240592406024061240622406324064240652406624067240682406924070240712407224073240742407524076240772407824079240802408124082240832408424085240862408724088240892409024091240922409324094240952409624097240982409924100241012410224103241042410524106241072410824109241102411124112241132411424115241162411724118241192412024121241222412324124241252412624127241282412924130241312413224133241342413524136241372413824139241402414124142241432414424145241462414724148241492415024151241522415324154241552415624157241582415924160241612416224163241642416524166241672416824169241702417124172241732417424175241762417724178241792418024181241822418324184241852418624187241882418924190241912419224193241942419524196241972419824199242002420124202242032420424205242062420724208242092421024211242122421324214242152421624217242182421924220242212422224223242242422524226242272422824229242302423124232242332423424235242362423724238242392424024241242422424324244242452424624247242482424924250242512425224253242542425524256242572425824259242602426124262242632426424265242662426724268242692427024271242722427324274242752427624277242782427924280242812428224283242842428524286242872428824289242902429124292242932429424295242962429724298242992430024301243022430324304243052430624307243082430924310243112431224313243142431524316243172431824319243202432124322243232432424325243262432724328243292433024331243322433324334243352433624337243382433924340243412434224343243442434524346243472434824349243502435124352243532435424355243562435724358243592436024361243622436324364243652436624367243682436924370243712437224373243742437524376243772437824379243802438124382243832438424385243862438724388243892439024391243922439324394243952439624397243982439924400244012440224403244042440524406244072440824409244102441124412244132441424415244162441724418244192442024421244222442324424244252442624427244282442924430244312443224433244342443524436244372443824439244402444124442244432444424445244462444724448244492445024451244522445324454244552445624457244582445924460244612446224463244642446524466244672446824469244702447124472244732447424475244762447724478244792448024481244822448324484244852448624487244882448924490244912449224493244942449524496244972449824499245002450124502245032450424505245062450724508245092451024511245122451324514245152451624517245182451924520245212452224523245242452524526245272452824529245302453124532245332453424535245362453724538245392454024541245422454324544245452454624547245482454924550245512455224553245542455524556245572455824559245602456124562245632456424565245662456724568245692457024571245722457324574245752457624577245782457924580245812458224583245842458524586245872458824589245902459124592245932459424595245962459724598245992460024601246022460324604246052460624607246082460924610246112461224613246142461524616246172461824619246202462124622246232462424625246262462724628246292463024631246322463324634246352463624637246382463924640246412464224643246442464524646246472464824649246502465124652246532465424655246562465724658246592466024661246622466324664246652466624667246682466924670246712467224673246742467524676246772467824679246802468124682246832468424685246862468724688246892469024691246922469324694246952469624697246982469924700247012470224703247042470524706247072470824709247102471124712247132471424715247162471724718247192472024721247222472324724247252472624727247282472924730247312473224733247342473524736247372473824739247402474124742247432474424745247462474724748247492475024751247522475324754247552475624757247582475924760247612476224763247642476524766247672476824769247702477124772247732477424775247762477724778247792478024781247822478324784247852478624787247882478924790247912479224793247942479524796247972479824799248002480124802248032480424805248062480724808248092481024811248122481324814248152481624817248182481924820248212482224823248242482524826248272482824829248302483124832248332483424835248362483724838248392484024841248422484324844248452484624847248482484924850248512485224853248542485524856248572485824859248602486124862248632486424865248662486724868248692487024871248722487324874248752487624877248782487924880248812488224883248842488524886248872488824889248902489124892248932489424895248962489724898248992490024901249022490324904249052490624907249082490924910249112491224913249142491524916249172491824919249202492124922249232492424925249262492724928249292493024931249322493324934249352493624937249382493924940249412494224943249442494524946249472494824949249502495124952249532495424955249562495724958249592496024961249622496324964249652496624967249682496924970249712497224973249742497524976249772497824979249802498124982249832498424985249862498724988249892499024991249922499324994249952499624997249982499925000250012500225003250042500525006250072500825009250102501125012250132501425015250162501725018250192502025021250222502325024250252502625027250282502925030250312503225033250342503525036250372503825039250402504125042250432504425045250462504725048250492505025051250522505325054250552505625057250582505925060250612506225063250642506525066250672506825069250702507125072250732507425075250762507725078250792508025081250822508325084250852508625087250882508925090250912509225093250942509525096250972509825099251002510125102251032510425105251062510725108251092511025111251122511325114251152511625117251182511925120251212512225123251242512525126251272512825129251302513125132251332513425135251362513725138251392514025141251422514325144251452514625147251482514925150251512515225153251542515525156251572515825159251602516125162251632516425165251662516725168251692517025171251722517325174251752517625177251782517925180251812518225183251842518525186251872518825189251902519125192251932519425195251962519725198251992520025201252022520325204252052520625207252082520925210252112521225213252142521525216252172521825219252202522125222252232522425225252262522725228252292523025231252322523325234252352523625237252382523925240252412524225243252442524525246252472524825249252502525125252252532525425255252562525725258252592526025261252622526325264252652526625267252682526925270252712527225273252742527525276252772527825279252802528125282252832528425285252862528725288252892529025291252922529325294252952529625297252982529925300253012530225303253042530525306253072530825309253102531125312253132531425315253162531725318253192532025321253222532325324253252532625327253282532925330253312533225333253342533525336253372533825339253402534125342253432534425345253462534725348253492535025351253522535325354253552535625357253582535925360253612536225363253642536525366253672536825369253702537125372253732537425375253762537725378253792538025381253822538325384253852538625387253882538925390253912539225393253942539525396253972539825399254002540125402254032540425405254062540725408254092541025411254122541325414254152541625417254182541925420254212542225423254242542525426254272542825429254302543125432254332543425435254362543725438254392544025441254422544325444254452544625447254482544925450254512545225453254542545525456254572545825459254602546125462254632546425465254662546725468254692547025471254722547325474254752547625477254782547925480254812548225483254842548525486254872548825489254902549125492254932549425495254962549725498254992550025501255022550325504255052550625507255082550925510255112551225513255142551525516255172551825519255202552125522255232552425525255262552725528255292553025531255322553325534255352553625537255382553925540255412554225543255442554525546255472554825549255502555125552255532555425555255562555725558255592556025561255622556325564255652556625567255682556925570255712557225573255742557525576255772557825579255802558125582255832558425585255862558725588255892559025591255922559325594255952559625597255982559925600256012560225603256042560525606256072560825609256102561125612256132561425615256162561725618256192562025621256222562325624256252562625627256282562925630256312563225633256342563525636256372563825639256402564125642256432564425645256462564725648256492565025651256522565325654256552565625657256582565925660256612566225663256642566525666256672566825669256702567125672256732567425675256762567725678256792568025681256822568325684256852568625687256882568925690256912569225693256942569525696256972569825699257002570125702257032570425705257062570725708257092571025711257122571325714257152571625717257182571925720257212572225723257242572525726257272572825729257302573125732257332573425735257362573725738257392574025741257422574325744257452574625747257482574925750257512575225753257542575525756257572575825759257602576125762257632576425765257662576725768257692577025771257722577325774257752577625777257782577925780257812578225783257842578525786257872578825789257902579125792257932579425795257962579725798257992580025801258022580325804258052580625807258082580925810258112581225813258142581525816258172581825819258202582125822258232582425825258262582725828258292583025831258322583325834258352583625837258382583925840258412584225843258442584525846258472584825849258502585125852258532585425855258562585725858258592586025861258622586325864258652586625867258682586925870258712587225873258742587525876258772587825879258802588125882258832588425885258862588725888258892589025891258922589325894258952589625897258982589925900259012590225903259042590525906259072590825909259102591125912259132591425915259162591725918259192592025921259222592325924259252592625927259282592925930259312593225933259342593525936259372593825939259402594125942259432594425945259462594725948259492595025951259522595325954259552595625957259582595925960259612596225963259642596525966259672596825969259702597125972259732597425975259762597725978259792598025981259822598325984259852598625987259882598925990259912599225993259942599525996259972599825999260002600126002260032600426005260062600726008260092601026011260122601326014260152601626017260182601926020260212602226023260242602526026260272602826029260302603126032260332603426035260362603726038260392604026041260422604326044260452604626047260482604926050260512605226053260542605526056260572605826059260602606126062260632606426065260662606726068260692607026071260722607326074260752607626077260782607926080260812608226083260842608526086260872608826089260902609126092260932609426095260962609726098260992610026101261022610326104261052610626107261082610926110261112611226113261142611526116261172611826119261202612126122261232612426125261262612726128261292613026131261322613326134261352613626137261382613926140261412614226143261442614526146261472614826149261502615126152261532615426155261562615726158261592616026161261622616326164261652616626167261682616926170261712617226173261742617526176261772617826179261802618126182261832618426185261862618726188261892619026191261922619326194261952619626197261982619926200262012620226203262042620526206262072620826209262102621126212262132621426215262162621726218262192622026221262222622326224262252622626227262282622926230262312623226233262342623526236262372623826239262402624126242262432624426245262462624726248262492625026251262522625326254262552625626257262582625926260262612626226263262642626526266262672626826269262702627126272262732627426275262762627726278262792628026281262822628326284262852628626287262882628926290262912629226293262942629526296262972629826299263002630126302263032630426305263062630726308263092631026311263122631326314263152631626317263182631926320263212632226323263242632526326263272632826329263302633126332263332633426335263362633726338263392634026341263422634326344263452634626347263482634926350263512635226353263542635526356263572635826359263602636126362263632636426365263662636726368263692637026371263722637326374263752637626377263782637926380263812638226383263842638526386263872638826389263902639126392263932639426395263962639726398263992640026401264022640326404264052640626407264082640926410264112641226413264142641526416264172641826419264202642126422264232642426425264262642726428264292643026431264322643326434264352643626437264382643926440264412644226443264442644526446264472644826449264502645126452264532645426455264562645726458264592646026461264622646326464264652646626467264682646926470264712647226473264742647526476264772647826479264802648126482264832648426485264862648726488264892649026491264922649326494264952649626497264982649926500265012650226503265042650526506265072650826509265102651126512265132651426515265162651726518265192652026521265222652326524265252652626527265282652926530265312653226533265342653526536265372653826539265402654126542265432654426545265462654726548265492655026551265522655326554265552655626557265582655926560265612656226563265642656526566265672656826569265702657126572265732657426575265762657726578265792658026581265822658326584265852658626587265882658926590265912659226593265942659526596265972659826599266002660126602266032660426605266062660726608266092661026611266122661326614266152661626617266182661926620266212662226623266242662526626266272662826629266302663126632266332663426635266362663726638266392664026641266422664326644266452664626647266482664926650266512665226653266542665526656266572665826659266602666126662266632666426665266662666726668266692667026671266722667326674266752667626677266782667926680266812668226683266842668526686266872668826689266902669126692266932669426695266962669726698266992670026701267022670326704267052670626707267082670926710267112671226713267142671526716267172671826719267202672126722267232672426725267262672726728267292673026731267322673326734267352673626737267382673926740267412674226743267442674526746267472674826749267502675126752267532675426755267562675726758267592676026761267622676326764267652676626767267682676926770267712677226773267742677526776267772677826779267802678126782267832678426785267862678726788267892679026791267922679326794267952679626797267982679926800268012680226803268042680526806268072680826809268102681126812268132681426815268162681726818268192682026821268222682326824268252682626827268282682926830268312683226833268342683526836268372683826839268402684126842268432684426845268462684726848268492685026851268522685326854268552685626857268582685926860268612686226863268642686526866268672686826869268702687126872268732687426875268762687726878268792688026881268822688326884268852688626887268882688926890268912689226893268942689526896268972689826899269002690126902269032690426905269062690726908269092691026911269122691326914269152691626917269182691926920269212692226923269242692526926269272692826929269302693126932269332693426935269362693726938269392694026941269422694326944269452694626947269482694926950269512695226953269542695526956269572695826959269602696126962269632696426965269662696726968269692697026971269722697326974269752697626977269782697926980269812698226983269842698526986269872698826989269902699126992269932699426995269962699726998269992700027001270022700327004270052700627007270082700927010270112701227013270142701527016270172701827019270202702127022270232702427025270262702727028270292703027031270322703327034270352703627037270382703927040270412704227043270442704527046270472704827049270502705127052270532705427055270562705727058270592706027061270622706327064270652706627067270682706927070270712707227073270742707527076270772707827079270802708127082270832708427085270862708727088270892709027091270922709327094270952709627097270982709927100271012710227103271042710527106271072710827109271102711127112271132711427115271162711727118271192712027121271222712327124271252712627127271282712927130271312713227133271342713527136271372713827139271402714127142271432714427145271462714727148271492715027151271522715327154271552715627157271582715927160271612716227163271642716527166271672716827169271702717127172271732717427175271762717727178271792718027181271822718327184271852718627187271882718927190271912719227193271942719527196271972719827199272002720127202272032720427205272062720727208272092721027211272122721327214272152721627217272182721927220272212722227223272242722527226272272722827229272302723127232272332723427235272362723727238272392724027241272422724327244272452724627247272482724927250272512725227253272542725527256272572725827259272602726127262272632726427265272662726727268272692727027271272722727327274272752727627277272782727927280272812728227283272842728527286272872728827289272902729127292272932729427295272962729727298272992730027301273022730327304273052730627307273082730927310273112731227313273142731527316273172731827319273202732127322273232732427325273262732727328273292733027331273322733327334273352733627337273382733927340273412734227343273442734527346273472734827349273502735127352273532735427355273562735727358273592736027361273622736327364273652736627367273682736927370273712737227373273742737527376273772737827379273802738127382273832738427385273862738727388273892739027391273922739327394273952739627397273982739927400274012740227403274042740527406274072740827409274102741127412274132741427415274162741727418274192742027421274222742327424274252742627427274282742927430274312743227433274342743527436274372743827439274402744127442274432744427445274462744727448274492745027451274522745327454274552745627457274582745927460274612746227463274642746527466274672746827469274702747127472274732747427475274762747727478274792748027481274822748327484274852748627487274882748927490274912749227493274942749527496274972749827499275002750127502275032750427505275062750727508275092751027511275122751327514275152751627517275182751927520275212752227523275242752527526275272752827529275302753127532275332753427535275362753727538275392754027541275422754327544275452754627547275482754927550275512755227553275542755527556275572755827559275602756127562275632756427565275662756727568275692757027571275722757327574275752757627577275782757927580275812758227583275842758527586275872758827589275902759127592275932759427595275962759727598275992760027601276022760327604276052760627607276082760927610276112761227613276142761527616276172761827619276202762127622276232762427625276262762727628276292763027631276322763327634276352763627637276382763927640276412764227643276442764527646276472764827649276502765127652276532765427655276562765727658276592766027661276622766327664276652766627667276682766927670276712767227673276742767527676276772767827679276802768127682276832768427685276862768727688276892769027691276922769327694276952769627697276982769927700277012770227703277042770527706277072770827709277102771127712277132771427715277162771727718277192772027721277222772327724277252772627727277282772927730277312773227733277342773527736277372773827739277402774127742277432774427745277462774727748277492775027751277522775327754277552775627757277582775927760277612776227763277642776527766277672776827769277702777127772277732777427775277762777727778277792778027781277822778327784277852778627787277882778927790277912779227793277942779527796277972779827799278002780127802278032780427805278062780727808278092781027811278122781327814278152781627817278182781927820278212782227823278242782527826278272782827829278302783127832278332783427835278362783727838278392784027841278422784327844278452784627847278482784927850278512785227853278542785527856278572785827859278602786127862278632786427865278662786727868278692787027871278722787327874278752787627877278782787927880278812788227883278842788527886278872788827889278902789127892278932789427895278962789727898278992790027901279022790327904279052790627907279082790927910279112791227913279142791527916279172791827919279202792127922279232792427925279262792727928279292793027931279322793327934279352793627937279382793927940279412794227943279442794527946279472794827949279502795127952279532795427955279562795727958279592796027961279622796327964279652796627967279682796927970279712797227973279742797527976279772797827979279802798127982279832798427985279862798727988279892799027991279922799327994279952799627997279982799928000280012800228003280042800528006280072800828009280102801128012280132801428015280162801728018280192802028021280222802328024280252802628027280282802928030280312803228033280342803528036280372803828039280402804128042280432804428045280462804728048280492805028051280522805328054280552805628057280582805928060280612806228063280642806528066280672806828069280702807128072280732807428075280762807728078280792808028081280822808328084280852808628087280882808928090280912809228093280942809528096280972809828099281002810128102281032810428105281062810728108281092811028111281122811328114281152811628117281182811928120281212812228123281242812528126281272812828129281302813128132281332813428135281362813728138281392814028141281422814328144281452814628147281482814928150281512815228153281542815528156281572815828159281602816128162281632816428165281662816728168281692817028171281722817328174281752817628177281782817928180281812818228183281842818528186281872818828189281902819128192281932819428195281962819728198281992820028201282022820328204282052820628207282082820928210282112821228213282142821528216282172821828219282202822128222282232822428225282262822728228282292823028231282322823328234282352823628237282382823928240282412824228243282442824528246282472824828249282502825128252282532825428255282562825728258282592826028261282622826328264282652826628267282682826928270282712827228273282742827528276282772827828279282802828128282282832828428285282862828728288282892829028291282922829328294282952829628297282982829928300283012830228303283042830528306283072830828309283102831128312283132831428315283162831728318283192832028321283222832328324283252832628327283282832928330283312833228333283342833528336283372833828339283402834128342283432834428345283462834728348283492835028351283522835328354283552835628357283582835928360283612836228363283642836528366283672836828369283702837128372283732837428375283762837728378283792838028381283822838328384283852838628387283882838928390283912839228393283942839528396283972839828399284002840128402284032840428405284062840728408284092841028411284122841328414284152841628417284182841928420284212842228423284242842528426284272842828429284302843128432284332843428435284362843728438284392844028441284422844328444284452844628447284482844928450284512845228453284542845528456284572845828459284602846128462284632846428465284662846728468284692847028471284722847328474284752847628477284782847928480284812848228483284842848528486284872848828489284902849128492284932849428495284962849728498284992850028501285022850328504285052850628507285082850928510285112851228513285142851528516285172851828519285202852128522285232852428525285262852728528285292853028531285322853328534285352853628537285382853928540285412854228543285442854528546285472854828549285502855128552285532855428555285562855728558285592856028561285622856328564285652856628567285682856928570285712857228573285742857528576285772857828579285802858128582285832858428585285862858728588285892859028591285922859328594285952859628597285982859928600286012860228603286042860528606286072860828609286102861128612286132861428615286162861728618286192862028621286222862328624286252862628627286282862928630286312863228633286342863528636286372863828639286402864128642286432864428645286462864728648286492865028651286522865328654286552865628657286582865928660286612866228663286642866528666286672866828669286702867128672286732867428675286762867728678286792868028681286822868328684286852868628687286882868928690286912869228693286942869528696286972869828699287002870128702287032870428705287062870728708287092871028711287122871328714287152871628717287182871928720287212872228723287242872528726287272872828729287302873128732287332873428735287362873728738287392874028741287422874328744287452874628747287482874928750287512875228753287542875528756287572875828759287602876128762287632876428765287662876728768287692877028771287722877328774287752877628777287782877928780287812878228783287842878528786287872878828789287902879128792287932879428795287962879728798287992880028801288022880328804288052880628807288082880928810288112881228813288142881528816288172881828819288202882128822288232882428825288262882728828288292883028831288322883328834288352883628837288382883928840288412884228843288442884528846288472884828849288502885128852288532885428855288562885728858288592886028861288622886328864288652886628867288682886928870288712887228873288742887528876288772887828879288802888128882288832888428885288862888728888288892889028891288922889328894288952889628897288982889928900289012890228903289042890528906289072890828909289102891128912289132891428915289162891728918289192892028921289222892328924289252892628927289282892928930289312893228933289342893528936289372893828939289402894128942289432894428945289462894728948289492895028951289522895328954289552895628957289582895928960289612896228963289642896528966289672896828969289702897128972289732897428975289762897728978289792898028981289822898328984289852898628987289882898928990289912899228993289942899528996289972899828999290002900129002290032900429005290062900729008290092901029011290122901329014290152901629017290182901929020290212902229023290242902529026290272902829029290302903129032290332903429035290362903729038290392904029041290422904329044290452904629047290482904929050290512905229053290542905529056290572905829059290602906129062290632906429065290662906729068290692907029071290722907329074290752907629077290782907929080290812908229083290842908529086290872908829089290902909129092290932909429095290962909729098290992910029101291022910329104291052910629107291082910929110291112911229113291142911529116291172911829119291202912129122291232912429125291262912729128291292913029131291322913329134291352913629137291382913929140291412914229143291442914529146291472914829149291502915129152291532915429155291562915729158291592916029161291622916329164291652916629167291682916929170291712917229173291742917529176291772917829179291802918129182291832918429185291862918729188291892919029191291922919329194291952919629197291982919929200292012920229203292042920529206292072920829209292102921129212292132921429215292162921729218292192922029221292222922329224292252922629227292282922929230292312923229233292342923529236292372923829239292402924129242292432924429245292462924729248292492925029251292522925329254292552925629257292582925929260292612926229263292642926529266292672926829269292702927129272292732927429275292762927729278292792928029281292822928329284292852928629287292882928929290292912929229293292942929529296292972929829299293002930129302293032930429305293062930729308293092931029311293122931329314293152931629317293182931929320293212932229323293242932529326293272932829329293302933129332293332933429335293362933729338293392934029341293422934329344293452934629347293482934929350293512935229353293542935529356293572935829359293602936129362293632936429365293662936729368293692937029371293722937329374293752937629377293782937929380293812938229383293842938529386293872938829389293902939129392293932939429395293962939729398293992940029401294022940329404294052940629407294082940929410294112941229413294142941529416294172941829419294202942129422294232942429425294262942729428294292943029431294322943329434294352943629437294382943929440294412944229443294442944529446294472944829449294502945129452294532945429455294562945729458294592946029461294622946329464294652946629467294682946929470294712947229473294742947529476294772947829479294802948129482294832948429485294862948729488294892949029491294922949329494294952949629497294982949929500295012950229503295042950529506295072950829509295102951129512295132951429515295162951729518295192952029521295222952329524295252952629527295282952929530295312953229533295342953529536295372953829539295402954129542295432954429545295462954729548295492955029551295522955329554295552955629557295582955929560295612956229563295642956529566295672956829569295702957129572295732957429575295762957729578295792958029581295822958329584295852958629587295882958929590295912959229593295942959529596295972959829599296002960129602296032960429605296062960729608296092961029611296122961329614296152961629617296182961929620296212962229623296242962529626296272962829629296302963129632296332963429635296362963729638296392964029641296422964329644296452964629647296482964929650296512965229653296542965529656296572965829659296602966129662296632966429665296662966729668296692967029671296722967329674296752967629677296782967929680296812968229683296842968529686296872968829689296902969129692296932969429695296962969729698296992970029701297022970329704297052970629707297082970929710297112971229713297142971529716297172971829719297202972129722297232972429725297262972729728297292973029731297322973329734297352973629737297382973929740297412974229743297442974529746297472974829749297502975129752297532975429755297562975729758297592976029761297622976329764297652976629767297682976929770297712977229773297742977529776297772977829779297802978129782297832978429785297862978729788297892979029791297922979329794297952979629797297982979929800298012980229803298042980529806298072980829809298102981129812298132981429815298162981729818298192982029821298222982329824298252982629827298282982929830298312983229833298342983529836298372983829839298402984129842298432984429845298462984729848298492985029851298522985329854298552985629857298582985929860298612986229863298642986529866298672986829869298702987129872298732987429875298762987729878298792988029881298822988329884298852988629887298882988929890298912989229893298942989529896298972989829899299002990129902299032990429905299062990729908299092991029911299122991329914299152991629917299182991929920299212992229923299242992529926299272992829929299302993129932299332993429935299362993729938299392994029941299422994329944299452994629947299482994929950299512995229953299542995529956299572995829959299602996129962299632996429965299662996729968299692997029971299722997329974299752997629977299782997929980299812998229983299842998529986299872998829989299902999129992299932999429995299962999729998299993000030001300023000330004300053000630007300083000930010300113001230013300143001530016300173001830019300203002130022300233002430025300263002730028300293003030031300323003330034300353003630037300383003930040300413004230043300443004530046300473004830049300503005130052300533005430055300563005730058300593006030061300623006330064300653006630067300683006930070300713007230073300743007530076300773007830079300803008130082300833008430085300863008730088300893009030091300923009330094300953009630097300983009930100301013010230103301043010530106301073010830109301103011130112301133011430115301163011730118301193012030121301223012330124301253012630127301283012930130301313013230133301343013530136301373013830139301403014130142301433014430145301463014730148301493015030151301523015330154301553015630157301583015930160301613016230163301643016530166301673016830169301703017130172301733017430175301763017730178301793018030181301823018330184301853018630187301883018930190301913019230193301943019530196301973019830199302003020130202302033020430205302063020730208302093021030211302123021330214302153021630217302183021930220302213022230223302243022530226302273022830229302303023130232302333023430235302363023730238302393024030241302423024330244302453024630247302483024930250302513025230253302543025530256302573025830259302603026130262302633026430265302663026730268302693027030271302723027330274302753027630277302783027930280302813028230283302843028530286302873028830289302903029130292302933029430295302963029730298302993030030301303023030330304303053030630307303083030930310303113031230313303143031530316303173031830319303203032130322303233032430325303263032730328303293033030331303323033330334303353033630337303383033930340303413034230343303443034530346303473034830349303503035130352303533035430355303563035730358303593036030361303623036330364303653036630367303683036930370303713037230373303743037530376303773037830379303803038130382303833038430385303863038730388303893039030391303923039330394303953039630397303983039930400304013040230403304043040530406304073040830409304103041130412304133041430415304163041730418304193042030421304223042330424304253042630427304283042930430304313043230433304343043530436304373043830439304403044130442304433044430445304463044730448304493045030451304523045330454304553045630457304583045930460304613046230463304643046530466304673046830469304703047130472304733047430475304763047730478304793048030481304823048330484304853048630487304883048930490304913049230493304943049530496304973049830499305003050130502305033050430505305063050730508305093051030511305123051330514305153051630517305183051930520305213052230523305243052530526305273052830529305303053130532305333053430535305363053730538305393054030541305423054330544305453054630547305483054930550305513055230553305543055530556305573055830559305603056130562305633056430565305663056730568305693057030571305723057330574305753057630577305783057930580305813058230583305843058530586305873058830589305903059130592305933059430595305963059730598305993060030601306023060330604306053060630607306083060930610306113061230613306143061530616306173061830619306203062130622306233062430625306263062730628306293063030631306323063330634306353063630637306383063930640306413064230643306443064530646306473064830649306503065130652306533065430655306563065730658306593066030661306623066330664306653066630667306683066930670306713067230673306743067530676306773067830679306803068130682306833068430685306863068730688306893069030691306923069330694306953069630697306983069930700307013070230703307043070530706307073070830709307103071130712307133071430715307163071730718307193072030721307223072330724307253072630727307283072930730307313073230733307343073530736307373073830739307403074130742307433074430745307463074730748307493075030751307523075330754307553075630757307583075930760307613076230763307643076530766307673076830769307703077130772307733077430775307763077730778307793078030781307823078330784307853078630787307883078930790307913079230793307943079530796307973079830799308003080130802308033080430805308063080730808308093081030811308123081330814308153081630817308183081930820308213082230823308243082530826308273082830829308303083130832308333083430835308363083730838308393084030841308423084330844308453084630847308483084930850308513085230853308543085530856308573085830859308603086130862308633086430865308663086730868308693087030871308723087330874308753087630877308783087930880308813088230883308843088530886308873088830889308903089130892308933089430895308963089730898308993090030901309023090330904309053090630907309083090930910309113091230913309143091530916309173091830919309203092130922309233092430925309263092730928309293093030931309323093330934309353093630937309383093930940309413094230943309443094530946309473094830949309503095130952309533095430955309563095730958309593096030961309623096330964309653096630967309683096930970309713097230973309743097530976309773097830979309803098130982309833098430985309863098730988309893099030991309923099330994309953099630997309983099931000310013100231003310043100531006310073100831009310103101131012310133101431015310163101731018310193102031021310223102331024310253102631027310283102931030310313103231033310343103531036310373103831039310403104131042310433104431045310463104731048310493105031051310523105331054310553105631057310583105931060310613106231063310643106531066310673106831069310703107131072310733107431075310763107731078310793108031081310823108331084310853108631087310883108931090310913109231093310943109531096310973109831099311003110131102311033110431105311063110731108311093111031111311123111331114311153111631117311183111931120311213112231123311243112531126311273112831129311303113131132311333113431135311363113731138311393114031141311423114331144311453114631147311483114931150311513115231153311543115531156311573115831159311603116131162311633116431165311663116731168311693117031171311723117331174311753117631177311783117931180311813118231183311843118531186311873118831189311903119131192311933119431195311963119731198311993120031201312023120331204312053120631207312083120931210312113121231213312143121531216312173121831219312203122131222312233122431225312263122731228312293123031231312323123331234312353123631237312383123931240312413124231243312443124531246312473124831249312503125131252312533125431255312563125731258312593126031261312623126331264312653126631267312683126931270312713127231273312743127531276312773127831279312803128131282312833128431285312863128731288312893129031291312923129331294312953129631297312983129931300313013130231303313043130531306313073130831309313103131131312313133131431315313163131731318313193132031321313223132331324313253132631327313283132931330313313133231333313343133531336313373133831339313403134131342313433134431345313463134731348313493135031351313523135331354313553135631357313583135931360313613136231363313643136531366313673136831369313703137131372313733137431375313763137731378313793138031381313823138331384313853138631387313883138931390313913139231393313943139531396313973139831399314003140131402314033140431405314063140731408314093141031411314123141331414314153141631417314183141931420314213142231423314243142531426314273142831429314303143131432314333143431435314363143731438314393144031441314423144331444314453144631447314483144931450314513145231453314543145531456314573145831459314603146131462314633146431465314663146731468314693147031471314723147331474314753147631477314783147931480314813148231483314843148531486314873148831489314903149131492314933149431495314963149731498314993150031501315023150331504315053150631507315083150931510315113151231513315143151531516315173151831519315203152131522315233152431525315263152731528315293153031531315323153331534315353153631537315383153931540315413154231543315443154531546315473154831549315503155131552315533155431555315563155731558315593156031561315623156331564315653156631567315683156931570315713157231573315743157531576315773157831579315803158131582315833158431585315863158731588315893159031591315923159331594315953159631597315983159931600316013160231603316043160531606316073160831609316103161131612316133161431615316163161731618316193162031621316223162331624316253162631627316283162931630316313163231633316343163531636316373163831639316403164131642316433164431645316463164731648316493165031651316523165331654316553165631657316583165931660316613166231663316643166531666316673166831669316703167131672316733167431675316763167731678316793168031681316823168331684316853168631687316883168931690316913169231693316943169531696316973169831699317003170131702317033170431705317063170731708317093171031711317123171331714317153171631717317183171931720317213172231723317243172531726317273172831729317303173131732317333173431735317363173731738317393174031741317423174331744317453174631747317483174931750317513175231753317543175531756317573175831759317603176131762317633176431765317663176731768317693177031771317723177331774317753177631777317783177931780317813178231783317843178531786317873178831789317903179131792317933179431795317963179731798317993180031801318023180331804318053180631807318083180931810318113181231813318143181531816318173181831819318203182131822318233182431825318263182731828318293183031831318323183331834318353183631837318383183931840318413184231843318443184531846318473184831849318503185131852318533185431855318563185731858318593186031861318623186331864318653186631867318683186931870318713187231873318743187531876318773187831879318803188131882318833188431885318863188731888318893189031891318923189331894318953189631897318983189931900319013190231903319043190531906319073190831909319103191131912319133191431915319163191731918319193192031921319223192331924319253192631927319283192931930319313193231933319343193531936319373193831939319403194131942319433194431945319463194731948319493195031951319523195331954319553195631957319583195931960319613196231963319643196531966319673196831969319703197131972319733197431975319763197731978319793198031981319823198331984319853198631987319883198931990319913199231993319943199531996319973199831999320003200132002320033200432005320063200732008320093201032011320123201332014320153201632017320183201932020320213202232023320243202532026320273202832029320303203132032320333203432035320363203732038320393204032041320423204332044320453204632047320483204932050320513205232053320543205532056320573205832059320603206132062320633206432065320663206732068320693207032071320723207332074320753207632077320783207932080320813208232083320843208532086320873208832089320903209132092320933209432095320963209732098320993210032101321023210332104321053210632107321083210932110321113211232113321143211532116321173211832119321203212132122321233212432125321263212732128321293213032131321323213332134321353213632137321383213932140321413214232143321443214532146321473214832149321503215132152321533215432155321563215732158321593216032161321623216332164321653216632167321683216932170321713217232173321743217532176321773217832179321803218132182321833218432185321863218732188321893219032191321923219332194321953219632197321983219932200322013220232203322043220532206322073220832209322103221132212322133221432215322163221732218322193222032221322223222332224322253222632227322283222932230322313223232233322343223532236322373223832239322403224132242322433224432245322463224732248322493225032251322523225332254322553225632257322583225932260322613226232263322643226532266322673226832269322703227132272322733227432275322763227732278322793228032281322823228332284322853228632287322883228932290322913229232293322943229532296322973229832299323003230132302323033230432305323063230732308323093231032311323123231332314323153231632317323183231932320323213232232323323243232532326323273232832329323303233132332323333233432335323363233732338323393234032341323423234332344323453234632347323483234932350323513235232353323543235532356323573235832359323603236132362323633236432365323663236732368323693237032371323723237332374323753237632377323783237932380323813238232383323843238532386323873238832389323903239132392323933239432395323963239732398323993240032401324023240332404324053240632407324083240932410324113241232413324143241532416324173241832419324203242132422324233242432425324263242732428324293243032431324323243332434324353243632437324383243932440324413244232443324443244532446324473244832449324503245132452324533245432455324563245732458324593246032461324623246332464324653246632467324683246932470324713247232473324743247532476324773247832479324803248132482324833248432485324863248732488324893249032491324923249332494324953249632497324983249932500325013250232503325043250532506325073250832509325103251132512325133251432515325163251732518325193252032521325223252332524325253252632527325283252932530325313253232533325343253532536325373253832539325403254132542325433254432545325463254732548325493255032551325523255332554325553255632557325583255932560325613256232563325643256532566325673256832569325703257132572325733257432575325763257732578325793258032581325823258332584325853258632587325883258932590325913259232593325943259532596325973259832599326003260132602326033260432605326063260732608326093261032611326123261332614326153261632617326183261932620326213262232623326243262532626326273262832629326303263132632326333263432635326363263732638326393264032641326423264332644326453264632647326483264932650326513265232653326543265532656326573265832659326603266132662326633266432665326663266732668326693267032671326723267332674326753267632677326783267932680326813268232683326843268532686326873268832689326903269132692326933269432695326963269732698326993270032701327023270332704327053270632707327083270932710327113271232713327143271532716327173271832719327203272132722327233272432725327263272732728327293273032731327323273332734327353273632737327383273932740327413274232743327443274532746327473274832749327503275132752327533275432755327563275732758327593276032761327623276332764327653276632767327683276932770327713277232773327743277532776327773277832779327803278132782327833278432785327863278732788327893279032791327923279332794327953279632797327983279932800328013280232803328043280532806328073280832809328103281132812328133281432815328163281732818328193282032821328223282332824328253282632827328283282932830328313283232833328343283532836328373283832839328403284132842328433284432845328463284732848328493285032851328523285332854328553285632857328583285932860328613286232863328643286532866328673286832869328703287132872328733287432875328763287732878328793288032881328823288332884328853288632887328883288932890328913289232893328943289532896328973289832899329003290132902329033290432905329063290732908329093291032911329123291332914329153291632917329183291932920329213292232923329243292532926329273292832929329303293132932329333293432935329363293732938329393294032941329423294332944329453294632947329483294932950329513295232953329543295532956329573295832959329603296132962329633296432965329663296732968329693297032971329723297332974329753297632977329783297932980329813298232983329843298532986329873298832989329903299132992329933299432995329963299732998329993300033001330023300333004330053300633007330083300933010330113301233013330143301533016330173301833019330203302133022330233302433025330263302733028330293303033031330323303333034330353303633037330383303933040330413304233043330443304533046330473304833049330503305133052330533305433055330563305733058330593306033061330623306333064330653306633067330683306933070330713307233073330743307533076330773307833079330803308133082330833308433085330863308733088330893309033091330923309333094330953309633097330983309933100331013310233103331043310533106331073310833109331103311133112331133311433115331163311733118331193312033121331223312333124331253312633127331283312933130331313313233133
  1. apiVersion: apiextensions.k8s.io/v1
  2. kind: CustomResourceDefinition
  3. metadata:
  4. annotations:
  5. controller-gen.kubebuilder.io/version: v0.19.0
  6. labels:
  7. external-secrets.io/component: controller
  8. name: clusterexternalsecrets.external-secrets.io
  9. spec:
  10. group: external-secrets.io
  11. names:
  12. categories:
  13. - external-secrets
  14. kind: ClusterExternalSecret
  15. listKind: ClusterExternalSecretList
  16. plural: clusterexternalsecrets
  17. shortNames:
  18. - ces
  19. singular: clusterexternalsecret
  20. scope: Cluster
  21. versions:
  22. - additionalPrinterColumns:
  23. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  24. name: Store
  25. type: string
  26. - jsonPath: .spec.refreshTime
  27. name: Refresh Interval
  28. type: string
  29. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  30. name: Ready
  31. type: string
  32. name: v1
  33. schema:
  34. openAPIV3Schema:
  35. description: ClusterExternalSecret is the Schema for the clusterexternalsecrets API.
  36. properties:
  37. apiVersion:
  38. description: |-
  39. APIVersion defines the versioned schema of this representation of an object.
  40. Servers should convert recognized schemas to the latest internal value, and
  41. may reject unrecognized values.
  42. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  43. type: string
  44. kind:
  45. description: |-
  46. Kind is a string value representing the REST resource this object represents.
  47. Servers may infer this from the endpoint the client submits requests to.
  48. Cannot be updated.
  49. In CamelCase.
  50. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  51. type: string
  52. metadata:
  53. type: object
  54. spec:
  55. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  56. properties:
  57. externalSecretMetadata:
  58. description: The metadata of the external secrets to be created
  59. properties:
  60. annotations:
  61. additionalProperties:
  62. type: string
  63. type: object
  64. labels:
  65. additionalProperties:
  66. type: string
  67. type: object
  68. type: object
  69. externalSecretName:
  70. description: |-
  71. The name of the external secrets to be created.
  72. Defaults to the name of the ClusterExternalSecret
  73. maxLength: 253
  74. minLength: 1
  75. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  76. type: string
  77. externalSecretSpec:
  78. description: The spec for the ExternalSecrets to be created
  79. properties:
  80. data:
  81. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  82. items:
  83. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  84. properties:
  85. remoteRef:
  86. description: |-
  87. RemoteRef points to the remote secret and defines
  88. which secret (version/property/..) to fetch.
  89. properties:
  90. conversionStrategy:
  91. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  92. enum:
  93. - Default
  94. - Unicode
  95. type: string
  96. decodingStrategy:
  97. description: Used to define a decoding Strategy. Defaults to None when omitted.
  98. enum:
  99. - Auto
  100. - Base64
  101. - Base64URL
  102. - None
  103. type: string
  104. key:
  105. description: Key is the key used in the Provider, mandatory
  106. type: string
  107. metadataPolicy:
  108. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  109. enum:
  110. - None
  111. - Fetch
  112. type: string
  113. nullBytePolicy:
  114. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  115. enum:
  116. - Ignore
  117. - Fail
  118. type: string
  119. property:
  120. description: Used to select a specific property of the Provider value (if a map), if supported
  121. type: string
  122. version:
  123. description: Used to select a specific version of the Provider value, if supported
  124. type: string
  125. required:
  126. - key
  127. type: object
  128. secretKey:
  129. description: The key in the Kubernetes Secret to store the value.
  130. maxLength: 253
  131. minLength: 1
  132. pattern: ^[-._a-zA-Z0-9]+$
  133. type: string
  134. sourceRef:
  135. description: |-
  136. SourceRef allows you to override the source
  137. from which the value will be pulled.
  138. maxProperties: 1
  139. minProperties: 1
  140. properties:
  141. generatorRef:
  142. description: |-
  143. GeneratorRef points to a generator custom resource.
  144. Deprecated: The generatorRef is not implemented in .data[].
  145. this will be removed with v1.
  146. properties:
  147. apiVersion:
  148. default: generators.external-secrets.io/v1alpha1
  149. description: Specify the apiVersion of the generator resource
  150. type: string
  151. kind:
  152. description: Specify the Kind of the generator resource
  153. enum:
  154. - ACRAccessToken
  155. - BeyondtrustWorkloadCredentialsDynamicSecret
  156. - ClusterGenerator
  157. - CloudsmithAccessToken
  158. - ECRAuthorizationToken
  159. - Fake
  160. - GCRAccessToken
  161. - GithubAccessToken
  162. - GitlabDeployToken
  163. - QuayAccessToken
  164. - Password
  165. - SSHKey
  166. - STSSessionToken
  167. - UUID
  168. - VaultDynamicSecret
  169. - Webhook
  170. - Grafana
  171. - MFA
  172. type: string
  173. name:
  174. description: Specify the name of the generator resource
  175. maxLength: 253
  176. minLength: 1
  177. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  178. type: string
  179. required:
  180. - kind
  181. - name
  182. type: object
  183. storeRef:
  184. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  185. properties:
  186. kind:
  187. description: |-
  188. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  189. Defaults to `SecretStore`
  190. enum:
  191. - SecretStore
  192. - ClusterSecretStore
  193. type: string
  194. name:
  195. description: Name of the SecretStore resource
  196. maxLength: 253
  197. minLength: 1
  198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  199. type: string
  200. type: object
  201. type: object
  202. required:
  203. - remoteRef
  204. - secretKey
  205. type: object
  206. type: array
  207. dataFrom:
  208. description: |-
  209. DataFrom is used to fetch all properties from a specific Provider data
  210. If multiple entries are specified, the Secret keys are merged in the specified order
  211. items:
  212. description: |-
  213. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  214. when using DataFrom to fetch multiple values from a Provider.
  215. properties:
  216. extract:
  217. description: |-
  218. Used to extract multiple key/value pairs from one secret
  219. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  220. properties:
  221. conversionStrategy:
  222. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  223. enum:
  224. - Default
  225. - Unicode
  226. type: string
  227. decodingStrategy:
  228. description: Used to define a decoding Strategy. Defaults to None when omitted.
  229. enum:
  230. - Auto
  231. - Base64
  232. - Base64URL
  233. - None
  234. type: string
  235. key:
  236. description: Key is the key used in the Provider, mandatory
  237. type: string
  238. metadataPolicy:
  239. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  240. enum:
  241. - None
  242. - Fetch
  243. type: string
  244. nullBytePolicy:
  245. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  246. enum:
  247. - Ignore
  248. - Fail
  249. type: string
  250. property:
  251. description: Used to select a specific property of the Provider value (if a map), if supported
  252. type: string
  253. version:
  254. description: Used to select a specific version of the Provider value, if supported
  255. type: string
  256. required:
  257. - key
  258. type: object
  259. find:
  260. description: |-
  261. Used to find secrets based on tags or regular expressions
  262. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  263. properties:
  264. conversionStrategy:
  265. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  266. enum:
  267. - Default
  268. - Unicode
  269. type: string
  270. decodingStrategy:
  271. description: Used to define a decoding Strategy. Defaults to None when omitted.
  272. enum:
  273. - Auto
  274. - Base64
  275. - Base64URL
  276. - None
  277. type: string
  278. name:
  279. description: Finds secrets based on the name.
  280. properties:
  281. regexp:
  282. description: Finds secrets base
  283. type: string
  284. type: object
  285. nullBytePolicy:
  286. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  287. enum:
  288. - Ignore
  289. - Fail
  290. type: string
  291. path:
  292. description: A root path to start the find operations.
  293. type: string
  294. tags:
  295. additionalProperties:
  296. type: string
  297. description: Find secrets based on tags.
  298. type: object
  299. type: object
  300. rewrite:
  301. description: |-
  302. Used to rewrite secret Keys after getting them from the secret Provider
  303. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  304. items:
  305. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  306. maxProperties: 1
  307. minProperties: 1
  308. properties:
  309. merge:
  310. description: |-
  311. Used to merge key/values in one single Secret
  312. The resulting key will contain all values from the specified secrets
  313. properties:
  314. conflictPolicy:
  315. default: Error
  316. description: Used to define the policy to use in conflict resolution.
  317. enum:
  318. - Ignore
  319. - Error
  320. type: string
  321. into:
  322. default: ""
  323. description: |-
  324. Used to define the target key of the merge operation.
  325. Required if strategy is JSON. Ignored otherwise.
  326. type: string
  327. priority:
  328. description: Used to define key priority in conflict resolution.
  329. items:
  330. type: string
  331. type: array
  332. priorityPolicy:
  333. default: Strict
  334. description: Used to define the policy when a key in the priority list does not exist in the input.
  335. enum:
  336. - IgnoreNotFound
  337. - Strict
  338. type: string
  339. strategy:
  340. default: Extract
  341. description: Used to define the strategy to use in the merge operation.
  342. enum:
  343. - Extract
  344. - JSON
  345. type: string
  346. type: object
  347. regexp:
  348. description: |-
  349. Used to rewrite with regular expressions.
  350. The resulting key will be the output of a regexp.ReplaceAll operation.
  351. properties:
  352. source:
  353. description: Used to define the regular expression of a re.Compiler.
  354. type: string
  355. target:
  356. description: Used to define the target pattern of a ReplaceAll operation.
  357. type: string
  358. required:
  359. - source
  360. - target
  361. type: object
  362. transform:
  363. description: |-
  364. Used to apply string transformation on the secrets.
  365. The resulting key will be the output of the template applied by the operation.
  366. properties:
  367. template:
  368. description: |-
  369. Used to define the template to apply on the secret name.
  370. `.value ` will specify the secret name in the template.
  371. type: string
  372. required:
  373. - template
  374. type: object
  375. type: object
  376. type: array
  377. sourceRef:
  378. description: |-
  379. SourceRef points to a store or generator
  380. which contains secret values ready to use.
  381. Use this in combination with Extract or Find pull values out of
  382. a specific SecretStore.
  383. When sourceRef points to a generator Extract or Find is not supported.
  384. The generator returns a static map of values
  385. maxProperties: 1
  386. minProperties: 1
  387. properties:
  388. generatorRef:
  389. description: GeneratorRef points to a generator custom resource.
  390. properties:
  391. apiVersion:
  392. default: generators.external-secrets.io/v1alpha1
  393. description: Specify the apiVersion of the generator resource
  394. type: string
  395. kind:
  396. description: Specify the Kind of the generator resource
  397. enum:
  398. - ACRAccessToken
  399. - BeyondtrustWorkloadCredentialsDynamicSecret
  400. - ClusterGenerator
  401. - CloudsmithAccessToken
  402. - ECRAuthorizationToken
  403. - Fake
  404. - GCRAccessToken
  405. - GithubAccessToken
  406. - GitlabDeployToken
  407. - QuayAccessToken
  408. - Password
  409. - SSHKey
  410. - STSSessionToken
  411. - UUID
  412. - VaultDynamicSecret
  413. - Webhook
  414. - Grafana
  415. - MFA
  416. type: string
  417. name:
  418. description: Specify the name of the generator resource
  419. maxLength: 253
  420. minLength: 1
  421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  422. type: string
  423. required:
  424. - kind
  425. - name
  426. type: object
  427. storeRef:
  428. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  429. properties:
  430. kind:
  431. description: |-
  432. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  433. Defaults to `SecretStore`
  434. enum:
  435. - SecretStore
  436. - ClusterSecretStore
  437. type: string
  438. name:
  439. description: Name of the SecretStore resource
  440. maxLength: 253
  441. minLength: 1
  442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  443. type: string
  444. type: object
  445. type: object
  446. type: object
  447. type: array
  448. refreshInterval:
  449. default: 1h0m0s
  450. description: |-
  451. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  452. specified as Golang Duration strings.
  453. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  454. Example values: "1h0m0s", "2h30m0s", "10m0s"
  455. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  456. type: string
  457. refreshPolicy:
  458. description: |-
  459. RefreshPolicy determines how the ExternalSecret should be refreshed:
  460. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  461. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  462. No periodic updates occur if refreshInterval is 0.
  463. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  464. enum:
  465. - CreatedOnce
  466. - Periodic
  467. - OnChange
  468. type: string
  469. secretStoreRef:
  470. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  471. properties:
  472. kind:
  473. description: |-
  474. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  475. Defaults to `SecretStore`
  476. enum:
  477. - SecretStore
  478. - ClusterSecretStore
  479. type: string
  480. name:
  481. description: Name of the SecretStore resource
  482. maxLength: 253
  483. minLength: 1
  484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  485. type: string
  486. type: object
  487. syncWindows:
  488. description: |-
  489. SyncWindows optionally restricts when periodic refreshes may occur.
  490. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  491. properties:
  492. kind:
  493. description: |-
  494. Kind applies to every window in the list.
  495. "allow" -- syncs are permitted only while at least one window is active;
  496. all other times are blocked.
  497. "deny" -- syncs are blocked while any window is active;
  498. all other times are permitted.
  499. enum:
  500. - allow
  501. - deny
  502. type: string
  503. windows:
  504. description: Windows is the list of schedule+duration pairs.
  505. items:
  506. description: |-
  507. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  508. within a SyncWindows block.
  509. properties:
  510. duration:
  511. description: |-
  512. Duration specifies how long the window stays open after each Schedule
  513. firing. Example: "8h".
  514. type: string
  515. schedule:
  516. description: |-
  517. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  518. named shorthand such as @daily or @every 1h. It marks the start time of
  519. each window occurrence.
  520. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  521. minLength: 1
  522. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  523. type: string
  524. required:
  525. - duration
  526. - schedule
  527. type: object
  528. minItems: 1
  529. type: array
  530. required:
  531. - kind
  532. - windows
  533. type: object
  534. target:
  535. default:
  536. creationPolicy: Owner
  537. deletionPolicy: Retain
  538. description: |-
  539. ExternalSecretTarget defines the Kubernetes Secret to be created,
  540. there can be only one target per ExternalSecret.
  541. properties:
  542. creationPolicy:
  543. default: Owner
  544. description: |-
  545. CreationPolicy defines rules on how to create the resulting Secret.
  546. Defaults to "Owner"
  547. enum:
  548. - Owner
  549. - Orphan
  550. - Merge
  551. - None
  552. - CreateOrMerge
  553. type: string
  554. deletionPolicy:
  555. default: Retain
  556. description: |-
  557. DeletionPolicy defines rules on how to delete the resulting Secret.
  558. Defaults to "Retain"
  559. enum:
  560. - Delete
  561. - Merge
  562. - Retain
  563. type: string
  564. immutable:
  565. description: Immutable defines if the final secret will be immutable
  566. type: boolean
  567. manifest:
  568. description: |-
  569. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  570. When specified, ExternalSecret will create the resource type defined here
  571. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  572. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  573. properties:
  574. apiVersion:
  575. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  576. minLength: 1
  577. type: string
  578. kind:
  579. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  580. minLength: 1
  581. type: string
  582. required:
  583. - apiVersion
  584. - kind
  585. type: object
  586. name:
  587. description: |-
  588. The name of the Secret resource to be managed.
  589. Defaults to the .metadata.name of the ExternalSecret resource
  590. maxLength: 253
  591. minLength: 1
  592. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  593. type: string
  594. template:
  595. description: Template defines a blueprint for the created Secret resource.
  596. properties:
  597. data:
  598. additionalProperties:
  599. type: string
  600. type: object
  601. engineVersion:
  602. default: v2
  603. description: |-
  604. EngineVersion specifies the template engine version
  605. that should be used to compile/execute the
  606. template specified in .data and .templateFrom[].
  607. enum:
  608. - v2
  609. type: string
  610. mergePolicy:
  611. default: Replace
  612. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  613. enum:
  614. - Replace
  615. - Merge
  616. type: string
  617. metadata:
  618. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  619. properties:
  620. annotations:
  621. additionalProperties:
  622. type: string
  623. type: object
  624. finalizers:
  625. items:
  626. type: string
  627. type: array
  628. labels:
  629. additionalProperties:
  630. type: string
  631. type: object
  632. type: object
  633. templateFrom:
  634. items:
  635. description: |-
  636. TemplateFrom specifies a source for templates.
  637. Each item in the list can either reference a ConfigMap or a Secret resource.
  638. properties:
  639. configMap:
  640. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  641. properties:
  642. items:
  643. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  644. items:
  645. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  646. properties:
  647. key:
  648. description: A key in the ConfigMap/Secret
  649. maxLength: 253
  650. minLength: 1
  651. pattern: ^[-._a-zA-Z0-9]+$
  652. type: string
  653. templateAs:
  654. default: Values
  655. description: TemplateScope specifies how the template keys should be interpreted.
  656. enum:
  657. - Values
  658. - KeysAndValues
  659. type: string
  660. required:
  661. - key
  662. type: object
  663. type: array
  664. name:
  665. description: The name of the ConfigMap/Secret resource
  666. maxLength: 253
  667. minLength: 1
  668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  669. type: string
  670. required:
  671. - items
  672. - name
  673. type: object
  674. literal:
  675. type: string
  676. secret:
  677. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  678. properties:
  679. items:
  680. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  681. items:
  682. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  683. properties:
  684. key:
  685. description: A key in the ConfigMap/Secret
  686. maxLength: 253
  687. minLength: 1
  688. pattern: ^[-._a-zA-Z0-9]+$
  689. type: string
  690. templateAs:
  691. default: Values
  692. description: TemplateScope specifies how the template keys should be interpreted.
  693. enum:
  694. - Values
  695. - KeysAndValues
  696. type: string
  697. required:
  698. - key
  699. type: object
  700. type: array
  701. name:
  702. description: The name of the ConfigMap/Secret resource
  703. maxLength: 253
  704. minLength: 1
  705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  706. type: string
  707. required:
  708. - items
  709. - name
  710. type: object
  711. target:
  712. default: Data
  713. description: |-
  714. Target specifies where to place the template result.
  715. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  716. any other value is rejected because it would allow writes to privileged Secret fields.
  717. For custom resources (when spec.target.manifest is set), this supports
  718. nested paths like "spec.database.config" or "data".
  719. type: string
  720. valuesDecodingStrategy:
  721. description: |-
  722. Used to define a decoding Strategy for the rendered template values.
  723. Defaults to None when omitted.
  724. enum:
  725. - Auto
  726. - Base64
  727. - Base64URL
  728. - None
  729. type: string
  730. type: object
  731. type: array
  732. type:
  733. type: string
  734. type: object
  735. type: object
  736. type: object
  737. namespaceSelector:
  738. description: |-
  739. The labels to select by to find the Namespaces to create the ExternalSecrets in.
  740. Deprecated: Use NamespaceSelectors instead.
  741. properties:
  742. matchExpressions:
  743. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  744. items:
  745. description: |-
  746. A label selector requirement is a selector that contains values, a key, and an operator that
  747. relates the key and values.
  748. properties:
  749. key:
  750. description: key is the label key that the selector applies to.
  751. type: string
  752. operator:
  753. description: |-
  754. operator represents a key's relationship to a set of values.
  755. Valid operators are In, NotIn, Exists and DoesNotExist.
  756. type: string
  757. values:
  758. description: |-
  759. values is an array of string values. If the operator is In or NotIn,
  760. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  761. the values array must be empty. This array is replaced during a strategic
  762. merge patch.
  763. items:
  764. type: string
  765. type: array
  766. x-kubernetes-list-type: atomic
  767. required:
  768. - key
  769. - operator
  770. type: object
  771. type: array
  772. x-kubernetes-list-type: atomic
  773. matchLabels:
  774. additionalProperties:
  775. type: string
  776. description: |-
  777. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  778. map is equivalent to an element of matchExpressions, whose key field is "key", the
  779. operator is "In", and the values array contains only "value". The requirements are ANDed.
  780. type: object
  781. type: object
  782. x-kubernetes-map-type: atomic
  783. namespaceSelectors:
  784. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  785. items:
  786. description: |-
  787. A label selector is a label query over a set of resources. The result of matchLabels and
  788. matchExpressions are ANDed. An empty label selector matches all objects. A null
  789. label selector matches no objects.
  790. properties:
  791. matchExpressions:
  792. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  793. items:
  794. description: |-
  795. A label selector requirement is a selector that contains values, a key, and an operator that
  796. relates the key and values.
  797. properties:
  798. key:
  799. description: key is the label key that the selector applies to.
  800. type: string
  801. operator:
  802. description: |-
  803. operator represents a key's relationship to a set of values.
  804. Valid operators are In, NotIn, Exists and DoesNotExist.
  805. type: string
  806. values:
  807. description: |-
  808. values is an array of string values. If the operator is In or NotIn,
  809. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  810. the values array must be empty. This array is replaced during a strategic
  811. merge patch.
  812. items:
  813. type: string
  814. type: array
  815. x-kubernetes-list-type: atomic
  816. required:
  817. - key
  818. - operator
  819. type: object
  820. type: array
  821. x-kubernetes-list-type: atomic
  822. matchLabels:
  823. additionalProperties:
  824. type: string
  825. description: |-
  826. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  827. map is equivalent to an element of matchExpressions, whose key field is "key", the
  828. operator is "In", and the values array contains only "value". The requirements are ANDed.
  829. type: object
  830. type: object
  831. x-kubernetes-map-type: atomic
  832. type: array
  833. namespaces:
  834. description: |-
  835. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  836. Deprecated: Use NamespaceSelectors instead.
  837. items:
  838. maxLength: 63
  839. minLength: 1
  840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  841. type: string
  842. type: array
  843. refreshTime:
  844. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  845. type: string
  846. required:
  847. - externalSecretSpec
  848. type: object
  849. status:
  850. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  851. properties:
  852. conditions:
  853. items:
  854. description: ClusterExternalSecretStatusCondition defines the observed state of a ClusterExternalSecret resource.
  855. properties:
  856. message:
  857. type: string
  858. status:
  859. type: string
  860. type:
  861. description: ClusterExternalSecretConditionType defines a value type for ClusterExternalSecret conditions.
  862. type: string
  863. required:
  864. - status
  865. - type
  866. type: object
  867. type: array
  868. externalSecretName:
  869. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  870. type: string
  871. failedNamespaces:
  872. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  873. items:
  874. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  875. properties:
  876. namespace:
  877. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  878. type: string
  879. reason:
  880. description: Reason is why the ExternalSecret failed to apply to the namespace
  881. type: string
  882. required:
  883. - namespace
  884. type: object
  885. type: array
  886. provisionedNamespaces:
  887. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  888. items:
  889. type: string
  890. type: array
  891. type: object
  892. type: object
  893. served: true
  894. storage: true
  895. subresources:
  896. status: {}
  897. - additionalPrinterColumns:
  898. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  899. name: Store
  900. type: string
  901. - jsonPath: .spec.refreshTime
  902. name: Refresh Interval
  903. type: string
  904. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  905. name: Ready
  906. type: string
  907. deprecated: true
  908. name: v1beta1
  909. schema:
  910. openAPIV3Schema:
  911. description: ClusterExternalSecret is the schema for the clusterexternalsecrets API.
  912. properties:
  913. apiVersion:
  914. description: |-
  915. APIVersion defines the versioned schema of this representation of an object.
  916. Servers should convert recognized schemas to the latest internal value, and
  917. may reject unrecognized values.
  918. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  919. type: string
  920. kind:
  921. description: |-
  922. Kind is a string value representing the REST resource this object represents.
  923. Servers may infer this from the endpoint the client submits requests to.
  924. Cannot be updated.
  925. In CamelCase.
  926. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  927. type: string
  928. metadata:
  929. type: object
  930. spec:
  931. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  932. properties:
  933. externalSecretMetadata:
  934. description: The metadata of the external secrets to be created
  935. properties:
  936. annotations:
  937. additionalProperties:
  938. type: string
  939. type: object
  940. labels:
  941. additionalProperties:
  942. type: string
  943. type: object
  944. type: object
  945. externalSecretName:
  946. description: |-
  947. The name of the external secrets to be created.
  948. Defaults to the name of the ClusterExternalSecret
  949. maxLength: 253
  950. minLength: 1
  951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  952. type: string
  953. externalSecretSpec:
  954. description: The spec for the ExternalSecrets to be created
  955. properties:
  956. data:
  957. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  958. items:
  959. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  960. properties:
  961. remoteRef:
  962. description: |-
  963. RemoteRef points to the remote secret and defines
  964. which secret (version/property/..) to fetch.
  965. properties:
  966. conversionStrategy:
  967. default: Default
  968. description: Used to define a conversion Strategy
  969. enum:
  970. - Default
  971. - Unicode
  972. type: string
  973. decodingStrategy:
  974. default: None
  975. description: Used to define a decoding Strategy
  976. enum:
  977. - Auto
  978. - Base64
  979. - Base64URL
  980. - None
  981. type: string
  982. key:
  983. description: Key is the key used in the Provider, mandatory
  984. type: string
  985. metadataPolicy:
  986. default: None
  987. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  988. enum:
  989. - None
  990. - Fetch
  991. type: string
  992. property:
  993. description: Used to select a specific property of the Provider value (if a map), if supported
  994. type: string
  995. version:
  996. description: Used to select a specific version of the Provider value, if supported
  997. type: string
  998. required:
  999. - key
  1000. type: object
  1001. secretKey:
  1002. description: The key in the Kubernetes Secret to store the value.
  1003. maxLength: 253
  1004. minLength: 1
  1005. pattern: ^[-._a-zA-Z0-9]+$
  1006. type: string
  1007. sourceRef:
  1008. description: |-
  1009. SourceRef allows you to override the source
  1010. from which the value will be pulled.
  1011. maxProperties: 1
  1012. minProperties: 1
  1013. properties:
  1014. generatorRef:
  1015. description: |-
  1016. GeneratorRef points to a generator custom resource.
  1017. Deprecated: The generatorRef is not implemented in .data[].
  1018. this will be removed with v1.
  1019. properties:
  1020. apiVersion:
  1021. default: generators.external-secrets.io/v1alpha1
  1022. description: Specify the apiVersion of the generator resource
  1023. type: string
  1024. kind:
  1025. description: Specify the Kind of the generator resource
  1026. enum:
  1027. - ACRAccessToken
  1028. - ClusterGenerator
  1029. - ECRAuthorizationToken
  1030. - Fake
  1031. - GCRAccessToken
  1032. - GithubAccessToken
  1033. - QuayAccessToken
  1034. - Password
  1035. - SSHKey
  1036. - STSSessionToken
  1037. - UUID
  1038. - VaultDynamicSecret
  1039. - Webhook
  1040. - Grafana
  1041. type: string
  1042. name:
  1043. description: Specify the name of the generator resource
  1044. maxLength: 253
  1045. minLength: 1
  1046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1047. type: string
  1048. required:
  1049. - kind
  1050. - name
  1051. type: object
  1052. storeRef:
  1053. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1054. properties:
  1055. kind:
  1056. description: |-
  1057. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1058. Defaults to `SecretStore`
  1059. enum:
  1060. - SecretStore
  1061. - ClusterSecretStore
  1062. type: string
  1063. name:
  1064. description: Name of the SecretStore resource
  1065. maxLength: 253
  1066. minLength: 1
  1067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1068. type: string
  1069. type: object
  1070. type: object
  1071. required:
  1072. - remoteRef
  1073. - secretKey
  1074. type: object
  1075. type: array
  1076. dataFrom:
  1077. description: |-
  1078. DataFrom is used to fetch all properties from a specific Provider data
  1079. If multiple entries are specified, the Secret keys are merged in the specified order
  1080. items:
  1081. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  1082. properties:
  1083. extract:
  1084. description: |-
  1085. Used to extract multiple key/value pairs from one secret
  1086. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1087. properties:
  1088. conversionStrategy:
  1089. default: Default
  1090. description: Used to define a conversion Strategy
  1091. enum:
  1092. - Default
  1093. - Unicode
  1094. type: string
  1095. decodingStrategy:
  1096. default: None
  1097. description: Used to define a decoding Strategy
  1098. enum:
  1099. - Auto
  1100. - Base64
  1101. - Base64URL
  1102. - None
  1103. type: string
  1104. key:
  1105. description: Key is the key used in the Provider, mandatory
  1106. type: string
  1107. metadataPolicy:
  1108. default: None
  1109. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  1110. enum:
  1111. - None
  1112. - Fetch
  1113. type: string
  1114. property:
  1115. description: Used to select a specific property of the Provider value (if a map), if supported
  1116. type: string
  1117. version:
  1118. description: Used to select a specific version of the Provider value, if supported
  1119. type: string
  1120. required:
  1121. - key
  1122. type: object
  1123. find:
  1124. description: |-
  1125. Used to find secrets based on tags or regular expressions
  1126. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1127. properties:
  1128. conversionStrategy:
  1129. default: Default
  1130. description: Used to define a conversion Strategy
  1131. enum:
  1132. - Default
  1133. - Unicode
  1134. type: string
  1135. decodingStrategy:
  1136. default: None
  1137. description: Used to define a decoding Strategy
  1138. enum:
  1139. - Auto
  1140. - Base64
  1141. - Base64URL
  1142. - None
  1143. type: string
  1144. name:
  1145. description: Finds secrets based on the name.
  1146. properties:
  1147. regexp:
  1148. description: Finds secrets base
  1149. type: string
  1150. type: object
  1151. path:
  1152. description: A root path to start the find operations.
  1153. type: string
  1154. tags:
  1155. additionalProperties:
  1156. type: string
  1157. description: Find secrets based on tags.
  1158. type: object
  1159. type: object
  1160. rewrite:
  1161. description: |-
  1162. Used to rewrite secret Keys after getting them from the secret Provider
  1163. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  1164. items:
  1165. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  1166. maxProperties: 1
  1167. minProperties: 1
  1168. properties:
  1169. regexp:
  1170. description: |-
  1171. Used to rewrite with regular expressions.
  1172. The resulting key will be the output of a regexp.ReplaceAll operation.
  1173. properties:
  1174. source:
  1175. description: Used to define the regular expression of a re.Compiler.
  1176. type: string
  1177. target:
  1178. description: Used to define the target pattern of a ReplaceAll operation.
  1179. type: string
  1180. required:
  1181. - source
  1182. - target
  1183. type: object
  1184. transform:
  1185. description: |-
  1186. Used to apply string transformation on the secrets.
  1187. The resulting key will be the output of the template applied by the operation.
  1188. properties:
  1189. template:
  1190. description: |-
  1191. Used to define the template to apply on the secret name.
  1192. `.value ` will specify the secret name in the template.
  1193. type: string
  1194. required:
  1195. - template
  1196. type: object
  1197. type: object
  1198. type: array
  1199. sourceRef:
  1200. description: |-
  1201. SourceRef points to a store or generator
  1202. which contains secret values ready to use.
  1203. Use this in combination with Extract or Find pull values out of
  1204. a specific SecretStore.
  1205. When sourceRef points to a generator Extract or Find is not supported.
  1206. The generator returns a static map of values
  1207. maxProperties: 1
  1208. minProperties: 1
  1209. properties:
  1210. generatorRef:
  1211. description: GeneratorRef points to a generator custom resource.
  1212. properties:
  1213. apiVersion:
  1214. default: generators.external-secrets.io/v1alpha1
  1215. description: Specify the apiVersion of the generator resource
  1216. type: string
  1217. kind:
  1218. description: Specify the Kind of the generator resource
  1219. enum:
  1220. - ACRAccessToken
  1221. - ClusterGenerator
  1222. - ECRAuthorizationToken
  1223. - Fake
  1224. - GCRAccessToken
  1225. - GithubAccessToken
  1226. - QuayAccessToken
  1227. - Password
  1228. - SSHKey
  1229. - STSSessionToken
  1230. - UUID
  1231. - VaultDynamicSecret
  1232. - Webhook
  1233. - Grafana
  1234. type: string
  1235. name:
  1236. description: Specify the name of the generator resource
  1237. maxLength: 253
  1238. minLength: 1
  1239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1240. type: string
  1241. required:
  1242. - kind
  1243. - name
  1244. type: object
  1245. storeRef:
  1246. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1247. properties:
  1248. kind:
  1249. description: |-
  1250. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1251. Defaults to `SecretStore`
  1252. enum:
  1253. - SecretStore
  1254. - ClusterSecretStore
  1255. type: string
  1256. name:
  1257. description: Name of the SecretStore resource
  1258. maxLength: 253
  1259. minLength: 1
  1260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1261. type: string
  1262. type: object
  1263. type: object
  1264. type: object
  1265. type: array
  1266. refreshInterval:
  1267. default: 1h0m0s
  1268. description: |-
  1269. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  1270. specified as Golang Duration strings.
  1271. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  1272. Example values: "1h0m0s", "2h30m0s", "10m0s"
  1273. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  1274. type: string
  1275. refreshPolicy:
  1276. description: |-
  1277. RefreshPolicy determines how the ExternalSecret should be refreshed:
  1278. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  1279. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  1280. No periodic updates occur if refreshInterval is 0.
  1281. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  1282. enum:
  1283. - CreatedOnce
  1284. - Periodic
  1285. - OnChange
  1286. type: string
  1287. secretStoreRef:
  1288. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1289. properties:
  1290. kind:
  1291. description: |-
  1292. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1293. Defaults to `SecretStore`
  1294. enum:
  1295. - SecretStore
  1296. - ClusterSecretStore
  1297. type: string
  1298. name:
  1299. description: Name of the SecretStore resource
  1300. maxLength: 253
  1301. minLength: 1
  1302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1303. type: string
  1304. type: object
  1305. target:
  1306. default:
  1307. creationPolicy: Owner
  1308. deletionPolicy: Retain
  1309. description: |-
  1310. ExternalSecretTarget defines the Kubernetes Secret to be created
  1311. There can be only one target per ExternalSecret.
  1312. properties:
  1313. creationPolicy:
  1314. default: Owner
  1315. description: |-
  1316. CreationPolicy defines rules on how to create the resulting Secret.
  1317. Defaults to "Owner"
  1318. enum:
  1319. - Owner
  1320. - Orphan
  1321. - Merge
  1322. - None
  1323. type: string
  1324. deletionPolicy:
  1325. default: Retain
  1326. description: |-
  1327. DeletionPolicy defines rules on how to delete the resulting Secret.
  1328. Defaults to "Retain"
  1329. enum:
  1330. - Delete
  1331. - Merge
  1332. - Retain
  1333. type: string
  1334. immutable:
  1335. description: Immutable defines if the final secret will be immutable
  1336. type: boolean
  1337. name:
  1338. description: |-
  1339. The name of the Secret resource to be managed.
  1340. Defaults to the .metadata.name of the ExternalSecret resource
  1341. maxLength: 253
  1342. minLength: 1
  1343. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1344. type: string
  1345. template:
  1346. description: Template defines a blueprint for the created Secret resource.
  1347. properties:
  1348. data:
  1349. additionalProperties:
  1350. type: string
  1351. type: object
  1352. engineVersion:
  1353. default: v2
  1354. description: |-
  1355. EngineVersion specifies the template engine version
  1356. that should be used to compile/execute the
  1357. template specified in .data and .templateFrom[].
  1358. enum:
  1359. - v2
  1360. type: string
  1361. mergePolicy:
  1362. default: Replace
  1363. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  1364. enum:
  1365. - Replace
  1366. - Merge
  1367. type: string
  1368. metadata:
  1369. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  1370. properties:
  1371. annotations:
  1372. additionalProperties:
  1373. type: string
  1374. type: object
  1375. labels:
  1376. additionalProperties:
  1377. type: string
  1378. type: object
  1379. type: object
  1380. templateFrom:
  1381. items:
  1382. description: TemplateFrom defines a source for template data.
  1383. properties:
  1384. configMap:
  1385. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1386. properties:
  1387. items:
  1388. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1389. items:
  1390. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1391. properties:
  1392. key:
  1393. description: A key in the ConfigMap/Secret
  1394. maxLength: 253
  1395. minLength: 1
  1396. pattern: ^[-._a-zA-Z0-9]+$
  1397. type: string
  1398. templateAs:
  1399. default: Values
  1400. description: TemplateScope defines the scope of the template when processing template data.
  1401. enum:
  1402. - Values
  1403. - KeysAndValues
  1404. type: string
  1405. required:
  1406. - key
  1407. type: object
  1408. type: array
  1409. name:
  1410. description: The name of the ConfigMap/Secret resource
  1411. maxLength: 253
  1412. minLength: 1
  1413. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1414. type: string
  1415. required:
  1416. - items
  1417. - name
  1418. type: object
  1419. literal:
  1420. type: string
  1421. secret:
  1422. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1423. properties:
  1424. items:
  1425. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1426. items:
  1427. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1428. properties:
  1429. key:
  1430. description: A key in the ConfigMap/Secret
  1431. maxLength: 253
  1432. minLength: 1
  1433. pattern: ^[-._a-zA-Z0-9]+$
  1434. type: string
  1435. templateAs:
  1436. default: Values
  1437. description: TemplateScope defines the scope of the template when processing template data.
  1438. enum:
  1439. - Values
  1440. - KeysAndValues
  1441. type: string
  1442. required:
  1443. - key
  1444. type: object
  1445. type: array
  1446. name:
  1447. description: The name of the ConfigMap/Secret resource
  1448. maxLength: 253
  1449. minLength: 1
  1450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1451. type: string
  1452. required:
  1453. - items
  1454. - name
  1455. type: object
  1456. target:
  1457. default: Data
  1458. description: TemplateTarget defines the target field where the template result will be stored.
  1459. enum:
  1460. - Data
  1461. - Annotations
  1462. - Labels
  1463. type: string
  1464. type: object
  1465. type: array
  1466. type:
  1467. type: string
  1468. type: object
  1469. type: object
  1470. type: object
  1471. namespaceSelector:
  1472. description: The labels to select by to find the Namespaces to create the ExternalSecrets in
  1473. properties:
  1474. matchExpressions:
  1475. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1476. items:
  1477. description: |-
  1478. A label selector requirement is a selector that contains values, a key, and an operator that
  1479. relates the key and values.
  1480. properties:
  1481. key:
  1482. description: key is the label key that the selector applies to.
  1483. type: string
  1484. operator:
  1485. description: |-
  1486. operator represents a key's relationship to a set of values.
  1487. Valid operators are In, NotIn, Exists and DoesNotExist.
  1488. type: string
  1489. values:
  1490. description: |-
  1491. values is an array of string values. If the operator is In or NotIn,
  1492. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1493. the values array must be empty. This array is replaced during a strategic
  1494. merge patch.
  1495. items:
  1496. type: string
  1497. type: array
  1498. x-kubernetes-list-type: atomic
  1499. required:
  1500. - key
  1501. - operator
  1502. type: object
  1503. type: array
  1504. x-kubernetes-list-type: atomic
  1505. matchLabels:
  1506. additionalProperties:
  1507. type: string
  1508. description: |-
  1509. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1510. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1511. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1512. type: object
  1513. type: object
  1514. x-kubernetes-map-type: atomic
  1515. namespaceSelectors:
  1516. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1517. items:
  1518. description: |-
  1519. A label selector is a label query over a set of resources. The result of matchLabels and
  1520. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1521. label selector matches no objects.
  1522. properties:
  1523. matchExpressions:
  1524. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1525. items:
  1526. description: |-
  1527. A label selector requirement is a selector that contains values, a key, and an operator that
  1528. relates the key and values.
  1529. properties:
  1530. key:
  1531. description: key is the label key that the selector applies to.
  1532. type: string
  1533. operator:
  1534. description: |-
  1535. operator represents a key's relationship to a set of values.
  1536. Valid operators are In, NotIn, Exists and DoesNotExist.
  1537. type: string
  1538. values:
  1539. description: |-
  1540. values is an array of string values. If the operator is In or NotIn,
  1541. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1542. the values array must be empty. This array is replaced during a strategic
  1543. merge patch.
  1544. items:
  1545. type: string
  1546. type: array
  1547. x-kubernetes-list-type: atomic
  1548. required:
  1549. - key
  1550. - operator
  1551. type: object
  1552. type: array
  1553. x-kubernetes-list-type: atomic
  1554. matchLabels:
  1555. additionalProperties:
  1556. type: string
  1557. description: |-
  1558. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1559. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1560. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1561. type: object
  1562. type: object
  1563. x-kubernetes-map-type: atomic
  1564. type: array
  1565. namespaces:
  1566. description: |-
  1567. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  1568. Deprecated: Use NamespaceSelectors instead.
  1569. items:
  1570. maxLength: 63
  1571. minLength: 1
  1572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1573. type: string
  1574. type: array
  1575. refreshTime:
  1576. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  1577. type: string
  1578. required:
  1579. - externalSecretSpec
  1580. type: object
  1581. status:
  1582. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  1583. properties:
  1584. conditions:
  1585. items:
  1586. description: ClusterExternalSecretStatusCondition indicates the status of the ClusterExternalSecret.
  1587. properties:
  1588. message:
  1589. type: string
  1590. status:
  1591. type: string
  1592. type:
  1593. description: ClusterExternalSecretConditionType indicates the condition of the ClusterExternalSecret.
  1594. type: string
  1595. required:
  1596. - status
  1597. - type
  1598. type: object
  1599. type: array
  1600. externalSecretName:
  1601. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  1602. type: string
  1603. failedNamespaces:
  1604. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  1605. items:
  1606. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  1607. properties:
  1608. namespace:
  1609. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  1610. type: string
  1611. reason:
  1612. description: Reason is why the ExternalSecret failed to apply to the namespace
  1613. type: string
  1614. required:
  1615. - namespace
  1616. type: object
  1617. type: array
  1618. provisionedNamespaces:
  1619. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  1620. items:
  1621. type: string
  1622. type: array
  1623. type: object
  1624. type: object
  1625. served: false
  1626. storage: false
  1627. subresources:
  1628. status: {}
  1629. ---
  1630. apiVersion: apiextensions.k8s.io/v1
  1631. kind: CustomResourceDefinition
  1632. metadata:
  1633. annotations:
  1634. controller-gen.kubebuilder.io/version: v0.19.0
  1635. labels:
  1636. external-secrets.io/component: controller
  1637. name: clusterpushsecrets.external-secrets.io
  1638. spec:
  1639. group: external-secrets.io
  1640. names:
  1641. categories:
  1642. - external-secrets
  1643. kind: ClusterPushSecret
  1644. listKind: ClusterPushSecretList
  1645. plural: clusterpushsecrets
  1646. singular: clusterpushsecret
  1647. scope: Cluster
  1648. versions:
  1649. - additionalPrinterColumns:
  1650. - jsonPath: .metadata.creationTimestamp
  1651. name: AGE
  1652. type: date
  1653. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  1654. name: Status
  1655. type: string
  1656. name: v1alpha1
  1657. schema:
  1658. openAPIV3Schema:
  1659. description: ClusterPushSecret is the Schema for the ClusterPushSecrets API that enables cluster-wide management of pushing Kubernetes secrets to external providers.
  1660. properties:
  1661. apiVersion:
  1662. description: |-
  1663. APIVersion defines the versioned schema of this representation of an object.
  1664. Servers should convert recognized schemas to the latest internal value, and
  1665. may reject unrecognized values.
  1666. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  1667. type: string
  1668. kind:
  1669. description: |-
  1670. Kind is a string value representing the REST resource this object represents.
  1671. Servers may infer this from the endpoint the client submits requests to.
  1672. Cannot be updated.
  1673. In CamelCase.
  1674. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  1675. type: string
  1676. metadata:
  1677. type: object
  1678. spec:
  1679. description: ClusterPushSecretSpec defines the configuration for a ClusterPushSecret resource.
  1680. properties:
  1681. namespaceSelectors:
  1682. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1683. items:
  1684. description: |-
  1685. A label selector is a label query over a set of resources. The result of matchLabels and
  1686. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1687. label selector matches no objects.
  1688. properties:
  1689. matchExpressions:
  1690. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1691. items:
  1692. description: |-
  1693. A label selector requirement is a selector that contains values, a key, and an operator that
  1694. relates the key and values.
  1695. properties:
  1696. key:
  1697. description: key is the label key that the selector applies to.
  1698. type: string
  1699. operator:
  1700. description: |-
  1701. operator represents a key's relationship to a set of values.
  1702. Valid operators are In, NotIn, Exists and DoesNotExist.
  1703. type: string
  1704. values:
  1705. description: |-
  1706. values is an array of string values. If the operator is In or NotIn,
  1707. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1708. the values array must be empty. This array is replaced during a strategic
  1709. merge patch.
  1710. items:
  1711. type: string
  1712. type: array
  1713. x-kubernetes-list-type: atomic
  1714. required:
  1715. - key
  1716. - operator
  1717. type: object
  1718. type: array
  1719. x-kubernetes-list-type: atomic
  1720. matchLabels:
  1721. additionalProperties:
  1722. type: string
  1723. description: |-
  1724. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1725. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1726. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1727. type: object
  1728. type: object
  1729. x-kubernetes-map-type: atomic
  1730. type: array
  1731. pushSecretMetadata:
  1732. description: The metadata of the external secrets to be created
  1733. properties:
  1734. annotations:
  1735. additionalProperties:
  1736. type: string
  1737. type: object
  1738. labels:
  1739. additionalProperties:
  1740. type: string
  1741. type: object
  1742. type: object
  1743. pushSecretName:
  1744. description: |-
  1745. The name of the push secrets to be created.
  1746. Defaults to the name of the ClusterPushSecret
  1747. maxLength: 253
  1748. minLength: 1
  1749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1750. type: string
  1751. pushSecretSpec:
  1752. description: PushSecretSpec defines what to do with the secrets.
  1753. properties:
  1754. data:
  1755. description: Secret Data that should be pushed to providers
  1756. items:
  1757. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  1758. properties:
  1759. conversionStrategy:
  1760. default: None
  1761. description: Used to define a conversion Strategy for the secret keys
  1762. enum:
  1763. - None
  1764. - ReverseUnicode
  1765. type: string
  1766. match:
  1767. description: Match a given Secret Key to be pushed to the provider.
  1768. properties:
  1769. remoteRef:
  1770. description: Remote Refs to push to providers.
  1771. properties:
  1772. property:
  1773. description: Name of the property in the resulting secret
  1774. type: string
  1775. remoteKey:
  1776. description: Name of the resulting provider secret.
  1777. type: string
  1778. required:
  1779. - remoteKey
  1780. type: object
  1781. secretKey:
  1782. description: Secret Key to be pushed
  1783. type: string
  1784. required:
  1785. - remoteRef
  1786. type: object
  1787. metadata:
  1788. description: |-
  1789. Metadata is metadata attached to the secret.
  1790. The structure of metadata is provider specific, please look it up in the provider documentation.
  1791. x-kubernetes-preserve-unknown-fields: true
  1792. required:
  1793. - match
  1794. type: object
  1795. type: array
  1796. dataTo:
  1797. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  1798. items:
  1799. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  1800. properties:
  1801. conversionStrategy:
  1802. default: None
  1803. description: Used to define a conversion Strategy for the secret keys
  1804. enum:
  1805. - None
  1806. - ReverseUnicode
  1807. type: string
  1808. match:
  1809. description: |-
  1810. Match pattern for selecting keys from the source Secret.
  1811. If not specified, all keys are selected.
  1812. properties:
  1813. regexp:
  1814. description: |-
  1815. Regexp matches keys by regular expression.
  1816. If not specified, all keys are matched.
  1817. type: string
  1818. type: object
  1819. metadata:
  1820. description: |-
  1821. Metadata is metadata attached to the secret.
  1822. The structure of metadata is provider specific, please look it up in the provider documentation.
  1823. x-kubernetes-preserve-unknown-fields: true
  1824. remoteKey:
  1825. description: |-
  1826. RemoteKey is the name of the single provider secret that will receive ALL
  1827. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  1828. When set, per-key expansion is skipped and a single push is performed.
  1829. The provider's store prefix (if any) is still prepended to this value.
  1830. When not set, each matched key is pushed as its own individual provider secret.
  1831. type: string
  1832. rewrite:
  1833. description: |-
  1834. Rewrite operations to transform keys before pushing to the provider.
  1835. Operations are applied sequentially.
  1836. items:
  1837. description: PushSecretRewrite defines how to transform secret keys before pushing.
  1838. properties:
  1839. regexp:
  1840. description: Used to rewrite with regular expressions.
  1841. properties:
  1842. source:
  1843. description: Used to define the regular expression of a re.Compiler.
  1844. type: string
  1845. target:
  1846. description: Used to define the target pattern of a ReplaceAll operation.
  1847. type: string
  1848. required:
  1849. - source
  1850. - target
  1851. type: object
  1852. transform:
  1853. description: Used to apply string transformation on the secrets.
  1854. properties:
  1855. template:
  1856. description: |-
  1857. Used to define the template to apply on the secret name.
  1858. `.value ` will specify the secret name in the template.
  1859. type: string
  1860. required:
  1861. - template
  1862. type: object
  1863. type: object
  1864. x-kubernetes-validations:
  1865. - message: exactly one of regexp or transform must be set
  1866. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  1867. type: array
  1868. storeRef:
  1869. description: StoreRef specifies which SecretStore to push to. Required.
  1870. properties:
  1871. kind:
  1872. default: SecretStore
  1873. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1874. enum:
  1875. - SecretStore
  1876. - ClusterSecretStore
  1877. type: string
  1878. labelSelector:
  1879. description: Optionally, sync to secret stores with label selector
  1880. properties:
  1881. matchExpressions:
  1882. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1883. items:
  1884. description: |-
  1885. A label selector requirement is a selector that contains values, a key, and an operator that
  1886. relates the key and values.
  1887. properties:
  1888. key:
  1889. description: key is the label key that the selector applies to.
  1890. type: string
  1891. operator:
  1892. description: |-
  1893. operator represents a key's relationship to a set of values.
  1894. Valid operators are In, NotIn, Exists and DoesNotExist.
  1895. type: string
  1896. values:
  1897. description: |-
  1898. values is an array of string values. If the operator is In or NotIn,
  1899. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1900. the values array must be empty. This array is replaced during a strategic
  1901. merge patch.
  1902. items:
  1903. type: string
  1904. type: array
  1905. x-kubernetes-list-type: atomic
  1906. required:
  1907. - key
  1908. - operator
  1909. type: object
  1910. type: array
  1911. x-kubernetes-list-type: atomic
  1912. matchLabels:
  1913. additionalProperties:
  1914. type: string
  1915. description: |-
  1916. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1917. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1918. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1919. type: object
  1920. type: object
  1921. x-kubernetes-map-type: atomic
  1922. name:
  1923. description: Optionally, sync to the SecretStore of the given name
  1924. maxLength: 253
  1925. minLength: 1
  1926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1927. type: string
  1928. type: object
  1929. type: object
  1930. x-kubernetes-validations:
  1931. - message: storeRef must specify either name or labelSelector
  1932. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  1933. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  1934. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  1935. type: array
  1936. deletionPolicy:
  1937. default: None
  1938. description: Deletion Policy to handle Secrets in the provider.
  1939. enum:
  1940. - Delete
  1941. - None
  1942. type: string
  1943. refreshInterval:
  1944. default: 1h0m0s
  1945. description: The Interval to which External Secrets will try to push a secret definition
  1946. type: string
  1947. secretStoreRefs:
  1948. items:
  1949. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  1950. properties:
  1951. kind:
  1952. default: SecretStore
  1953. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1954. enum:
  1955. - SecretStore
  1956. - ClusterSecretStore
  1957. type: string
  1958. labelSelector:
  1959. description: Optionally, sync to secret stores with label selector
  1960. properties:
  1961. matchExpressions:
  1962. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1963. items:
  1964. description: |-
  1965. A label selector requirement is a selector that contains values, a key, and an operator that
  1966. relates the key and values.
  1967. properties:
  1968. key:
  1969. description: key is the label key that the selector applies to.
  1970. type: string
  1971. operator:
  1972. description: |-
  1973. operator represents a key's relationship to a set of values.
  1974. Valid operators are In, NotIn, Exists and DoesNotExist.
  1975. type: string
  1976. values:
  1977. description: |-
  1978. values is an array of string values. If the operator is In or NotIn,
  1979. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1980. the values array must be empty. This array is replaced during a strategic
  1981. merge patch.
  1982. items:
  1983. type: string
  1984. type: array
  1985. x-kubernetes-list-type: atomic
  1986. required:
  1987. - key
  1988. - operator
  1989. type: object
  1990. type: array
  1991. x-kubernetes-list-type: atomic
  1992. matchLabels:
  1993. additionalProperties:
  1994. type: string
  1995. description: |-
  1996. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1997. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1998. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1999. type: object
  2000. type: object
  2001. x-kubernetes-map-type: atomic
  2002. name:
  2003. description: Optionally, sync to the SecretStore of the given name
  2004. maxLength: 253
  2005. minLength: 1
  2006. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2007. type: string
  2008. type: object
  2009. type: array
  2010. selector:
  2011. description: The Secret Selector (k8s source) for the Push Secret
  2012. maxProperties: 1
  2013. minProperties: 1
  2014. properties:
  2015. generatorRef:
  2016. description: Point to a generator to create a Secret.
  2017. properties:
  2018. apiVersion:
  2019. default: generators.external-secrets.io/v1alpha1
  2020. description: Specify the apiVersion of the generator resource
  2021. type: string
  2022. kind:
  2023. description: Specify the Kind of the generator resource
  2024. enum:
  2025. - ACRAccessToken
  2026. - BeyondtrustWorkloadCredentialsDynamicSecret
  2027. - ClusterGenerator
  2028. - CloudsmithAccessToken
  2029. - ECRAuthorizationToken
  2030. - Fake
  2031. - GCRAccessToken
  2032. - GithubAccessToken
  2033. - GitlabDeployToken
  2034. - QuayAccessToken
  2035. - Password
  2036. - SSHKey
  2037. - STSSessionToken
  2038. - UUID
  2039. - VaultDynamicSecret
  2040. - Webhook
  2041. - Grafana
  2042. - MFA
  2043. type: string
  2044. name:
  2045. description: Specify the name of the generator resource
  2046. maxLength: 253
  2047. minLength: 1
  2048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2049. type: string
  2050. required:
  2051. - kind
  2052. - name
  2053. type: object
  2054. secret:
  2055. description: Select a Secret to Push.
  2056. properties:
  2057. name:
  2058. description: |-
  2059. Name of the Secret.
  2060. The Secret must exist in the same namespace as the PushSecret manifest.
  2061. maxLength: 253
  2062. minLength: 1
  2063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2064. type: string
  2065. selector:
  2066. description: Selector chooses secrets using a labelSelector.
  2067. properties:
  2068. matchExpressions:
  2069. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2070. items:
  2071. description: |-
  2072. A label selector requirement is a selector that contains values, a key, and an operator that
  2073. relates the key and values.
  2074. properties:
  2075. key:
  2076. description: key is the label key that the selector applies to.
  2077. type: string
  2078. operator:
  2079. description: |-
  2080. operator represents a key's relationship to a set of values.
  2081. Valid operators are In, NotIn, Exists and DoesNotExist.
  2082. type: string
  2083. values:
  2084. description: |-
  2085. values is an array of string values. If the operator is In or NotIn,
  2086. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2087. the values array must be empty. This array is replaced during a strategic
  2088. merge patch.
  2089. items:
  2090. type: string
  2091. type: array
  2092. x-kubernetes-list-type: atomic
  2093. required:
  2094. - key
  2095. - operator
  2096. type: object
  2097. type: array
  2098. x-kubernetes-list-type: atomic
  2099. matchLabels:
  2100. additionalProperties:
  2101. type: string
  2102. description: |-
  2103. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2104. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2105. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2106. type: object
  2107. type: object
  2108. x-kubernetes-map-type: atomic
  2109. type: object
  2110. type: object
  2111. template:
  2112. description: Template defines a blueprint for the created Secret resource.
  2113. properties:
  2114. data:
  2115. additionalProperties:
  2116. type: string
  2117. type: object
  2118. engineVersion:
  2119. default: v2
  2120. description: |-
  2121. EngineVersion specifies the template engine version
  2122. that should be used to compile/execute the
  2123. template specified in .data and .templateFrom[].
  2124. enum:
  2125. - v2
  2126. type: string
  2127. mergePolicy:
  2128. default: Replace
  2129. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  2130. enum:
  2131. - Replace
  2132. - Merge
  2133. type: string
  2134. metadata:
  2135. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  2136. properties:
  2137. annotations:
  2138. additionalProperties:
  2139. type: string
  2140. type: object
  2141. finalizers:
  2142. items:
  2143. type: string
  2144. type: array
  2145. labels:
  2146. additionalProperties:
  2147. type: string
  2148. type: object
  2149. type: object
  2150. templateFrom:
  2151. items:
  2152. description: |-
  2153. TemplateFrom specifies a source for templates.
  2154. Each item in the list can either reference a ConfigMap or a Secret resource.
  2155. properties:
  2156. configMap:
  2157. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2158. properties:
  2159. items:
  2160. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2161. items:
  2162. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2163. properties:
  2164. key:
  2165. description: A key in the ConfigMap/Secret
  2166. maxLength: 253
  2167. minLength: 1
  2168. pattern: ^[-._a-zA-Z0-9]+$
  2169. type: string
  2170. templateAs:
  2171. default: Values
  2172. description: TemplateScope specifies how the template keys should be interpreted.
  2173. enum:
  2174. - Values
  2175. - KeysAndValues
  2176. type: string
  2177. required:
  2178. - key
  2179. type: object
  2180. type: array
  2181. name:
  2182. description: The name of the ConfigMap/Secret resource
  2183. maxLength: 253
  2184. minLength: 1
  2185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2186. type: string
  2187. required:
  2188. - items
  2189. - name
  2190. type: object
  2191. literal:
  2192. type: string
  2193. secret:
  2194. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2195. properties:
  2196. items:
  2197. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2198. items:
  2199. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2200. properties:
  2201. key:
  2202. description: A key in the ConfigMap/Secret
  2203. maxLength: 253
  2204. minLength: 1
  2205. pattern: ^[-._a-zA-Z0-9]+$
  2206. type: string
  2207. templateAs:
  2208. default: Values
  2209. description: TemplateScope specifies how the template keys should be interpreted.
  2210. enum:
  2211. - Values
  2212. - KeysAndValues
  2213. type: string
  2214. required:
  2215. - key
  2216. type: object
  2217. type: array
  2218. name:
  2219. description: The name of the ConfigMap/Secret resource
  2220. maxLength: 253
  2221. minLength: 1
  2222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2223. type: string
  2224. required:
  2225. - items
  2226. - name
  2227. type: object
  2228. target:
  2229. default: Data
  2230. description: |-
  2231. Target specifies where to place the template result.
  2232. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  2233. any other value is rejected because it would allow writes to privileged Secret fields.
  2234. For custom resources (when spec.target.manifest is set), this supports
  2235. nested paths like "spec.database.config" or "data".
  2236. type: string
  2237. valuesDecodingStrategy:
  2238. description: |-
  2239. Used to define a decoding Strategy for the rendered template values.
  2240. Defaults to None when omitted.
  2241. enum:
  2242. - Auto
  2243. - Base64
  2244. - Base64URL
  2245. - None
  2246. type: string
  2247. type: object
  2248. type: array
  2249. type:
  2250. type: string
  2251. type: object
  2252. updatePolicy:
  2253. default: Replace
  2254. description: UpdatePolicy to handle Secrets in the provider.
  2255. enum:
  2256. - Replace
  2257. - IfNotExists
  2258. type: string
  2259. required:
  2260. - secretStoreRefs
  2261. - selector
  2262. type: object
  2263. refreshTime:
  2264. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  2265. type: string
  2266. required:
  2267. - pushSecretSpec
  2268. type: object
  2269. status:
  2270. description: ClusterPushSecretStatus contains the status information for the ClusterPushSecret resource.
  2271. properties:
  2272. conditions:
  2273. items:
  2274. description: PushSecretStatusCondition indicates the status of the PushSecret.
  2275. properties:
  2276. lastTransitionTime:
  2277. format: date-time
  2278. type: string
  2279. message:
  2280. type: string
  2281. reason:
  2282. type: string
  2283. status:
  2284. type: string
  2285. type:
  2286. description: PushSecretConditionType indicates the condition of the PushSecret.
  2287. type: string
  2288. required:
  2289. - status
  2290. - type
  2291. type: object
  2292. type: array
  2293. failedNamespaces:
  2294. description: Failed namespaces are the namespaces that failed to apply an PushSecret
  2295. items:
  2296. description: ClusterPushSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  2297. properties:
  2298. namespace:
  2299. description: Namespace is the namespace that failed when trying to apply an PushSecret
  2300. type: string
  2301. reason:
  2302. description: Reason is why the PushSecret failed to apply to the namespace
  2303. type: string
  2304. required:
  2305. - namespace
  2306. type: object
  2307. type: array
  2308. provisionedNamespaces:
  2309. description: ProvisionedNamespaces are the namespaces where the ClusterPushSecret has secrets
  2310. items:
  2311. type: string
  2312. type: array
  2313. pushSecretName:
  2314. type: string
  2315. type: object
  2316. type: object
  2317. served: true
  2318. storage: true
  2319. subresources:
  2320. status: {}
  2321. ---
  2322. apiVersion: apiextensions.k8s.io/v1
  2323. kind: CustomResourceDefinition
  2324. metadata:
  2325. annotations:
  2326. controller-gen.kubebuilder.io/version: v0.19.0
  2327. labels:
  2328. external-secrets.io/component: controller
  2329. name: clustersecretstores.external-secrets.io
  2330. spec:
  2331. group: external-secrets.io
  2332. names:
  2333. categories:
  2334. - external-secrets
  2335. kind: ClusterSecretStore
  2336. listKind: ClusterSecretStoreList
  2337. plural: clustersecretstores
  2338. shortNames:
  2339. - css
  2340. singular: clustersecretstore
  2341. scope: Cluster
  2342. versions:
  2343. - additionalPrinterColumns:
  2344. - jsonPath: .metadata.creationTimestamp
  2345. name: AGE
  2346. type: date
  2347. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  2348. name: Status
  2349. type: string
  2350. - jsonPath: .status.capabilities
  2351. name: Capabilities
  2352. type: string
  2353. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  2354. name: Ready
  2355. type: string
  2356. name: v1
  2357. schema:
  2358. openAPIV3Schema:
  2359. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  2360. properties:
  2361. apiVersion:
  2362. description: |-
  2363. APIVersion defines the versioned schema of this representation of an object.
  2364. Servers should convert recognized schemas to the latest internal value, and
  2365. may reject unrecognized values.
  2366. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  2367. type: string
  2368. kind:
  2369. description: |-
  2370. Kind is a string value representing the REST resource this object represents.
  2371. Servers may infer this from the endpoint the client submits requests to.
  2372. Cannot be updated.
  2373. In CamelCase.
  2374. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  2375. type: string
  2376. metadata:
  2377. type: object
  2378. spec:
  2379. description: SecretStoreSpec defines the desired state of SecretStore.
  2380. properties:
  2381. conditions:
  2382. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  2383. items:
  2384. description: |-
  2385. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  2386. for a ClusterSecretStore instance.
  2387. properties:
  2388. namespaceRegexes:
  2389. description: Choose namespaces by using regex matching
  2390. items:
  2391. type: string
  2392. type: array
  2393. namespaceSelector:
  2394. description: Choose namespace using a labelSelector
  2395. properties:
  2396. matchExpressions:
  2397. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2398. items:
  2399. description: |-
  2400. A label selector requirement is a selector that contains values, a key, and an operator that
  2401. relates the key and values.
  2402. properties:
  2403. key:
  2404. description: key is the label key that the selector applies to.
  2405. type: string
  2406. operator:
  2407. description: |-
  2408. operator represents a key's relationship to a set of values.
  2409. Valid operators are In, NotIn, Exists and DoesNotExist.
  2410. type: string
  2411. values:
  2412. description: |-
  2413. values is an array of string values. If the operator is In or NotIn,
  2414. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2415. the values array must be empty. This array is replaced during a strategic
  2416. merge patch.
  2417. items:
  2418. type: string
  2419. type: array
  2420. x-kubernetes-list-type: atomic
  2421. required:
  2422. - key
  2423. - operator
  2424. type: object
  2425. type: array
  2426. x-kubernetes-list-type: atomic
  2427. matchLabels:
  2428. additionalProperties:
  2429. type: string
  2430. description: |-
  2431. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2432. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2433. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2434. type: object
  2435. type: object
  2436. x-kubernetes-map-type: atomic
  2437. namespaces:
  2438. description: Choose namespaces by name
  2439. items:
  2440. maxLength: 63
  2441. minLength: 1
  2442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2443. type: string
  2444. type: array
  2445. type: object
  2446. type: array
  2447. controller:
  2448. description: |-
  2449. Used to select the correct ESO controller (think: ingress.ingressClassName)
  2450. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  2451. type: string
  2452. provider:
  2453. description: Used to configure the provider. Only one provider may be set
  2454. maxProperties: 1
  2455. minProperties: 1
  2456. properties:
  2457. akeyless:
  2458. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  2459. properties:
  2460. akeylessGWApiURL:
  2461. description: Akeyless GW API Url from which the secrets to be fetched from.
  2462. type: string
  2463. authSecretRef:
  2464. description: Auth configures how the operator authenticates with Akeyless.
  2465. properties:
  2466. kubernetesAuth:
  2467. description: |-
  2468. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  2469. token stored in the named Secret resource.
  2470. properties:
  2471. accessID:
  2472. description: the Akeyless Kubernetes auth-method access-id
  2473. type: string
  2474. k8sConfName:
  2475. description: Kubernetes-auth configuration name in Akeyless-Gateway
  2476. type: string
  2477. secretRef:
  2478. description: |-
  2479. Optional secret field containing a Kubernetes ServiceAccount JWT used
  2480. for authenticating with Akeyless. If a name is specified without a key,
  2481. `token` is the default. If one is not specified, the one bound to
  2482. the controller will be used.
  2483. properties:
  2484. key:
  2485. description: |-
  2486. A key in the referenced Secret.
  2487. Some instances of this field may be defaulted, in others it may be required.
  2488. maxLength: 253
  2489. minLength: 1
  2490. pattern: ^[-._a-zA-Z0-9]+$
  2491. type: string
  2492. name:
  2493. description: The name of the Secret resource being referred to.
  2494. maxLength: 253
  2495. minLength: 1
  2496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2497. type: string
  2498. namespace:
  2499. description: |-
  2500. The namespace of the Secret resource being referred to.
  2501. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2502. maxLength: 63
  2503. minLength: 1
  2504. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2505. type: string
  2506. type: object
  2507. serviceAccountRef:
  2508. description: |-
  2509. Optional service account field containing the name of a kubernetes ServiceAccount.
  2510. If the service account is specified, the service account secret token JWT will be used
  2511. for authenticating with Akeyless. If the service account selector is not supplied,
  2512. the secretRef will be used instead.
  2513. properties:
  2514. audiences:
  2515. description: |-
  2516. Audience specifies the `aud` claim for the service account token
  2517. Some providers automatically extend the audience field based on well-known annotations for workload
  2518. identity (e.g. IRSA or GCP Workload Identity)
  2519. items:
  2520. type: string
  2521. type: array
  2522. name:
  2523. description: The name of the ServiceAccount resource being referred to.
  2524. maxLength: 253
  2525. minLength: 1
  2526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2527. type: string
  2528. namespace:
  2529. description: |-
  2530. Namespace of the resource being referred to.
  2531. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2532. maxLength: 63
  2533. minLength: 1
  2534. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2535. type: string
  2536. required:
  2537. - name
  2538. type: object
  2539. required:
  2540. - accessID
  2541. - k8sConfName
  2542. type: object
  2543. secretRef:
  2544. description: |-
  2545. Reference to a Secret that contains the details
  2546. to authenticate with Akeyless.
  2547. properties:
  2548. accessID:
  2549. description: The SecretAccessID is used for authentication
  2550. properties:
  2551. key:
  2552. description: |-
  2553. A key in the referenced Secret.
  2554. Some instances of this field may be defaulted, in others it may be required.
  2555. maxLength: 253
  2556. minLength: 1
  2557. pattern: ^[-._a-zA-Z0-9]+$
  2558. type: string
  2559. name:
  2560. description: The name of the Secret resource being referred to.
  2561. maxLength: 253
  2562. minLength: 1
  2563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2564. type: string
  2565. namespace:
  2566. description: |-
  2567. The namespace of the Secret resource being referred to.
  2568. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2569. maxLength: 63
  2570. minLength: 1
  2571. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2572. type: string
  2573. type: object
  2574. accessType:
  2575. description: |-
  2576. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2577. In some instances, `key` is a required field.
  2578. properties:
  2579. key:
  2580. description: |-
  2581. A key in the referenced Secret.
  2582. Some instances of this field may be defaulted, in others it may be required.
  2583. maxLength: 253
  2584. minLength: 1
  2585. pattern: ^[-._a-zA-Z0-9]+$
  2586. type: string
  2587. name:
  2588. description: The name of the Secret resource being referred to.
  2589. maxLength: 253
  2590. minLength: 1
  2591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2592. type: string
  2593. namespace:
  2594. description: |-
  2595. The namespace of the Secret resource being referred to.
  2596. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2597. maxLength: 63
  2598. minLength: 1
  2599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2600. type: string
  2601. type: object
  2602. accessTypeParam:
  2603. description: |-
  2604. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2605. In some instances, `key` is a required field.
  2606. properties:
  2607. key:
  2608. description: |-
  2609. A key in the referenced Secret.
  2610. Some instances of this field may be defaulted, in others it may be required.
  2611. maxLength: 253
  2612. minLength: 1
  2613. pattern: ^[-._a-zA-Z0-9]+$
  2614. type: string
  2615. name:
  2616. description: The name of the Secret resource being referred to.
  2617. maxLength: 253
  2618. minLength: 1
  2619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2620. type: string
  2621. namespace:
  2622. description: |-
  2623. The namespace of the Secret resource being referred to.
  2624. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2625. maxLength: 63
  2626. minLength: 1
  2627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2628. type: string
  2629. type: object
  2630. type: object
  2631. serviceAccountRef:
  2632. description: |-
  2633. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  2634. authentication on AKS Workload Identity. The operator obtains a federated
  2635. identity token from this ServiceAccount via the TokenRequest API instead
  2636. of using the ESO controller pod identity. Ignored for other access types.
  2637. properties:
  2638. audiences:
  2639. description: |-
  2640. Audience specifies the `aud` claim for the service account token
  2641. Some providers automatically extend the audience field based on well-known annotations for workload
  2642. identity (e.g. IRSA or GCP Workload Identity)
  2643. items:
  2644. type: string
  2645. type: array
  2646. name:
  2647. description: The name of the ServiceAccount resource being referred to.
  2648. maxLength: 253
  2649. minLength: 1
  2650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2651. type: string
  2652. namespace:
  2653. description: |-
  2654. Namespace of the resource being referred to.
  2655. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2656. maxLength: 63
  2657. minLength: 1
  2658. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2659. type: string
  2660. required:
  2661. - name
  2662. type: object
  2663. type: object
  2664. caBundle:
  2665. description: |-
  2666. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  2667. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  2668. are used to validate the TLS connection.
  2669. format: byte
  2670. type: string
  2671. caProvider:
  2672. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  2673. properties:
  2674. key:
  2675. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  2676. maxLength: 253
  2677. minLength: 1
  2678. pattern: ^[-._a-zA-Z0-9]+$
  2679. type: string
  2680. name:
  2681. description: The name of the object located at the provider type.
  2682. maxLength: 253
  2683. minLength: 1
  2684. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2685. type: string
  2686. namespace:
  2687. description: |-
  2688. The namespace the Provider type is in.
  2689. Can only be defined when used in a ClusterSecretStore.
  2690. maxLength: 63
  2691. minLength: 1
  2692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2693. type: string
  2694. type:
  2695. description: The type of provider to use such as "Secret", or "ConfigMap".
  2696. enum:
  2697. - Secret
  2698. - ConfigMap
  2699. type: string
  2700. required:
  2701. - name
  2702. - type
  2703. type: object
  2704. ignoreCache:
  2705. description: |-
  2706. IgnoreCache bypasses the Gateway cache for secret reads when true.
  2707. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  2708. type: boolean
  2709. required:
  2710. - akeylessGWApiURL
  2711. - authSecretRef
  2712. type: object
  2713. aws:
  2714. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  2715. properties:
  2716. additionalRoles:
  2717. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  2718. items:
  2719. type: string
  2720. type: array
  2721. auth:
  2722. description: |-
  2723. Auth defines the information necessary to authenticate against AWS
  2724. if not set aws sdk will infer credentials from your environment
  2725. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  2726. properties:
  2727. jwt:
  2728. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  2729. properties:
  2730. serviceAccountRef:
  2731. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  2732. properties:
  2733. audiences:
  2734. description: |-
  2735. Audience specifies the `aud` claim for the service account token
  2736. Some providers automatically extend the audience field based on well-known annotations for workload
  2737. identity (e.g. IRSA or GCP Workload Identity)
  2738. items:
  2739. type: string
  2740. type: array
  2741. name:
  2742. description: The name of the ServiceAccount resource being referred to.
  2743. maxLength: 253
  2744. minLength: 1
  2745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2746. type: string
  2747. namespace:
  2748. description: |-
  2749. Namespace of the resource being referred to.
  2750. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2751. maxLength: 63
  2752. minLength: 1
  2753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2754. type: string
  2755. required:
  2756. - name
  2757. type: object
  2758. type: object
  2759. secretRef:
  2760. description: |-
  2761. AWSAuthSecretRef holds secret references for AWS credentials
  2762. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  2763. properties:
  2764. accessKeyIDSecretRef:
  2765. description: The AccessKeyID is used for authentication
  2766. properties:
  2767. key:
  2768. description: |-
  2769. A key in the referenced Secret.
  2770. Some instances of this field may be defaulted, in others it may be required.
  2771. maxLength: 253
  2772. minLength: 1
  2773. pattern: ^[-._a-zA-Z0-9]+$
  2774. type: string
  2775. name:
  2776. description: The name of the Secret resource being referred to.
  2777. maxLength: 253
  2778. minLength: 1
  2779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2780. type: string
  2781. namespace:
  2782. description: |-
  2783. The namespace of the Secret resource being referred to.
  2784. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2785. maxLength: 63
  2786. minLength: 1
  2787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2788. type: string
  2789. type: object
  2790. secretAccessKeySecretRef:
  2791. description: The SecretAccessKey is used for authentication
  2792. properties:
  2793. key:
  2794. description: |-
  2795. A key in the referenced Secret.
  2796. Some instances of this field may be defaulted, in others it may be required.
  2797. maxLength: 253
  2798. minLength: 1
  2799. pattern: ^[-._a-zA-Z0-9]+$
  2800. type: string
  2801. name:
  2802. description: The name of the Secret resource being referred to.
  2803. maxLength: 253
  2804. minLength: 1
  2805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2806. type: string
  2807. namespace:
  2808. description: |-
  2809. The namespace of the Secret resource being referred to.
  2810. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2811. maxLength: 63
  2812. minLength: 1
  2813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2814. type: string
  2815. type: object
  2816. sessionTokenSecretRef:
  2817. description: |-
  2818. The SessionToken used for authentication
  2819. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  2820. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  2821. properties:
  2822. key:
  2823. description: |-
  2824. A key in the referenced Secret.
  2825. Some instances of this field may be defaulted, in others it may be required.
  2826. maxLength: 253
  2827. minLength: 1
  2828. pattern: ^[-._a-zA-Z0-9]+$
  2829. type: string
  2830. name:
  2831. description: The name of the Secret resource being referred to.
  2832. maxLength: 253
  2833. minLength: 1
  2834. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2835. type: string
  2836. namespace:
  2837. description: |-
  2838. The namespace of the Secret resource being referred to.
  2839. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2840. maxLength: 63
  2841. minLength: 1
  2842. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2843. type: string
  2844. type: object
  2845. type: object
  2846. type: object
  2847. customSessionTags:
  2848. additionalProperties:
  2849. type: string
  2850. description: |-
  2851. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  2852. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  2853. type: object
  2854. x-kubernetes-validations:
  2855. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  2856. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  2857. externalID:
  2858. description: AWS External ID set on assumed IAM roles
  2859. type: string
  2860. prefix:
  2861. description: Prefix adds a prefix to all retrieved values.
  2862. type: string
  2863. region:
  2864. description: AWS Region to be used for the provider
  2865. type: string
  2866. role:
  2867. description: Role is a Role ARN which the provider will assume
  2868. type: string
  2869. secretsManager:
  2870. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  2871. properties:
  2872. forceDeleteWithoutRecovery:
  2873. description: |-
  2874. Specifies whether to delete the secret without any recovery window. You
  2875. can't use both this parameter and RecoveryWindowInDays in the same call.
  2876. If you don't use either, then by default Secrets Manager uses a 30 day
  2877. recovery window.
  2878. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  2879. type: boolean
  2880. recoveryWindowInDays:
  2881. description: |-
  2882. The number of days from 7 to 30 that Secrets Manager waits before
  2883. permanently deleting the secret. You can't use both this parameter and
  2884. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  2885. then by default Secrets Manager uses a 30-day recovery window.
  2886. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  2887. format: int64
  2888. type: integer
  2889. type: object
  2890. service:
  2891. description: Service defines which service should be used to fetch the secrets
  2892. enum:
  2893. - SecretsManager
  2894. - ParameterStore
  2895. - CertificateManager
  2896. type: string
  2897. sessionTags:
  2898. description: AWS STS assume role session tags
  2899. items:
  2900. description: |-
  2901. Tag is a key-value pair that can be attached to an AWS resource.
  2902. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  2903. properties:
  2904. key:
  2905. type: string
  2906. value:
  2907. type: string
  2908. required:
  2909. - key
  2910. - value
  2911. type: object
  2912. type: array
  2913. sessionTagsPolicy:
  2914. default: None
  2915. description: |-
  2916. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  2917. None (default): no tags are added.
  2918. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  2919. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  2920. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  2921. enum:
  2922. - None
  2923. - Simple
  2924. - Custom
  2925. type: string
  2926. transitiveTagKeys:
  2927. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  2928. items:
  2929. type: string
  2930. type: array
  2931. required:
  2932. - region
  2933. - service
  2934. type: object
  2935. azurekv:
  2936. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  2937. properties:
  2938. authSecretRef:
  2939. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  2940. properties:
  2941. clientCertificate:
  2942. description: The Azure ClientCertificate of the service principle used for authentication.
  2943. properties:
  2944. key:
  2945. description: |-
  2946. A key in the referenced Secret.
  2947. Some instances of this field may be defaulted, in others it may be required.
  2948. maxLength: 253
  2949. minLength: 1
  2950. pattern: ^[-._a-zA-Z0-9]+$
  2951. type: string
  2952. name:
  2953. description: The name of the Secret resource being referred to.
  2954. maxLength: 253
  2955. minLength: 1
  2956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2957. type: string
  2958. namespace:
  2959. description: |-
  2960. The namespace of the Secret resource being referred to.
  2961. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2962. maxLength: 63
  2963. minLength: 1
  2964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2965. type: string
  2966. type: object
  2967. clientId:
  2968. description: The Azure clientId of the service principle or managed identity used for authentication.
  2969. properties:
  2970. key:
  2971. description: |-
  2972. A key in the referenced Secret.
  2973. Some instances of this field may be defaulted, in others it may be required.
  2974. maxLength: 253
  2975. minLength: 1
  2976. pattern: ^[-._a-zA-Z0-9]+$
  2977. type: string
  2978. name:
  2979. description: The name of the Secret resource being referred to.
  2980. maxLength: 253
  2981. minLength: 1
  2982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2983. type: string
  2984. namespace:
  2985. description: |-
  2986. The namespace of the Secret resource being referred to.
  2987. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2988. maxLength: 63
  2989. minLength: 1
  2990. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2991. type: string
  2992. type: object
  2993. clientSecret:
  2994. description: The Azure ClientSecret of the service principle used for authentication.
  2995. properties:
  2996. key:
  2997. description: |-
  2998. A key in the referenced Secret.
  2999. Some instances of this field may be defaulted, in others it may be required.
  3000. maxLength: 253
  3001. minLength: 1
  3002. pattern: ^[-._a-zA-Z0-9]+$
  3003. type: string
  3004. name:
  3005. description: The name of the Secret resource being referred to.
  3006. maxLength: 253
  3007. minLength: 1
  3008. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3009. type: string
  3010. namespace:
  3011. description: |-
  3012. The namespace of the Secret resource being referred to.
  3013. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3014. maxLength: 63
  3015. minLength: 1
  3016. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3017. type: string
  3018. type: object
  3019. tenantId:
  3020. description: The Azure tenantId of the managed identity used for authentication.
  3021. properties:
  3022. key:
  3023. description: |-
  3024. A key in the referenced Secret.
  3025. Some instances of this field may be defaulted, in others it may be required.
  3026. maxLength: 253
  3027. minLength: 1
  3028. pattern: ^[-._a-zA-Z0-9]+$
  3029. type: string
  3030. name:
  3031. description: The name of the Secret resource being referred to.
  3032. maxLength: 253
  3033. minLength: 1
  3034. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3035. type: string
  3036. namespace:
  3037. description: |-
  3038. The namespace of the Secret resource being referred to.
  3039. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3040. maxLength: 63
  3041. minLength: 1
  3042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3043. type: string
  3044. type: object
  3045. type: object
  3046. authType:
  3047. default: ServicePrincipal
  3048. description: |-
  3049. Auth type defines how to authenticate to the keyvault service.
  3050. Valid values are:
  3051. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  3052. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  3053. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  3054. enum:
  3055. - ServicePrincipal
  3056. - ManagedIdentity
  3057. - WorkloadIdentity
  3058. type: string
  3059. customCloudConfig:
  3060. description: |-
  3061. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  3062. Required when EnvironmentType is AzureStackCloud.
  3063. Optional for other environment types - useful for Azure China when using Workload Identity
  3064. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  3065. standard China Cloud endpoint (login.chinacloudapi.cn).
  3066. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  3067. configuration is not supported with the legacy go-autorest SDK.
  3068. properties:
  3069. activeDirectoryEndpoint:
  3070. description: |-
  3071. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  3072. Required when using custom cloud configuration
  3073. type: string
  3074. keyVaultDNSSuffix:
  3075. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  3076. type: string
  3077. keyVaultEndpoint:
  3078. description: KeyVaultEndpoint is the Key Vault service endpoint
  3079. type: string
  3080. resourceManagerEndpoint:
  3081. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  3082. type: string
  3083. required:
  3084. - activeDirectoryEndpoint
  3085. type: object
  3086. environmentType:
  3087. default: PublicCloud
  3088. description: |-
  3089. EnvironmentType specifies the Azure cloud environment endpoints to use for
  3090. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  3091. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  3092. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  3093. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  3094. enum:
  3095. - PublicCloud
  3096. - USGovernmentCloud
  3097. - ChinaCloud
  3098. - GermanCloud
  3099. - AzureStackCloud
  3100. type: string
  3101. identityId:
  3102. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  3103. type: string
  3104. serviceAccountRef:
  3105. description: |-
  3106. ServiceAccountRef specified the service account
  3107. that should be used when authenticating with WorkloadIdentity.
  3108. properties:
  3109. audiences:
  3110. description: |-
  3111. Audience specifies the `aud` claim for the service account token
  3112. Some providers automatically extend the audience field based on well-known annotations for workload
  3113. identity (e.g. IRSA or GCP Workload Identity)
  3114. items:
  3115. type: string
  3116. type: array
  3117. name:
  3118. description: The name of the ServiceAccount resource being referred to.
  3119. maxLength: 253
  3120. minLength: 1
  3121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3122. type: string
  3123. namespace:
  3124. description: |-
  3125. Namespace of the resource being referred to.
  3126. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3127. maxLength: 63
  3128. minLength: 1
  3129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3130. type: string
  3131. required:
  3132. - name
  3133. type: object
  3134. tenantId:
  3135. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  3136. type: string
  3137. useAzureSDK:
  3138. default: false
  3139. description: |-
  3140. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  3141. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  3142. type: boolean
  3143. vaultUrl:
  3144. description: Vault Url from which the secrets to be fetched from.
  3145. type: string
  3146. required:
  3147. - vaultUrl
  3148. type: object
  3149. barbican:
  3150. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  3151. properties:
  3152. auth:
  3153. description: BarbicanAuth contains the authentication information for Barbican.
  3154. properties:
  3155. applicationCredentialID:
  3156. description: ID of the application credential used for authentication.
  3157. maxProperties: 1
  3158. minProperties: 1
  3159. properties:
  3160. secretRef:
  3161. description: |-
  3162. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3163. In some instances, `key` is a required field.
  3164. properties:
  3165. key:
  3166. description: |-
  3167. A key in the referenced Secret.
  3168. Some instances of this field may be defaulted, in others it may be required.
  3169. maxLength: 253
  3170. minLength: 1
  3171. pattern: ^[-._a-zA-Z0-9]+$
  3172. type: string
  3173. name:
  3174. description: The name of the Secret resource being referred to.
  3175. maxLength: 253
  3176. minLength: 1
  3177. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3178. type: string
  3179. namespace:
  3180. description: |-
  3181. The namespace of the Secret resource being referred to.
  3182. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3183. maxLength: 63
  3184. minLength: 1
  3185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3186. type: string
  3187. type: object
  3188. value:
  3189. minLength: 1
  3190. type: string
  3191. type: object
  3192. applicationCredentialSecret:
  3193. description: BarbicanProviderAppCredSecretRef defines a reference to an Application Credential Secret.
  3194. properties:
  3195. secretRef:
  3196. description: |-
  3197. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3198. In some instances, `key` is a required field.
  3199. properties:
  3200. key:
  3201. description: |-
  3202. A key in the referenced Secret.
  3203. Some instances of this field may be defaulted, in others it may be required.
  3204. maxLength: 253
  3205. minLength: 1
  3206. pattern: ^[-._a-zA-Z0-9]+$
  3207. type: string
  3208. name:
  3209. description: The name of the Secret resource being referred to.
  3210. maxLength: 253
  3211. minLength: 1
  3212. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3213. type: string
  3214. namespace:
  3215. description: |-
  3216. The namespace of the Secret resource being referred to.
  3217. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3218. maxLength: 63
  3219. minLength: 1
  3220. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3221. type: string
  3222. type: object
  3223. required:
  3224. - secretRef
  3225. type: object
  3226. authType:
  3227. default: password
  3228. description: |-
  3229. AuthType selects how Barbican authenticates.
  3230. - "password": use username and password.
  3231. - "applicationCredential": use application credential ID and secret.
  3232. Defaults to "password".
  3233. enum:
  3234. - password
  3235. - applicationCredential
  3236. type: string
  3237. password:
  3238. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  3239. properties:
  3240. secretRef:
  3241. description: |-
  3242. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3243. In some instances, `key` is a required field.
  3244. properties:
  3245. key:
  3246. description: |-
  3247. A key in the referenced Secret.
  3248. Some instances of this field may be defaulted, in others it may be required.
  3249. maxLength: 253
  3250. minLength: 1
  3251. pattern: ^[-._a-zA-Z0-9]+$
  3252. type: string
  3253. name:
  3254. description: The name of the Secret resource being referred to.
  3255. maxLength: 253
  3256. minLength: 1
  3257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3258. type: string
  3259. namespace:
  3260. description: |-
  3261. The namespace of the Secret resource being referred to.
  3262. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3263. maxLength: 63
  3264. minLength: 1
  3265. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3266. type: string
  3267. type: object
  3268. required:
  3269. - secretRef
  3270. type: object
  3271. username:
  3272. description: Username / Password authentication fields.
  3273. maxProperties: 1
  3274. minProperties: 1
  3275. properties:
  3276. secretRef:
  3277. description: |-
  3278. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3279. In some instances, `key` is a required field.
  3280. properties:
  3281. key:
  3282. description: |-
  3283. A key in the referenced Secret.
  3284. Some instances of this field may be defaulted, in others it may be required.
  3285. maxLength: 253
  3286. minLength: 1
  3287. pattern: ^[-._a-zA-Z0-9]+$
  3288. type: string
  3289. name:
  3290. description: The name of the Secret resource being referred to.
  3291. maxLength: 253
  3292. minLength: 1
  3293. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3294. type: string
  3295. namespace:
  3296. description: |-
  3297. The namespace of the Secret resource being referred to.
  3298. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3299. maxLength: 63
  3300. minLength: 1
  3301. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3302. type: string
  3303. type: object
  3304. value:
  3305. minLength: 1
  3306. type: string
  3307. type: object
  3308. type: object
  3309. x-kubernetes-validations:
  3310. - message: password auth requires both username and password
  3311. rule: (has(self.authType) && self.authType == 'applicationCredential') || (has(self.username) && has(self.password))
  3312. - message: applicationCredential auth requires both applicationCredentialID and applicationCredentialSecret
  3313. rule: self.authType != 'applicationCredential' || (has(self.applicationCredentialID) && has(self.applicationCredentialSecret))
  3314. - message: password auth should not include applicationCredential fields
  3315. rule: (has(self.authType) && self.authType == 'applicationCredential') || (!has(self.applicationCredentialID) && !has(self.applicationCredentialSecret))
  3316. - message: applicationCredential auth should not include password fields
  3317. rule: self.authType != 'applicationCredential' || (!has(self.username) && !has(self.password))
  3318. authURL:
  3319. type: string
  3320. domainName:
  3321. type: string
  3322. region:
  3323. type: string
  3324. tenantName:
  3325. type: string
  3326. required:
  3327. - auth
  3328. type: object
  3329. beyondtrust:
  3330. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  3331. properties:
  3332. auth:
  3333. description: Auth configures how the operator authenticates with Beyondtrust.
  3334. properties:
  3335. apiKey:
  3336. description: APIKey If not provided then ClientID/ClientSecret become required.
  3337. properties:
  3338. secretRef:
  3339. description: SecretRef references a key in a secret that will be used as value.
  3340. properties:
  3341. key:
  3342. description: |-
  3343. A key in the referenced Secret.
  3344. Some instances of this field may be defaulted, in others it may be required.
  3345. maxLength: 253
  3346. minLength: 1
  3347. pattern: ^[-._a-zA-Z0-9]+$
  3348. type: string
  3349. name:
  3350. description: The name of the Secret resource being referred to.
  3351. maxLength: 253
  3352. minLength: 1
  3353. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3354. type: string
  3355. namespace:
  3356. description: |-
  3357. The namespace of the Secret resource being referred to.
  3358. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3359. maxLength: 63
  3360. minLength: 1
  3361. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3362. type: string
  3363. type: object
  3364. value:
  3365. description: Value can be specified directly to set a value without using a secret.
  3366. type: string
  3367. type: object
  3368. certificate:
  3369. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  3370. properties:
  3371. secretRef:
  3372. description: SecretRef references a key in a secret that will be used as value.
  3373. properties:
  3374. key:
  3375. description: |-
  3376. A key in the referenced Secret.
  3377. Some instances of this field may be defaulted, in others it may be required.
  3378. maxLength: 253
  3379. minLength: 1
  3380. pattern: ^[-._a-zA-Z0-9]+$
  3381. type: string
  3382. name:
  3383. description: The name of the Secret resource being referred to.
  3384. maxLength: 253
  3385. minLength: 1
  3386. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3387. type: string
  3388. namespace:
  3389. description: |-
  3390. The namespace of the Secret resource being referred to.
  3391. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3392. maxLength: 63
  3393. minLength: 1
  3394. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3395. type: string
  3396. type: object
  3397. value:
  3398. description: Value can be specified directly to set a value without using a secret.
  3399. type: string
  3400. type: object
  3401. certificateKey:
  3402. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  3403. properties:
  3404. secretRef:
  3405. description: SecretRef references a key in a secret that will be used as value.
  3406. properties:
  3407. key:
  3408. description: |-
  3409. A key in the referenced Secret.
  3410. Some instances of this field may be defaulted, in others it may be required.
  3411. maxLength: 253
  3412. minLength: 1
  3413. pattern: ^[-._a-zA-Z0-9]+$
  3414. type: string
  3415. name:
  3416. description: The name of the Secret resource being referred to.
  3417. maxLength: 253
  3418. minLength: 1
  3419. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3420. type: string
  3421. namespace:
  3422. description: |-
  3423. The namespace of the Secret resource being referred to.
  3424. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3425. maxLength: 63
  3426. minLength: 1
  3427. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3428. type: string
  3429. type: object
  3430. value:
  3431. description: Value can be specified directly to set a value without using a secret.
  3432. type: string
  3433. type: object
  3434. clientId:
  3435. description: ClientID is the API OAuth Client ID.
  3436. properties:
  3437. secretRef:
  3438. description: SecretRef references a key in a secret that will be used as value.
  3439. properties:
  3440. key:
  3441. description: |-
  3442. A key in the referenced Secret.
  3443. Some instances of this field may be defaulted, in others it may be required.
  3444. maxLength: 253
  3445. minLength: 1
  3446. pattern: ^[-._a-zA-Z0-9]+$
  3447. type: string
  3448. name:
  3449. description: The name of the Secret resource being referred to.
  3450. maxLength: 253
  3451. minLength: 1
  3452. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3453. type: string
  3454. namespace:
  3455. description: |-
  3456. The namespace of the Secret resource being referred to.
  3457. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3458. maxLength: 63
  3459. minLength: 1
  3460. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3461. type: string
  3462. type: object
  3463. value:
  3464. description: Value can be specified directly to set a value without using a secret.
  3465. type: string
  3466. type: object
  3467. clientSecret:
  3468. description: ClientSecret is the API OAuth Client Secret.
  3469. properties:
  3470. secretRef:
  3471. description: SecretRef references a key in a secret that will be used as value.
  3472. properties:
  3473. key:
  3474. description: |-
  3475. A key in the referenced Secret.
  3476. Some instances of this field may be defaulted, in others it may be required.
  3477. maxLength: 253
  3478. minLength: 1
  3479. pattern: ^[-._a-zA-Z0-9]+$
  3480. type: string
  3481. name:
  3482. description: The name of the Secret resource being referred to.
  3483. maxLength: 253
  3484. minLength: 1
  3485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3486. type: string
  3487. namespace:
  3488. description: |-
  3489. The namespace of the Secret resource being referred to.
  3490. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3491. maxLength: 63
  3492. minLength: 1
  3493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3494. type: string
  3495. type: object
  3496. value:
  3497. description: Value can be specified directly to set a value without using a secret.
  3498. type: string
  3499. type: object
  3500. type: object
  3501. server:
  3502. description: Auth configures how API server works.
  3503. properties:
  3504. apiUrl:
  3505. type: string
  3506. apiVersion:
  3507. type: string
  3508. clientTimeOutSeconds:
  3509. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  3510. type: integer
  3511. decrypt:
  3512. default: true
  3513. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  3514. type: boolean
  3515. retrievalType:
  3516. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  3517. type: string
  3518. separator:
  3519. description: A character that separates the folder names.
  3520. type: string
  3521. verifyCA:
  3522. type: boolean
  3523. required:
  3524. - apiUrl
  3525. - verifyCA
  3526. type: object
  3527. required:
  3528. - auth
  3529. - server
  3530. type: object
  3531. beyondtrustworkloadcredentials:
  3532. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  3533. properties:
  3534. auth:
  3535. description: |-
  3536. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  3537. Currently supports API key authentication via Kubernetes secret reference.
  3538. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3539. properties:
  3540. apikey:
  3541. description: |-
  3542. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  3543. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  3544. properties:
  3545. token:
  3546. description: |-
  3547. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  3548. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  3549. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  3550. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3551. properties:
  3552. key:
  3553. description: |-
  3554. A key in the referenced Secret.
  3555. Some instances of this field may be defaulted, in others it may be required.
  3556. maxLength: 253
  3557. minLength: 1
  3558. pattern: ^[-._a-zA-Z0-9]+$
  3559. type: string
  3560. name:
  3561. description: The name of the Secret resource being referred to.
  3562. maxLength: 253
  3563. minLength: 1
  3564. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3565. type: string
  3566. namespace:
  3567. description: |-
  3568. The namespace of the Secret resource being referred to.
  3569. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3570. maxLength: 63
  3571. minLength: 1
  3572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3573. type: string
  3574. type: object
  3575. required:
  3576. - token
  3577. type: object
  3578. required:
  3579. - apikey
  3580. type: object
  3581. caBundle:
  3582. description: |-
  3583. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3584. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  3585. If not set, the system's trusted root certificates are used.
  3586. format: byte
  3587. type: string
  3588. caProvider:
  3589. description: |-
  3590. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  3591. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3592. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  3593. properties:
  3594. key:
  3595. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3596. maxLength: 253
  3597. minLength: 1
  3598. pattern: ^[-._a-zA-Z0-9]+$
  3599. type: string
  3600. name:
  3601. description: The name of the object located at the provider type.
  3602. maxLength: 253
  3603. minLength: 1
  3604. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3605. type: string
  3606. namespace:
  3607. description: |-
  3608. The namespace the Provider type is in.
  3609. Can only be defined when used in a ClusterSecretStore.
  3610. maxLength: 63
  3611. minLength: 1
  3612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3613. type: string
  3614. type:
  3615. description: The type of provider to use such as "Secret", or "ConfigMap".
  3616. enum:
  3617. - Secret
  3618. - ConfigMap
  3619. type: string
  3620. required:
  3621. - name
  3622. - type
  3623. type: object
  3624. folderPath:
  3625. description: |-
  3626. FolderPath specifies the default folder path for secret retrieval.
  3627. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  3628. Example: "production/database" or "dev/api-keys"
  3629. Leave empty to retrieve secrets from the root folder.
  3630. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  3631. type: string
  3632. server:
  3633. description: |-
  3634. Server configures the BeyondTrust Workload Credentials server connection details.
  3635. Includes the API URL and Site ID for your BeyondTrust instance.
  3636. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3637. properties:
  3638. apiUrl:
  3639. description: |-
  3640. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  3641. This should be the full URL to your BeyondTrust instance.
  3642. Example: https://api.beyondtrust.io/siie
  3643. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  3644. type: string
  3645. siteId:
  3646. description: |-
  3647. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  3648. This identifier is unique to your BeyondTrust Workload Credentials instance.
  3649. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  3650. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  3651. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3652. type: string
  3653. required:
  3654. - apiUrl
  3655. - siteId
  3656. type: object
  3657. required:
  3658. - auth
  3659. - server
  3660. type: object
  3661. bitwardensecretsmanager:
  3662. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  3663. properties:
  3664. apiURL:
  3665. type: string
  3666. auth:
  3667. description: |-
  3668. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  3669. Make sure that the token being used has permissions on the given secret.
  3670. properties:
  3671. secretRef:
  3672. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  3673. properties:
  3674. credentials:
  3675. description: AccessToken used for the bitwarden instance.
  3676. properties:
  3677. key:
  3678. description: |-
  3679. A key in the referenced Secret.
  3680. Some instances of this field may be defaulted, in others it may be required.
  3681. maxLength: 253
  3682. minLength: 1
  3683. pattern: ^[-._a-zA-Z0-9]+$
  3684. type: string
  3685. name:
  3686. description: The name of the Secret resource being referred to.
  3687. maxLength: 253
  3688. minLength: 1
  3689. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3690. type: string
  3691. namespace:
  3692. description: |-
  3693. The namespace of the Secret resource being referred to.
  3694. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3695. maxLength: 63
  3696. minLength: 1
  3697. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3698. type: string
  3699. type: object
  3700. required:
  3701. - credentials
  3702. type: object
  3703. required:
  3704. - secretRef
  3705. type: object
  3706. bitwardenServerSDKURL:
  3707. type: string
  3708. caBundle:
  3709. description: |-
  3710. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  3711. can be performed.
  3712. type: string
  3713. caProvider:
  3714. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  3715. properties:
  3716. key:
  3717. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3718. maxLength: 253
  3719. minLength: 1
  3720. pattern: ^[-._a-zA-Z0-9]+$
  3721. type: string
  3722. name:
  3723. description: The name of the object located at the provider type.
  3724. maxLength: 253
  3725. minLength: 1
  3726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3727. type: string
  3728. namespace:
  3729. description: |-
  3730. The namespace the Provider type is in.
  3731. Can only be defined when used in a ClusterSecretStore.
  3732. maxLength: 63
  3733. minLength: 1
  3734. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3735. type: string
  3736. type:
  3737. description: The type of provider to use such as "Secret", or "ConfigMap".
  3738. enum:
  3739. - Secret
  3740. - ConfigMap
  3741. type: string
  3742. required:
  3743. - name
  3744. - type
  3745. type: object
  3746. identityURL:
  3747. type: string
  3748. organizationID:
  3749. description: OrganizationID determines which organization this secret store manages.
  3750. type: string
  3751. projectID:
  3752. description: ProjectID determines which project this secret store manages.
  3753. type: string
  3754. required:
  3755. - auth
  3756. - organizationID
  3757. - projectID
  3758. type: object
  3759. chef:
  3760. description: Chef configures this store to sync secrets with chef server
  3761. properties:
  3762. auth:
  3763. description: Auth defines the information necessary to authenticate against chef Server
  3764. properties:
  3765. secretRef:
  3766. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  3767. properties:
  3768. privateKeySecretRef:
  3769. description: SecretKey is the Signing Key in PEM format, used for authentication.
  3770. properties:
  3771. key:
  3772. description: |-
  3773. A key in the referenced Secret.
  3774. Some instances of this field may be defaulted, in others it may be required.
  3775. maxLength: 253
  3776. minLength: 1
  3777. pattern: ^[-._a-zA-Z0-9]+$
  3778. type: string
  3779. name:
  3780. description: The name of the Secret resource being referred to.
  3781. maxLength: 253
  3782. minLength: 1
  3783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3784. type: string
  3785. namespace:
  3786. description: |-
  3787. The namespace of the Secret resource being referred to.
  3788. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3789. maxLength: 63
  3790. minLength: 1
  3791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3792. type: string
  3793. type: object
  3794. required:
  3795. - privateKeySecretRef
  3796. type: object
  3797. required:
  3798. - secretRef
  3799. type: object
  3800. serverUrl:
  3801. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  3802. type: string
  3803. username:
  3804. description: UserName should be the user ID on the chef server
  3805. type: string
  3806. required:
  3807. - auth
  3808. - serverUrl
  3809. - username
  3810. type: object
  3811. cloudrusm:
  3812. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  3813. properties:
  3814. auth:
  3815. description: CSMAuth contains a secretRef for credentials.
  3816. properties:
  3817. secretRef:
  3818. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  3819. properties:
  3820. accessKeyIDSecretRef:
  3821. description: The AccessKeyID is used for authentication
  3822. properties:
  3823. key:
  3824. description: |-
  3825. A key in the referenced Secret.
  3826. Some instances of this field may be defaulted, in others it may be required.
  3827. maxLength: 253
  3828. minLength: 1
  3829. pattern: ^[-._a-zA-Z0-9]+$
  3830. type: string
  3831. name:
  3832. description: The name of the Secret resource being referred to.
  3833. maxLength: 253
  3834. minLength: 1
  3835. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3836. type: string
  3837. namespace:
  3838. description: |-
  3839. The namespace of the Secret resource being referred to.
  3840. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3841. maxLength: 63
  3842. minLength: 1
  3843. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3844. type: string
  3845. type: object
  3846. accessKeySecretSecretRef:
  3847. description: The AccessKeySecret is used for authentication
  3848. properties:
  3849. key:
  3850. description: |-
  3851. A key in the referenced Secret.
  3852. Some instances of this field may be defaulted, in others it may be required.
  3853. maxLength: 253
  3854. minLength: 1
  3855. pattern: ^[-._a-zA-Z0-9]+$
  3856. type: string
  3857. name:
  3858. description: The name of the Secret resource being referred to.
  3859. maxLength: 253
  3860. minLength: 1
  3861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3862. type: string
  3863. namespace:
  3864. description: |-
  3865. The namespace of the Secret resource being referred to.
  3866. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3867. maxLength: 63
  3868. minLength: 1
  3869. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3870. type: string
  3871. type: object
  3872. required:
  3873. - accessKeyIDSecretRef
  3874. - accessKeySecretSecretRef
  3875. type: object
  3876. type: object
  3877. projectID:
  3878. description: ProjectID is the project, which the secrets are stored in.
  3879. type: string
  3880. required:
  3881. - auth
  3882. type: object
  3883. conjur:
  3884. description: Conjur configures this store to sync secrets using conjur provider
  3885. properties:
  3886. auth:
  3887. description: Defines authentication settings for connecting to Conjur.
  3888. maxProperties: 1
  3889. minProperties: 1
  3890. properties:
  3891. apikey:
  3892. description: Authenticates with Conjur using an API key.
  3893. properties:
  3894. account:
  3895. description: Account is the Conjur organization account name.
  3896. type: string
  3897. apiKeyRef:
  3898. description: |-
  3899. A reference to a specific 'key' containing the Conjur API key
  3900. within a Secret resource. In some instances, `key` is a required field.
  3901. properties:
  3902. key:
  3903. description: |-
  3904. A key in the referenced Secret.
  3905. Some instances of this field may be defaulted, in others it may be required.
  3906. maxLength: 253
  3907. minLength: 1
  3908. pattern: ^[-._a-zA-Z0-9]+$
  3909. type: string
  3910. name:
  3911. description: The name of the Secret resource being referred to.
  3912. maxLength: 253
  3913. minLength: 1
  3914. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3915. type: string
  3916. namespace:
  3917. description: |-
  3918. The namespace of the Secret resource being referred to.
  3919. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3920. maxLength: 63
  3921. minLength: 1
  3922. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3923. type: string
  3924. type: object
  3925. userRef:
  3926. description: |-
  3927. A reference to a specific 'key' containing the Conjur username
  3928. within a Secret resource. In some instances, `key` is a required field.
  3929. properties:
  3930. key:
  3931. description: |-
  3932. A key in the referenced Secret.
  3933. Some instances of this field may be defaulted, in others it may be required.
  3934. maxLength: 253
  3935. minLength: 1
  3936. pattern: ^[-._a-zA-Z0-9]+$
  3937. type: string
  3938. name:
  3939. description: The name of the Secret resource being referred to.
  3940. maxLength: 253
  3941. minLength: 1
  3942. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3943. type: string
  3944. namespace:
  3945. description: |-
  3946. The namespace of the Secret resource being referred to.
  3947. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3948. maxLength: 63
  3949. minLength: 1
  3950. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3951. type: string
  3952. type: object
  3953. required:
  3954. - account
  3955. - apiKeyRef
  3956. - userRef
  3957. type: object
  3958. cert:
  3959. description: Cert enables certificate-based authentication using a client certificate and key.
  3960. properties:
  3961. account:
  3962. description: Account is the Conjur organization account name.
  3963. type: string
  3964. clientCertRef:
  3965. description: |-
  3966. ClientCertRef is a reference to a specific 'key' containing the client certificate
  3967. within a Secret resource. The certificate must be PEM-encoded.
  3968. properties:
  3969. key:
  3970. description: |-
  3971. A key in the referenced Secret.
  3972. Some instances of this field may be defaulted, in others it may be required.
  3973. maxLength: 253
  3974. minLength: 1
  3975. pattern: ^[-._a-zA-Z0-9]+$
  3976. type: string
  3977. name:
  3978. description: The name of the Secret resource being referred to.
  3979. maxLength: 253
  3980. minLength: 1
  3981. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3982. type: string
  3983. namespace:
  3984. description: |-
  3985. The namespace of the Secret resource being referred to.
  3986. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3987. maxLength: 63
  3988. minLength: 1
  3989. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3990. type: string
  3991. type: object
  3992. clientKeyRef:
  3993. description: |-
  3994. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  3995. within a Secret resource. The key must be PEM-encoded.
  3996. properties:
  3997. key:
  3998. description: |-
  3999. A key in the referenced Secret.
  4000. Some instances of this field may be defaulted, in others it may be required.
  4001. maxLength: 253
  4002. minLength: 1
  4003. pattern: ^[-._a-zA-Z0-9]+$
  4004. type: string
  4005. name:
  4006. description: The name of the Secret resource being referred to.
  4007. maxLength: 253
  4008. minLength: 1
  4009. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4010. type: string
  4011. namespace:
  4012. description: |-
  4013. The namespace of the Secret resource being referred to.
  4014. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4015. maxLength: 63
  4016. minLength: 1
  4017. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4018. type: string
  4019. type: object
  4020. hostId:
  4021. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  4022. type: string
  4023. serviceID:
  4024. description: The conjur authn cert webservice id
  4025. type: string
  4026. required:
  4027. - account
  4028. - clientCertRef
  4029. - clientKeyRef
  4030. - serviceID
  4031. type: object
  4032. jwt:
  4033. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  4034. properties:
  4035. account:
  4036. description: Account is the Conjur organization account name.
  4037. type: string
  4038. hostId:
  4039. description: |-
  4040. Optional HostID for JWT authentication. This may be used depending
  4041. on how the Conjur JWT authenticator policy is configured.
  4042. type: string
  4043. secretRef:
  4044. description: |-
  4045. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  4046. authenticate with Conjur using the JWT authentication method.
  4047. properties:
  4048. key:
  4049. description: |-
  4050. A key in the referenced Secret.
  4051. Some instances of this field may be defaulted, in others it may be required.
  4052. maxLength: 253
  4053. minLength: 1
  4054. pattern: ^[-._a-zA-Z0-9]+$
  4055. type: string
  4056. name:
  4057. description: The name of the Secret resource being referred to.
  4058. maxLength: 253
  4059. minLength: 1
  4060. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4061. type: string
  4062. namespace:
  4063. description: |-
  4064. The namespace of the Secret resource being referred to.
  4065. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4066. maxLength: 63
  4067. minLength: 1
  4068. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4069. type: string
  4070. type: object
  4071. serviceAccountRef:
  4072. description: |-
  4073. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  4074. a token for with the `TokenRequest` API.
  4075. properties:
  4076. audiences:
  4077. description: |-
  4078. Audience specifies the `aud` claim for the service account token
  4079. Some providers automatically extend the audience field based on well-known annotations for workload
  4080. identity (e.g. IRSA or GCP Workload Identity)
  4081. items:
  4082. type: string
  4083. type: array
  4084. name:
  4085. description: The name of the ServiceAccount resource being referred to.
  4086. maxLength: 253
  4087. minLength: 1
  4088. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4089. type: string
  4090. namespace:
  4091. description: |-
  4092. Namespace of the resource being referred to.
  4093. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4094. maxLength: 63
  4095. minLength: 1
  4096. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4097. type: string
  4098. required:
  4099. - name
  4100. type: object
  4101. serviceID:
  4102. description: The conjur authn jwt webservice id
  4103. type: string
  4104. required:
  4105. - account
  4106. - serviceID
  4107. type: object
  4108. type: object
  4109. caBundle:
  4110. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  4111. type: string
  4112. caProvider:
  4113. description: |-
  4114. Used to provide custom certificate authority (CA) certificates
  4115. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  4116. that contains a PEM-encoded certificate.
  4117. properties:
  4118. key:
  4119. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4120. maxLength: 253
  4121. minLength: 1
  4122. pattern: ^[-._a-zA-Z0-9]+$
  4123. type: string
  4124. name:
  4125. description: The name of the object located at the provider type.
  4126. maxLength: 253
  4127. minLength: 1
  4128. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4129. type: string
  4130. namespace:
  4131. description: |-
  4132. The namespace the Provider type is in.
  4133. Can only be defined when used in a ClusterSecretStore.
  4134. maxLength: 63
  4135. minLength: 1
  4136. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4137. type: string
  4138. type:
  4139. description: The type of provider to use such as "Secret", or "ConfigMap".
  4140. enum:
  4141. - Secret
  4142. - ConfigMap
  4143. type: string
  4144. required:
  4145. - name
  4146. - type
  4147. type: object
  4148. url:
  4149. description: URL is the endpoint of the Conjur instance.
  4150. type: string
  4151. required:
  4152. - auth
  4153. - url
  4154. type: object
  4155. crd:
  4156. description: |-
  4157. CRD configures this store to sync secrets from arbitrary Kubernetes resources,
  4158. including both custom resources (CRDs) and core API resources. Resources are
  4159. selected by API group, version and kind, where group can be "" (empty string)
  4160. for core resources such as ConfigMap. Reading the core v1 Secret is
  4161. intentionally blocked — use the Kubernetes provider for that.
  4162. properties:
  4163. auth:
  4164. description: |-
  4165. Auth configures authentication to the Kubernetes API, same as the
  4166. Kubernetes provider. Required when Server.URL is set (unless using AuthRef).
  4167. maxProperties: 1
  4168. minProperties: 1
  4169. properties:
  4170. cert:
  4171. description: has both clientCert and clientKey as secretKeySelector
  4172. properties:
  4173. clientCert:
  4174. description: |-
  4175. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4176. In some instances, `key` is a required field.
  4177. properties:
  4178. key:
  4179. description: |-
  4180. A key in the referenced Secret.
  4181. Some instances of this field may be defaulted, in others it may be required.
  4182. maxLength: 253
  4183. minLength: 1
  4184. pattern: ^[-._a-zA-Z0-9]+$
  4185. type: string
  4186. name:
  4187. description: The name of the Secret resource being referred to.
  4188. maxLength: 253
  4189. minLength: 1
  4190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4191. type: string
  4192. namespace:
  4193. description: |-
  4194. The namespace of the Secret resource being referred to.
  4195. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4196. maxLength: 63
  4197. minLength: 1
  4198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4199. type: string
  4200. type: object
  4201. clientKey:
  4202. description: |-
  4203. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4204. In some instances, `key` is a required field.
  4205. properties:
  4206. key:
  4207. description: |-
  4208. A key in the referenced Secret.
  4209. Some instances of this field may be defaulted, in others it may be required.
  4210. maxLength: 253
  4211. minLength: 1
  4212. pattern: ^[-._a-zA-Z0-9]+$
  4213. type: string
  4214. name:
  4215. description: The name of the Secret resource being referred to.
  4216. maxLength: 253
  4217. minLength: 1
  4218. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4219. type: string
  4220. namespace:
  4221. description: |-
  4222. The namespace of the Secret resource being referred to.
  4223. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4224. maxLength: 63
  4225. minLength: 1
  4226. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4227. type: string
  4228. type: object
  4229. required:
  4230. - clientCert
  4231. - clientKey
  4232. type: object
  4233. serviceAccount:
  4234. description: points to a service account that should be used for authentication
  4235. properties:
  4236. audiences:
  4237. description: |-
  4238. Audience specifies the `aud` claim for the service account token
  4239. Some providers automatically extend the audience field based on well-known annotations for workload
  4240. identity (e.g. IRSA or GCP Workload Identity)
  4241. items:
  4242. type: string
  4243. type: array
  4244. name:
  4245. description: The name of the ServiceAccount resource being referred to.
  4246. maxLength: 253
  4247. minLength: 1
  4248. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4249. type: string
  4250. namespace:
  4251. description: |-
  4252. Namespace of the resource being referred to.
  4253. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4254. maxLength: 63
  4255. minLength: 1
  4256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4257. type: string
  4258. required:
  4259. - name
  4260. type: object
  4261. token:
  4262. description: use static token to authenticate with
  4263. properties:
  4264. bearerToken:
  4265. description: |-
  4266. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4267. In some instances, `key` is a required field.
  4268. properties:
  4269. key:
  4270. description: |-
  4271. A key in the referenced Secret.
  4272. Some instances of this field may be defaulted, in others it may be required.
  4273. maxLength: 253
  4274. minLength: 1
  4275. pattern: ^[-._a-zA-Z0-9]+$
  4276. type: string
  4277. name:
  4278. description: The name of the Secret resource being referred to.
  4279. maxLength: 253
  4280. minLength: 1
  4281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4282. type: string
  4283. namespace:
  4284. description: |-
  4285. The namespace of the Secret resource being referred to.
  4286. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4287. maxLength: 63
  4288. minLength: 1
  4289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4290. type: string
  4291. type: object
  4292. required:
  4293. - bearerToken
  4294. type: object
  4295. type: object
  4296. authRef:
  4297. description: |-
  4298. AuthRef references a Secret containing a kubeconfig. Same semantics as the
  4299. Kubernetes provider.
  4300. properties:
  4301. key:
  4302. description: |-
  4303. A key in the referenced Secret.
  4304. Some instances of this field may be defaulted, in others it may be required.
  4305. maxLength: 253
  4306. minLength: 1
  4307. pattern: ^[-._a-zA-Z0-9]+$
  4308. type: string
  4309. name:
  4310. description: The name of the Secret resource being referred to.
  4311. maxLength: 253
  4312. minLength: 1
  4313. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4314. type: string
  4315. namespace:
  4316. description: |-
  4317. The namespace of the Secret resource being referred to.
  4318. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4319. maxLength: 63
  4320. minLength: 1
  4321. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4322. type: string
  4323. type: object
  4324. resource:
  4325. description: Resource identifies the CRD by its API group, version and kind.
  4326. properties:
  4327. group:
  4328. description: |-
  4329. Group is the API group of the resource. Use "" (empty string) for core
  4330. Kubernetes resources such as ConfigMap; use e.g. "config.example.io"
  4331. for a CRD. The field is required to be present in the manifest — write
  4332. `group: ""` explicitly for core resources so typos fail at admission
  4333. time rather than later at discovery.
  4334. type: string
  4335. kind:
  4336. description: Kind is the Kubernetes resource kind (e.g. "MyCustomResource").
  4337. minLength: 1
  4338. type: string
  4339. version:
  4340. description: Version is the API version of the resource (e.g. "v1alpha1").
  4341. minLength: 1
  4342. type: string
  4343. required:
  4344. - group
  4345. - kind
  4346. - version
  4347. type: object
  4348. server:
  4349. description: |-
  4350. Server configures the Kubernetes API address and TLS trust, same as the
  4351. Kubernetes provider. When omitted, the URL defaults to the in-cluster API.
  4352. properties:
  4353. caBundle:
  4354. description: CABundle is a base64-encoded CA certificate
  4355. format: byte
  4356. type: string
  4357. caProvider:
  4358. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  4359. properties:
  4360. key:
  4361. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4362. maxLength: 253
  4363. minLength: 1
  4364. pattern: ^[-._a-zA-Z0-9]+$
  4365. type: string
  4366. name:
  4367. description: The name of the object located at the provider type.
  4368. maxLength: 253
  4369. minLength: 1
  4370. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4371. type: string
  4372. namespace:
  4373. description: |-
  4374. The namespace the Provider type is in.
  4375. Can only be defined when used in a ClusterSecretStore.
  4376. maxLength: 63
  4377. minLength: 1
  4378. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4379. type: string
  4380. type:
  4381. description: The type of provider to use such as "Secret", or "ConfigMap".
  4382. enum:
  4383. - Secret
  4384. - ConfigMap
  4385. type: string
  4386. required:
  4387. - name
  4388. - type
  4389. type: object
  4390. url:
  4391. default: kubernetes.default
  4392. description: configures the Kubernetes server Address.
  4393. type: string
  4394. type: object
  4395. whitelist:
  4396. description: |-
  4397. Whitelist optionally restricts which object names and requested properties
  4398. are allowed to be read.
  4399. properties:
  4400. rules:
  4401. description: |-
  4402. Rules is a list of allow rules. If rules are set, at least one rule must
  4403. match for a request to be allowed.
  4404. items:
  4405. description: CRDProviderWhitelistRule defines a single allow rule for CRD reads.
  4406. properties:
  4407. name:
  4408. description: |-
  4409. Name is an optional regular expression matched against the bare object name.
  4410. For both SecretStore and ClusterSecretStore this is always the object name
  4411. without any namespace prefix (e.g. "my-db-spec", not "prod/my-db-spec").
  4412. type: string
  4413. namespace:
  4414. description: |-
  4415. Namespace is an optional regular expression matched against the namespace of
  4416. the object. Applies only when a ClusterSecretStore is used; it is ignored
  4417. for SecretStore (where the namespace is fixed to the store namespace).
  4418. type: string
  4419. properties:
  4420. description: |-
  4421. Properties is an optional list of regular expressions matched against
  4422. requested property keys (for example: "spec.secretValue").
  4423. items:
  4424. type: string
  4425. type: array
  4426. type: object
  4427. type: array
  4428. type: object
  4429. required:
  4430. - resource
  4431. type: object
  4432. x-kubernetes-validations:
  4433. - message: one of auth or authRef is required
  4434. rule: has(self.auth) || has(self.authRef)
  4435. - message: at most one of the fields in [auth authRef] may be set
  4436. rule: '[has(self.auth),has(self.authRef)].filter(x,x==true).size() <= 1'
  4437. delinea:
  4438. description: |-
  4439. Delinea DevOps Secrets Vault
  4440. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  4441. properties:
  4442. clientId:
  4443. description: ClientID is the non-secret part of the credential.
  4444. properties:
  4445. secretRef:
  4446. description: SecretRef references a key in a secret that will be used as value.
  4447. properties:
  4448. key:
  4449. description: |-
  4450. A key in the referenced Secret.
  4451. Some instances of this field may be defaulted, in others it may be required.
  4452. maxLength: 253
  4453. minLength: 1
  4454. pattern: ^[-._a-zA-Z0-9]+$
  4455. type: string
  4456. name:
  4457. description: The name of the Secret resource being referred to.
  4458. maxLength: 253
  4459. minLength: 1
  4460. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4461. type: string
  4462. namespace:
  4463. description: |-
  4464. The namespace of the Secret resource being referred to.
  4465. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4466. maxLength: 63
  4467. minLength: 1
  4468. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4469. type: string
  4470. type: object
  4471. value:
  4472. description: Value can be specified directly to set a value without using a secret.
  4473. type: string
  4474. type: object
  4475. clientSecret:
  4476. description: ClientSecret is the secret part of the credential.
  4477. properties:
  4478. secretRef:
  4479. description: SecretRef references a key in a secret that will be used as value.
  4480. properties:
  4481. key:
  4482. description: |-
  4483. A key in the referenced Secret.
  4484. Some instances of this field may be defaulted, in others it may be required.
  4485. maxLength: 253
  4486. minLength: 1
  4487. pattern: ^[-._a-zA-Z0-9]+$
  4488. type: string
  4489. name:
  4490. description: The name of the Secret resource being referred to.
  4491. maxLength: 253
  4492. minLength: 1
  4493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4494. type: string
  4495. namespace:
  4496. description: |-
  4497. The namespace of the Secret resource being referred to.
  4498. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4499. maxLength: 63
  4500. minLength: 1
  4501. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4502. type: string
  4503. type: object
  4504. value:
  4505. description: Value can be specified directly to set a value without using a secret.
  4506. type: string
  4507. type: object
  4508. tenant:
  4509. description: Tenant is the chosen hostname / site name.
  4510. type: string
  4511. tld:
  4512. description: |-
  4513. TLD is based on the server location that was chosen during provisioning.
  4514. If unset, defaults to "com".
  4515. type: string
  4516. urlTemplate:
  4517. description: |-
  4518. URLTemplate
  4519. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  4520. type: string
  4521. required:
  4522. - clientId
  4523. - clientSecret
  4524. - tenant
  4525. type: object
  4526. doppler:
  4527. description: Doppler configures this store to sync secrets using the Doppler provider
  4528. properties:
  4529. auth:
  4530. description: Auth configures how the Operator authenticates with the Doppler API
  4531. properties:
  4532. oidcConfig:
  4533. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  4534. properties:
  4535. expirationSeconds:
  4536. default: 600
  4537. description: |-
  4538. ExpirationSeconds sets the ServiceAccount token validity duration.
  4539. Defaults to 10 minutes.
  4540. format: int64
  4541. type: integer
  4542. identity:
  4543. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  4544. type: string
  4545. serviceAccountRef:
  4546. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  4547. properties:
  4548. audiences:
  4549. description: |-
  4550. Audience specifies the `aud` claim for the service account token
  4551. Some providers automatically extend the audience field based on well-known annotations for workload
  4552. identity (e.g. IRSA or GCP Workload Identity)
  4553. items:
  4554. type: string
  4555. type: array
  4556. name:
  4557. description: The name of the ServiceAccount resource being referred to.
  4558. maxLength: 253
  4559. minLength: 1
  4560. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4561. type: string
  4562. namespace:
  4563. description: |-
  4564. Namespace of the resource being referred to.
  4565. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4566. maxLength: 63
  4567. minLength: 1
  4568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4569. type: string
  4570. required:
  4571. - name
  4572. type: object
  4573. required:
  4574. - identity
  4575. - serviceAccountRef
  4576. type: object
  4577. secretRef:
  4578. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  4579. properties:
  4580. dopplerToken:
  4581. description: |-
  4582. The DopplerToken is used for authentication.
  4583. See https://docs.doppler.com/reference/api#authentication for auth token types.
  4584. The Key attribute defaults to dopplerToken if not specified.
  4585. properties:
  4586. key:
  4587. description: |-
  4588. A key in the referenced Secret.
  4589. Some instances of this field may be defaulted, in others it may be required.
  4590. maxLength: 253
  4591. minLength: 1
  4592. pattern: ^[-._a-zA-Z0-9]+$
  4593. type: string
  4594. name:
  4595. description: The name of the Secret resource being referred to.
  4596. maxLength: 253
  4597. minLength: 1
  4598. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4599. type: string
  4600. namespace:
  4601. description: |-
  4602. The namespace of the Secret resource being referred to.
  4603. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4604. maxLength: 63
  4605. minLength: 1
  4606. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4607. type: string
  4608. type: object
  4609. required:
  4610. - dopplerToken
  4611. type: object
  4612. type: object
  4613. x-kubernetes-validations:
  4614. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  4615. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  4616. config:
  4617. description: Doppler config (required if not using a Service Token)
  4618. type: string
  4619. format:
  4620. description: Format enables the downloading of secrets as a file (string)
  4621. enum:
  4622. - json
  4623. - dotnet-json
  4624. - env
  4625. - yaml
  4626. - docker
  4627. type: string
  4628. nameTransformer:
  4629. description: Environment variable compatible name transforms that change secret names to a different format
  4630. enum:
  4631. - upper-camel
  4632. - camel
  4633. - lower-snake
  4634. - tf-var
  4635. - dotnet-env
  4636. - lower-kebab
  4637. type: string
  4638. project:
  4639. description: Doppler project (required if not using a Service Token)
  4640. type: string
  4641. required:
  4642. - auth
  4643. type: object
  4644. dvls:
  4645. description: DVLS configures this store to sync secrets using Devolutions Server provider
  4646. properties:
  4647. auth:
  4648. description: Auth defines the authentication method to use.
  4649. properties:
  4650. secretRef:
  4651. description: SecretRef contains the Application ID and Application Secret for authentication.
  4652. properties:
  4653. appId:
  4654. description: AppID is the reference to the secret containing the Application ID.
  4655. properties:
  4656. key:
  4657. description: |-
  4658. A key in the referenced Secret.
  4659. Some instances of this field may be defaulted, in others it may be required.
  4660. maxLength: 253
  4661. minLength: 1
  4662. pattern: ^[-._a-zA-Z0-9]+$
  4663. type: string
  4664. name:
  4665. description: The name of the Secret resource being referred to.
  4666. maxLength: 253
  4667. minLength: 1
  4668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4669. type: string
  4670. namespace:
  4671. description: |-
  4672. The namespace of the Secret resource being referred to.
  4673. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4674. maxLength: 63
  4675. minLength: 1
  4676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4677. type: string
  4678. type: object
  4679. appSecret:
  4680. description: AppSecret is the reference to the secret containing the Application Secret.
  4681. properties:
  4682. key:
  4683. description: |-
  4684. A key in the referenced Secret.
  4685. Some instances of this field may be defaulted, in others it may be required.
  4686. maxLength: 253
  4687. minLength: 1
  4688. pattern: ^[-._a-zA-Z0-9]+$
  4689. type: string
  4690. name:
  4691. description: The name of the Secret resource being referred to.
  4692. maxLength: 253
  4693. minLength: 1
  4694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4695. type: string
  4696. namespace:
  4697. description: |-
  4698. The namespace of the Secret resource being referred to.
  4699. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4700. maxLength: 63
  4701. minLength: 1
  4702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4703. type: string
  4704. type: object
  4705. required:
  4706. - appId
  4707. - appSecret
  4708. type: object
  4709. required:
  4710. - secretRef
  4711. type: object
  4712. insecure:
  4713. description: |-
  4714. Insecure allows connecting to DVLS over plain HTTP.
  4715. This is NOT RECOMMENDED for production use.
  4716. Set to true only if you understand the security implications.
  4717. type: boolean
  4718. serverUrl:
  4719. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  4720. type: string
  4721. vault:
  4722. description: |-
  4723. Vault is the name or UUID of the vault to fetch secrets from.
  4724. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  4725. type: string
  4726. required:
  4727. - auth
  4728. - serverUrl
  4729. type: object
  4730. fake:
  4731. description: Fake configures a store with static key/value pairs
  4732. properties:
  4733. data:
  4734. items:
  4735. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  4736. properties:
  4737. key:
  4738. type: string
  4739. value:
  4740. type: string
  4741. version:
  4742. type: string
  4743. required:
  4744. - key
  4745. - value
  4746. type: object
  4747. type: array
  4748. validationResult:
  4749. description: ValidationResult is defined type for the number of validation results.
  4750. type: integer
  4751. required:
  4752. - data
  4753. type: object
  4754. fortanix:
  4755. description: Fortanix configures this store to sync secrets using the Fortanix provider
  4756. properties:
  4757. apiKey:
  4758. description: APIKey is the API token to access SDKMS Applications.
  4759. properties:
  4760. secretRef:
  4761. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  4762. properties:
  4763. key:
  4764. description: |-
  4765. A key in the referenced Secret.
  4766. Some instances of this field may be defaulted, in others it may be required.
  4767. maxLength: 253
  4768. minLength: 1
  4769. pattern: ^[-._a-zA-Z0-9]+$
  4770. type: string
  4771. name:
  4772. description: The name of the Secret resource being referred to.
  4773. maxLength: 253
  4774. minLength: 1
  4775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4776. type: string
  4777. namespace:
  4778. description: |-
  4779. The namespace of the Secret resource being referred to.
  4780. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4781. maxLength: 63
  4782. minLength: 1
  4783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4784. type: string
  4785. type: object
  4786. type: object
  4787. apiUrl:
  4788. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  4789. type: string
  4790. type: object
  4791. gcpsm:
  4792. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  4793. properties:
  4794. auth:
  4795. description: Auth defines the information necessary to authenticate against GCP
  4796. properties:
  4797. secretRef:
  4798. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  4799. properties:
  4800. secretAccessKeySecretRef:
  4801. description: The SecretAccessKey is used for authentication
  4802. properties:
  4803. key:
  4804. description: |-
  4805. A key in the referenced Secret.
  4806. Some instances of this field may be defaulted, in others it may be required.
  4807. maxLength: 253
  4808. minLength: 1
  4809. pattern: ^[-._a-zA-Z0-9]+$
  4810. type: string
  4811. name:
  4812. description: The name of the Secret resource being referred to.
  4813. maxLength: 253
  4814. minLength: 1
  4815. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4816. type: string
  4817. namespace:
  4818. description: |-
  4819. The namespace of the Secret resource being referred to.
  4820. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4821. maxLength: 63
  4822. minLength: 1
  4823. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4824. type: string
  4825. type: object
  4826. type: object
  4827. workloadIdentity:
  4828. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  4829. properties:
  4830. clusterLocation:
  4831. description: |-
  4832. ClusterLocation is the location of the cluster
  4833. If not specified, it fetches information from the metadata server
  4834. type: string
  4835. clusterName:
  4836. description: |-
  4837. ClusterName is the name of the cluster
  4838. If not specified, it fetches information from the metadata server
  4839. type: string
  4840. clusterProjectID:
  4841. description: |-
  4842. ClusterProjectID is the project ID of the cluster
  4843. If not specified, it fetches information from the metadata server
  4844. type: string
  4845. serviceAccountRef:
  4846. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  4847. properties:
  4848. audiences:
  4849. description: |-
  4850. Audience specifies the `aud` claim for the service account token
  4851. Some providers automatically extend the audience field based on well-known annotations for workload
  4852. identity (e.g. IRSA or GCP Workload Identity)
  4853. items:
  4854. type: string
  4855. type: array
  4856. name:
  4857. description: The name of the ServiceAccount resource being referred to.
  4858. maxLength: 253
  4859. minLength: 1
  4860. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4861. type: string
  4862. namespace:
  4863. description: |-
  4864. Namespace of the resource being referred to.
  4865. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4866. maxLength: 63
  4867. minLength: 1
  4868. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4869. type: string
  4870. required:
  4871. - name
  4872. type: object
  4873. required:
  4874. - serviceAccountRef
  4875. type: object
  4876. workloadIdentityFederation:
  4877. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  4878. properties:
  4879. audience:
  4880. description: |-
  4881. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  4882. If specified, Audience found in the external account credential config will be overridden with the configured value.
  4883. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  4884. type: string
  4885. awsSecurityCredentials:
  4886. description: |-
  4887. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  4888. when using the AWS metadata server is not an option.
  4889. properties:
  4890. awsCredentialsSecretRef:
  4891. description: |-
  4892. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  4893. Secret should be created with below names for keys
  4894. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  4895. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  4896. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  4897. properties:
  4898. name:
  4899. description: name of the secret.
  4900. maxLength: 253
  4901. minLength: 1
  4902. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4903. type: string
  4904. namespace:
  4905. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  4906. maxLength: 63
  4907. minLength: 1
  4908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4909. type: string
  4910. required:
  4911. - name
  4912. type: object
  4913. region:
  4914. description: region is for configuring the AWS region to be used.
  4915. example: ap-south-1
  4916. maxLength: 50
  4917. minLength: 1
  4918. pattern: ^[a-z0-9-]+$
  4919. type: string
  4920. required:
  4921. - awsCredentialsSecretRef
  4922. - region
  4923. type: object
  4924. credConfig:
  4925. description: |-
  4926. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  4927. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  4928. serviceAccountRef must be used by providing operators service account details.
  4929. properties:
  4930. key:
  4931. description: key name holding the external account credential config.
  4932. maxLength: 253
  4933. minLength: 1
  4934. pattern: ^[-._a-zA-Z0-9]+$
  4935. type: string
  4936. name:
  4937. description: name of the configmap.
  4938. maxLength: 253
  4939. minLength: 1
  4940. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4941. type: string
  4942. namespace:
  4943. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  4944. maxLength: 63
  4945. minLength: 1
  4946. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4947. type: string
  4948. required:
  4949. - key
  4950. - name
  4951. type: object
  4952. externalTokenEndpoint:
  4953. description: |-
  4954. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  4955. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  4956. URL is having the expected value.
  4957. type: string
  4958. gcpServiceAccountEmail:
  4959. description: |-
  4960. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  4961. after Workload Identity Federation. Use this to grant access through the service account's
  4962. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  4963. service_account_impersonation_url in the external account JSON from credConfig;
  4964. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  4965. on that ServiceAccount.
  4966. example: my-gsa@my-project.iam.gserviceaccount.com
  4967. minLength: 1
  4968. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  4969. type: string
  4970. serviceAccountRef:
  4971. description: |-
  4972. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  4973. when Kubernetes is configured as provider in workload identity pool.
  4974. properties:
  4975. audiences:
  4976. description: |-
  4977. Audience specifies the `aud` claim for the service account token
  4978. Some providers automatically extend the audience field based on well-known annotations for workload
  4979. identity (e.g. IRSA or GCP Workload Identity)
  4980. items:
  4981. type: string
  4982. type: array
  4983. name:
  4984. description: The name of the ServiceAccount resource being referred to.
  4985. maxLength: 253
  4986. minLength: 1
  4987. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4988. type: string
  4989. namespace:
  4990. description: |-
  4991. Namespace of the resource being referred to.
  4992. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4993. maxLength: 63
  4994. minLength: 1
  4995. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4996. type: string
  4997. required:
  4998. - name
  4999. type: object
  5000. type: object
  5001. type: object
  5002. location:
  5003. description: Location optionally defines a location for a secret
  5004. type: string
  5005. projectID:
  5006. description: ProjectID project where secret is located
  5007. type: string
  5008. secretVersionSelectionPolicy:
  5009. default: LatestOrFail
  5010. description: |-
  5011. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  5012. when "latest" is disabled or destroyed.
  5013. Possible values are:
  5014. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  5015. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  5016. type: string
  5017. type: object
  5018. github:
  5019. description: |-
  5020. Github configures this store to push GitHub Actions or Dependabot secrets using the GitHub API provider.
  5021. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  5022. properties:
  5023. appID:
  5024. description: appID specifies the Github APP that will be used to authenticate the client
  5025. format: int64
  5026. type: integer
  5027. auth:
  5028. description: auth configures how secret-manager authenticates with a Github instance.
  5029. properties:
  5030. privateKey:
  5031. description: |-
  5032. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5033. In some instances, `key` is a required field.
  5034. properties:
  5035. key:
  5036. description: |-
  5037. A key in the referenced Secret.
  5038. Some instances of this field may be defaulted, in others it may be required.
  5039. maxLength: 253
  5040. minLength: 1
  5041. pattern: ^[-._a-zA-Z0-9]+$
  5042. type: string
  5043. name:
  5044. description: The name of the Secret resource being referred to.
  5045. maxLength: 253
  5046. minLength: 1
  5047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5048. type: string
  5049. namespace:
  5050. description: |-
  5051. The namespace of the Secret resource being referred to.
  5052. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5053. maxLength: 63
  5054. minLength: 1
  5055. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5056. type: string
  5057. type: object
  5058. required:
  5059. - privateKey
  5060. type: object
  5061. environment:
  5062. description: environment will be used to fetch secrets from a particular environment within a github repository
  5063. type: string
  5064. installationID:
  5065. description: installationID specifies the Github APP installation that will be used to authenticate the client
  5066. format: int64
  5067. type: integer
  5068. orgSecretVisibility:
  5069. description: |-
  5070. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  5071. Valid values are "all" or "private".
  5072. When unset, new secrets are created with visibility "all" and existing secrets preserve
  5073. whatever visibility they already have in GitHub.
  5074. enum:
  5075. - all
  5076. - private
  5077. type: string
  5078. organization:
  5079. description: organization will be used to fetch secrets from the Github organization
  5080. type: string
  5081. repository:
  5082. description: repository will be used to fetch secrets from the Github repository within an organization
  5083. type: string
  5084. secretType:
  5085. default: Actions
  5086. description: |-
  5087. secretType specifies which GitHub secret service to use.
  5088. Defaults to Actions for backwards compatibility.
  5089. enum:
  5090. - Actions
  5091. - Dependabot
  5092. type: string
  5093. uploadURL:
  5094. description: Upload URL for enterprise instances. Default to URL.
  5095. type: string
  5096. url:
  5097. default: https://github.com/
  5098. description: URL configures the Github instance URL. Defaults to https://github.com/.
  5099. type: string
  5100. required:
  5101. - appID
  5102. - auth
  5103. - installationID
  5104. - organization
  5105. type: object
  5106. x-kubernetes-validations:
  5107. - message: Dependabot secrets do not support environments
  5108. rule: self.secretType != 'Dependabot' || !has(self.environment) || size(self.environment) == 0
  5109. gitlab:
  5110. description: GitLab configures this store to sync secrets using GitLab Variables provider
  5111. properties:
  5112. auth:
  5113. description: Auth configures how secret-manager authenticates with a GitLab instance.
  5114. properties:
  5115. SecretRef:
  5116. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  5117. properties:
  5118. accessToken:
  5119. description: AccessToken is used for authentication.
  5120. properties:
  5121. key:
  5122. description: |-
  5123. A key in the referenced Secret.
  5124. Some instances of this field may be defaulted, in others it may be required.
  5125. maxLength: 253
  5126. minLength: 1
  5127. pattern: ^[-._a-zA-Z0-9]+$
  5128. type: string
  5129. name:
  5130. description: The name of the Secret resource being referred to.
  5131. maxLength: 253
  5132. minLength: 1
  5133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5134. type: string
  5135. namespace:
  5136. description: |-
  5137. The namespace of the Secret resource being referred to.
  5138. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5139. maxLength: 63
  5140. minLength: 1
  5141. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5142. type: string
  5143. type: object
  5144. type: object
  5145. required:
  5146. - SecretRef
  5147. type: object
  5148. caBundle:
  5149. description: |-
  5150. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  5151. can be performed.
  5152. format: byte
  5153. type: string
  5154. caProvider:
  5155. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  5156. properties:
  5157. key:
  5158. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5159. maxLength: 253
  5160. minLength: 1
  5161. pattern: ^[-._a-zA-Z0-9]+$
  5162. type: string
  5163. name:
  5164. description: The name of the object located at the provider type.
  5165. maxLength: 253
  5166. minLength: 1
  5167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5168. type: string
  5169. namespace:
  5170. description: |-
  5171. The namespace the Provider type is in.
  5172. Can only be defined when used in a ClusterSecretStore.
  5173. maxLength: 63
  5174. minLength: 1
  5175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5176. type: string
  5177. type:
  5178. description: The type of provider to use such as "Secret", or "ConfigMap".
  5179. enum:
  5180. - Secret
  5181. - ConfigMap
  5182. type: string
  5183. required:
  5184. - name
  5185. - type
  5186. type: object
  5187. environment:
  5188. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  5189. type: string
  5190. groupIDs:
  5191. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  5192. items:
  5193. type: string
  5194. type: array
  5195. inheritFromGroups:
  5196. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  5197. type: boolean
  5198. projectID:
  5199. description: ProjectID specifies a project where secrets are located.
  5200. type: string
  5201. url:
  5202. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  5203. type: string
  5204. required:
  5205. - auth
  5206. type: object
  5207. ibm:
  5208. description: IBM configures this store to sync secrets using IBM Cloud provider
  5209. properties:
  5210. auth:
  5211. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  5212. maxProperties: 1
  5213. minProperties: 1
  5214. properties:
  5215. containerAuth:
  5216. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  5217. properties:
  5218. iamEndpoint:
  5219. type: string
  5220. profile:
  5221. description: the IBM Trusted Profile
  5222. type: string
  5223. tokenLocation:
  5224. description: Location the token is mounted on the pod
  5225. type: string
  5226. required:
  5227. - profile
  5228. type: object
  5229. secretRef:
  5230. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  5231. properties:
  5232. iamEndpoint:
  5233. description: The IAM endpoint used to obain a token
  5234. type: string
  5235. secretApiKeySecretRef:
  5236. description: The SecretAccessKey is used for authentication
  5237. properties:
  5238. key:
  5239. description: |-
  5240. A key in the referenced Secret.
  5241. Some instances of this field may be defaulted, in others it may be required.
  5242. maxLength: 253
  5243. minLength: 1
  5244. pattern: ^[-._a-zA-Z0-9]+$
  5245. type: string
  5246. name:
  5247. description: The name of the Secret resource being referred to.
  5248. maxLength: 253
  5249. minLength: 1
  5250. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5251. type: string
  5252. namespace:
  5253. description: |-
  5254. The namespace of the Secret resource being referred to.
  5255. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5256. maxLength: 63
  5257. minLength: 1
  5258. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5259. type: string
  5260. type: object
  5261. type: object
  5262. type: object
  5263. serviceUrl:
  5264. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  5265. type: string
  5266. required:
  5267. - auth
  5268. type: object
  5269. infisical:
  5270. description: Infisical configures this store to sync secrets using the Infisical provider
  5271. properties:
  5272. auth:
  5273. description: Auth configures how the Operator authenticates with the Infisical API
  5274. properties:
  5275. awsAuthCredentials:
  5276. description: AwsAuthCredentials represents the credentials for AWS authentication.
  5277. properties:
  5278. identityId:
  5279. description: |-
  5280. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5281. In some instances, `key` is a required field.
  5282. properties:
  5283. key:
  5284. description: |-
  5285. A key in the referenced Secret.
  5286. Some instances of this field may be defaulted, in others it may be required.
  5287. maxLength: 253
  5288. minLength: 1
  5289. pattern: ^[-._a-zA-Z0-9]+$
  5290. type: string
  5291. name:
  5292. description: The name of the Secret resource being referred to.
  5293. maxLength: 253
  5294. minLength: 1
  5295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5296. type: string
  5297. namespace:
  5298. description: |-
  5299. The namespace of the Secret resource being referred to.
  5300. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5301. maxLength: 63
  5302. minLength: 1
  5303. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5304. type: string
  5305. type: object
  5306. required:
  5307. - identityId
  5308. type: object
  5309. azureAuthCredentials:
  5310. description: AzureAuthCredentials represents the credentials for Azure authentication.
  5311. properties:
  5312. identityId:
  5313. description: |-
  5314. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5315. In some instances, `key` is a required field.
  5316. properties:
  5317. key:
  5318. description: |-
  5319. A key in the referenced Secret.
  5320. Some instances of this field may be defaulted, in others it may be required.
  5321. maxLength: 253
  5322. minLength: 1
  5323. pattern: ^[-._a-zA-Z0-9]+$
  5324. type: string
  5325. name:
  5326. description: The name of the Secret resource being referred to.
  5327. maxLength: 253
  5328. minLength: 1
  5329. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5330. type: string
  5331. namespace:
  5332. description: |-
  5333. The namespace of the Secret resource being referred to.
  5334. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5335. maxLength: 63
  5336. minLength: 1
  5337. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5338. type: string
  5339. type: object
  5340. resource:
  5341. description: |-
  5342. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5343. In some instances, `key` is a required field.
  5344. properties:
  5345. key:
  5346. description: |-
  5347. A key in the referenced Secret.
  5348. Some instances of this field may be defaulted, in others it may be required.
  5349. maxLength: 253
  5350. minLength: 1
  5351. pattern: ^[-._a-zA-Z0-9]+$
  5352. type: string
  5353. name:
  5354. description: The name of the Secret resource being referred to.
  5355. maxLength: 253
  5356. minLength: 1
  5357. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5358. type: string
  5359. namespace:
  5360. description: |-
  5361. The namespace of the Secret resource being referred to.
  5362. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5363. maxLength: 63
  5364. minLength: 1
  5365. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5366. type: string
  5367. type: object
  5368. required:
  5369. - identityId
  5370. type: object
  5371. gcpIamAuthCredentials:
  5372. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  5373. properties:
  5374. identityId:
  5375. description: |-
  5376. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5377. In some instances, `key` is a required field.
  5378. properties:
  5379. key:
  5380. description: |-
  5381. A key in the referenced Secret.
  5382. Some instances of this field may be defaulted, in others it may be required.
  5383. maxLength: 253
  5384. minLength: 1
  5385. pattern: ^[-._a-zA-Z0-9]+$
  5386. type: string
  5387. name:
  5388. description: The name of the Secret resource being referred to.
  5389. maxLength: 253
  5390. minLength: 1
  5391. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5392. type: string
  5393. namespace:
  5394. description: |-
  5395. The namespace of the Secret resource being referred to.
  5396. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5397. maxLength: 63
  5398. minLength: 1
  5399. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5400. type: string
  5401. type: object
  5402. serviceAccountKeyFilePath:
  5403. description: |-
  5404. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5405. In some instances, `key` is a required field.
  5406. properties:
  5407. key:
  5408. description: |-
  5409. A key in the referenced Secret.
  5410. Some instances of this field may be defaulted, in others it may be required.
  5411. maxLength: 253
  5412. minLength: 1
  5413. pattern: ^[-._a-zA-Z0-9]+$
  5414. type: string
  5415. name:
  5416. description: The name of the Secret resource being referred to.
  5417. maxLength: 253
  5418. minLength: 1
  5419. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5420. type: string
  5421. namespace:
  5422. description: |-
  5423. The namespace of the Secret resource being referred to.
  5424. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5425. maxLength: 63
  5426. minLength: 1
  5427. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5428. type: string
  5429. type: object
  5430. required:
  5431. - identityId
  5432. - serviceAccountKeyFilePath
  5433. type: object
  5434. gcpIdTokenAuthCredentials:
  5435. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  5436. properties:
  5437. identityId:
  5438. description: |-
  5439. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5440. In some instances, `key` is a required field.
  5441. properties:
  5442. key:
  5443. description: |-
  5444. A key in the referenced Secret.
  5445. Some instances of this field may be defaulted, in others it may be required.
  5446. maxLength: 253
  5447. minLength: 1
  5448. pattern: ^[-._a-zA-Z0-9]+$
  5449. type: string
  5450. name:
  5451. description: The name of the Secret resource being referred to.
  5452. maxLength: 253
  5453. minLength: 1
  5454. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5455. type: string
  5456. namespace:
  5457. description: |-
  5458. The namespace of the Secret resource being referred to.
  5459. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5460. maxLength: 63
  5461. minLength: 1
  5462. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5463. type: string
  5464. type: object
  5465. required:
  5466. - identityId
  5467. type: object
  5468. jwtAuthCredentials:
  5469. description: JwtAuthCredentials represents the credentials for JWT authentication.
  5470. properties:
  5471. identityId:
  5472. description: |-
  5473. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5474. In some instances, `key` is a required field.
  5475. properties:
  5476. key:
  5477. description: |-
  5478. A key in the referenced Secret.
  5479. Some instances of this field may be defaulted, in others it may be required.
  5480. maxLength: 253
  5481. minLength: 1
  5482. pattern: ^[-._a-zA-Z0-9]+$
  5483. type: string
  5484. name:
  5485. description: The name of the Secret resource being referred to.
  5486. maxLength: 253
  5487. minLength: 1
  5488. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5489. type: string
  5490. namespace:
  5491. description: |-
  5492. The namespace of the Secret resource being referred to.
  5493. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5494. maxLength: 63
  5495. minLength: 1
  5496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5497. type: string
  5498. type: object
  5499. jwt:
  5500. description: |-
  5501. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5502. In some instances, `key` is a required field.
  5503. properties:
  5504. key:
  5505. description: |-
  5506. A key in the referenced Secret.
  5507. Some instances of this field may be defaulted, in others it may be required.
  5508. maxLength: 253
  5509. minLength: 1
  5510. pattern: ^[-._a-zA-Z0-9]+$
  5511. type: string
  5512. name:
  5513. description: The name of the Secret resource being referred to.
  5514. maxLength: 253
  5515. minLength: 1
  5516. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5517. type: string
  5518. namespace:
  5519. description: |-
  5520. The namespace of the Secret resource being referred to.
  5521. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5522. maxLength: 63
  5523. minLength: 1
  5524. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5525. type: string
  5526. type: object
  5527. required:
  5528. - identityId
  5529. - jwt
  5530. type: object
  5531. kubernetesAuthCredentials:
  5532. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  5533. properties:
  5534. identityId:
  5535. description: |-
  5536. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5537. In some instances, `key` is a required field.
  5538. properties:
  5539. key:
  5540. description: |-
  5541. A key in the referenced Secret.
  5542. Some instances of this field may be defaulted, in others it may be required.
  5543. maxLength: 253
  5544. minLength: 1
  5545. pattern: ^[-._a-zA-Z0-9]+$
  5546. type: string
  5547. name:
  5548. description: The name of the Secret resource being referred to.
  5549. maxLength: 253
  5550. minLength: 1
  5551. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5552. type: string
  5553. namespace:
  5554. description: |-
  5555. The namespace of the Secret resource being referred to.
  5556. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5557. maxLength: 63
  5558. minLength: 1
  5559. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5560. type: string
  5561. type: object
  5562. serviceAccountTokenPath:
  5563. description: |-
  5564. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5565. In some instances, `key` is a required field.
  5566. properties:
  5567. key:
  5568. description: |-
  5569. A key in the referenced Secret.
  5570. Some instances of this field may be defaulted, in others it may be required.
  5571. maxLength: 253
  5572. minLength: 1
  5573. pattern: ^[-._a-zA-Z0-9]+$
  5574. type: string
  5575. name:
  5576. description: The name of the Secret resource being referred to.
  5577. maxLength: 253
  5578. minLength: 1
  5579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5580. type: string
  5581. namespace:
  5582. description: |-
  5583. The namespace of the Secret resource being referred to.
  5584. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5585. maxLength: 63
  5586. minLength: 1
  5587. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5588. type: string
  5589. type: object
  5590. required:
  5591. - identityId
  5592. type: object
  5593. ldapAuthCredentials:
  5594. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  5595. properties:
  5596. identityId:
  5597. description: |-
  5598. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5599. In some instances, `key` is a required field.
  5600. properties:
  5601. key:
  5602. description: |-
  5603. A key in the referenced Secret.
  5604. Some instances of this field may be defaulted, in others it may be required.
  5605. maxLength: 253
  5606. minLength: 1
  5607. pattern: ^[-._a-zA-Z0-9]+$
  5608. type: string
  5609. name:
  5610. description: The name of the Secret resource being referred to.
  5611. maxLength: 253
  5612. minLength: 1
  5613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5614. type: string
  5615. namespace:
  5616. description: |-
  5617. The namespace of the Secret resource being referred to.
  5618. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5619. maxLength: 63
  5620. minLength: 1
  5621. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5622. type: string
  5623. type: object
  5624. ldapPassword:
  5625. description: |-
  5626. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5627. In some instances, `key` is a required field.
  5628. properties:
  5629. key:
  5630. description: |-
  5631. A key in the referenced Secret.
  5632. Some instances of this field may be defaulted, in others it may be required.
  5633. maxLength: 253
  5634. minLength: 1
  5635. pattern: ^[-._a-zA-Z0-9]+$
  5636. type: string
  5637. name:
  5638. description: The name of the Secret resource being referred to.
  5639. maxLength: 253
  5640. minLength: 1
  5641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5642. type: string
  5643. namespace:
  5644. description: |-
  5645. The namespace of the Secret resource being referred to.
  5646. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5647. maxLength: 63
  5648. minLength: 1
  5649. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5650. type: string
  5651. type: object
  5652. ldapUsername:
  5653. description: |-
  5654. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5655. In some instances, `key` is a required field.
  5656. properties:
  5657. key:
  5658. description: |-
  5659. A key in the referenced Secret.
  5660. Some instances of this field may be defaulted, in others it may be required.
  5661. maxLength: 253
  5662. minLength: 1
  5663. pattern: ^[-._a-zA-Z0-9]+$
  5664. type: string
  5665. name:
  5666. description: The name of the Secret resource being referred to.
  5667. maxLength: 253
  5668. minLength: 1
  5669. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5670. type: string
  5671. namespace:
  5672. description: |-
  5673. The namespace of the Secret resource being referred to.
  5674. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5675. maxLength: 63
  5676. minLength: 1
  5677. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5678. type: string
  5679. type: object
  5680. required:
  5681. - identityId
  5682. - ldapPassword
  5683. - ldapUsername
  5684. type: object
  5685. ociAuthCredentials:
  5686. description: OciAuthCredentials represents the credentials for OCI authentication.
  5687. properties:
  5688. fingerprint:
  5689. description: |-
  5690. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5691. In some instances, `key` is a required field.
  5692. properties:
  5693. key:
  5694. description: |-
  5695. A key in the referenced Secret.
  5696. Some instances of this field may be defaulted, in others it may be required.
  5697. maxLength: 253
  5698. minLength: 1
  5699. pattern: ^[-._a-zA-Z0-9]+$
  5700. type: string
  5701. name:
  5702. description: The name of the Secret resource being referred to.
  5703. maxLength: 253
  5704. minLength: 1
  5705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5706. type: string
  5707. namespace:
  5708. description: |-
  5709. The namespace of the Secret resource being referred to.
  5710. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5711. maxLength: 63
  5712. minLength: 1
  5713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5714. type: string
  5715. type: object
  5716. identityId:
  5717. description: |-
  5718. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5719. In some instances, `key` is a required field.
  5720. properties:
  5721. key:
  5722. description: |-
  5723. A key in the referenced Secret.
  5724. Some instances of this field may be defaulted, in others it may be required.
  5725. maxLength: 253
  5726. minLength: 1
  5727. pattern: ^[-._a-zA-Z0-9]+$
  5728. type: string
  5729. name:
  5730. description: The name of the Secret resource being referred to.
  5731. maxLength: 253
  5732. minLength: 1
  5733. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5734. type: string
  5735. namespace:
  5736. description: |-
  5737. The namespace of the Secret resource being referred to.
  5738. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5739. maxLength: 63
  5740. minLength: 1
  5741. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5742. type: string
  5743. type: object
  5744. privateKey:
  5745. description: |-
  5746. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5747. In some instances, `key` is a required field.
  5748. properties:
  5749. key:
  5750. description: |-
  5751. A key in the referenced Secret.
  5752. Some instances of this field may be defaulted, in others it may be required.
  5753. maxLength: 253
  5754. minLength: 1
  5755. pattern: ^[-._a-zA-Z0-9]+$
  5756. type: string
  5757. name:
  5758. description: The name of the Secret resource being referred to.
  5759. maxLength: 253
  5760. minLength: 1
  5761. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5762. type: string
  5763. namespace:
  5764. description: |-
  5765. The namespace of the Secret resource being referred to.
  5766. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5767. maxLength: 63
  5768. minLength: 1
  5769. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5770. type: string
  5771. type: object
  5772. privateKeyPassphrase:
  5773. description: |-
  5774. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5775. In some instances, `key` is a required field.
  5776. properties:
  5777. key:
  5778. description: |-
  5779. A key in the referenced Secret.
  5780. Some instances of this field may be defaulted, in others it may be required.
  5781. maxLength: 253
  5782. minLength: 1
  5783. pattern: ^[-._a-zA-Z0-9]+$
  5784. type: string
  5785. name:
  5786. description: The name of the Secret resource being referred to.
  5787. maxLength: 253
  5788. minLength: 1
  5789. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5790. type: string
  5791. namespace:
  5792. description: |-
  5793. The namespace of the Secret resource being referred to.
  5794. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5795. maxLength: 63
  5796. minLength: 1
  5797. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5798. type: string
  5799. type: object
  5800. region:
  5801. description: |-
  5802. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5803. In some instances, `key` is a required field.
  5804. properties:
  5805. key:
  5806. description: |-
  5807. A key in the referenced Secret.
  5808. Some instances of this field may be defaulted, in others it may be required.
  5809. maxLength: 253
  5810. minLength: 1
  5811. pattern: ^[-._a-zA-Z0-9]+$
  5812. type: string
  5813. name:
  5814. description: The name of the Secret resource being referred to.
  5815. maxLength: 253
  5816. minLength: 1
  5817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5818. type: string
  5819. namespace:
  5820. description: |-
  5821. The namespace of the Secret resource being referred to.
  5822. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5823. maxLength: 63
  5824. minLength: 1
  5825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5826. type: string
  5827. type: object
  5828. tenancyId:
  5829. description: |-
  5830. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5831. In some instances, `key` is a required field.
  5832. properties:
  5833. key:
  5834. description: |-
  5835. A key in the referenced Secret.
  5836. Some instances of this field may be defaulted, in others it may be required.
  5837. maxLength: 253
  5838. minLength: 1
  5839. pattern: ^[-._a-zA-Z0-9]+$
  5840. type: string
  5841. name:
  5842. description: The name of the Secret resource being referred to.
  5843. maxLength: 253
  5844. minLength: 1
  5845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5846. type: string
  5847. namespace:
  5848. description: |-
  5849. The namespace of the Secret resource being referred to.
  5850. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5851. maxLength: 63
  5852. minLength: 1
  5853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5854. type: string
  5855. type: object
  5856. userId:
  5857. description: |-
  5858. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5859. In some instances, `key` is a required field.
  5860. properties:
  5861. key:
  5862. description: |-
  5863. A key in the referenced Secret.
  5864. Some instances of this field may be defaulted, in others it may be required.
  5865. maxLength: 253
  5866. minLength: 1
  5867. pattern: ^[-._a-zA-Z0-9]+$
  5868. type: string
  5869. name:
  5870. description: The name of the Secret resource being referred to.
  5871. maxLength: 253
  5872. minLength: 1
  5873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5874. type: string
  5875. namespace:
  5876. description: |-
  5877. The namespace of the Secret resource being referred to.
  5878. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5879. maxLength: 63
  5880. minLength: 1
  5881. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5882. type: string
  5883. type: object
  5884. required:
  5885. - fingerprint
  5886. - identityId
  5887. - privateKey
  5888. - region
  5889. - tenancyId
  5890. - userId
  5891. type: object
  5892. tokenAuthCredentials:
  5893. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  5894. properties:
  5895. accessToken:
  5896. description: |-
  5897. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5898. In some instances, `key` is a required field.
  5899. properties:
  5900. key:
  5901. description: |-
  5902. A key in the referenced Secret.
  5903. Some instances of this field may be defaulted, in others it may be required.
  5904. maxLength: 253
  5905. minLength: 1
  5906. pattern: ^[-._a-zA-Z0-9]+$
  5907. type: string
  5908. name:
  5909. description: The name of the Secret resource being referred to.
  5910. maxLength: 253
  5911. minLength: 1
  5912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5913. type: string
  5914. namespace:
  5915. description: |-
  5916. The namespace of the Secret resource being referred to.
  5917. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5918. maxLength: 63
  5919. minLength: 1
  5920. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5921. type: string
  5922. type: object
  5923. required:
  5924. - accessToken
  5925. type: object
  5926. universalAuthCredentials:
  5927. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  5928. properties:
  5929. clientId:
  5930. description: |-
  5931. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5932. In some instances, `key` is a required field.
  5933. properties:
  5934. key:
  5935. description: |-
  5936. A key in the referenced Secret.
  5937. Some instances of this field may be defaulted, in others it may be required.
  5938. maxLength: 253
  5939. minLength: 1
  5940. pattern: ^[-._a-zA-Z0-9]+$
  5941. type: string
  5942. name:
  5943. description: The name of the Secret resource being referred to.
  5944. maxLength: 253
  5945. minLength: 1
  5946. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5947. type: string
  5948. namespace:
  5949. description: |-
  5950. The namespace of the Secret resource being referred to.
  5951. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5952. maxLength: 63
  5953. minLength: 1
  5954. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5955. type: string
  5956. type: object
  5957. clientSecret:
  5958. description: |-
  5959. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5960. In some instances, `key` is a required field.
  5961. properties:
  5962. key:
  5963. description: |-
  5964. A key in the referenced Secret.
  5965. Some instances of this field may be defaulted, in others it may be required.
  5966. maxLength: 253
  5967. minLength: 1
  5968. pattern: ^[-._a-zA-Z0-9]+$
  5969. type: string
  5970. name:
  5971. description: The name of the Secret resource being referred to.
  5972. maxLength: 253
  5973. minLength: 1
  5974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5975. type: string
  5976. namespace:
  5977. description: |-
  5978. The namespace of the Secret resource being referred to.
  5979. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5980. maxLength: 63
  5981. minLength: 1
  5982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5983. type: string
  5984. type: object
  5985. required:
  5986. - clientId
  5987. - clientSecret
  5988. type: object
  5989. type: object
  5990. caBundle:
  5991. description: |-
  5992. CABundle is a PEM-encoded CA certificate bundle used to validate
  5993. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  5994. format: byte
  5995. type: string
  5996. caProvider:
  5997. description: |-
  5998. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  5999. The certificate is used to validate the Infisical server's TLS certificate.
  6000. Mutually exclusive with CABundle.
  6001. properties:
  6002. key:
  6003. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6004. maxLength: 253
  6005. minLength: 1
  6006. pattern: ^[-._a-zA-Z0-9]+$
  6007. type: string
  6008. name:
  6009. description: The name of the object located at the provider type.
  6010. maxLength: 253
  6011. minLength: 1
  6012. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6013. type: string
  6014. namespace:
  6015. description: |-
  6016. The namespace the Provider type is in.
  6017. Can only be defined when used in a ClusterSecretStore.
  6018. maxLength: 63
  6019. minLength: 1
  6020. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6021. type: string
  6022. type:
  6023. description: The type of provider to use such as "Secret", or "ConfigMap".
  6024. enum:
  6025. - Secret
  6026. - ConfigMap
  6027. type: string
  6028. required:
  6029. - name
  6030. - type
  6031. type: object
  6032. hostAPI:
  6033. default: https://app.infisical.com/api
  6034. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  6035. type: string
  6036. secretsScope:
  6037. description: SecretsScope defines the scope of the secrets within the workspace
  6038. properties:
  6039. environmentSlug:
  6040. description: EnvironmentSlug is the required slug identifier for the environment.
  6041. type: string
  6042. expandSecretReferences:
  6043. default: true
  6044. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  6045. type: boolean
  6046. includeSecretPath:
  6047. default: false
  6048. description: |-
  6049. IncludeSecretPath indicates whether the secret path should be included as a prefix
  6050. in the secret key. Secrets at the root path (/) are not prefixed.
  6051. type: boolean
  6052. organizationSlug:
  6053. description: |-
  6054. OrganizationSlug is the optional slug that identifies the organization that will be used
  6055. during authentication. Useful for sub-organization setups
  6056. type: string
  6057. projectSlug:
  6058. description: ProjectSlug is the required slug identifier for the project.
  6059. type: string
  6060. recursive:
  6061. default: false
  6062. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  6063. type: boolean
  6064. secretsPath:
  6065. default: /
  6066. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  6067. type: string
  6068. required:
  6069. - environmentSlug
  6070. - projectSlug
  6071. type: object
  6072. required:
  6073. - auth
  6074. - secretsScope
  6075. type: object
  6076. keepersecurity:
  6077. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  6078. properties:
  6079. authRef:
  6080. description: |-
  6081. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6082. In some instances, `key` is a required field.
  6083. properties:
  6084. key:
  6085. description: |-
  6086. A key in the referenced Secret.
  6087. Some instances of this field may be defaulted, in others it may be required.
  6088. maxLength: 253
  6089. minLength: 1
  6090. pattern: ^[-._a-zA-Z0-9]+$
  6091. type: string
  6092. name:
  6093. description: The name of the Secret resource being referred to.
  6094. maxLength: 253
  6095. minLength: 1
  6096. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6097. type: string
  6098. namespace:
  6099. description: |-
  6100. The namespace of the Secret resource being referred to.
  6101. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6102. maxLength: 63
  6103. minLength: 1
  6104. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6105. type: string
  6106. type: object
  6107. folderID:
  6108. type: string
  6109. getByTitleFallback:
  6110. type: boolean
  6111. required:
  6112. - authRef
  6113. type: object
  6114. kubernetes:
  6115. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  6116. properties:
  6117. auth:
  6118. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  6119. maxProperties: 1
  6120. minProperties: 1
  6121. properties:
  6122. cert:
  6123. description: has both clientCert and clientKey as secretKeySelector
  6124. properties:
  6125. clientCert:
  6126. description: |-
  6127. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6128. In some instances, `key` is a required field.
  6129. properties:
  6130. key:
  6131. description: |-
  6132. A key in the referenced Secret.
  6133. Some instances of this field may be defaulted, in others it may be required.
  6134. maxLength: 253
  6135. minLength: 1
  6136. pattern: ^[-._a-zA-Z0-9]+$
  6137. type: string
  6138. name:
  6139. description: The name of the Secret resource being referred to.
  6140. maxLength: 253
  6141. minLength: 1
  6142. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6143. type: string
  6144. namespace:
  6145. description: |-
  6146. The namespace of the Secret resource being referred to.
  6147. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6148. maxLength: 63
  6149. minLength: 1
  6150. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6151. type: string
  6152. type: object
  6153. clientKey:
  6154. description: |-
  6155. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6156. In some instances, `key` is a required field.
  6157. properties:
  6158. key:
  6159. description: |-
  6160. A key in the referenced Secret.
  6161. Some instances of this field may be defaulted, in others it may be required.
  6162. maxLength: 253
  6163. minLength: 1
  6164. pattern: ^[-._a-zA-Z0-9]+$
  6165. type: string
  6166. name:
  6167. description: The name of the Secret resource being referred to.
  6168. maxLength: 253
  6169. minLength: 1
  6170. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6171. type: string
  6172. namespace:
  6173. description: |-
  6174. The namespace of the Secret resource being referred to.
  6175. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6176. maxLength: 63
  6177. minLength: 1
  6178. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6179. type: string
  6180. type: object
  6181. required:
  6182. - clientCert
  6183. - clientKey
  6184. type: object
  6185. serviceAccount:
  6186. description: points to a service account that should be used for authentication
  6187. properties:
  6188. audiences:
  6189. description: |-
  6190. Audience specifies the `aud` claim for the service account token
  6191. Some providers automatically extend the audience field based on well-known annotations for workload
  6192. identity (e.g. IRSA or GCP Workload Identity)
  6193. items:
  6194. type: string
  6195. type: array
  6196. name:
  6197. description: The name of the ServiceAccount resource being referred to.
  6198. maxLength: 253
  6199. minLength: 1
  6200. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6201. type: string
  6202. namespace:
  6203. description: |-
  6204. Namespace of the resource being referred to.
  6205. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6206. maxLength: 63
  6207. minLength: 1
  6208. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6209. type: string
  6210. required:
  6211. - name
  6212. type: object
  6213. token:
  6214. description: use static token to authenticate with
  6215. properties:
  6216. bearerToken:
  6217. description: |-
  6218. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6219. In some instances, `key` is a required field.
  6220. properties:
  6221. key:
  6222. description: |-
  6223. A key in the referenced Secret.
  6224. Some instances of this field may be defaulted, in others it may be required.
  6225. maxLength: 253
  6226. minLength: 1
  6227. pattern: ^[-._a-zA-Z0-9]+$
  6228. type: string
  6229. name:
  6230. description: The name of the Secret resource being referred to.
  6231. maxLength: 253
  6232. minLength: 1
  6233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6234. type: string
  6235. namespace:
  6236. description: |-
  6237. The namespace of the Secret resource being referred to.
  6238. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6239. maxLength: 63
  6240. minLength: 1
  6241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6242. type: string
  6243. type: object
  6244. required:
  6245. - bearerToken
  6246. type: object
  6247. type: object
  6248. authRef:
  6249. description: A reference to a secret that contains the auth information.
  6250. properties:
  6251. key:
  6252. description: |-
  6253. A key in the referenced Secret.
  6254. Some instances of this field may be defaulted, in others it may be required.
  6255. maxLength: 253
  6256. minLength: 1
  6257. pattern: ^[-._a-zA-Z0-9]+$
  6258. type: string
  6259. name:
  6260. description: The name of the Secret resource being referred to.
  6261. maxLength: 253
  6262. minLength: 1
  6263. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6264. type: string
  6265. namespace:
  6266. description: |-
  6267. The namespace of the Secret resource being referred to.
  6268. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6269. maxLength: 63
  6270. minLength: 1
  6271. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6272. type: string
  6273. type: object
  6274. remoteNamespace:
  6275. default: default
  6276. description: Remote namespace to fetch the secrets from
  6277. maxLength: 63
  6278. minLength: 1
  6279. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6280. type: string
  6281. server:
  6282. description: configures the Kubernetes server Address.
  6283. properties:
  6284. caBundle:
  6285. description: CABundle is a base64-encoded CA certificate
  6286. format: byte
  6287. type: string
  6288. caProvider:
  6289. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  6290. properties:
  6291. key:
  6292. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6293. maxLength: 253
  6294. minLength: 1
  6295. pattern: ^[-._a-zA-Z0-9]+$
  6296. type: string
  6297. name:
  6298. description: The name of the object located at the provider type.
  6299. maxLength: 253
  6300. minLength: 1
  6301. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6302. type: string
  6303. namespace:
  6304. description: |-
  6305. The namespace the Provider type is in.
  6306. Can only be defined when used in a ClusterSecretStore.
  6307. maxLength: 63
  6308. minLength: 1
  6309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6310. type: string
  6311. type:
  6312. description: The type of provider to use such as "Secret", or "ConfigMap".
  6313. enum:
  6314. - Secret
  6315. - ConfigMap
  6316. type: string
  6317. required:
  6318. - name
  6319. - type
  6320. type: object
  6321. url:
  6322. default: kubernetes.default
  6323. description: configures the Kubernetes server Address.
  6324. type: string
  6325. type: object
  6326. type: object
  6327. nebiusmysterybox:
  6328. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  6329. properties:
  6330. apiDomain:
  6331. description: NebiusMysterybox API endpoint
  6332. type: string
  6333. auth:
  6334. description: Auth defines parameters to authenticate in MysteryBox
  6335. properties:
  6336. serviceAccountCredsSecretRef:
  6337. description: |-
  6338. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  6339. document with service account credentials used to get an IAM token.
  6340. Expected JSON structure:
  6341. {
  6342. "subject-credentials": {
  6343. "alg": "RS256",
  6344. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  6345. "kid": "<public-key-id>",
  6346. "iss": "<issuer-service-account-id>",
  6347. "sub": "<subject-service-account-id>"
  6348. }
  6349. }
  6350. properties:
  6351. key:
  6352. description: |-
  6353. A key in the referenced Secret.
  6354. Some instances of this field may be defaulted, in others it may be required.
  6355. maxLength: 253
  6356. minLength: 1
  6357. pattern: ^[-._a-zA-Z0-9]+$
  6358. type: string
  6359. name:
  6360. description: The name of the Secret resource being referred to.
  6361. maxLength: 253
  6362. minLength: 1
  6363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6364. type: string
  6365. namespace:
  6366. description: |-
  6367. The namespace of the Secret resource being referred to.
  6368. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6369. maxLength: 63
  6370. minLength: 1
  6371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6372. type: string
  6373. type: object
  6374. tokenSecretRef:
  6375. description: Token authenticates with Nebius Mysterybox by presenting a token.
  6376. properties:
  6377. key:
  6378. description: |-
  6379. A key in the referenced Secret.
  6380. Some instances of this field may be defaulted, in others it may be required.
  6381. maxLength: 253
  6382. minLength: 1
  6383. pattern: ^[-._a-zA-Z0-9]+$
  6384. type: string
  6385. name:
  6386. description: The name of the Secret resource being referred to.
  6387. maxLength: 253
  6388. minLength: 1
  6389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6390. type: string
  6391. namespace:
  6392. description: |-
  6393. The namespace of the Secret resource being referred to.
  6394. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6395. maxLength: 63
  6396. minLength: 1
  6397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6398. type: string
  6399. type: object
  6400. workloadIdentity:
  6401. description: WorkloadIdentity defines configuration for workload identity authentication to Nebius IAM.
  6402. properties:
  6403. iamServiceAccountID:
  6404. description: |-
  6405. IAMServiceAccountID is the Nebius IAM service account identifier that the
  6406. federated Kubernetes service account should impersonate during token exchange.
  6407. example: serviceaccount-e00example
  6408. minLength: 1
  6409. pattern: ^serviceaccount-[a-z][a-z0-9]{2}
  6410. type: string
  6411. serviceAccountRef:
  6412. description: |-
  6413. ServiceAccountRef references a Kubernetes ServiceAccount used to request a
  6414. temporary JWT via the TokenRequest API. The JWT is then exchanged for a
  6415. Nebius IAM token using workload federation.
  6416. properties:
  6417. audiences:
  6418. description: |-
  6419. Audience specifies the `aud` claim for the service account token
  6420. Some providers automatically extend the audience field based on well-known annotations for workload
  6421. identity (e.g. IRSA or GCP Workload Identity)
  6422. items:
  6423. type: string
  6424. type: array
  6425. name:
  6426. description: The name of the ServiceAccount resource being referred to.
  6427. maxLength: 253
  6428. minLength: 1
  6429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6430. type: string
  6431. namespace:
  6432. description: |-
  6433. Namespace of the resource being referred to.
  6434. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6435. maxLength: 63
  6436. minLength: 1
  6437. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6438. type: string
  6439. required:
  6440. - name
  6441. type: object
  6442. required:
  6443. - iamServiceAccountID
  6444. - serviceAccountRef
  6445. type: object
  6446. type: object
  6447. x-kubernetes-validations:
  6448. - message: exactly one of serviceAccountCredsSecretRef, tokenSecretRef, or workloadIdentity must be set
  6449. rule: '(has(self.serviceAccountCredsSecretRef) && has(self.serviceAccountCredsSecretRef.name) && size(self.serviceAccountCredsSecretRef.name) > 0 ? 1 : 0) + (has(self.tokenSecretRef) && has(self.tokenSecretRef.name) && size(self.tokenSecretRef.name) > 0 ? 1 : 0) + (has(self.workloadIdentity) ? 1 : 0) == 1'
  6450. caProvider:
  6451. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  6452. properties:
  6453. certSecretRef:
  6454. description: |-
  6455. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6456. In some instances, `key` is a required field.
  6457. properties:
  6458. key:
  6459. description: |-
  6460. A key in the referenced Secret.
  6461. Some instances of this field may be defaulted, in others it may be required.
  6462. maxLength: 253
  6463. minLength: 1
  6464. pattern: ^[-._a-zA-Z0-9]+$
  6465. type: string
  6466. name:
  6467. description: The name of the Secret resource being referred to.
  6468. maxLength: 253
  6469. minLength: 1
  6470. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6471. type: string
  6472. namespace:
  6473. description: |-
  6474. The namespace of the Secret resource being referred to.
  6475. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6476. maxLength: 63
  6477. minLength: 1
  6478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6479. type: string
  6480. type: object
  6481. type: object
  6482. required:
  6483. - apiDomain
  6484. - auth
  6485. type: object
  6486. ngrok:
  6487. description: Ngrok configures this store to sync secrets using the ngrok provider.
  6488. properties:
  6489. apiUrl:
  6490. default: https://api.ngrok.com
  6491. description: APIURL is the URL of the ngrok API.
  6492. type: string
  6493. auth:
  6494. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  6495. maxProperties: 1
  6496. minProperties: 1
  6497. properties:
  6498. apiKey:
  6499. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  6500. properties:
  6501. secretRef:
  6502. description: SecretRef is a reference to a secret containing the ngrok API key.
  6503. properties:
  6504. key:
  6505. description: |-
  6506. A key in the referenced Secret.
  6507. Some instances of this field may be defaulted, in others it may be required.
  6508. maxLength: 253
  6509. minLength: 1
  6510. pattern: ^[-._a-zA-Z0-9]+$
  6511. type: string
  6512. name:
  6513. description: The name of the Secret resource being referred to.
  6514. maxLength: 253
  6515. minLength: 1
  6516. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6517. type: string
  6518. namespace:
  6519. description: |-
  6520. The namespace of the Secret resource being referred to.
  6521. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6522. maxLength: 63
  6523. minLength: 1
  6524. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6525. type: string
  6526. type: object
  6527. type: object
  6528. type: object
  6529. vault:
  6530. description: Vault configures the ngrok vault to sync secrets with.
  6531. properties:
  6532. name:
  6533. description: Name is the name of the ngrok vault to sync secrets with.
  6534. type: string
  6535. required:
  6536. - name
  6537. type: object
  6538. required:
  6539. - auth
  6540. - vault
  6541. type: object
  6542. onboardbase:
  6543. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  6544. properties:
  6545. apiHost:
  6546. default: https://public.onboardbase.com/api/v1/
  6547. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  6548. type: string
  6549. auth:
  6550. description: Auth configures how the Operator authenticates with the Onboardbase API
  6551. properties:
  6552. apiKeyRef:
  6553. description: |-
  6554. OnboardbaseAPIKey is the APIKey generated by an admin account.
  6555. It is used to recognize and authorize access to a project and environment within onboardbase
  6556. properties:
  6557. key:
  6558. description: |-
  6559. A key in the referenced Secret.
  6560. Some instances of this field may be defaulted, in others it may be required.
  6561. maxLength: 253
  6562. minLength: 1
  6563. pattern: ^[-._a-zA-Z0-9]+$
  6564. type: string
  6565. name:
  6566. description: The name of the Secret resource being referred to.
  6567. maxLength: 253
  6568. minLength: 1
  6569. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6570. type: string
  6571. namespace:
  6572. description: |-
  6573. The namespace of the Secret resource being referred to.
  6574. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6575. maxLength: 63
  6576. minLength: 1
  6577. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6578. type: string
  6579. type: object
  6580. passcodeRef:
  6581. description: OnboardbasePasscode is the passcode attached to the API Key
  6582. properties:
  6583. key:
  6584. description: |-
  6585. A key in the referenced Secret.
  6586. Some instances of this field may be defaulted, in others it may be required.
  6587. maxLength: 253
  6588. minLength: 1
  6589. pattern: ^[-._a-zA-Z0-9]+$
  6590. type: string
  6591. name:
  6592. description: The name of the Secret resource being referred to.
  6593. maxLength: 253
  6594. minLength: 1
  6595. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6596. type: string
  6597. namespace:
  6598. description: |-
  6599. The namespace of the Secret resource being referred to.
  6600. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6601. maxLength: 63
  6602. minLength: 1
  6603. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6604. type: string
  6605. type: object
  6606. required:
  6607. - apiKeyRef
  6608. - passcodeRef
  6609. type: object
  6610. environment:
  6611. default: development
  6612. description: Environment is the name of an environmnent within a project to pull the secrets from
  6613. type: string
  6614. project:
  6615. default: development
  6616. description: Project is an onboardbase project that the secrets should be pulled from
  6617. type: string
  6618. required:
  6619. - apiHost
  6620. - auth
  6621. - environment
  6622. - project
  6623. type: object
  6624. onepassword:
  6625. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  6626. properties:
  6627. auth:
  6628. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  6629. properties:
  6630. secretRef:
  6631. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  6632. properties:
  6633. connectTokenSecretRef:
  6634. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  6635. properties:
  6636. key:
  6637. description: |-
  6638. A key in the referenced Secret.
  6639. Some instances of this field may be defaulted, in others it may be required.
  6640. maxLength: 253
  6641. minLength: 1
  6642. pattern: ^[-._a-zA-Z0-9]+$
  6643. type: string
  6644. name:
  6645. description: The name of the Secret resource being referred to.
  6646. maxLength: 253
  6647. minLength: 1
  6648. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6649. type: string
  6650. namespace:
  6651. description: |-
  6652. The namespace of the Secret resource being referred to.
  6653. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6654. maxLength: 63
  6655. minLength: 1
  6656. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6657. type: string
  6658. type: object
  6659. required:
  6660. - connectTokenSecretRef
  6661. type: object
  6662. required:
  6663. - secretRef
  6664. type: object
  6665. connectHost:
  6666. description: ConnectHost defines the OnePassword Connect Server to connect to
  6667. type: string
  6668. vaults:
  6669. additionalProperties:
  6670. type: integer
  6671. description: Vaults defines which OnePassword vaults to search in which order
  6672. type: object
  6673. required:
  6674. - auth
  6675. - connectHost
  6676. - vaults
  6677. type: object
  6678. onepasswordSDK:
  6679. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  6680. properties:
  6681. auth:
  6682. description: Auth defines the information necessary to authenticate against OnePassword API.
  6683. properties:
  6684. serviceAccountSecretRef:
  6685. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  6686. properties:
  6687. key:
  6688. description: |-
  6689. A key in the referenced Secret.
  6690. Some instances of this field may be defaulted, in others it may be required.
  6691. maxLength: 253
  6692. minLength: 1
  6693. pattern: ^[-._a-zA-Z0-9]+$
  6694. type: string
  6695. name:
  6696. description: The name of the Secret resource being referred to.
  6697. maxLength: 253
  6698. minLength: 1
  6699. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6700. type: string
  6701. namespace:
  6702. description: |-
  6703. The namespace of the Secret resource being referred to.
  6704. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6705. maxLength: 63
  6706. minLength: 1
  6707. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6708. type: string
  6709. type: object
  6710. required:
  6711. - serviceAccountSecretRef
  6712. type: object
  6713. cache:
  6714. description: |-
  6715. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  6716. When enabled, secrets are cached with the specified TTL.
  6717. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  6718. If omitted, caching is disabled (default).
  6719. cache: {} is a valid option to set.
  6720. properties:
  6721. maxSize:
  6722. default: 100
  6723. description: |-
  6724. MaxSize is the maximum number of secrets to cache.
  6725. When the cache is full, least-recently-used entries are evicted.
  6726. minimum: 1
  6727. type: integer
  6728. ttl:
  6729. default: 5m
  6730. description: |-
  6731. TTL is the time-to-live for cached secrets.
  6732. Format: duration string (e.g., "5m", "1h", "30s")
  6733. type: string
  6734. type: object
  6735. environment:
  6736. description: |-
  6737. Environment defines the 1Password Environment ID to read variables from.
  6738. Environments are read-only: PushSecret, DeleteSecret, and SecretExists return an error when set.
  6739. Mutually exclusive with Vault.
  6740. type: string
  6741. integrationInfo:
  6742. description: |-
  6743. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  6744. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  6745. properties:
  6746. name:
  6747. default: 1Password SDK
  6748. description: Name defaults to "1Password SDK".
  6749. type: string
  6750. version:
  6751. default: v1.0.0
  6752. description: Version defaults to "v1.0.0".
  6753. type: string
  6754. type: object
  6755. vault:
  6756. description: |-
  6757. Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  6758. Mutually exclusive with Environment.
  6759. type: string
  6760. required:
  6761. - auth
  6762. type: object
  6763. x-kubernetes-validations:
  6764. - message: at most one of the fields in [vault environment] may be set
  6765. rule: '[has(self.vault),has(self.environment)].filter(x,x==true).size() <= 1'
  6766. openBao:
  6767. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  6768. properties:
  6769. auth:
  6770. description: Auth configures how secret-manager authenticates with the OpenBao server.
  6771. properties:
  6772. appRole:
  6773. description: |-
  6774. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  6775. with the role and secret stored in a Kubernetes Secret resource.
  6776. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  6777. properties:
  6778. path:
  6779. default: approle
  6780. description: |-
  6781. Path where the App Role authentication backend is mounted
  6782. in OpenBao, e.g: "approle"
  6783. type: string
  6784. roleId:
  6785. description: |-
  6786. RoleID configured in the App Role authentication backend when setting
  6787. up the authentication backend in OpenBao.
  6788. minLength: 1
  6789. type: string
  6790. roleRef:
  6791. description: |-
  6792. Reference to a key in a Secret that contains the App Role ID used
  6793. to authenticate with OpenBao.
  6794. The `key` field must be specified and denotes which entry within the Secret
  6795. resource is used as the app role id.
  6796. properties:
  6797. key:
  6798. description: |-
  6799. A key in the referenced Secret.
  6800. Some instances of this field may be defaulted, in others it may be required.
  6801. maxLength: 253
  6802. minLength: 1
  6803. pattern: ^[-._a-zA-Z0-9]+$
  6804. type: string
  6805. name:
  6806. description: The name of the Secret resource being referred to.
  6807. maxLength: 253
  6808. minLength: 1
  6809. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6810. type: string
  6811. namespace:
  6812. description: |-
  6813. The namespace of the Secret resource being referred to.
  6814. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6815. maxLength: 63
  6816. minLength: 1
  6817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6818. type: string
  6819. type: object
  6820. secretRef:
  6821. description: |-
  6822. Reference to a key in a Secret that contains the App Role secret used
  6823. to authenticate with OpenBao.
  6824. The `key` field must be specified and denotes which entry within the Secret
  6825. resource is used as the app role secret.
  6826. properties:
  6827. key:
  6828. description: |-
  6829. A key in the referenced Secret.
  6830. Some instances of this field may be defaulted, in others it may be required.
  6831. maxLength: 253
  6832. minLength: 1
  6833. pattern: ^[-._a-zA-Z0-9]+$
  6834. type: string
  6835. name:
  6836. description: The name of the Secret resource being referred to.
  6837. maxLength: 253
  6838. minLength: 1
  6839. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6840. type: string
  6841. namespace:
  6842. description: |-
  6843. The namespace of the Secret resource being referred to.
  6844. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6845. maxLength: 63
  6846. minLength: 1
  6847. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6848. type: string
  6849. type: object
  6850. required:
  6851. - path
  6852. - secretRef
  6853. type: object
  6854. x-kubernetes-validations:
  6855. - message: exactly one of the fields in [roleId roleRef] must be set
  6856. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  6857. kubernetes:
  6858. description: |-
  6859. Kubernetes authenticates with OpenBao by passing a ServiceAccount
  6860. token to the [Kubernetes auth mechanism].
  6861. [Kubernetes auth mechanism]: https://openbao.org/docs/auth/kubernetes/
  6862. properties:
  6863. path:
  6864. default: kubernetes
  6865. description: |-
  6866. Path where the Kubernetes authentication backend is mounted in OpenBao, e.g:
  6867. "kubernetes"
  6868. type: string
  6869. role:
  6870. description: |-
  6871. A required field containing the OpenBao Role to assume. A Role binds a
  6872. Kubernetes ServiceAccount with a set of OpenBao policies.
  6873. minLength: 1
  6874. type: string
  6875. secretRef:
  6876. description: |-
  6877. Optional secret field containing a Kubernetes ServiceAccount JWT used
  6878. for authenticating with OpenBao. If a name is specified without a key,
  6879. `token` is the default.
  6880. properties:
  6881. key:
  6882. description: |-
  6883. A key in the referenced Secret.
  6884. Some instances of this field may be defaulted, in others it may be required.
  6885. maxLength: 253
  6886. minLength: 1
  6887. pattern: ^[-._a-zA-Z0-9]+$
  6888. type: string
  6889. name:
  6890. description: The name of the Secret resource being referred to.
  6891. maxLength: 253
  6892. minLength: 1
  6893. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6894. type: string
  6895. namespace:
  6896. description: |-
  6897. The namespace of the Secret resource being referred to.
  6898. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6899. maxLength: 63
  6900. minLength: 1
  6901. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6902. type: string
  6903. type: object
  6904. serviceAccountRef:
  6905. description: |-
  6906. Optional service account field containing the name of a Kubernetes ServiceAccount.
  6907. If the service account is specified, a token will be requested from the Kubernetes
  6908. TokenRequest API for authenticating with OpenBao.
  6909. Any configured audiences will be passed to the TokenRequest as-is.
  6910. properties:
  6911. audiences:
  6912. description: |-
  6913. Audience specifies the `aud` claim for the service account token
  6914. Some providers automatically extend the audience field based on well-known annotations for workload
  6915. identity (e.g. IRSA or GCP Workload Identity)
  6916. items:
  6917. type: string
  6918. type: array
  6919. name:
  6920. description: The name of the ServiceAccount resource being referred to.
  6921. maxLength: 253
  6922. minLength: 1
  6923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6924. type: string
  6925. namespace:
  6926. description: |-
  6927. Namespace of the resource being referred to.
  6928. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6929. maxLength: 63
  6930. minLength: 1
  6931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6932. type: string
  6933. required:
  6934. - name
  6935. type: object
  6936. required:
  6937. - path
  6938. - role
  6939. type: object
  6940. x-kubernetes-validations:
  6941. - message: exactly one of the fields in [serviceAccountRef secretRef] must be set
  6942. rule: '[has(self.serviceAccountRef),has(self.secretRef)].filter(x,x==true).size() == 1'
  6943. namespace:
  6944. description: |-
  6945. Name of the [OpenBao Namespace] to authenticate to. This can be different
  6946. than the namespace your secret is in. Namespaces is a set of features
  6947. within OpenBao that allows OpenBao environments to support secure
  6948. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  6949. if set, or empty otherwise
  6950. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6951. type: string
  6952. tokenSecretRef:
  6953. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  6954. properties:
  6955. key:
  6956. description: |-
  6957. A key in the referenced Secret.
  6958. Some instances of this field may be defaulted, in others it may be required.
  6959. maxLength: 253
  6960. minLength: 1
  6961. pattern: ^[-._a-zA-Z0-9]+$
  6962. type: string
  6963. name:
  6964. description: The name of the Secret resource being referred to.
  6965. maxLength: 253
  6966. minLength: 1
  6967. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6968. type: string
  6969. namespace:
  6970. description: |-
  6971. The namespace of the Secret resource being referred to.
  6972. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6973. maxLength: 63
  6974. minLength: 1
  6975. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6976. type: string
  6977. type: object
  6978. userPass:
  6979. description: UserPass authenticates with OpenBao by passing a username/password pair
  6980. properties:
  6981. path:
  6982. default: userpass
  6983. description: |-
  6984. Path where the UserPassword authentication backend is mounted
  6985. in OpenBao, e.g: "userpass"
  6986. type: string
  6987. secretRef:
  6988. description: |-
  6989. SecretRef to a key in a Secret resource containing password for the user
  6990. used to authenticate with OpenBao using the [UserPass authentication
  6991. method]
  6992. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6993. properties:
  6994. key:
  6995. description: |-
  6996. A key in the referenced Secret.
  6997. Some instances of this field may be defaulted, in others it may be required.
  6998. maxLength: 253
  6999. minLength: 1
  7000. pattern: ^[-._a-zA-Z0-9]+$
  7001. type: string
  7002. name:
  7003. description: The name of the Secret resource being referred to.
  7004. maxLength: 253
  7005. minLength: 1
  7006. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7007. type: string
  7008. namespace:
  7009. description: |-
  7010. The namespace of the Secret resource being referred to.
  7011. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7012. maxLength: 63
  7013. minLength: 1
  7014. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7015. type: string
  7016. type: object
  7017. username:
  7018. description: |-
  7019. Username is a username used to authenticate using the [UserPass
  7020. authentication method]
  7021. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  7022. type: string
  7023. required:
  7024. - path
  7025. - username
  7026. type: object
  7027. type: object
  7028. x-kubernetes-validations:
  7029. - message: exactly one of the fields in [appRole tokenSecretRef userPass kubernetes] must be set
  7030. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass),has(self.kubernetes)].filter(x,x==true).size() == 1'
  7031. caBundle:
  7032. description: |-
  7033. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  7034. this and `caProvider` are not set the system root certificates are used
  7035. to validate the TLS connection.
  7036. format: byte
  7037. type: string
  7038. caProvider:
  7039. description: |-
  7040. The provider for the CA bundle to use to validate OpenBao server
  7041. certificate. If this and `caBundle` are not set the system root
  7042. certificates are used to validate the TLS connection.
  7043. properties:
  7044. key:
  7045. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7046. maxLength: 253
  7047. minLength: 1
  7048. pattern: ^[-._a-zA-Z0-9]+$
  7049. type: string
  7050. name:
  7051. description: The name of the object located at the provider type.
  7052. maxLength: 253
  7053. minLength: 1
  7054. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7055. type: string
  7056. namespace:
  7057. description: |-
  7058. The namespace the Provider type is in.
  7059. Can only be defined when used in a ClusterSecretStore.
  7060. maxLength: 63
  7061. minLength: 1
  7062. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7063. type: string
  7064. type:
  7065. description: The type of provider to use such as "Secret", or "ConfigMap".
  7066. enum:
  7067. - Secret
  7068. - ConfigMap
  7069. type: string
  7070. required:
  7071. - name
  7072. - type
  7073. type: object
  7074. namespace:
  7075. description: |-
  7076. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  7077. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  7078. e.g: "ns1".
  7079. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  7080. type: string
  7081. path:
  7082. description: |-
  7083. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  7084. "secret". The v2 KV secret engine version specific "/data" path suffix
  7085. for fetching secrets from OpenBao is optional and will be appended
  7086. if not present in specified path.
  7087. type: string
  7088. server:
  7089. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  7090. type: string
  7091. version:
  7092. default: v2
  7093. description: |-
  7094. Version is the OpenBao KV secret engine version. This can be either "v1" or
  7095. "v2". Version defaults to "v2".
  7096. enum:
  7097. - v1
  7098. - v2
  7099. type: string
  7100. required:
  7101. - server
  7102. type: object
  7103. x-kubernetes-validations:
  7104. - message: at most one of the fields in [caBundle caProvider] may be set
  7105. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  7106. oracle:
  7107. description: Oracle configures this store to sync secrets using Oracle Vault provider
  7108. properties:
  7109. auth:
  7110. description: |-
  7111. Auth configures how secret-manager authenticates with the Oracle Vault.
  7112. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  7113. properties:
  7114. secretRef:
  7115. description: SecretRef to pass through sensitive information.
  7116. properties:
  7117. fingerprint:
  7118. description: Fingerprint is the fingerprint of the API private key.
  7119. properties:
  7120. key:
  7121. description: |-
  7122. A key in the referenced Secret.
  7123. Some instances of this field may be defaulted, in others it may be required.
  7124. maxLength: 253
  7125. minLength: 1
  7126. pattern: ^[-._a-zA-Z0-9]+$
  7127. type: string
  7128. name:
  7129. description: The name of the Secret resource being referred to.
  7130. maxLength: 253
  7131. minLength: 1
  7132. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7133. type: string
  7134. namespace:
  7135. description: |-
  7136. The namespace of the Secret resource being referred to.
  7137. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7138. maxLength: 63
  7139. minLength: 1
  7140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7141. type: string
  7142. type: object
  7143. privatekey:
  7144. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  7145. properties:
  7146. key:
  7147. description: |-
  7148. A key in the referenced Secret.
  7149. Some instances of this field may be defaulted, in others it may be required.
  7150. maxLength: 253
  7151. minLength: 1
  7152. pattern: ^[-._a-zA-Z0-9]+$
  7153. type: string
  7154. name:
  7155. description: The name of the Secret resource being referred to.
  7156. maxLength: 253
  7157. minLength: 1
  7158. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7159. type: string
  7160. namespace:
  7161. description: |-
  7162. The namespace of the Secret resource being referred to.
  7163. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7164. maxLength: 63
  7165. minLength: 1
  7166. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7167. type: string
  7168. type: object
  7169. required:
  7170. - fingerprint
  7171. - privatekey
  7172. type: object
  7173. tenancy:
  7174. description: Tenancy is the tenancy OCID where user is located.
  7175. type: string
  7176. user:
  7177. description: User is an access OCID specific to the account.
  7178. type: string
  7179. required:
  7180. - secretRef
  7181. - tenancy
  7182. - user
  7183. type: object
  7184. compartment:
  7185. description: |-
  7186. Compartment is the vault compartment OCID.
  7187. Required for PushSecret
  7188. type: string
  7189. encryptionKey:
  7190. description: |-
  7191. EncryptionKey is the OCID of the encryption key within the vault.
  7192. Required for PushSecret
  7193. type: string
  7194. principalType:
  7195. description: |-
  7196. The type of principal to use for authentication. If left blank, the Auth struct will
  7197. determine the principal type. This optional field must be specified if using
  7198. workload identity.
  7199. enum:
  7200. - ""
  7201. - UserPrincipal
  7202. - InstancePrincipal
  7203. - Workload
  7204. type: string
  7205. region:
  7206. description: Region is the region where vault is located.
  7207. type: string
  7208. serviceAccountRef:
  7209. description: |-
  7210. ServiceAccountRef specified the service account
  7211. that should be used when authenticating with WorkloadIdentity.
  7212. properties:
  7213. audiences:
  7214. description: |-
  7215. Audience specifies the `aud` claim for the service account token
  7216. Some providers automatically extend the audience field based on well-known annotations for workload
  7217. identity (e.g. IRSA or GCP Workload Identity)
  7218. items:
  7219. type: string
  7220. type: array
  7221. name:
  7222. description: The name of the ServiceAccount resource being referred to.
  7223. maxLength: 253
  7224. minLength: 1
  7225. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7226. type: string
  7227. namespace:
  7228. description: |-
  7229. Namespace of the resource being referred to.
  7230. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7231. maxLength: 63
  7232. minLength: 1
  7233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7234. type: string
  7235. required:
  7236. - name
  7237. type: object
  7238. vault:
  7239. description: Vault is the vault's OCID of the specific vault where secret is located.
  7240. type: string
  7241. required:
  7242. - region
  7243. - vault
  7244. type: object
  7245. ovh:
  7246. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  7247. properties:
  7248. auth:
  7249. description: Authentication method (mtls or token).
  7250. properties:
  7251. mtls:
  7252. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  7253. properties:
  7254. caBundle:
  7255. format: byte
  7256. type: string
  7257. caProvider:
  7258. description: |-
  7259. CAProvider provides a custom certificate authority for accessing the provider's store.
  7260. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  7261. properties:
  7262. key:
  7263. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7264. maxLength: 253
  7265. minLength: 1
  7266. pattern: ^[-._a-zA-Z0-9]+$
  7267. type: string
  7268. name:
  7269. description: The name of the object located at the provider type.
  7270. maxLength: 253
  7271. minLength: 1
  7272. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7273. type: string
  7274. namespace:
  7275. description: |-
  7276. The namespace the Provider type is in.
  7277. Can only be defined when used in a ClusterSecretStore.
  7278. maxLength: 63
  7279. minLength: 1
  7280. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7281. type: string
  7282. type:
  7283. description: The type of provider to use such as "Secret", or "ConfigMap".
  7284. enum:
  7285. - Secret
  7286. - ConfigMap
  7287. type: string
  7288. required:
  7289. - name
  7290. - type
  7291. type: object
  7292. certSecretRef:
  7293. description: |-
  7294. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7295. In some instances, `key` is a required field.
  7296. properties:
  7297. key:
  7298. description: |-
  7299. A key in the referenced Secret.
  7300. Some instances of this field may be defaulted, in others it may be required.
  7301. maxLength: 253
  7302. minLength: 1
  7303. pattern: ^[-._a-zA-Z0-9]+$
  7304. type: string
  7305. name:
  7306. description: The name of the Secret resource being referred to.
  7307. maxLength: 253
  7308. minLength: 1
  7309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7310. type: string
  7311. namespace:
  7312. description: |-
  7313. The namespace of the Secret resource being referred to.
  7314. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7315. maxLength: 63
  7316. minLength: 1
  7317. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7318. type: string
  7319. type: object
  7320. keySecretRef:
  7321. description: |-
  7322. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7323. In some instances, `key` is a required field.
  7324. properties:
  7325. key:
  7326. description: |-
  7327. A key in the referenced Secret.
  7328. Some instances of this field may be defaulted, in others it may be required.
  7329. maxLength: 253
  7330. minLength: 1
  7331. pattern: ^[-._a-zA-Z0-9]+$
  7332. type: string
  7333. name:
  7334. description: The name of the Secret resource being referred to.
  7335. maxLength: 253
  7336. minLength: 1
  7337. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7338. type: string
  7339. namespace:
  7340. description: |-
  7341. The namespace of the Secret resource being referred to.
  7342. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7343. maxLength: 63
  7344. minLength: 1
  7345. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7346. type: string
  7347. type: object
  7348. required:
  7349. - certSecretRef
  7350. - keySecretRef
  7351. type: object
  7352. token:
  7353. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  7354. properties:
  7355. tokenSecretRef:
  7356. description: |-
  7357. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7358. In some instances, `key` is a required field.
  7359. properties:
  7360. key:
  7361. description: |-
  7362. A key in the referenced Secret.
  7363. Some instances of this field may be defaulted, in others it may be required.
  7364. maxLength: 253
  7365. minLength: 1
  7366. pattern: ^[-._a-zA-Z0-9]+$
  7367. type: string
  7368. name:
  7369. description: The name of the Secret resource being referred to.
  7370. maxLength: 253
  7371. minLength: 1
  7372. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7373. type: string
  7374. namespace:
  7375. description: |-
  7376. The namespace of the Secret resource being referred to.
  7377. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7378. maxLength: 63
  7379. minLength: 1
  7380. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7381. type: string
  7382. type: object
  7383. required:
  7384. - tokenSecretRef
  7385. type: object
  7386. type: object
  7387. casRequired:
  7388. description: 'Enables or disables check-and-set (CAS) (default: false).'
  7389. type: boolean
  7390. okmsTimeout:
  7391. default: 30
  7392. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  7393. format: int32
  7394. minimum: 1
  7395. type: integer
  7396. okmsid:
  7397. description: specifies the OKMS ID.
  7398. type: string
  7399. server:
  7400. description: specifies the OKMS server endpoint.
  7401. type: string
  7402. required:
  7403. - auth
  7404. - okmsid
  7405. - server
  7406. type: object
  7407. passbolt:
  7408. description: |-
  7409. PassboltProvider provides access to Passbolt secrets manager.
  7410. See: https://www.passbolt.com.
  7411. properties:
  7412. auth:
  7413. description: Auth defines the information necessary to authenticate against Passbolt Server
  7414. properties:
  7415. passwordSecretRef:
  7416. description: |-
  7417. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7418. In some instances, `key` is a required field.
  7419. properties:
  7420. key:
  7421. description: |-
  7422. A key in the referenced Secret.
  7423. Some instances of this field may be defaulted, in others it may be required.
  7424. maxLength: 253
  7425. minLength: 1
  7426. pattern: ^[-._a-zA-Z0-9]+$
  7427. type: string
  7428. name:
  7429. description: The name of the Secret resource being referred to.
  7430. maxLength: 253
  7431. minLength: 1
  7432. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7433. type: string
  7434. namespace:
  7435. description: |-
  7436. The namespace of the Secret resource being referred to.
  7437. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7438. maxLength: 63
  7439. minLength: 1
  7440. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7441. type: string
  7442. type: object
  7443. privateKeySecretRef:
  7444. description: |-
  7445. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7446. In some instances, `key` is a required field.
  7447. properties:
  7448. key:
  7449. description: |-
  7450. A key in the referenced Secret.
  7451. Some instances of this field may be defaulted, in others it may be required.
  7452. maxLength: 253
  7453. minLength: 1
  7454. pattern: ^[-._a-zA-Z0-9]+$
  7455. type: string
  7456. name:
  7457. description: The name of the Secret resource being referred to.
  7458. maxLength: 253
  7459. minLength: 1
  7460. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7461. type: string
  7462. namespace:
  7463. description: |-
  7464. The namespace of the Secret resource being referred to.
  7465. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7466. maxLength: 63
  7467. minLength: 1
  7468. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7469. type: string
  7470. type: object
  7471. required:
  7472. - passwordSecretRef
  7473. - privateKeySecretRef
  7474. type: object
  7475. caBundle:
  7476. description: |-
  7477. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  7478. if the Host URL is using HTTPS protocol. If not set the system root certificates
  7479. are used to validate the TLS connection.
  7480. format: byte
  7481. type: string
  7482. caProvider:
  7483. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  7484. properties:
  7485. key:
  7486. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7487. maxLength: 253
  7488. minLength: 1
  7489. pattern: ^[-._a-zA-Z0-9]+$
  7490. type: string
  7491. name:
  7492. description: The name of the object located at the provider type.
  7493. maxLength: 253
  7494. minLength: 1
  7495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7496. type: string
  7497. namespace:
  7498. description: |-
  7499. The namespace the Provider type is in.
  7500. Can only be defined when used in a ClusterSecretStore.
  7501. maxLength: 63
  7502. minLength: 1
  7503. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7504. type: string
  7505. type:
  7506. description: The type of provider to use such as "Secret", or "ConfigMap".
  7507. enum:
  7508. - Secret
  7509. - ConfigMap
  7510. type: string
  7511. required:
  7512. - name
  7513. - type
  7514. type: object
  7515. host:
  7516. description: Host defines the Passbolt Server to connect to
  7517. type: string
  7518. required:
  7519. - auth
  7520. - host
  7521. type: object
  7522. passworddepot:
  7523. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  7524. properties:
  7525. auth:
  7526. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  7527. properties:
  7528. secretRef:
  7529. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  7530. properties:
  7531. credentials:
  7532. description: Username / Password is used for authentication.
  7533. properties:
  7534. key:
  7535. description: |-
  7536. A key in the referenced Secret.
  7537. Some instances of this field may be defaulted, in others it may be required.
  7538. maxLength: 253
  7539. minLength: 1
  7540. pattern: ^[-._a-zA-Z0-9]+$
  7541. type: string
  7542. name:
  7543. description: The name of the Secret resource being referred to.
  7544. maxLength: 253
  7545. minLength: 1
  7546. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7547. type: string
  7548. namespace:
  7549. description: |-
  7550. The namespace of the Secret resource being referred to.
  7551. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7552. maxLength: 63
  7553. minLength: 1
  7554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7555. type: string
  7556. type: object
  7557. type: object
  7558. required:
  7559. - secretRef
  7560. type: object
  7561. database:
  7562. description: Database to use as source
  7563. type: string
  7564. host:
  7565. description: URL configures the Password Depot instance URL.
  7566. type: string
  7567. required:
  7568. - auth
  7569. - database
  7570. - host
  7571. type: object
  7572. previder:
  7573. description: Previder configures this store to sync secrets using the Previder provider
  7574. properties:
  7575. auth:
  7576. description: PreviderAuth contains a secretRef for credentials.
  7577. properties:
  7578. secretRef:
  7579. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  7580. properties:
  7581. accessToken:
  7582. description: The AccessToken is used for authentication
  7583. properties:
  7584. key:
  7585. description: |-
  7586. A key in the referenced Secret.
  7587. Some instances of this field may be defaulted, in others it may be required.
  7588. maxLength: 253
  7589. minLength: 1
  7590. pattern: ^[-._a-zA-Z0-9]+$
  7591. type: string
  7592. name:
  7593. description: The name of the Secret resource being referred to.
  7594. maxLength: 253
  7595. minLength: 1
  7596. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7597. type: string
  7598. namespace:
  7599. description: |-
  7600. The namespace of the Secret resource being referred to.
  7601. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7602. maxLength: 63
  7603. minLength: 1
  7604. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7605. type: string
  7606. type: object
  7607. required:
  7608. - accessToken
  7609. type: object
  7610. type: object
  7611. baseUri:
  7612. type: string
  7613. required:
  7614. - auth
  7615. type: object
  7616. pulumi:
  7617. description: Pulumi configures this store to sync secrets using the Pulumi provider
  7618. properties:
  7619. accessToken:
  7620. description: |-
  7621. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  7622. Deprecated: Use auth.accessToken instead.
  7623. properties:
  7624. secretRef:
  7625. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7626. properties:
  7627. key:
  7628. description: |-
  7629. A key in the referenced Secret.
  7630. Some instances of this field may be defaulted, in others it may be required.
  7631. maxLength: 253
  7632. minLength: 1
  7633. pattern: ^[-._a-zA-Z0-9]+$
  7634. type: string
  7635. name:
  7636. description: The name of the Secret resource being referred to.
  7637. maxLength: 253
  7638. minLength: 1
  7639. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7640. type: string
  7641. namespace:
  7642. description: |-
  7643. The namespace of the Secret resource being referred to.
  7644. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7645. maxLength: 63
  7646. minLength: 1
  7647. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7648. type: string
  7649. type: object
  7650. type: object
  7651. apiUrl:
  7652. default: https://api.pulumi.com/api/esc
  7653. description: APIURL is the URL of the Pulumi API.
  7654. type: string
  7655. auth:
  7656. description: |-
  7657. Auth configures how the Operator authenticates with the Pulumi API.
  7658. Either auth or the deprecated accessToken field must be specified.
  7659. properties:
  7660. accessToken:
  7661. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  7662. properties:
  7663. secretRef:
  7664. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7665. properties:
  7666. key:
  7667. description: |-
  7668. A key in the referenced Secret.
  7669. Some instances of this field may be defaulted, in others it may be required.
  7670. maxLength: 253
  7671. minLength: 1
  7672. pattern: ^[-._a-zA-Z0-9]+$
  7673. type: string
  7674. name:
  7675. description: The name of the Secret resource being referred to.
  7676. maxLength: 253
  7677. minLength: 1
  7678. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7679. type: string
  7680. namespace:
  7681. description: |-
  7682. The namespace of the Secret resource being referred to.
  7683. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7684. maxLength: 63
  7685. minLength: 1
  7686. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7687. type: string
  7688. type: object
  7689. type: object
  7690. oidcConfig:
  7691. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  7692. properties:
  7693. expirationSeconds:
  7694. default: 600
  7695. description: |-
  7696. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  7697. Defaults to 10 minutes.
  7698. format: int64
  7699. minimum: 600
  7700. type: integer
  7701. organization:
  7702. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  7703. type: string
  7704. serviceAccountRef:
  7705. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  7706. properties:
  7707. audiences:
  7708. description: |-
  7709. Audience specifies the `aud` claim for the service account token
  7710. Some providers automatically extend the audience field based on well-known annotations for workload
  7711. identity (e.g. IRSA or GCP Workload Identity)
  7712. items:
  7713. type: string
  7714. type: array
  7715. name:
  7716. description: The name of the ServiceAccount resource being referred to.
  7717. maxLength: 253
  7718. minLength: 1
  7719. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7720. type: string
  7721. namespace:
  7722. description: |-
  7723. Namespace of the resource being referred to.
  7724. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7725. maxLength: 63
  7726. minLength: 1
  7727. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7728. type: string
  7729. required:
  7730. - name
  7731. type: object
  7732. required:
  7733. - organization
  7734. - serviceAccountRef
  7735. type: object
  7736. type: object
  7737. x-kubernetes-validations:
  7738. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  7739. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  7740. environment:
  7741. description: |-
  7742. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  7743. dynamically retrieved values from supported providers including all major clouds,
  7744. and other Pulumi ESC environments.
  7745. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  7746. type: string
  7747. organization:
  7748. description: |-
  7749. Organization are a space to collaborate on shared projects and stacks.
  7750. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  7751. type: string
  7752. project:
  7753. description: Project is the name of the Pulumi ESC project the environment belongs to.
  7754. type: string
  7755. required:
  7756. - environment
  7757. - organization
  7758. - project
  7759. type: object
  7760. x-kubernetes-validations:
  7761. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  7762. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  7763. scaleway:
  7764. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  7765. properties:
  7766. accessKey:
  7767. description: AccessKey is the non-secret part of the api key.
  7768. properties:
  7769. secretRef:
  7770. description: SecretRef references a key in a secret that will be used as value.
  7771. properties:
  7772. key:
  7773. description: |-
  7774. A key in the referenced Secret.
  7775. Some instances of this field may be defaulted, in others it may be required.
  7776. maxLength: 253
  7777. minLength: 1
  7778. pattern: ^[-._a-zA-Z0-9]+$
  7779. type: string
  7780. name:
  7781. description: The name of the Secret resource being referred to.
  7782. maxLength: 253
  7783. minLength: 1
  7784. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7785. type: string
  7786. namespace:
  7787. description: |-
  7788. The namespace of the Secret resource being referred to.
  7789. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7790. maxLength: 63
  7791. minLength: 1
  7792. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7793. type: string
  7794. type: object
  7795. value:
  7796. description: Value can be specified directly to set a value without using a secret.
  7797. type: string
  7798. type: object
  7799. apiUrl:
  7800. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  7801. type: string
  7802. projectId:
  7803. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  7804. type: string
  7805. region:
  7806. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  7807. type: string
  7808. secretKey:
  7809. description: SecretKey is the non-secret part of the api key.
  7810. properties:
  7811. secretRef:
  7812. description: SecretRef references a key in a secret that will be used as value.
  7813. properties:
  7814. key:
  7815. description: |-
  7816. A key in the referenced Secret.
  7817. Some instances of this field may be defaulted, in others it may be required.
  7818. maxLength: 253
  7819. minLength: 1
  7820. pattern: ^[-._a-zA-Z0-9]+$
  7821. type: string
  7822. name:
  7823. description: The name of the Secret resource being referred to.
  7824. maxLength: 253
  7825. minLength: 1
  7826. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7827. type: string
  7828. namespace:
  7829. description: |-
  7830. The namespace of the Secret resource being referred to.
  7831. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7832. maxLength: 63
  7833. minLength: 1
  7834. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7835. type: string
  7836. type: object
  7837. value:
  7838. description: Value can be specified directly to set a value without using a secret.
  7839. type: string
  7840. type: object
  7841. required:
  7842. - accessKey
  7843. - projectId
  7844. - region
  7845. - secretKey
  7846. type: object
  7847. secretserver:
  7848. description: |-
  7849. SecretServer configures this store to sync secrets using SecretServer provider
  7850. https://docs.delinea.com/online-help/secret-server/start.htm
  7851. properties:
  7852. caBundle:
  7853. description: |-
  7854. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  7855. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  7856. are used to validate the TLS connection.
  7857. format: byte
  7858. type: string
  7859. caProvider:
  7860. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  7861. properties:
  7862. key:
  7863. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7864. maxLength: 253
  7865. minLength: 1
  7866. pattern: ^[-._a-zA-Z0-9]+$
  7867. type: string
  7868. name:
  7869. description: The name of the object located at the provider type.
  7870. maxLength: 253
  7871. minLength: 1
  7872. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7873. type: string
  7874. namespace:
  7875. description: |-
  7876. The namespace the Provider type is in.
  7877. Can only be defined when used in a ClusterSecretStore.
  7878. maxLength: 63
  7879. minLength: 1
  7880. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7881. type: string
  7882. type:
  7883. description: The type of provider to use such as "Secret", or "ConfigMap".
  7884. enum:
  7885. - Secret
  7886. - ConfigMap
  7887. type: string
  7888. required:
  7889. - name
  7890. - type
  7891. type: object
  7892. disableSiteIDValidation:
  7893. description: |-
  7894. DisableSiteIDValidation permits a missing site ID for new secrets.
  7895. The provider sends 0 if no site ID is set.
  7896. type: boolean
  7897. domain:
  7898. description: Domain is the secret server domain.
  7899. type: string
  7900. password:
  7901. description: |-
  7902. Password is the secret server account password.
  7903. Required unless Token is set.
  7904. properties:
  7905. secretRef:
  7906. description: SecretRef references a key in a secret that will be used as value.
  7907. properties:
  7908. key:
  7909. description: |-
  7910. A key in the referenced Secret.
  7911. Some instances of this field may be defaulted, in others it may be required.
  7912. maxLength: 253
  7913. minLength: 1
  7914. pattern: ^[-._a-zA-Z0-9]+$
  7915. type: string
  7916. name:
  7917. description: The name of the Secret resource being referred to.
  7918. maxLength: 253
  7919. minLength: 1
  7920. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7921. type: string
  7922. namespace:
  7923. description: |-
  7924. The namespace of the Secret resource being referred to.
  7925. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7926. maxLength: 63
  7927. minLength: 1
  7928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7929. type: string
  7930. type: object
  7931. value:
  7932. description: Value can be specified directly to set a value without using a secret.
  7933. minLength: 1
  7934. type: string
  7935. type: object
  7936. x-kubernetes-validations:
  7937. - message: exactly one of value or secretRef must be set
  7938. rule: has(self.value) != has(self.secretRef)
  7939. serverURL:
  7940. description: |-
  7941. ServerURL
  7942. URL to your secret server installation
  7943. type: string
  7944. siteId:
  7945. description: |-
  7946. SiteID is the ID of the Secret Server site for new secrets.
  7947. PushSecret metadata can override this value for one secret.
  7948. The provider uses 1 if this field is not set.
  7949. minimum: 1
  7950. type: integer
  7951. token:
  7952. description: |-
  7953. Token is an access token used to authenticate to the secret server,
  7954. as an alternative to Username and Password. When set, Username and
  7955. Password are not required and are ignored.
  7956. properties:
  7957. secretRef:
  7958. description: SecretRef references a key in a secret that will be used as value.
  7959. properties:
  7960. key:
  7961. description: |-
  7962. A key in the referenced Secret.
  7963. Some instances of this field may be defaulted, in others it may be required.
  7964. maxLength: 253
  7965. minLength: 1
  7966. pattern: ^[-._a-zA-Z0-9]+$
  7967. type: string
  7968. name:
  7969. description: The name of the Secret resource being referred to.
  7970. maxLength: 253
  7971. minLength: 1
  7972. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7973. type: string
  7974. namespace:
  7975. description: |-
  7976. The namespace of the Secret resource being referred to.
  7977. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7978. maxLength: 63
  7979. minLength: 1
  7980. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7981. type: string
  7982. type: object
  7983. value:
  7984. description: Value can be specified directly to set a value without using a secret.
  7985. minLength: 1
  7986. type: string
  7987. type: object
  7988. x-kubernetes-validations:
  7989. - message: exactly one of value or secretRef must be set
  7990. rule: has(self.value) != has(self.secretRef)
  7991. username:
  7992. description: |-
  7993. Username is the secret server account username.
  7994. Required unless Token is set.
  7995. properties:
  7996. secretRef:
  7997. description: SecretRef references a key in a secret that will be used as value.
  7998. properties:
  7999. key:
  8000. description: |-
  8001. A key in the referenced Secret.
  8002. Some instances of this field may be defaulted, in others it may be required.
  8003. maxLength: 253
  8004. minLength: 1
  8005. pattern: ^[-._a-zA-Z0-9]+$
  8006. type: string
  8007. name:
  8008. description: The name of the Secret resource being referred to.
  8009. maxLength: 253
  8010. minLength: 1
  8011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8012. type: string
  8013. namespace:
  8014. description: |-
  8015. The namespace of the Secret resource being referred to.
  8016. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8017. maxLength: 63
  8018. minLength: 1
  8019. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8020. type: string
  8021. type: object
  8022. value:
  8023. description: Value can be specified directly to set a value without using a secret.
  8024. minLength: 1
  8025. type: string
  8026. type: object
  8027. x-kubernetes-validations:
  8028. - message: exactly one of value or secretRef must be set
  8029. rule: has(self.value) != has(self.secretRef)
  8030. required:
  8031. - serverURL
  8032. type: object
  8033. x-kubernetes-validations:
  8034. - message: either token, or both username and password, must be set
  8035. rule: has(self.token) || (has(self.username) && has(self.password))
  8036. senhasegura:
  8037. description: Senhasegura configures this store to sync secrets using senhasegura provider
  8038. properties:
  8039. auth:
  8040. description: Auth defines parameters to authenticate in senhasegura
  8041. properties:
  8042. clientId:
  8043. type: string
  8044. clientSecretSecretRef:
  8045. description: |-
  8046. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8047. In some instances, `key` is a required field.
  8048. properties:
  8049. key:
  8050. description: |-
  8051. A key in the referenced Secret.
  8052. Some instances of this field may be defaulted, in others it may be required.
  8053. maxLength: 253
  8054. minLength: 1
  8055. pattern: ^[-._a-zA-Z0-9]+$
  8056. type: string
  8057. name:
  8058. description: The name of the Secret resource being referred to.
  8059. maxLength: 253
  8060. minLength: 1
  8061. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8062. type: string
  8063. namespace:
  8064. description: |-
  8065. The namespace of the Secret resource being referred to.
  8066. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8067. maxLength: 63
  8068. minLength: 1
  8069. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8070. type: string
  8071. type: object
  8072. required:
  8073. - clientId
  8074. - clientSecretSecretRef
  8075. type: object
  8076. ignoreSslCertificate:
  8077. default: false
  8078. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  8079. type: boolean
  8080. module:
  8081. description: Module defines which senhasegura module should be used to get secrets
  8082. type: string
  8083. url:
  8084. description: URL of senhasegura
  8085. type: string
  8086. required:
  8087. - auth
  8088. - module
  8089. - url
  8090. type: object
  8091. vault:
  8092. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  8093. properties:
  8094. auth:
  8095. description: Auth configures how secret-manager authenticates with the Vault server.
  8096. properties:
  8097. appRole:
  8098. description: |-
  8099. AppRole authenticates with Vault using the App Role auth mechanism,
  8100. with the role and secret stored in a Kubernetes Secret resource.
  8101. properties:
  8102. path:
  8103. default: approle
  8104. description: |-
  8105. Path where the App Role authentication backend is mounted
  8106. in Vault, e.g: "approle"
  8107. type: string
  8108. roleId:
  8109. description: |-
  8110. RoleID configured in the App Role authentication backend when setting
  8111. up the authentication backend in Vault.
  8112. type: string
  8113. roleRef:
  8114. description: |-
  8115. Reference to a key in a Secret that contains the App Role ID used
  8116. to authenticate with Vault.
  8117. The `key` field must be specified and denotes which entry within the Secret
  8118. resource is used as the app role id.
  8119. properties:
  8120. key:
  8121. description: |-
  8122. A key in the referenced Secret.
  8123. Some instances of this field may be defaulted, in others it may be required.
  8124. maxLength: 253
  8125. minLength: 1
  8126. pattern: ^[-._a-zA-Z0-9]+$
  8127. type: string
  8128. name:
  8129. description: The name of the Secret resource being referred to.
  8130. maxLength: 253
  8131. minLength: 1
  8132. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8133. type: string
  8134. namespace:
  8135. description: |-
  8136. The namespace of the Secret resource being referred to.
  8137. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8138. maxLength: 63
  8139. minLength: 1
  8140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8141. type: string
  8142. type: object
  8143. secretRef:
  8144. description: |-
  8145. Reference to a key in a Secret that contains the App Role secret used
  8146. to authenticate with Vault.
  8147. The `key` field must be specified and denotes which entry within the Secret
  8148. resource is used as the app role secret.
  8149. properties:
  8150. key:
  8151. description: |-
  8152. A key in the referenced Secret.
  8153. Some instances of this field may be defaulted, in others it may be required.
  8154. maxLength: 253
  8155. minLength: 1
  8156. pattern: ^[-._a-zA-Z0-9]+$
  8157. type: string
  8158. name:
  8159. description: The name of the Secret resource being referred to.
  8160. maxLength: 253
  8161. minLength: 1
  8162. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8163. type: string
  8164. namespace:
  8165. description: |-
  8166. The namespace of the Secret resource being referred to.
  8167. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8168. maxLength: 63
  8169. minLength: 1
  8170. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8171. type: string
  8172. type: object
  8173. required:
  8174. - path
  8175. - secretRef
  8176. type: object
  8177. cert:
  8178. description: |-
  8179. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  8180. Cert authentication method
  8181. properties:
  8182. clientCert:
  8183. description: |-
  8184. ClientCert is a certificate to authenticate using the Cert Vault
  8185. authentication method
  8186. properties:
  8187. key:
  8188. description: |-
  8189. A key in the referenced Secret.
  8190. Some instances of this field may be defaulted, in others it may be required.
  8191. maxLength: 253
  8192. minLength: 1
  8193. pattern: ^[-._a-zA-Z0-9]+$
  8194. type: string
  8195. name:
  8196. description: The name of the Secret resource being referred to.
  8197. maxLength: 253
  8198. minLength: 1
  8199. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8200. type: string
  8201. namespace:
  8202. description: |-
  8203. The namespace of the Secret resource being referred to.
  8204. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8205. maxLength: 63
  8206. minLength: 1
  8207. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8208. type: string
  8209. type: object
  8210. path:
  8211. default: cert
  8212. description: |-
  8213. Path where the Certificate authentication backend is mounted
  8214. in Vault, e.g: "cert"
  8215. type: string
  8216. secretRef:
  8217. description: |-
  8218. SecretRef to a key in a Secret resource containing client private key to
  8219. authenticate with Vault using the Cert authentication method
  8220. properties:
  8221. key:
  8222. description: |-
  8223. A key in the referenced Secret.
  8224. Some instances of this field may be defaulted, in others it may be required.
  8225. maxLength: 253
  8226. minLength: 1
  8227. pattern: ^[-._a-zA-Z0-9]+$
  8228. type: string
  8229. name:
  8230. description: The name of the Secret resource being referred to.
  8231. maxLength: 253
  8232. minLength: 1
  8233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8234. type: string
  8235. namespace:
  8236. description: |-
  8237. The namespace of the Secret resource being referred to.
  8238. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8239. maxLength: 63
  8240. minLength: 1
  8241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8242. type: string
  8243. type: object
  8244. vaultRole:
  8245. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  8246. type: string
  8247. type: object
  8248. gcp:
  8249. description: |-
  8250. Gcp authenticates with Vault using Google Cloud Platform authentication method
  8251. GCP authentication method
  8252. properties:
  8253. location:
  8254. description: Location optionally defines a location/region for the secret
  8255. type: string
  8256. path:
  8257. default: gcp
  8258. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  8259. type: string
  8260. projectID:
  8261. description: Project ID of the Google Cloud Platform project
  8262. type: string
  8263. role:
  8264. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  8265. type: string
  8266. secretRef:
  8267. description: Specify credentials in a Secret object
  8268. properties:
  8269. secretAccessKeySecretRef:
  8270. description: The SecretAccessKey is used for authentication
  8271. properties:
  8272. key:
  8273. description: |-
  8274. A key in the referenced Secret.
  8275. Some instances of this field may be defaulted, in others it may be required.
  8276. maxLength: 253
  8277. minLength: 1
  8278. pattern: ^[-._a-zA-Z0-9]+$
  8279. type: string
  8280. name:
  8281. description: The name of the Secret resource being referred to.
  8282. maxLength: 253
  8283. minLength: 1
  8284. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8285. type: string
  8286. namespace:
  8287. description: |-
  8288. The namespace of the Secret resource being referred to.
  8289. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8290. maxLength: 63
  8291. minLength: 1
  8292. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8293. type: string
  8294. type: object
  8295. type: object
  8296. serviceAccountRef:
  8297. description: ServiceAccountRef to a service account for impersonation
  8298. properties:
  8299. audiences:
  8300. description: |-
  8301. Audience specifies the `aud` claim for the service account token
  8302. Some providers automatically extend the audience field based on well-known annotations for workload
  8303. identity (e.g. IRSA or GCP Workload Identity)
  8304. items:
  8305. type: string
  8306. type: array
  8307. name:
  8308. description: The name of the ServiceAccount resource being referred to.
  8309. maxLength: 253
  8310. minLength: 1
  8311. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8312. type: string
  8313. namespace:
  8314. description: |-
  8315. Namespace of the resource being referred to.
  8316. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8317. maxLength: 63
  8318. minLength: 1
  8319. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8320. type: string
  8321. required:
  8322. - name
  8323. type: object
  8324. workloadIdentity:
  8325. description: Specify a service account with Workload Identity
  8326. properties:
  8327. clusterLocation:
  8328. description: |-
  8329. ClusterLocation is the location of the cluster
  8330. If not specified, it fetches information from the metadata server
  8331. type: string
  8332. clusterName:
  8333. description: |-
  8334. ClusterName is the name of the cluster
  8335. If not specified, it fetches information from the metadata server
  8336. type: string
  8337. clusterProjectID:
  8338. description: |-
  8339. ClusterProjectID is the project ID of the cluster
  8340. If not specified, it fetches information from the metadata server
  8341. type: string
  8342. serviceAccountRef:
  8343. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  8344. properties:
  8345. audiences:
  8346. description: |-
  8347. Audience specifies the `aud` claim for the service account token
  8348. Some providers automatically extend the audience field based on well-known annotations for workload
  8349. identity (e.g. IRSA or GCP Workload Identity)
  8350. items:
  8351. type: string
  8352. type: array
  8353. name:
  8354. description: The name of the ServiceAccount resource being referred to.
  8355. maxLength: 253
  8356. minLength: 1
  8357. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8358. type: string
  8359. namespace:
  8360. description: |-
  8361. Namespace of the resource being referred to.
  8362. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8363. maxLength: 63
  8364. minLength: 1
  8365. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8366. type: string
  8367. required:
  8368. - name
  8369. type: object
  8370. required:
  8371. - serviceAccountRef
  8372. type: object
  8373. required:
  8374. - role
  8375. type: object
  8376. iam:
  8377. description: |-
  8378. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  8379. AWS IAM authentication method
  8380. properties:
  8381. externalID:
  8382. description: AWS External ID set on assumed IAM roles
  8383. type: string
  8384. jwt:
  8385. description: Specify a service account with IRSA enabled
  8386. properties:
  8387. serviceAccountRef:
  8388. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  8389. properties:
  8390. audiences:
  8391. description: |-
  8392. Audience specifies the `aud` claim for the service account token
  8393. Some providers automatically extend the audience field based on well-known annotations for workload
  8394. identity (e.g. IRSA or GCP Workload Identity)
  8395. items:
  8396. type: string
  8397. type: array
  8398. name:
  8399. description: The name of the ServiceAccount resource being referred to.
  8400. maxLength: 253
  8401. minLength: 1
  8402. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8403. type: string
  8404. namespace:
  8405. description: |-
  8406. Namespace of the resource being referred to.
  8407. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8408. maxLength: 63
  8409. minLength: 1
  8410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8411. type: string
  8412. required:
  8413. - name
  8414. type: object
  8415. type: object
  8416. path:
  8417. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  8418. type: string
  8419. region:
  8420. description: AWS region
  8421. type: string
  8422. role:
  8423. description: This is the AWS role to be assumed before talking to vault
  8424. type: string
  8425. secretRef:
  8426. description: Specify credentials in a Secret object
  8427. properties:
  8428. accessKeyIDSecretRef:
  8429. description: The AccessKeyID is used for authentication
  8430. properties:
  8431. key:
  8432. description: |-
  8433. A key in the referenced Secret.
  8434. Some instances of this field may be defaulted, in others it may be required.
  8435. maxLength: 253
  8436. minLength: 1
  8437. pattern: ^[-._a-zA-Z0-9]+$
  8438. type: string
  8439. name:
  8440. description: The name of the Secret resource being referred to.
  8441. maxLength: 253
  8442. minLength: 1
  8443. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8444. type: string
  8445. namespace:
  8446. description: |-
  8447. The namespace of the Secret resource being referred to.
  8448. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8449. maxLength: 63
  8450. minLength: 1
  8451. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8452. type: string
  8453. type: object
  8454. secretAccessKeySecretRef:
  8455. description: The SecretAccessKey is used for authentication
  8456. properties:
  8457. key:
  8458. description: |-
  8459. A key in the referenced Secret.
  8460. Some instances of this field may be defaulted, in others it may be required.
  8461. maxLength: 253
  8462. minLength: 1
  8463. pattern: ^[-._a-zA-Z0-9]+$
  8464. type: string
  8465. name:
  8466. description: The name of the Secret resource being referred to.
  8467. maxLength: 253
  8468. minLength: 1
  8469. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8470. type: string
  8471. namespace:
  8472. description: |-
  8473. The namespace of the Secret resource being referred to.
  8474. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8475. maxLength: 63
  8476. minLength: 1
  8477. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8478. type: string
  8479. type: object
  8480. sessionTokenSecretRef:
  8481. description: |-
  8482. The SessionToken used for authentication
  8483. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  8484. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  8485. properties:
  8486. key:
  8487. description: |-
  8488. A key in the referenced Secret.
  8489. Some instances of this field may be defaulted, in others it may be required.
  8490. maxLength: 253
  8491. minLength: 1
  8492. pattern: ^[-._a-zA-Z0-9]+$
  8493. type: string
  8494. name:
  8495. description: The name of the Secret resource being referred to.
  8496. maxLength: 253
  8497. minLength: 1
  8498. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8499. type: string
  8500. namespace:
  8501. description: |-
  8502. The namespace of the Secret resource being referred to.
  8503. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8504. maxLength: 63
  8505. minLength: 1
  8506. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8507. type: string
  8508. type: object
  8509. type: object
  8510. vaultAwsIamServerID:
  8511. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  8512. type: string
  8513. vaultRole:
  8514. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  8515. type: string
  8516. required:
  8517. - vaultRole
  8518. type: object
  8519. jwt:
  8520. description: |-
  8521. Jwt authenticates with Vault by passing role and JWT token using the
  8522. JWT/OIDC authentication method
  8523. properties:
  8524. kubernetesServiceAccountToken:
  8525. description: |-
  8526. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  8527. a token for with the `TokenRequest` API.
  8528. properties:
  8529. audiences:
  8530. description: |-
  8531. Optional audiences field that will be used to request a temporary Kubernetes service
  8532. account token for the service account referenced by `serviceAccountRef`.
  8533. Defaults to a single audience `vault` it not specified.
  8534. Deprecated: use serviceAccountRef.Audiences instead
  8535. items:
  8536. type: string
  8537. type: array
  8538. expirationSeconds:
  8539. description: |-
  8540. Optional expiration time in seconds that will be used to request a temporary
  8541. Kubernetes service account token for the service account referenced by
  8542. `serviceAccountRef`.
  8543. Deprecated: this will be removed in the future.
  8544. Defaults to 10 minutes.
  8545. format: int64
  8546. type: integer
  8547. serviceAccountRef:
  8548. description: Service account field containing the name of a kubernetes ServiceAccount.
  8549. properties:
  8550. audiences:
  8551. description: |-
  8552. Audience specifies the `aud` claim for the service account token
  8553. Some providers automatically extend the audience field based on well-known annotations for workload
  8554. identity (e.g. IRSA or GCP Workload Identity)
  8555. items:
  8556. type: string
  8557. type: array
  8558. name:
  8559. description: The name of the ServiceAccount resource being referred to.
  8560. maxLength: 253
  8561. minLength: 1
  8562. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8563. type: string
  8564. namespace:
  8565. description: |-
  8566. Namespace of the resource being referred to.
  8567. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8568. maxLength: 63
  8569. minLength: 1
  8570. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8571. type: string
  8572. required:
  8573. - name
  8574. type: object
  8575. required:
  8576. - serviceAccountRef
  8577. type: object
  8578. path:
  8579. default: jwt
  8580. description: |-
  8581. Path where the JWT authentication backend is mounted
  8582. in Vault, e.g: "jwt"
  8583. type: string
  8584. role:
  8585. description: |-
  8586. Role is a JWT role to authenticate using the JWT/OIDC Vault
  8587. authentication method
  8588. type: string
  8589. secretRef:
  8590. description: |-
  8591. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  8592. authenticate with Vault using the JWT/OIDC authentication method.
  8593. properties:
  8594. key:
  8595. description: |-
  8596. A key in the referenced Secret.
  8597. Some instances of this field may be defaulted, in others it may be required.
  8598. maxLength: 253
  8599. minLength: 1
  8600. pattern: ^[-._a-zA-Z0-9]+$
  8601. type: string
  8602. name:
  8603. description: The name of the Secret resource being referred to.
  8604. maxLength: 253
  8605. minLength: 1
  8606. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8607. type: string
  8608. namespace:
  8609. description: |-
  8610. The namespace of the Secret resource being referred to.
  8611. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8612. maxLength: 63
  8613. minLength: 1
  8614. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8615. type: string
  8616. type: object
  8617. required:
  8618. - path
  8619. type: object
  8620. kubernetes:
  8621. description: |-
  8622. Kubernetes authenticates with Vault by passing the ServiceAccount
  8623. token stored in the named Secret resource to the Vault server.
  8624. properties:
  8625. mountPath:
  8626. default: kubernetes
  8627. description: |-
  8628. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  8629. "kubernetes"
  8630. type: string
  8631. role:
  8632. description: |-
  8633. A required field containing the Vault Role to assume. A Role binds a
  8634. Kubernetes ServiceAccount with a set of Vault policies.
  8635. type: string
  8636. secretRef:
  8637. description: |-
  8638. Optional secret field containing a Kubernetes ServiceAccount JWT used
  8639. for authenticating with Vault. If a name is specified without a key,
  8640. `token` is the default. If one is not specified, the one bound to
  8641. the controller will be used.
  8642. properties:
  8643. key:
  8644. description: |-
  8645. A key in the referenced Secret.
  8646. Some instances of this field may be defaulted, in others it may be required.
  8647. maxLength: 253
  8648. minLength: 1
  8649. pattern: ^[-._a-zA-Z0-9]+$
  8650. type: string
  8651. name:
  8652. description: The name of the Secret resource being referred to.
  8653. maxLength: 253
  8654. minLength: 1
  8655. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8656. type: string
  8657. namespace:
  8658. description: |-
  8659. The namespace of the Secret resource being referred to.
  8660. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8661. maxLength: 63
  8662. minLength: 1
  8663. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8664. type: string
  8665. type: object
  8666. serviceAccountRef:
  8667. description: |-
  8668. Optional service account field containing the name of a kubernetes ServiceAccount.
  8669. If the service account is specified, the service account secret token JWT will be used
  8670. for authenticating with Vault. If the service account selector is not supplied,
  8671. the secretRef will be used instead.
  8672. properties:
  8673. audiences:
  8674. description: |-
  8675. Audience specifies the `aud` claim for the service account token
  8676. Some providers automatically extend the audience field based on well-known annotations for workload
  8677. identity (e.g. IRSA or GCP Workload Identity)
  8678. items:
  8679. type: string
  8680. type: array
  8681. name:
  8682. description: The name of the ServiceAccount resource being referred to.
  8683. maxLength: 253
  8684. minLength: 1
  8685. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8686. type: string
  8687. namespace:
  8688. description: |-
  8689. Namespace of the resource being referred to.
  8690. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8691. maxLength: 63
  8692. minLength: 1
  8693. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8694. type: string
  8695. required:
  8696. - name
  8697. type: object
  8698. required:
  8699. - mountPath
  8700. - role
  8701. type: object
  8702. ldap:
  8703. description: |-
  8704. Ldap authenticates with Vault by passing username/password pair using
  8705. the LDAP authentication method
  8706. properties:
  8707. path:
  8708. default: ldap
  8709. description: |-
  8710. Path where the LDAP authentication backend is mounted
  8711. in Vault, e.g: "ldap"
  8712. type: string
  8713. secretRef:
  8714. description: |-
  8715. SecretRef to a key in a Secret resource containing password for the LDAP
  8716. user used to authenticate with Vault using the LDAP authentication
  8717. method
  8718. properties:
  8719. key:
  8720. description: |-
  8721. A key in the referenced Secret.
  8722. Some instances of this field may be defaulted, in others it may be required.
  8723. maxLength: 253
  8724. minLength: 1
  8725. pattern: ^[-._a-zA-Z0-9]+$
  8726. type: string
  8727. name:
  8728. description: The name of the Secret resource being referred to.
  8729. maxLength: 253
  8730. minLength: 1
  8731. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8732. type: string
  8733. namespace:
  8734. description: |-
  8735. The namespace of the Secret resource being referred to.
  8736. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8737. maxLength: 63
  8738. minLength: 1
  8739. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8740. type: string
  8741. type: object
  8742. username:
  8743. description: |-
  8744. Username is an LDAP username used to authenticate using the LDAP Vault
  8745. authentication method
  8746. type: string
  8747. required:
  8748. - path
  8749. - username
  8750. type: object
  8751. namespace:
  8752. description: |-
  8753. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  8754. Namespaces is a set of features within Vault Enterprise that allows
  8755. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8756. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8757. This will default to Vault.Namespace field if set, or empty otherwise
  8758. type: string
  8759. tokenSecretRef:
  8760. description: TokenSecretRef authenticates with Vault by presenting a token.
  8761. properties:
  8762. key:
  8763. description: |-
  8764. A key in the referenced Secret.
  8765. Some instances of this field may be defaulted, in others it may be required.
  8766. maxLength: 253
  8767. minLength: 1
  8768. pattern: ^[-._a-zA-Z0-9]+$
  8769. type: string
  8770. name:
  8771. description: The name of the Secret resource being referred to.
  8772. maxLength: 253
  8773. minLength: 1
  8774. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8775. type: string
  8776. namespace:
  8777. description: |-
  8778. The namespace of the Secret resource being referred to.
  8779. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8780. maxLength: 63
  8781. minLength: 1
  8782. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8783. type: string
  8784. type: object
  8785. userPass:
  8786. description: UserPass authenticates with Vault by passing username/password pair
  8787. properties:
  8788. path:
  8789. default: userpass
  8790. description: |-
  8791. Path where the UserPassword authentication backend is mounted
  8792. in Vault, e.g: "userpass"
  8793. type: string
  8794. secretRef:
  8795. description: |-
  8796. SecretRef to a key in a Secret resource containing password for the
  8797. user used to authenticate with Vault using the UserPass authentication
  8798. method
  8799. properties:
  8800. key:
  8801. description: |-
  8802. A key in the referenced Secret.
  8803. Some instances of this field may be defaulted, in others it may be required.
  8804. maxLength: 253
  8805. minLength: 1
  8806. pattern: ^[-._a-zA-Z0-9]+$
  8807. type: string
  8808. name:
  8809. description: The name of the Secret resource being referred to.
  8810. maxLength: 253
  8811. minLength: 1
  8812. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8813. type: string
  8814. namespace:
  8815. description: |-
  8816. The namespace of the Secret resource being referred to.
  8817. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8818. maxLength: 63
  8819. minLength: 1
  8820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8821. type: string
  8822. type: object
  8823. username:
  8824. description: |-
  8825. Username is a username used to authenticate using the UserPass Vault
  8826. authentication method
  8827. type: string
  8828. required:
  8829. - path
  8830. - username
  8831. type: object
  8832. type: object
  8833. caBundle:
  8834. description: |-
  8835. PEM encoded CA bundle used to validate Vault server certificate. Only used
  8836. if the Server URL is using HTTPS protocol. This parameter is ignored for
  8837. plain HTTP protocol connection. If not set the system root certificates
  8838. are used to validate the TLS connection.
  8839. format: byte
  8840. type: string
  8841. caProvider:
  8842. description: The provider for the CA bundle to use to validate Vault server certificate.
  8843. properties:
  8844. key:
  8845. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8846. maxLength: 253
  8847. minLength: 1
  8848. pattern: ^[-._a-zA-Z0-9]+$
  8849. type: string
  8850. name:
  8851. description: The name of the object located at the provider type.
  8852. maxLength: 253
  8853. minLength: 1
  8854. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8855. type: string
  8856. namespace:
  8857. description: |-
  8858. The namespace the Provider type is in.
  8859. Can only be defined when used in a ClusterSecretStore.
  8860. maxLength: 63
  8861. minLength: 1
  8862. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8863. type: string
  8864. type:
  8865. description: The type of provider to use such as "Secret", or "ConfigMap".
  8866. enum:
  8867. - Secret
  8868. - ConfigMap
  8869. type: string
  8870. required:
  8871. - name
  8872. - type
  8873. type: object
  8874. checkAndSet:
  8875. description: |-
  8876. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  8877. Only applies to Vault KV v2 stores. When enabled, write operations must include
  8878. the current version of the secret to prevent unintentional overwrites.
  8879. properties:
  8880. required:
  8881. description: |-
  8882. Required when true, all write operations must include a check-and-set parameter.
  8883. This helps prevent unintentional overwrites of secrets.
  8884. type: boolean
  8885. type: object
  8886. forwardInconsistent:
  8887. description: |-
  8888. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  8889. leader instead of simply retrying within a loop. This can increase performance if
  8890. the option is enabled serverside.
  8891. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  8892. type: boolean
  8893. headers:
  8894. additionalProperties:
  8895. type: string
  8896. description: Headers to be added in Vault request
  8897. type: object
  8898. namespace:
  8899. description: |-
  8900. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  8901. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8902. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8903. type: string
  8904. path:
  8905. description: |-
  8906. Path is the mount path of the Vault KV backend endpoint, e.g:
  8907. "secret". The v2 KV secret engine version specific "/data" path suffix
  8908. for fetching secrets from Vault is optional and will be appended
  8909. if not present in specified path.
  8910. type: string
  8911. readYourWrites:
  8912. description: |-
  8913. ReadYourWrites ensures isolated read-after-write semantics by
  8914. providing discovered cluster replication states in each request.
  8915. More information about eventual consistency in Vault can be found here
  8916. https://www.vaultproject.io/docs/enterprise/consistency
  8917. type: boolean
  8918. server:
  8919. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  8920. type: string
  8921. tls:
  8922. description: |-
  8923. The configuration used for client side related TLS communication, when the Vault server
  8924. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  8925. This parameter is ignored for plain HTTP protocol connection.
  8926. It's worth noting this configuration is different from the "TLS certificates auth method",
  8927. which is available under the `auth.cert` section.
  8928. properties:
  8929. certSecretRef:
  8930. description: |-
  8931. CertSecretRef is a certificate added to the transport layer
  8932. when communicating with the Vault server.
  8933. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  8934. properties:
  8935. key:
  8936. description: |-
  8937. A key in the referenced Secret.
  8938. Some instances of this field may be defaulted, in others it may be required.
  8939. maxLength: 253
  8940. minLength: 1
  8941. pattern: ^[-._a-zA-Z0-9]+$
  8942. type: string
  8943. name:
  8944. description: The name of the Secret resource being referred to.
  8945. maxLength: 253
  8946. minLength: 1
  8947. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8948. type: string
  8949. namespace:
  8950. description: |-
  8951. The namespace of the Secret resource being referred to.
  8952. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8953. maxLength: 63
  8954. minLength: 1
  8955. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8956. type: string
  8957. type: object
  8958. keySecretRef:
  8959. description: |-
  8960. KeySecretRef to a key in a Secret resource containing client private key
  8961. added to the transport layer when communicating with the Vault server.
  8962. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  8963. properties:
  8964. key:
  8965. description: |-
  8966. A key in the referenced Secret.
  8967. Some instances of this field may be defaulted, in others it may be required.
  8968. maxLength: 253
  8969. minLength: 1
  8970. pattern: ^[-._a-zA-Z0-9]+$
  8971. type: string
  8972. name:
  8973. description: The name of the Secret resource being referred to.
  8974. maxLength: 253
  8975. minLength: 1
  8976. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8977. type: string
  8978. namespace:
  8979. description: |-
  8980. The namespace of the Secret resource being referred to.
  8981. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8982. maxLength: 63
  8983. minLength: 1
  8984. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8985. type: string
  8986. type: object
  8987. type: object
  8988. version:
  8989. default: v2
  8990. description: |-
  8991. Version is the Vault KV secret engine version. This can be either "v1" or
  8992. "v2". Version defaults to "v2".
  8993. enum:
  8994. - v1
  8995. - v2
  8996. type: string
  8997. required:
  8998. - server
  8999. type: object
  9000. volcengine:
  9001. description: Volcengine configures this store to sync secrets using the Volcengine provider
  9002. properties:
  9003. auth:
  9004. description: |-
  9005. Auth defines the authentication method to use.
  9006. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  9007. properties:
  9008. secretRef:
  9009. description: |-
  9010. SecretRef defines the static credentials to use for authentication.
  9011. If not set, IRSA is used.
  9012. properties:
  9013. accessKeyID:
  9014. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  9015. properties:
  9016. key:
  9017. description: |-
  9018. A key in the referenced Secret.
  9019. Some instances of this field may be defaulted, in others it may be required.
  9020. maxLength: 253
  9021. minLength: 1
  9022. pattern: ^[-._a-zA-Z0-9]+$
  9023. type: string
  9024. name:
  9025. description: The name of the Secret resource being referred to.
  9026. maxLength: 253
  9027. minLength: 1
  9028. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9029. type: string
  9030. namespace:
  9031. description: |-
  9032. The namespace of the Secret resource being referred to.
  9033. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9034. maxLength: 63
  9035. minLength: 1
  9036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9037. type: string
  9038. type: object
  9039. secretAccessKey:
  9040. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  9041. properties:
  9042. key:
  9043. description: |-
  9044. A key in the referenced Secret.
  9045. Some instances of this field may be defaulted, in others it may be required.
  9046. maxLength: 253
  9047. minLength: 1
  9048. pattern: ^[-._a-zA-Z0-9]+$
  9049. type: string
  9050. name:
  9051. description: The name of the Secret resource being referred to.
  9052. maxLength: 253
  9053. minLength: 1
  9054. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9055. type: string
  9056. namespace:
  9057. description: |-
  9058. The namespace of the Secret resource being referred to.
  9059. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9060. maxLength: 63
  9061. minLength: 1
  9062. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9063. type: string
  9064. type: object
  9065. token:
  9066. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  9067. properties:
  9068. key:
  9069. description: |-
  9070. A key in the referenced Secret.
  9071. Some instances of this field may be defaulted, in others it may be required.
  9072. maxLength: 253
  9073. minLength: 1
  9074. pattern: ^[-._a-zA-Z0-9]+$
  9075. type: string
  9076. name:
  9077. description: The name of the Secret resource being referred to.
  9078. maxLength: 253
  9079. minLength: 1
  9080. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9081. type: string
  9082. namespace:
  9083. description: |-
  9084. The namespace of the Secret resource being referred to.
  9085. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9086. maxLength: 63
  9087. minLength: 1
  9088. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9089. type: string
  9090. type: object
  9091. required:
  9092. - accessKeyID
  9093. - secretAccessKey
  9094. type: object
  9095. type: object
  9096. region:
  9097. description: Region specifies the Volcengine region to connect to.
  9098. type: string
  9099. required:
  9100. - region
  9101. type: object
  9102. webhook:
  9103. description: Webhook configures this store to sync secrets using a generic templated webhook
  9104. properties:
  9105. auth:
  9106. description: Auth specifies a authorization protocol. Only one protocol may be set.
  9107. maxProperties: 1
  9108. minProperties: 1
  9109. properties:
  9110. ntlm:
  9111. description: NTLMProtocol configures the store to use NTLM for auth
  9112. properties:
  9113. passwordSecret:
  9114. description: |-
  9115. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9116. In some instances, `key` is a required field.
  9117. properties:
  9118. key:
  9119. description: |-
  9120. A key in the referenced Secret.
  9121. Some instances of this field may be defaulted, in others it may be required.
  9122. maxLength: 253
  9123. minLength: 1
  9124. pattern: ^[-._a-zA-Z0-9]+$
  9125. type: string
  9126. name:
  9127. description: The name of the Secret resource being referred to.
  9128. maxLength: 253
  9129. minLength: 1
  9130. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9131. type: string
  9132. namespace:
  9133. description: |-
  9134. The namespace of the Secret resource being referred to.
  9135. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9136. maxLength: 63
  9137. minLength: 1
  9138. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9139. type: string
  9140. type: object
  9141. usernameSecret:
  9142. description: |-
  9143. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9144. In some instances, `key` is a required field.
  9145. properties:
  9146. key:
  9147. description: |-
  9148. A key in the referenced Secret.
  9149. Some instances of this field may be defaulted, in others it may be required.
  9150. maxLength: 253
  9151. minLength: 1
  9152. pattern: ^[-._a-zA-Z0-9]+$
  9153. type: string
  9154. name:
  9155. description: The name of the Secret resource being referred to.
  9156. maxLength: 253
  9157. minLength: 1
  9158. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9159. type: string
  9160. namespace:
  9161. description: |-
  9162. The namespace of the Secret resource being referred to.
  9163. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9164. maxLength: 63
  9165. minLength: 1
  9166. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9167. type: string
  9168. type: object
  9169. required:
  9170. - passwordSecret
  9171. - usernameSecret
  9172. type: object
  9173. type: object
  9174. body:
  9175. description: Body
  9176. type: string
  9177. caBundle:
  9178. description: |-
  9179. PEM encoded CA bundle used to validate webhook server certificate. Only used
  9180. if the Server URL is using HTTPS protocol. This parameter is ignored for
  9181. plain HTTP protocol connection. If not set the system root certificates
  9182. are used to validate the TLS connection.
  9183. format: byte
  9184. type: string
  9185. caProvider:
  9186. description: The provider for the CA bundle to use to validate webhook server certificate.
  9187. properties:
  9188. key:
  9189. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9190. maxLength: 253
  9191. minLength: 1
  9192. pattern: ^[-._a-zA-Z0-9]+$
  9193. type: string
  9194. name:
  9195. description: The name of the object located at the provider type.
  9196. maxLength: 253
  9197. minLength: 1
  9198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9199. type: string
  9200. namespace:
  9201. description: The namespace the Provider type is in.
  9202. maxLength: 63
  9203. minLength: 1
  9204. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9205. type: string
  9206. type:
  9207. description: The type of provider to use such as "Secret", or "ConfigMap".
  9208. enum:
  9209. - Secret
  9210. - ConfigMap
  9211. type: string
  9212. required:
  9213. - name
  9214. - type
  9215. type: object
  9216. headers:
  9217. additionalProperties:
  9218. type: string
  9219. description: Headers
  9220. type: object
  9221. method:
  9222. description: Webhook Method
  9223. type: string
  9224. result:
  9225. description: Result formatting
  9226. properties:
  9227. jsonPath:
  9228. description: Json path of return value
  9229. type: string
  9230. type: object
  9231. secrets:
  9232. description: |-
  9233. Secrets to fill in templates
  9234. These secrets will be passed to the templating function as key value pairs under the given name
  9235. items:
  9236. description: WebhookSecret defines a secret that will be passed to the webhook request.
  9237. properties:
  9238. name:
  9239. description: Name of this secret in templates
  9240. type: string
  9241. secretRef:
  9242. description: Secret ref to fill in credentials
  9243. properties:
  9244. key:
  9245. description: |-
  9246. A key in the referenced Secret.
  9247. Some instances of this field may be defaulted, in others it may be required.
  9248. maxLength: 253
  9249. minLength: 1
  9250. pattern: ^[-._a-zA-Z0-9]+$
  9251. type: string
  9252. name:
  9253. description: The name of the Secret resource being referred to.
  9254. maxLength: 253
  9255. minLength: 1
  9256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9257. type: string
  9258. namespace:
  9259. description: |-
  9260. The namespace of the Secret resource being referred to.
  9261. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9262. maxLength: 63
  9263. minLength: 1
  9264. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9265. type: string
  9266. type: object
  9267. required:
  9268. - name
  9269. - secretRef
  9270. type: object
  9271. type: array
  9272. timeout:
  9273. description: Timeout
  9274. type: string
  9275. url:
  9276. description: Webhook url to call
  9277. type: string
  9278. required:
  9279. - url
  9280. type: object
  9281. yandexcertificatemanager:
  9282. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  9283. properties:
  9284. apiEndpoint:
  9285. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9286. type: string
  9287. auth:
  9288. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  9289. properties:
  9290. authorizedKeySecretRef:
  9291. description: The authorized key used for authentication
  9292. properties:
  9293. key:
  9294. description: |-
  9295. A key in the referenced Secret.
  9296. Some instances of this field may be defaulted, in others it may be required.
  9297. maxLength: 253
  9298. minLength: 1
  9299. pattern: ^[-._a-zA-Z0-9]+$
  9300. type: string
  9301. name:
  9302. description: The name of the Secret resource being referred to.
  9303. maxLength: 253
  9304. minLength: 1
  9305. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9306. type: string
  9307. namespace:
  9308. description: |-
  9309. The namespace of the Secret resource being referred to.
  9310. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9311. maxLength: 63
  9312. minLength: 1
  9313. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9314. type: string
  9315. type: object
  9316. type: object
  9317. caProvider:
  9318. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9319. properties:
  9320. certSecretRef:
  9321. description: |-
  9322. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9323. In some instances, `key` is a required field.
  9324. properties:
  9325. key:
  9326. description: |-
  9327. A key in the referenced Secret.
  9328. Some instances of this field may be defaulted, in others it may be required.
  9329. maxLength: 253
  9330. minLength: 1
  9331. pattern: ^[-._a-zA-Z0-9]+$
  9332. type: string
  9333. name:
  9334. description: The name of the Secret resource being referred to.
  9335. maxLength: 253
  9336. minLength: 1
  9337. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9338. type: string
  9339. namespace:
  9340. description: |-
  9341. The namespace of the Secret resource being referred to.
  9342. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9343. maxLength: 63
  9344. minLength: 1
  9345. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9346. type: string
  9347. type: object
  9348. type: object
  9349. fetching:
  9350. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  9351. maxProperties: 1
  9352. minProperties: 1
  9353. properties:
  9354. byID:
  9355. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  9356. type: object
  9357. byName:
  9358. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  9359. properties:
  9360. folderID:
  9361. description: The folder to fetch secrets from
  9362. type: string
  9363. required:
  9364. - folderID
  9365. type: object
  9366. type: object
  9367. required:
  9368. - auth
  9369. type: object
  9370. yandexlockbox:
  9371. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  9372. properties:
  9373. apiEndpoint:
  9374. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9375. type: string
  9376. auth:
  9377. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  9378. properties:
  9379. authorizedKeySecretRef:
  9380. description: The authorized key used for authentication
  9381. properties:
  9382. key:
  9383. description: |-
  9384. A key in the referenced Secret.
  9385. Some instances of this field may be defaulted, in others it may be required.
  9386. maxLength: 253
  9387. minLength: 1
  9388. pattern: ^[-._a-zA-Z0-9]+$
  9389. type: string
  9390. name:
  9391. description: The name of the Secret resource being referred to.
  9392. maxLength: 253
  9393. minLength: 1
  9394. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9395. type: string
  9396. namespace:
  9397. description: |-
  9398. The namespace of the Secret resource being referred to.
  9399. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9400. maxLength: 63
  9401. minLength: 1
  9402. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9403. type: string
  9404. type: object
  9405. type: object
  9406. caProvider:
  9407. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9408. properties:
  9409. certSecretRef:
  9410. description: |-
  9411. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9412. In some instances, `key` is a required field.
  9413. properties:
  9414. key:
  9415. description: |-
  9416. A key in the referenced Secret.
  9417. Some instances of this field may be defaulted, in others it may be required.
  9418. maxLength: 253
  9419. minLength: 1
  9420. pattern: ^[-._a-zA-Z0-9]+$
  9421. type: string
  9422. name:
  9423. description: The name of the Secret resource being referred to.
  9424. maxLength: 253
  9425. minLength: 1
  9426. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9427. type: string
  9428. namespace:
  9429. description: |-
  9430. The namespace of the Secret resource being referred to.
  9431. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9432. maxLength: 63
  9433. minLength: 1
  9434. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9435. type: string
  9436. type: object
  9437. type: object
  9438. fetching:
  9439. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  9440. maxProperties: 1
  9441. minProperties: 1
  9442. properties:
  9443. byID:
  9444. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  9445. type: object
  9446. byName:
  9447. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  9448. properties:
  9449. folderID:
  9450. description: The folder to fetch secrets from
  9451. type: string
  9452. required:
  9453. - folderID
  9454. type: object
  9455. type: object
  9456. required:
  9457. - auth
  9458. type: object
  9459. type: object
  9460. refreshInterval:
  9461. anyOf:
  9462. - type: integer
  9463. - type: string
  9464. description: |-
  9465. Used to configure store refresh interval. Accepts either an integer number
  9466. of seconds (legacy) or a Go duration string such as "1h" or "5m". Empty or
  9467. 0 will default to the controller config.
  9468. x-kubernetes-int-or-string: true
  9469. retrySettings:
  9470. description: Used to configure HTTP retries on failures.
  9471. properties:
  9472. maxRetries:
  9473. format: int32
  9474. type: integer
  9475. retryInterval:
  9476. type: string
  9477. type: object
  9478. required:
  9479. - provider
  9480. type: object
  9481. status:
  9482. description: SecretStoreStatus defines the observed state of the SecretStore.
  9483. properties:
  9484. capabilities:
  9485. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  9486. type: string
  9487. conditions:
  9488. items:
  9489. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  9490. properties:
  9491. lastTransitionTime:
  9492. format: date-time
  9493. type: string
  9494. message:
  9495. type: string
  9496. reason:
  9497. type: string
  9498. status:
  9499. type: string
  9500. type:
  9501. description: SecretStoreConditionType represents the condition of the SecretStore.
  9502. type: string
  9503. required:
  9504. - status
  9505. - type
  9506. type: object
  9507. type: array
  9508. type: object
  9509. type: object
  9510. served: true
  9511. storage: true
  9512. subresources:
  9513. status: {}
  9514. - additionalPrinterColumns:
  9515. - jsonPath: .metadata.creationTimestamp
  9516. name: AGE
  9517. type: date
  9518. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  9519. name: Status
  9520. type: string
  9521. - jsonPath: .status.capabilities
  9522. name: Capabilities
  9523. type: string
  9524. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  9525. name: Ready
  9526. type: string
  9527. deprecated: true
  9528. name: v1beta1
  9529. schema:
  9530. openAPIV3Schema:
  9531. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  9532. properties:
  9533. apiVersion:
  9534. description: |-
  9535. APIVersion defines the versioned schema of this representation of an object.
  9536. Servers should convert recognized schemas to the latest internal value, and
  9537. may reject unrecognized values.
  9538. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  9539. type: string
  9540. kind:
  9541. description: |-
  9542. Kind is a string value representing the REST resource this object represents.
  9543. Servers may infer this from the endpoint the client submits requests to.
  9544. Cannot be updated.
  9545. In CamelCase.
  9546. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  9547. type: string
  9548. metadata:
  9549. type: object
  9550. spec:
  9551. description: SecretStoreSpec defines the desired state of SecretStore.
  9552. properties:
  9553. conditions:
  9554. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  9555. items:
  9556. description: |-
  9557. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  9558. for a ClusterSecretStore instance.
  9559. properties:
  9560. namespaceRegexes:
  9561. description: Choose namespaces by using regex matching
  9562. items:
  9563. type: string
  9564. type: array
  9565. namespaceSelector:
  9566. description: Choose namespace using a labelSelector
  9567. properties:
  9568. matchExpressions:
  9569. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  9570. items:
  9571. description: |-
  9572. A label selector requirement is a selector that contains values, a key, and an operator that
  9573. relates the key and values.
  9574. properties:
  9575. key:
  9576. description: key is the label key that the selector applies to.
  9577. type: string
  9578. operator:
  9579. description: |-
  9580. operator represents a key's relationship to a set of values.
  9581. Valid operators are In, NotIn, Exists and DoesNotExist.
  9582. type: string
  9583. values:
  9584. description: |-
  9585. values is an array of string values. If the operator is In or NotIn,
  9586. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  9587. the values array must be empty. This array is replaced during a strategic
  9588. merge patch.
  9589. items:
  9590. type: string
  9591. type: array
  9592. x-kubernetes-list-type: atomic
  9593. required:
  9594. - key
  9595. - operator
  9596. type: object
  9597. type: array
  9598. x-kubernetes-list-type: atomic
  9599. matchLabels:
  9600. additionalProperties:
  9601. type: string
  9602. description: |-
  9603. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  9604. map is equivalent to an element of matchExpressions, whose key field is "key", the
  9605. operator is "In", and the values array contains only "value". The requirements are ANDed.
  9606. type: object
  9607. type: object
  9608. x-kubernetes-map-type: atomic
  9609. namespaces:
  9610. description: Choose namespaces by name
  9611. items:
  9612. maxLength: 63
  9613. minLength: 1
  9614. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9615. type: string
  9616. type: array
  9617. type: object
  9618. type: array
  9619. controller:
  9620. description: |-
  9621. Used to select the correct ESO controller (think: ingress.ingressClassName)
  9622. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  9623. type: string
  9624. provider:
  9625. description: Used to configure the provider. Only one provider may be set
  9626. maxProperties: 1
  9627. minProperties: 1
  9628. properties:
  9629. akeyless:
  9630. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  9631. properties:
  9632. akeylessGWApiURL:
  9633. description: Akeyless GW API Url from which the secrets to be fetched from.
  9634. type: string
  9635. authSecretRef:
  9636. description: Auth configures how the operator authenticates with Akeyless.
  9637. properties:
  9638. kubernetesAuth:
  9639. description: |-
  9640. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  9641. token stored in the named Secret resource.
  9642. properties:
  9643. accessID:
  9644. description: the Akeyless Kubernetes auth-method access-id
  9645. type: string
  9646. k8sConfName:
  9647. description: Kubernetes-auth configuration name in Akeyless-Gateway
  9648. type: string
  9649. secretRef:
  9650. description: |-
  9651. Optional secret field containing a Kubernetes ServiceAccount JWT used
  9652. for authenticating with Akeyless. If a name is specified without a key,
  9653. `token` is the default. If one is not specified, the one bound to
  9654. the controller will be used.
  9655. properties:
  9656. key:
  9657. description: |-
  9658. A key in the referenced Secret.
  9659. Some instances of this field may be defaulted, in others it may be required.
  9660. maxLength: 253
  9661. minLength: 1
  9662. pattern: ^[-._a-zA-Z0-9]+$
  9663. type: string
  9664. name:
  9665. description: The name of the Secret resource being referred to.
  9666. maxLength: 253
  9667. minLength: 1
  9668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9669. type: string
  9670. namespace:
  9671. description: |-
  9672. The namespace of the Secret resource being referred to.
  9673. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9674. maxLength: 63
  9675. minLength: 1
  9676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9677. type: string
  9678. type: object
  9679. serviceAccountRef:
  9680. description: |-
  9681. Optional service account field containing the name of a kubernetes ServiceAccount.
  9682. If the service account is specified, the service account secret token JWT will be used
  9683. for authenticating with Akeyless. If the service account selector is not supplied,
  9684. the secretRef will be used instead.
  9685. properties:
  9686. audiences:
  9687. description: |-
  9688. Audience specifies the `aud` claim for the service account token
  9689. Some providers automatically extend the audience field based on well-known annotations for workload
  9690. identity (e.g. IRSA or GCP Workload Identity)
  9691. items:
  9692. type: string
  9693. type: array
  9694. name:
  9695. description: The name of the ServiceAccount resource being referred to.
  9696. maxLength: 253
  9697. minLength: 1
  9698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9699. type: string
  9700. namespace:
  9701. description: |-
  9702. Namespace of the resource being referred to.
  9703. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9704. maxLength: 63
  9705. minLength: 1
  9706. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9707. type: string
  9708. required:
  9709. - name
  9710. type: object
  9711. required:
  9712. - accessID
  9713. - k8sConfName
  9714. type: object
  9715. secretRef:
  9716. description: |-
  9717. Reference to a Secret that contains the details
  9718. to authenticate with Akeyless.
  9719. properties:
  9720. accessID:
  9721. description: The SecretAccessID is used for authentication
  9722. properties:
  9723. key:
  9724. description: |-
  9725. A key in the referenced Secret.
  9726. Some instances of this field may be defaulted, in others it may be required.
  9727. maxLength: 253
  9728. minLength: 1
  9729. pattern: ^[-._a-zA-Z0-9]+$
  9730. type: string
  9731. name:
  9732. description: The name of the Secret resource being referred to.
  9733. maxLength: 253
  9734. minLength: 1
  9735. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9736. type: string
  9737. namespace:
  9738. description: |-
  9739. The namespace of the Secret resource being referred to.
  9740. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9741. maxLength: 63
  9742. minLength: 1
  9743. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9744. type: string
  9745. type: object
  9746. accessType:
  9747. description: |-
  9748. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9749. In some instances, `key` is a required field.
  9750. properties:
  9751. key:
  9752. description: |-
  9753. A key in the referenced Secret.
  9754. Some instances of this field may be defaulted, in others it may be required.
  9755. maxLength: 253
  9756. minLength: 1
  9757. pattern: ^[-._a-zA-Z0-9]+$
  9758. type: string
  9759. name:
  9760. description: The name of the Secret resource being referred to.
  9761. maxLength: 253
  9762. minLength: 1
  9763. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9764. type: string
  9765. namespace:
  9766. description: |-
  9767. The namespace of the Secret resource being referred to.
  9768. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9769. maxLength: 63
  9770. minLength: 1
  9771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9772. type: string
  9773. type: object
  9774. accessTypeParam:
  9775. description: |-
  9776. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9777. In some instances, `key` is a required field.
  9778. properties:
  9779. key:
  9780. description: |-
  9781. A key in the referenced Secret.
  9782. Some instances of this field may be defaulted, in others it may be required.
  9783. maxLength: 253
  9784. minLength: 1
  9785. pattern: ^[-._a-zA-Z0-9]+$
  9786. type: string
  9787. name:
  9788. description: The name of the Secret resource being referred to.
  9789. maxLength: 253
  9790. minLength: 1
  9791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9792. type: string
  9793. namespace:
  9794. description: |-
  9795. The namespace of the Secret resource being referred to.
  9796. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9797. maxLength: 63
  9798. minLength: 1
  9799. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9800. type: string
  9801. type: object
  9802. type: object
  9803. type: object
  9804. caBundle:
  9805. description: |-
  9806. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  9807. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  9808. are used to validate the TLS connection.
  9809. format: byte
  9810. type: string
  9811. caProvider:
  9812. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  9813. properties:
  9814. key:
  9815. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9816. maxLength: 253
  9817. minLength: 1
  9818. pattern: ^[-._a-zA-Z0-9]+$
  9819. type: string
  9820. name:
  9821. description: The name of the object located at the provider type.
  9822. maxLength: 253
  9823. minLength: 1
  9824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9825. type: string
  9826. namespace:
  9827. description: |-
  9828. The namespace the Provider type is in.
  9829. Can only be defined when used in a ClusterSecretStore.
  9830. maxLength: 63
  9831. minLength: 1
  9832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9833. type: string
  9834. type:
  9835. description: The type of provider to use such as "Secret", or "ConfigMap".
  9836. enum:
  9837. - Secret
  9838. - ConfigMap
  9839. type: string
  9840. required:
  9841. - name
  9842. - type
  9843. type: object
  9844. required:
  9845. - akeylessGWApiURL
  9846. - authSecretRef
  9847. type: object
  9848. alibaba:
  9849. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  9850. properties:
  9851. auth:
  9852. description: AlibabaAuth contains a secretRef for credentials.
  9853. properties:
  9854. rrsa:
  9855. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  9856. properties:
  9857. oidcProviderArn:
  9858. type: string
  9859. oidcTokenFilePath:
  9860. type: string
  9861. roleArn:
  9862. type: string
  9863. sessionName:
  9864. type: string
  9865. required:
  9866. - oidcProviderArn
  9867. - oidcTokenFilePath
  9868. - roleArn
  9869. - sessionName
  9870. type: object
  9871. secretRef:
  9872. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  9873. properties:
  9874. accessKeyIDSecretRef:
  9875. description: The AccessKeyID is used for authentication
  9876. properties:
  9877. key:
  9878. description: |-
  9879. A key in the referenced Secret.
  9880. Some instances of this field may be defaulted, in others it may be required.
  9881. maxLength: 253
  9882. minLength: 1
  9883. pattern: ^[-._a-zA-Z0-9]+$
  9884. type: string
  9885. name:
  9886. description: The name of the Secret resource being referred to.
  9887. maxLength: 253
  9888. minLength: 1
  9889. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9890. type: string
  9891. namespace:
  9892. description: |-
  9893. The namespace of the Secret resource being referred to.
  9894. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9895. maxLength: 63
  9896. minLength: 1
  9897. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9898. type: string
  9899. type: object
  9900. accessKeySecretSecretRef:
  9901. description: The AccessKeySecret is used for authentication
  9902. properties:
  9903. key:
  9904. description: |-
  9905. A key in the referenced Secret.
  9906. Some instances of this field may be defaulted, in others it may be required.
  9907. maxLength: 253
  9908. minLength: 1
  9909. pattern: ^[-._a-zA-Z0-9]+$
  9910. type: string
  9911. name:
  9912. description: The name of the Secret resource being referred to.
  9913. maxLength: 253
  9914. minLength: 1
  9915. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9916. type: string
  9917. namespace:
  9918. description: |-
  9919. The namespace of the Secret resource being referred to.
  9920. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9921. maxLength: 63
  9922. minLength: 1
  9923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9924. type: string
  9925. type: object
  9926. required:
  9927. - accessKeyIDSecretRef
  9928. - accessKeySecretSecretRef
  9929. type: object
  9930. type: object
  9931. regionID:
  9932. description: Alibaba Region to be used for the provider
  9933. type: string
  9934. required:
  9935. - auth
  9936. - regionID
  9937. type: object
  9938. aws:
  9939. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  9940. properties:
  9941. additionalRoles:
  9942. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  9943. items:
  9944. type: string
  9945. type: array
  9946. auth:
  9947. description: |-
  9948. Auth defines the information necessary to authenticate against AWS
  9949. if not set aws sdk will infer credentials from your environment
  9950. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  9951. properties:
  9952. jwt:
  9953. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  9954. properties:
  9955. serviceAccountRef:
  9956. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  9957. properties:
  9958. audiences:
  9959. description: |-
  9960. Audience specifies the `aud` claim for the service account token
  9961. Some providers automatically extend the audience field based on well-known annotations for workload
  9962. identity (e.g. IRSA or GCP Workload Identity)
  9963. items:
  9964. type: string
  9965. type: array
  9966. name:
  9967. description: The name of the ServiceAccount resource being referred to.
  9968. maxLength: 253
  9969. minLength: 1
  9970. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9971. type: string
  9972. namespace:
  9973. description: |-
  9974. Namespace of the resource being referred to.
  9975. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9976. maxLength: 63
  9977. minLength: 1
  9978. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9979. type: string
  9980. required:
  9981. - name
  9982. type: object
  9983. type: object
  9984. secretRef:
  9985. description: |-
  9986. AWSAuthSecretRef holds secret references for AWS credentials
  9987. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  9988. properties:
  9989. accessKeyIDSecretRef:
  9990. description: The AccessKeyID is used for authentication
  9991. properties:
  9992. key:
  9993. description: |-
  9994. A key in the referenced Secret.
  9995. Some instances of this field may be defaulted, in others it may be required.
  9996. maxLength: 253
  9997. minLength: 1
  9998. pattern: ^[-._a-zA-Z0-9]+$
  9999. type: string
  10000. name:
  10001. description: The name of the Secret resource being referred to.
  10002. maxLength: 253
  10003. minLength: 1
  10004. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10005. type: string
  10006. namespace:
  10007. description: |-
  10008. The namespace of the Secret resource being referred to.
  10009. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10010. maxLength: 63
  10011. minLength: 1
  10012. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10013. type: string
  10014. type: object
  10015. secretAccessKeySecretRef:
  10016. description: The SecretAccessKey is used for authentication
  10017. properties:
  10018. key:
  10019. description: |-
  10020. A key in the referenced Secret.
  10021. Some instances of this field may be defaulted, in others it may be required.
  10022. maxLength: 253
  10023. minLength: 1
  10024. pattern: ^[-._a-zA-Z0-9]+$
  10025. type: string
  10026. name:
  10027. description: The name of the Secret resource being referred to.
  10028. maxLength: 253
  10029. minLength: 1
  10030. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10031. type: string
  10032. namespace:
  10033. description: |-
  10034. The namespace of the Secret resource being referred to.
  10035. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10036. maxLength: 63
  10037. minLength: 1
  10038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10039. type: string
  10040. type: object
  10041. sessionTokenSecretRef:
  10042. description: |-
  10043. The SessionToken used for authentication
  10044. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  10045. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  10046. properties:
  10047. key:
  10048. description: |-
  10049. A key in the referenced Secret.
  10050. Some instances of this field may be defaulted, in others it may be required.
  10051. maxLength: 253
  10052. minLength: 1
  10053. pattern: ^[-._a-zA-Z0-9]+$
  10054. type: string
  10055. name:
  10056. description: The name of the Secret resource being referred to.
  10057. maxLength: 253
  10058. minLength: 1
  10059. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10060. type: string
  10061. namespace:
  10062. description: |-
  10063. The namespace of the Secret resource being referred to.
  10064. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10065. maxLength: 63
  10066. minLength: 1
  10067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10068. type: string
  10069. type: object
  10070. type: object
  10071. type: object
  10072. externalID:
  10073. description: AWS External ID set on assumed IAM roles
  10074. type: string
  10075. prefix:
  10076. description: Prefix adds a prefix to all retrieved values.
  10077. type: string
  10078. region:
  10079. description: AWS Region to be used for the provider
  10080. type: string
  10081. role:
  10082. description: Role is a Role ARN which the provider will assume
  10083. type: string
  10084. secretsManager:
  10085. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  10086. properties:
  10087. forceDeleteWithoutRecovery:
  10088. description: |-
  10089. Specifies whether to delete the secret without any recovery window. You
  10090. can't use both this parameter and RecoveryWindowInDays in the same call.
  10091. If you don't use either, then by default Secrets Manager uses a 30 day
  10092. recovery window.
  10093. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  10094. type: boolean
  10095. recoveryWindowInDays:
  10096. description: |-
  10097. The number of days from 7 to 30 that Secrets Manager waits before
  10098. permanently deleting the secret. You can't use both this parameter and
  10099. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  10100. then by default Secrets Manager uses a 30 day recovery window.
  10101. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  10102. format: int64
  10103. type: integer
  10104. type: object
  10105. service:
  10106. description: Service defines which service should be used to fetch the secrets
  10107. enum:
  10108. - SecretsManager
  10109. - ParameterStore
  10110. type: string
  10111. sessionTags:
  10112. description: AWS STS assume role session tags
  10113. items:
  10114. description: Tag defines a tag key and value for AWS resources.
  10115. properties:
  10116. key:
  10117. type: string
  10118. value:
  10119. type: string
  10120. required:
  10121. - key
  10122. - value
  10123. type: object
  10124. type: array
  10125. transitiveTagKeys:
  10126. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  10127. items:
  10128. type: string
  10129. type: array
  10130. required:
  10131. - region
  10132. - service
  10133. type: object
  10134. azurekv:
  10135. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  10136. properties:
  10137. authSecretRef:
  10138. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  10139. properties:
  10140. clientCertificate:
  10141. description: The Azure ClientCertificate of the service principle used for authentication.
  10142. properties:
  10143. key:
  10144. description: |-
  10145. A key in the referenced Secret.
  10146. Some instances of this field may be defaulted, in others it may be required.
  10147. maxLength: 253
  10148. minLength: 1
  10149. pattern: ^[-._a-zA-Z0-9]+$
  10150. type: string
  10151. name:
  10152. description: The name of the Secret resource being referred to.
  10153. maxLength: 253
  10154. minLength: 1
  10155. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10156. type: string
  10157. namespace:
  10158. description: |-
  10159. The namespace of the Secret resource being referred to.
  10160. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10161. maxLength: 63
  10162. minLength: 1
  10163. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10164. type: string
  10165. type: object
  10166. clientId:
  10167. description: The Azure clientId of the service principle or managed identity used for authentication.
  10168. properties:
  10169. key:
  10170. description: |-
  10171. A key in the referenced Secret.
  10172. Some instances of this field may be defaulted, in others it may be required.
  10173. maxLength: 253
  10174. minLength: 1
  10175. pattern: ^[-._a-zA-Z0-9]+$
  10176. type: string
  10177. name:
  10178. description: The name of the Secret resource being referred to.
  10179. maxLength: 253
  10180. minLength: 1
  10181. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10182. type: string
  10183. namespace:
  10184. description: |-
  10185. The namespace of the Secret resource being referred to.
  10186. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10187. maxLength: 63
  10188. minLength: 1
  10189. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10190. type: string
  10191. type: object
  10192. clientSecret:
  10193. description: The Azure ClientSecret of the service principle used for authentication.
  10194. properties:
  10195. key:
  10196. description: |-
  10197. A key in the referenced Secret.
  10198. Some instances of this field may be defaulted, in others it may be required.
  10199. maxLength: 253
  10200. minLength: 1
  10201. pattern: ^[-._a-zA-Z0-9]+$
  10202. type: string
  10203. name:
  10204. description: The name of the Secret resource being referred to.
  10205. maxLength: 253
  10206. minLength: 1
  10207. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10208. type: string
  10209. namespace:
  10210. description: |-
  10211. The namespace of the Secret resource being referred to.
  10212. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10213. maxLength: 63
  10214. minLength: 1
  10215. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10216. type: string
  10217. type: object
  10218. tenantId:
  10219. description: The Azure tenantId of the managed identity used for authentication.
  10220. properties:
  10221. key:
  10222. description: |-
  10223. A key in the referenced Secret.
  10224. Some instances of this field may be defaulted, in others it may be required.
  10225. maxLength: 253
  10226. minLength: 1
  10227. pattern: ^[-._a-zA-Z0-9]+$
  10228. type: string
  10229. name:
  10230. description: The name of the Secret resource being referred to.
  10231. maxLength: 253
  10232. minLength: 1
  10233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10234. type: string
  10235. namespace:
  10236. description: |-
  10237. The namespace of the Secret resource being referred to.
  10238. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10239. maxLength: 63
  10240. minLength: 1
  10241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10242. type: string
  10243. type: object
  10244. type: object
  10245. authType:
  10246. default: ServicePrincipal
  10247. description: |-
  10248. Auth type defines how to authenticate to the keyvault service.
  10249. Valid values are:
  10250. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  10251. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  10252. enum:
  10253. - ServicePrincipal
  10254. - ManagedIdentity
  10255. - WorkloadIdentity
  10256. type: string
  10257. environmentType:
  10258. default: PublicCloud
  10259. description: |-
  10260. EnvironmentType specifies the Azure cloud environment endpoints to use for
  10261. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  10262. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  10263. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  10264. enum:
  10265. - PublicCloud
  10266. - USGovernmentCloud
  10267. - ChinaCloud
  10268. - GermanCloud
  10269. type: string
  10270. identityId:
  10271. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  10272. type: string
  10273. serviceAccountRef:
  10274. description: |-
  10275. ServiceAccountRef specified the service account
  10276. that should be used when authenticating with WorkloadIdentity.
  10277. properties:
  10278. audiences:
  10279. description: |-
  10280. Audience specifies the `aud` claim for the service account token
  10281. Some providers automatically extend the audience field based on well-known annotations for workload
  10282. identity (e.g. IRSA or GCP Workload Identity)
  10283. items:
  10284. type: string
  10285. type: array
  10286. name:
  10287. description: The name of the ServiceAccount resource being referred to.
  10288. maxLength: 253
  10289. minLength: 1
  10290. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10291. type: string
  10292. namespace:
  10293. description: |-
  10294. Namespace of the resource being referred to.
  10295. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10296. maxLength: 63
  10297. minLength: 1
  10298. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10299. type: string
  10300. required:
  10301. - name
  10302. type: object
  10303. tenantId:
  10304. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  10305. type: string
  10306. vaultUrl:
  10307. description: Vault Url from which the secrets to be fetched from.
  10308. type: string
  10309. required:
  10310. - vaultUrl
  10311. type: object
  10312. beyondtrust:
  10313. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  10314. properties:
  10315. auth:
  10316. description: Auth configures how the operator authenticates with Beyondtrust.
  10317. properties:
  10318. apiKey:
  10319. description: APIKey If not provided then ClientID/ClientSecret become required.
  10320. properties:
  10321. secretRef:
  10322. description: SecretRef references a key in a secret that will be used as value.
  10323. properties:
  10324. key:
  10325. description: |-
  10326. A key in the referenced Secret.
  10327. Some instances of this field may be defaulted, in others it may be required.
  10328. maxLength: 253
  10329. minLength: 1
  10330. pattern: ^[-._a-zA-Z0-9]+$
  10331. type: string
  10332. name:
  10333. description: The name of the Secret resource being referred to.
  10334. maxLength: 253
  10335. minLength: 1
  10336. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10337. type: string
  10338. namespace:
  10339. description: |-
  10340. The namespace of the Secret resource being referred to.
  10341. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10342. maxLength: 63
  10343. minLength: 1
  10344. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10345. type: string
  10346. type: object
  10347. value:
  10348. description: Value can be specified directly to set a value without using a secret.
  10349. type: string
  10350. type: object
  10351. certificate:
  10352. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  10353. properties:
  10354. secretRef:
  10355. description: SecretRef references a key in a secret that will be used as value.
  10356. properties:
  10357. key:
  10358. description: |-
  10359. A key in the referenced Secret.
  10360. Some instances of this field may be defaulted, in others it may be required.
  10361. maxLength: 253
  10362. minLength: 1
  10363. pattern: ^[-._a-zA-Z0-9]+$
  10364. type: string
  10365. name:
  10366. description: The name of the Secret resource being referred to.
  10367. maxLength: 253
  10368. minLength: 1
  10369. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10370. type: string
  10371. namespace:
  10372. description: |-
  10373. The namespace of the Secret resource being referred to.
  10374. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10375. maxLength: 63
  10376. minLength: 1
  10377. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10378. type: string
  10379. type: object
  10380. value:
  10381. description: Value can be specified directly to set a value without using a secret.
  10382. type: string
  10383. type: object
  10384. certificateKey:
  10385. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  10386. properties:
  10387. secretRef:
  10388. description: SecretRef references a key in a secret that will be used as value.
  10389. properties:
  10390. key:
  10391. description: |-
  10392. A key in the referenced Secret.
  10393. Some instances of this field may be defaulted, in others it may be required.
  10394. maxLength: 253
  10395. minLength: 1
  10396. pattern: ^[-._a-zA-Z0-9]+$
  10397. type: string
  10398. name:
  10399. description: The name of the Secret resource being referred to.
  10400. maxLength: 253
  10401. minLength: 1
  10402. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10403. type: string
  10404. namespace:
  10405. description: |-
  10406. The namespace of the Secret resource being referred to.
  10407. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10408. maxLength: 63
  10409. minLength: 1
  10410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10411. type: string
  10412. type: object
  10413. value:
  10414. description: Value can be specified directly to set a value without using a secret.
  10415. type: string
  10416. type: object
  10417. clientId:
  10418. description: ClientID is the API OAuth Client ID.
  10419. properties:
  10420. secretRef:
  10421. description: SecretRef references a key in a secret that will be used as value.
  10422. properties:
  10423. key:
  10424. description: |-
  10425. A key in the referenced Secret.
  10426. Some instances of this field may be defaulted, in others it may be required.
  10427. maxLength: 253
  10428. minLength: 1
  10429. pattern: ^[-._a-zA-Z0-9]+$
  10430. type: string
  10431. name:
  10432. description: The name of the Secret resource being referred to.
  10433. maxLength: 253
  10434. minLength: 1
  10435. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10436. type: string
  10437. namespace:
  10438. description: |-
  10439. The namespace of the Secret resource being referred to.
  10440. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10441. maxLength: 63
  10442. minLength: 1
  10443. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10444. type: string
  10445. type: object
  10446. value:
  10447. description: Value can be specified directly to set a value without using a secret.
  10448. type: string
  10449. type: object
  10450. clientSecret:
  10451. description: ClientSecret is the API OAuth Client Secret.
  10452. properties:
  10453. secretRef:
  10454. description: SecretRef references a key in a secret that will be used as value.
  10455. properties:
  10456. key:
  10457. description: |-
  10458. A key in the referenced Secret.
  10459. Some instances of this field may be defaulted, in others it may be required.
  10460. maxLength: 253
  10461. minLength: 1
  10462. pattern: ^[-._a-zA-Z0-9]+$
  10463. type: string
  10464. name:
  10465. description: The name of the Secret resource being referred to.
  10466. maxLength: 253
  10467. minLength: 1
  10468. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10469. type: string
  10470. namespace:
  10471. description: |-
  10472. The namespace of the Secret resource being referred to.
  10473. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10474. maxLength: 63
  10475. minLength: 1
  10476. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10477. type: string
  10478. type: object
  10479. value:
  10480. description: Value can be specified directly to set a value without using a secret.
  10481. type: string
  10482. type: object
  10483. type: object
  10484. server:
  10485. description: Auth configures how API server works.
  10486. properties:
  10487. apiUrl:
  10488. type: string
  10489. apiVersion:
  10490. type: string
  10491. clientTimeOutSeconds:
  10492. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  10493. type: integer
  10494. decrypt:
  10495. default: true
  10496. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  10497. type: boolean
  10498. retrievalType:
  10499. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  10500. type: string
  10501. separator:
  10502. description: A character that separates the folder names.
  10503. type: string
  10504. verifyCA:
  10505. type: boolean
  10506. required:
  10507. - apiUrl
  10508. - verifyCA
  10509. type: object
  10510. required:
  10511. - auth
  10512. - server
  10513. type: object
  10514. bitwardensecretsmanager:
  10515. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  10516. properties:
  10517. apiURL:
  10518. type: string
  10519. auth:
  10520. description: |-
  10521. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  10522. Make sure that the token being used has permissions on the given secret.
  10523. properties:
  10524. secretRef:
  10525. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  10526. properties:
  10527. credentials:
  10528. description: AccessToken used for the bitwarden instance.
  10529. properties:
  10530. key:
  10531. description: |-
  10532. A key in the referenced Secret.
  10533. Some instances of this field may be defaulted, in others it may be required.
  10534. maxLength: 253
  10535. minLength: 1
  10536. pattern: ^[-._a-zA-Z0-9]+$
  10537. type: string
  10538. name:
  10539. description: The name of the Secret resource being referred to.
  10540. maxLength: 253
  10541. minLength: 1
  10542. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10543. type: string
  10544. namespace:
  10545. description: |-
  10546. The namespace of the Secret resource being referred to.
  10547. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10548. maxLength: 63
  10549. minLength: 1
  10550. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10551. type: string
  10552. type: object
  10553. required:
  10554. - credentials
  10555. type: object
  10556. required:
  10557. - secretRef
  10558. type: object
  10559. bitwardenServerSDKURL:
  10560. type: string
  10561. caBundle:
  10562. description: |-
  10563. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  10564. can be performed.
  10565. type: string
  10566. caProvider:
  10567. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  10568. properties:
  10569. key:
  10570. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10571. maxLength: 253
  10572. minLength: 1
  10573. pattern: ^[-._a-zA-Z0-9]+$
  10574. type: string
  10575. name:
  10576. description: The name of the object located at the provider type.
  10577. maxLength: 253
  10578. minLength: 1
  10579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10580. type: string
  10581. namespace:
  10582. description: |-
  10583. The namespace the Provider type is in.
  10584. Can only be defined when used in a ClusterSecretStore.
  10585. maxLength: 63
  10586. minLength: 1
  10587. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10588. type: string
  10589. type:
  10590. description: The type of provider to use such as "Secret", or "ConfigMap".
  10591. enum:
  10592. - Secret
  10593. - ConfigMap
  10594. type: string
  10595. required:
  10596. - name
  10597. - type
  10598. type: object
  10599. identityURL:
  10600. type: string
  10601. organizationID:
  10602. description: OrganizationID determines which organization this secret store manages.
  10603. type: string
  10604. projectID:
  10605. description: ProjectID determines which project this secret store manages.
  10606. type: string
  10607. required:
  10608. - auth
  10609. - organizationID
  10610. - projectID
  10611. type: object
  10612. chef:
  10613. description: Chef configures this store to sync secrets with chef server
  10614. properties:
  10615. auth:
  10616. description: Auth defines the information necessary to authenticate against chef Server
  10617. properties:
  10618. secretRef:
  10619. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  10620. properties:
  10621. privateKeySecretRef:
  10622. description: SecretKey is the Signing Key in PEM format, used for authentication.
  10623. properties:
  10624. key:
  10625. description: |-
  10626. A key in the referenced Secret.
  10627. Some instances of this field may be defaulted, in others it may be required.
  10628. maxLength: 253
  10629. minLength: 1
  10630. pattern: ^[-._a-zA-Z0-9]+$
  10631. type: string
  10632. name:
  10633. description: The name of the Secret resource being referred to.
  10634. maxLength: 253
  10635. minLength: 1
  10636. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10637. type: string
  10638. namespace:
  10639. description: |-
  10640. The namespace of the Secret resource being referred to.
  10641. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10642. maxLength: 63
  10643. minLength: 1
  10644. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10645. type: string
  10646. type: object
  10647. required:
  10648. - privateKeySecretRef
  10649. type: object
  10650. required:
  10651. - secretRef
  10652. type: object
  10653. serverUrl:
  10654. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  10655. type: string
  10656. username:
  10657. description: UserName should be the user ID on the chef server
  10658. type: string
  10659. required:
  10660. - auth
  10661. - serverUrl
  10662. - username
  10663. type: object
  10664. cloudrusm:
  10665. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  10666. properties:
  10667. auth:
  10668. description: CSMAuth contains a secretRef for credentials.
  10669. properties:
  10670. secretRef:
  10671. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  10672. properties:
  10673. accessKeyIDSecretRef:
  10674. description: The AccessKeyID is used for authentication
  10675. properties:
  10676. key:
  10677. description: |-
  10678. A key in the referenced Secret.
  10679. Some instances of this field may be defaulted, in others it may be required.
  10680. maxLength: 253
  10681. minLength: 1
  10682. pattern: ^[-._a-zA-Z0-9]+$
  10683. type: string
  10684. name:
  10685. description: The name of the Secret resource being referred to.
  10686. maxLength: 253
  10687. minLength: 1
  10688. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10689. type: string
  10690. namespace:
  10691. description: |-
  10692. The namespace of the Secret resource being referred to.
  10693. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10694. maxLength: 63
  10695. minLength: 1
  10696. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10697. type: string
  10698. type: object
  10699. accessKeySecretSecretRef:
  10700. description: The AccessKeySecret is used for authentication
  10701. properties:
  10702. key:
  10703. description: |-
  10704. A key in the referenced Secret.
  10705. Some instances of this field may be defaulted, in others it may be required.
  10706. maxLength: 253
  10707. minLength: 1
  10708. pattern: ^[-._a-zA-Z0-9]+$
  10709. type: string
  10710. name:
  10711. description: The name of the Secret resource being referred to.
  10712. maxLength: 253
  10713. minLength: 1
  10714. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10715. type: string
  10716. namespace:
  10717. description: |-
  10718. The namespace of the Secret resource being referred to.
  10719. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10720. maxLength: 63
  10721. minLength: 1
  10722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10723. type: string
  10724. type: object
  10725. required:
  10726. - accessKeyIDSecretRef
  10727. - accessKeySecretSecretRef
  10728. type: object
  10729. type: object
  10730. projectID:
  10731. description: ProjectID is the project, which the secrets are stored in.
  10732. type: string
  10733. required:
  10734. - auth
  10735. type: object
  10736. conjur:
  10737. description: Conjur configures this store to sync secrets using conjur provider
  10738. properties:
  10739. auth:
  10740. description: Defines authentication settings for connecting to Conjur.
  10741. properties:
  10742. apikey:
  10743. description: Authenticates with Conjur using an API key.
  10744. properties:
  10745. account:
  10746. description: Account is the Conjur organization account name.
  10747. type: string
  10748. apiKeyRef:
  10749. description: |-
  10750. A reference to a specific 'key' containing the Conjur API key
  10751. within a Secret resource. In some instances, `key` is a required field.
  10752. properties:
  10753. key:
  10754. description: |-
  10755. A key in the referenced Secret.
  10756. Some instances of this field may be defaulted, in others it may be required.
  10757. maxLength: 253
  10758. minLength: 1
  10759. pattern: ^[-._a-zA-Z0-9]+$
  10760. type: string
  10761. name:
  10762. description: The name of the Secret resource being referred to.
  10763. maxLength: 253
  10764. minLength: 1
  10765. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10766. type: string
  10767. namespace:
  10768. description: |-
  10769. The namespace of the Secret resource being referred to.
  10770. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10771. maxLength: 63
  10772. minLength: 1
  10773. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10774. type: string
  10775. type: object
  10776. userRef:
  10777. description: |-
  10778. A reference to a specific 'key' containing the Conjur username
  10779. within a Secret resource. In some instances, `key` is a required field.
  10780. properties:
  10781. key:
  10782. description: |-
  10783. A key in the referenced Secret.
  10784. Some instances of this field may be defaulted, in others it may be required.
  10785. maxLength: 253
  10786. minLength: 1
  10787. pattern: ^[-._a-zA-Z0-9]+$
  10788. type: string
  10789. name:
  10790. description: The name of the Secret resource being referred to.
  10791. maxLength: 253
  10792. minLength: 1
  10793. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10794. type: string
  10795. namespace:
  10796. description: |-
  10797. The namespace of the Secret resource being referred to.
  10798. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10799. maxLength: 63
  10800. minLength: 1
  10801. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10802. type: string
  10803. type: object
  10804. required:
  10805. - account
  10806. - apiKeyRef
  10807. - userRef
  10808. type: object
  10809. jwt:
  10810. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  10811. properties:
  10812. account:
  10813. description: Account is the Conjur organization account name.
  10814. type: string
  10815. hostId:
  10816. description: |-
  10817. Optional HostID for JWT authentication. This may be used depending
  10818. on how the Conjur JWT authenticator policy is configured.
  10819. type: string
  10820. secretRef:
  10821. description: |-
  10822. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  10823. authenticate with Conjur using the JWT authentication method.
  10824. properties:
  10825. key:
  10826. description: |-
  10827. A key in the referenced Secret.
  10828. Some instances of this field may be defaulted, in others it may be required.
  10829. maxLength: 253
  10830. minLength: 1
  10831. pattern: ^[-._a-zA-Z0-9]+$
  10832. type: string
  10833. name:
  10834. description: The name of the Secret resource being referred to.
  10835. maxLength: 253
  10836. minLength: 1
  10837. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10838. type: string
  10839. namespace:
  10840. description: |-
  10841. The namespace of the Secret resource being referred to.
  10842. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10843. maxLength: 63
  10844. minLength: 1
  10845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10846. type: string
  10847. type: object
  10848. serviceAccountRef:
  10849. description: |-
  10850. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  10851. a token for with the `TokenRequest` API.
  10852. properties:
  10853. audiences:
  10854. description: |-
  10855. Audience specifies the `aud` claim for the service account token
  10856. Some providers automatically extend the audience field based on well-known annotations for workload
  10857. identity (e.g. IRSA or GCP Workload Identity)
  10858. items:
  10859. type: string
  10860. type: array
  10861. name:
  10862. description: The name of the ServiceAccount resource being referred to.
  10863. maxLength: 253
  10864. minLength: 1
  10865. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10866. type: string
  10867. namespace:
  10868. description: |-
  10869. Namespace of the resource being referred to.
  10870. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10871. maxLength: 63
  10872. minLength: 1
  10873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10874. type: string
  10875. required:
  10876. - name
  10877. type: object
  10878. serviceID:
  10879. description: The conjur authn jwt webservice id
  10880. type: string
  10881. required:
  10882. - account
  10883. - serviceID
  10884. type: object
  10885. type: object
  10886. caBundle:
  10887. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  10888. type: string
  10889. caProvider:
  10890. description: |-
  10891. Used to provide custom certificate authority (CA) certificates
  10892. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  10893. that contains a PEM-encoded certificate.
  10894. properties:
  10895. key:
  10896. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10897. maxLength: 253
  10898. minLength: 1
  10899. pattern: ^[-._a-zA-Z0-9]+$
  10900. type: string
  10901. name:
  10902. description: The name of the object located at the provider type.
  10903. maxLength: 253
  10904. minLength: 1
  10905. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10906. type: string
  10907. namespace:
  10908. description: |-
  10909. The namespace the Provider type is in.
  10910. Can only be defined when used in a ClusterSecretStore.
  10911. maxLength: 63
  10912. minLength: 1
  10913. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10914. type: string
  10915. type:
  10916. description: The type of provider to use such as "Secret", or "ConfigMap".
  10917. enum:
  10918. - Secret
  10919. - ConfigMap
  10920. type: string
  10921. required:
  10922. - name
  10923. - type
  10924. type: object
  10925. url:
  10926. description: URL is the endpoint of the Conjur instance.
  10927. type: string
  10928. required:
  10929. - auth
  10930. - url
  10931. type: object
  10932. delinea:
  10933. description: |-
  10934. Delinea DevOps Secrets Vault
  10935. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  10936. properties:
  10937. clientId:
  10938. description: ClientID is the non-secret part of the credential.
  10939. properties:
  10940. secretRef:
  10941. description: SecretRef references a key in a secret that will be used as value.
  10942. properties:
  10943. key:
  10944. description: |-
  10945. A key in the referenced Secret.
  10946. Some instances of this field may be defaulted, in others it may be required.
  10947. maxLength: 253
  10948. minLength: 1
  10949. pattern: ^[-._a-zA-Z0-9]+$
  10950. type: string
  10951. name:
  10952. description: The name of the Secret resource being referred to.
  10953. maxLength: 253
  10954. minLength: 1
  10955. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10956. type: string
  10957. namespace:
  10958. description: |-
  10959. The namespace of the Secret resource being referred to.
  10960. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10961. maxLength: 63
  10962. minLength: 1
  10963. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10964. type: string
  10965. type: object
  10966. value:
  10967. description: Value can be specified directly to set a value without using a secret.
  10968. type: string
  10969. type: object
  10970. clientSecret:
  10971. description: ClientSecret is the secret part of the credential.
  10972. properties:
  10973. secretRef:
  10974. description: SecretRef references a key in a secret that will be used as value.
  10975. properties:
  10976. key:
  10977. description: |-
  10978. A key in the referenced Secret.
  10979. Some instances of this field may be defaulted, in others it may be required.
  10980. maxLength: 253
  10981. minLength: 1
  10982. pattern: ^[-._a-zA-Z0-9]+$
  10983. type: string
  10984. name:
  10985. description: The name of the Secret resource being referred to.
  10986. maxLength: 253
  10987. minLength: 1
  10988. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10989. type: string
  10990. namespace:
  10991. description: |-
  10992. The namespace of the Secret resource being referred to.
  10993. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10994. maxLength: 63
  10995. minLength: 1
  10996. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10997. type: string
  10998. type: object
  10999. value:
  11000. description: Value can be specified directly to set a value without using a secret.
  11001. type: string
  11002. type: object
  11003. tenant:
  11004. description: Tenant is the chosen hostname / site name.
  11005. type: string
  11006. tld:
  11007. description: |-
  11008. TLD is based on the server location that was chosen during provisioning.
  11009. If unset, defaults to "com".
  11010. type: string
  11011. urlTemplate:
  11012. description: |-
  11013. URLTemplate
  11014. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  11015. type: string
  11016. required:
  11017. - clientId
  11018. - clientSecret
  11019. - tenant
  11020. type: object
  11021. device42:
  11022. description: Device42 configures this store to sync secrets using the Device42 provider
  11023. properties:
  11024. auth:
  11025. description: Auth configures how secret-manager authenticates with a Device42 instance.
  11026. properties:
  11027. secretRef:
  11028. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  11029. properties:
  11030. credentials:
  11031. description: Username / Password is used for authentication.
  11032. properties:
  11033. key:
  11034. description: |-
  11035. A key in the referenced Secret.
  11036. Some instances of this field may be defaulted, in others it may be required.
  11037. maxLength: 253
  11038. minLength: 1
  11039. pattern: ^[-._a-zA-Z0-9]+$
  11040. type: string
  11041. name:
  11042. description: The name of the Secret resource being referred to.
  11043. maxLength: 253
  11044. minLength: 1
  11045. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11046. type: string
  11047. namespace:
  11048. description: |-
  11049. The namespace of the Secret resource being referred to.
  11050. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11051. maxLength: 63
  11052. minLength: 1
  11053. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11054. type: string
  11055. type: object
  11056. type: object
  11057. required:
  11058. - secretRef
  11059. type: object
  11060. host:
  11061. description: URL configures the Device42 instance URL.
  11062. type: string
  11063. required:
  11064. - auth
  11065. - host
  11066. type: object
  11067. doppler:
  11068. description: Doppler configures this store to sync secrets using the Doppler provider
  11069. properties:
  11070. auth:
  11071. description: Auth configures how the Operator authenticates with the Doppler API
  11072. properties:
  11073. secretRef:
  11074. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  11075. properties:
  11076. dopplerToken:
  11077. description: |-
  11078. The DopplerToken is used for authentication.
  11079. See https://docs.doppler.com/reference/api#authentication for auth token types.
  11080. The Key attribute defaults to dopplerToken if not specified.
  11081. properties:
  11082. key:
  11083. description: |-
  11084. A key in the referenced Secret.
  11085. Some instances of this field may be defaulted, in others it may be required.
  11086. maxLength: 253
  11087. minLength: 1
  11088. pattern: ^[-._a-zA-Z0-9]+$
  11089. type: string
  11090. name:
  11091. description: The name of the Secret resource being referred to.
  11092. maxLength: 253
  11093. minLength: 1
  11094. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11095. type: string
  11096. namespace:
  11097. description: |-
  11098. The namespace of the Secret resource being referred to.
  11099. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11100. maxLength: 63
  11101. minLength: 1
  11102. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11103. type: string
  11104. type: object
  11105. required:
  11106. - dopplerToken
  11107. type: object
  11108. required:
  11109. - secretRef
  11110. type: object
  11111. config:
  11112. description: Doppler config (required if not using a Service Token)
  11113. type: string
  11114. format:
  11115. description: Format enables the downloading of secrets as a file (string)
  11116. enum:
  11117. - json
  11118. - dotnet-json
  11119. - env
  11120. - yaml
  11121. - docker
  11122. type: string
  11123. nameTransformer:
  11124. description: Environment variable compatible name transforms that change secret names to a different format
  11125. enum:
  11126. - upper-camel
  11127. - camel
  11128. - lower-snake
  11129. - tf-var
  11130. - dotnet-env
  11131. - lower-kebab
  11132. type: string
  11133. project:
  11134. description: Doppler project (required if not using a Service Token)
  11135. type: string
  11136. required:
  11137. - auth
  11138. type: object
  11139. fake:
  11140. description: Fake configures a store with static key/value pairs
  11141. properties:
  11142. data:
  11143. items:
  11144. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  11145. properties:
  11146. key:
  11147. type: string
  11148. value:
  11149. type: string
  11150. version:
  11151. type: string
  11152. required:
  11153. - key
  11154. - value
  11155. type: object
  11156. type: array
  11157. required:
  11158. - data
  11159. type: object
  11160. fortanix:
  11161. description: Fortanix configures this store to sync secrets using the Fortanix provider
  11162. properties:
  11163. apiKey:
  11164. description: APIKey is the API token to access SDKMS Applications.
  11165. properties:
  11166. secretRef:
  11167. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  11168. properties:
  11169. key:
  11170. description: |-
  11171. A key in the referenced Secret.
  11172. Some instances of this field may be defaulted, in others it may be required.
  11173. maxLength: 253
  11174. minLength: 1
  11175. pattern: ^[-._a-zA-Z0-9]+$
  11176. type: string
  11177. name:
  11178. description: The name of the Secret resource being referred to.
  11179. maxLength: 253
  11180. minLength: 1
  11181. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11182. type: string
  11183. namespace:
  11184. description: |-
  11185. The namespace of the Secret resource being referred to.
  11186. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11187. maxLength: 63
  11188. minLength: 1
  11189. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11190. type: string
  11191. type: object
  11192. type: object
  11193. apiUrl:
  11194. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  11195. type: string
  11196. type: object
  11197. gcpsm:
  11198. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  11199. properties:
  11200. auth:
  11201. description: Auth defines the information necessary to authenticate against GCP
  11202. properties:
  11203. secretRef:
  11204. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  11205. properties:
  11206. secretAccessKeySecretRef:
  11207. description: The SecretAccessKey is used for authentication
  11208. properties:
  11209. key:
  11210. description: |-
  11211. A key in the referenced Secret.
  11212. Some instances of this field may be defaulted, in others it may be required.
  11213. maxLength: 253
  11214. minLength: 1
  11215. pattern: ^[-._a-zA-Z0-9]+$
  11216. type: string
  11217. name:
  11218. description: The name of the Secret resource being referred to.
  11219. maxLength: 253
  11220. minLength: 1
  11221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11222. type: string
  11223. namespace:
  11224. description: |-
  11225. The namespace of the Secret resource being referred to.
  11226. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11227. maxLength: 63
  11228. minLength: 1
  11229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11230. type: string
  11231. type: object
  11232. type: object
  11233. workloadIdentity:
  11234. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  11235. properties:
  11236. clusterLocation:
  11237. description: |-
  11238. ClusterLocation is the location of the cluster
  11239. If not specified, it fetches information from the metadata server
  11240. type: string
  11241. clusterName:
  11242. description: |-
  11243. ClusterName is the name of the cluster
  11244. If not specified, it fetches information from the metadata server
  11245. type: string
  11246. clusterProjectID:
  11247. description: |-
  11248. ClusterProjectID is the project ID of the cluster
  11249. If not specified, it fetches information from the metadata server
  11250. type: string
  11251. serviceAccountRef:
  11252. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  11253. properties:
  11254. audiences:
  11255. description: |-
  11256. Audience specifies the `aud` claim for the service account token
  11257. Some providers automatically extend the audience field based on well-known annotations for workload
  11258. identity (e.g. IRSA or GCP Workload Identity)
  11259. items:
  11260. type: string
  11261. type: array
  11262. name:
  11263. description: The name of the ServiceAccount resource being referred to.
  11264. maxLength: 253
  11265. minLength: 1
  11266. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11267. type: string
  11268. namespace:
  11269. description: |-
  11270. Namespace of the resource being referred to.
  11271. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11272. maxLength: 63
  11273. minLength: 1
  11274. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11275. type: string
  11276. required:
  11277. - name
  11278. type: object
  11279. required:
  11280. - serviceAccountRef
  11281. type: object
  11282. type: object
  11283. location:
  11284. description: Location optionally defines a location for a secret
  11285. type: string
  11286. projectID:
  11287. description: ProjectID project where secret is located
  11288. type: string
  11289. type: object
  11290. github:
  11291. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  11292. properties:
  11293. appID:
  11294. description: appID specifies the Github APP that will be used to authenticate the client
  11295. format: int64
  11296. type: integer
  11297. auth:
  11298. description: auth configures how secret-manager authenticates with a Github instance.
  11299. properties:
  11300. privateKey:
  11301. description: |-
  11302. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11303. In some instances, `key` is a required field.
  11304. properties:
  11305. key:
  11306. description: |-
  11307. A key in the referenced Secret.
  11308. Some instances of this field may be defaulted, in others it may be required.
  11309. maxLength: 253
  11310. minLength: 1
  11311. pattern: ^[-._a-zA-Z0-9]+$
  11312. type: string
  11313. name:
  11314. description: The name of the Secret resource being referred to.
  11315. maxLength: 253
  11316. minLength: 1
  11317. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11318. type: string
  11319. namespace:
  11320. description: |-
  11321. The namespace of the Secret resource being referred to.
  11322. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11323. maxLength: 63
  11324. minLength: 1
  11325. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11326. type: string
  11327. type: object
  11328. required:
  11329. - privateKey
  11330. type: object
  11331. environment:
  11332. description: environment will be used to fetch secrets from a particular environment within a github repository
  11333. type: string
  11334. installationID:
  11335. description: installationID specifies the Github APP installation that will be used to authenticate the client
  11336. format: int64
  11337. type: integer
  11338. organization:
  11339. description: organization will be used to fetch secrets from the Github organization
  11340. type: string
  11341. repository:
  11342. description: repository will be used to fetch secrets from the Github repository within an organization
  11343. type: string
  11344. uploadURL:
  11345. description: Upload URL for enterprise instances. Default to URL.
  11346. type: string
  11347. url:
  11348. default: https://github.com/
  11349. description: URL configures the Github instance URL. Defaults to https://github.com/.
  11350. type: string
  11351. required:
  11352. - appID
  11353. - auth
  11354. - installationID
  11355. - organization
  11356. type: object
  11357. gitlab:
  11358. description: GitLab configures this store to sync secrets using GitLab Variables provider
  11359. properties:
  11360. auth:
  11361. description: Auth configures how secret-manager authenticates with a GitLab instance.
  11362. properties:
  11363. SecretRef:
  11364. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  11365. properties:
  11366. accessToken:
  11367. description: AccessToken is used for authentication.
  11368. properties:
  11369. key:
  11370. description: |-
  11371. A key in the referenced Secret.
  11372. Some instances of this field may be defaulted, in others it may be required.
  11373. maxLength: 253
  11374. minLength: 1
  11375. pattern: ^[-._a-zA-Z0-9]+$
  11376. type: string
  11377. name:
  11378. description: The name of the Secret resource being referred to.
  11379. maxLength: 253
  11380. minLength: 1
  11381. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11382. type: string
  11383. namespace:
  11384. description: |-
  11385. The namespace of the Secret resource being referred to.
  11386. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11387. maxLength: 63
  11388. minLength: 1
  11389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11390. type: string
  11391. type: object
  11392. type: object
  11393. required:
  11394. - SecretRef
  11395. type: object
  11396. caBundle:
  11397. description: |-
  11398. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  11399. can be performed.
  11400. format: byte
  11401. type: string
  11402. caProvider:
  11403. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  11404. properties:
  11405. key:
  11406. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11407. maxLength: 253
  11408. minLength: 1
  11409. pattern: ^[-._a-zA-Z0-9]+$
  11410. type: string
  11411. name:
  11412. description: The name of the object located at the provider type.
  11413. maxLength: 253
  11414. minLength: 1
  11415. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11416. type: string
  11417. namespace:
  11418. description: |-
  11419. The namespace the Provider type is in.
  11420. Can only be defined when used in a ClusterSecretStore.
  11421. maxLength: 63
  11422. minLength: 1
  11423. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11424. type: string
  11425. type:
  11426. description: The type of provider to use such as "Secret", or "ConfigMap".
  11427. enum:
  11428. - Secret
  11429. - ConfigMap
  11430. type: string
  11431. required:
  11432. - name
  11433. - type
  11434. type: object
  11435. environment:
  11436. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  11437. type: string
  11438. groupIDs:
  11439. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  11440. items:
  11441. type: string
  11442. type: array
  11443. inheritFromGroups:
  11444. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  11445. type: boolean
  11446. projectID:
  11447. description: ProjectID specifies a project where secrets are located.
  11448. type: string
  11449. url:
  11450. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  11451. type: string
  11452. required:
  11453. - auth
  11454. type: object
  11455. ibm:
  11456. description: IBM configures this store to sync secrets using IBM Cloud provider
  11457. properties:
  11458. auth:
  11459. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  11460. maxProperties: 1
  11461. minProperties: 1
  11462. properties:
  11463. containerAuth:
  11464. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  11465. properties:
  11466. iamEndpoint:
  11467. type: string
  11468. profile:
  11469. description: the IBM Trusted Profile
  11470. type: string
  11471. tokenLocation:
  11472. description: Location the token is mounted on the pod
  11473. type: string
  11474. required:
  11475. - profile
  11476. type: object
  11477. secretRef:
  11478. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  11479. properties:
  11480. secretApiKeySecretRef:
  11481. description: The SecretAccessKey is used for authentication
  11482. properties:
  11483. key:
  11484. description: |-
  11485. A key in the referenced Secret.
  11486. Some instances of this field may be defaulted, in others it may be required.
  11487. maxLength: 253
  11488. minLength: 1
  11489. pattern: ^[-._a-zA-Z0-9]+$
  11490. type: string
  11491. name:
  11492. description: The name of the Secret resource being referred to.
  11493. maxLength: 253
  11494. minLength: 1
  11495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11496. type: string
  11497. namespace:
  11498. description: |-
  11499. The namespace of the Secret resource being referred to.
  11500. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11501. maxLength: 63
  11502. minLength: 1
  11503. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11504. type: string
  11505. type: object
  11506. type: object
  11507. type: object
  11508. serviceUrl:
  11509. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  11510. type: string
  11511. required:
  11512. - auth
  11513. type: object
  11514. infisical:
  11515. description: Infisical configures this store to sync secrets using the Infisical provider
  11516. properties:
  11517. auth:
  11518. description: Auth configures how the Operator authenticates with the Infisical API
  11519. properties:
  11520. universalAuthCredentials:
  11521. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  11522. properties:
  11523. clientId:
  11524. description: |-
  11525. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11526. In some instances, `key` is a required field.
  11527. properties:
  11528. key:
  11529. description: |-
  11530. A key in the referenced Secret.
  11531. Some instances of this field may be defaulted, in others it may be required.
  11532. maxLength: 253
  11533. minLength: 1
  11534. pattern: ^[-._a-zA-Z0-9]+$
  11535. type: string
  11536. name:
  11537. description: The name of the Secret resource being referred to.
  11538. maxLength: 253
  11539. minLength: 1
  11540. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11541. type: string
  11542. namespace:
  11543. description: |-
  11544. The namespace of the Secret resource being referred to.
  11545. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11546. maxLength: 63
  11547. minLength: 1
  11548. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11549. type: string
  11550. type: object
  11551. clientSecret:
  11552. description: |-
  11553. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11554. In some instances, `key` is a required field.
  11555. properties:
  11556. key:
  11557. description: |-
  11558. A key in the referenced Secret.
  11559. Some instances of this field may be defaulted, in others it may be required.
  11560. maxLength: 253
  11561. minLength: 1
  11562. pattern: ^[-._a-zA-Z0-9]+$
  11563. type: string
  11564. name:
  11565. description: The name of the Secret resource being referred to.
  11566. maxLength: 253
  11567. minLength: 1
  11568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11569. type: string
  11570. namespace:
  11571. description: |-
  11572. The namespace of the Secret resource being referred to.
  11573. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11574. maxLength: 63
  11575. minLength: 1
  11576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11577. type: string
  11578. type: object
  11579. required:
  11580. - clientId
  11581. - clientSecret
  11582. type: object
  11583. type: object
  11584. hostAPI:
  11585. default: https://app.infisical.com/api
  11586. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  11587. type: string
  11588. secretsScope:
  11589. description: SecretsScope defines the scope of the secrets within the workspace
  11590. properties:
  11591. environmentSlug:
  11592. description: EnvironmentSlug is the required slug identifier for the environment.
  11593. type: string
  11594. expandSecretReferences:
  11595. default: true
  11596. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  11597. type: boolean
  11598. projectSlug:
  11599. description: ProjectSlug is the required slug identifier for the project.
  11600. type: string
  11601. recursive:
  11602. default: false
  11603. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  11604. type: boolean
  11605. secretsPath:
  11606. default: /
  11607. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  11608. type: string
  11609. required:
  11610. - environmentSlug
  11611. - projectSlug
  11612. type: object
  11613. required:
  11614. - auth
  11615. - secretsScope
  11616. type: object
  11617. keepersecurity:
  11618. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  11619. properties:
  11620. authRef:
  11621. description: |-
  11622. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11623. In some instances, `key` is a required field.
  11624. properties:
  11625. key:
  11626. description: |-
  11627. A key in the referenced Secret.
  11628. Some instances of this field may be defaulted, in others it may be required.
  11629. maxLength: 253
  11630. minLength: 1
  11631. pattern: ^[-._a-zA-Z0-9]+$
  11632. type: string
  11633. name:
  11634. description: The name of the Secret resource being referred to.
  11635. maxLength: 253
  11636. minLength: 1
  11637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11638. type: string
  11639. namespace:
  11640. description: |-
  11641. The namespace of the Secret resource being referred to.
  11642. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11643. maxLength: 63
  11644. minLength: 1
  11645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11646. type: string
  11647. type: object
  11648. folderID:
  11649. type: string
  11650. required:
  11651. - authRef
  11652. - folderID
  11653. type: object
  11654. kubernetes:
  11655. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  11656. properties:
  11657. auth:
  11658. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  11659. maxProperties: 1
  11660. minProperties: 1
  11661. properties:
  11662. cert:
  11663. description: has both clientCert and clientKey as secretKeySelector
  11664. properties:
  11665. clientCert:
  11666. description: |-
  11667. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11668. In some instances, `key` is a required field.
  11669. properties:
  11670. key:
  11671. description: |-
  11672. A key in the referenced Secret.
  11673. Some instances of this field may be defaulted, in others it may be required.
  11674. maxLength: 253
  11675. minLength: 1
  11676. pattern: ^[-._a-zA-Z0-9]+$
  11677. type: string
  11678. name:
  11679. description: The name of the Secret resource being referred to.
  11680. maxLength: 253
  11681. minLength: 1
  11682. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11683. type: string
  11684. namespace:
  11685. description: |-
  11686. The namespace of the Secret resource being referred to.
  11687. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11688. maxLength: 63
  11689. minLength: 1
  11690. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11691. type: string
  11692. type: object
  11693. clientKey:
  11694. description: |-
  11695. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11696. In some instances, `key` is a required field.
  11697. properties:
  11698. key:
  11699. description: |-
  11700. A key in the referenced Secret.
  11701. Some instances of this field may be defaulted, in others it may be required.
  11702. maxLength: 253
  11703. minLength: 1
  11704. pattern: ^[-._a-zA-Z0-9]+$
  11705. type: string
  11706. name:
  11707. description: The name of the Secret resource being referred to.
  11708. maxLength: 253
  11709. minLength: 1
  11710. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11711. type: string
  11712. namespace:
  11713. description: |-
  11714. The namespace of the Secret resource being referred to.
  11715. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11716. maxLength: 63
  11717. minLength: 1
  11718. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11719. type: string
  11720. type: object
  11721. type: object
  11722. serviceAccount:
  11723. description: points to a service account that should be used for authentication
  11724. properties:
  11725. audiences:
  11726. description: |-
  11727. Audience specifies the `aud` claim for the service account token
  11728. Some providers automatically extend the audience field based on well-known annotations for workload
  11729. identity (e.g. IRSA or GCP Workload Identity)
  11730. items:
  11731. type: string
  11732. type: array
  11733. name:
  11734. description: The name of the ServiceAccount resource being referred to.
  11735. maxLength: 253
  11736. minLength: 1
  11737. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11738. type: string
  11739. namespace:
  11740. description: |-
  11741. Namespace of the resource being referred to.
  11742. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11743. maxLength: 63
  11744. minLength: 1
  11745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11746. type: string
  11747. required:
  11748. - name
  11749. type: object
  11750. token:
  11751. description: use static token to authenticate with
  11752. properties:
  11753. bearerToken:
  11754. description: |-
  11755. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11756. In some instances, `key` is a required field.
  11757. properties:
  11758. key:
  11759. description: |-
  11760. A key in the referenced Secret.
  11761. Some instances of this field may be defaulted, in others it may be required.
  11762. maxLength: 253
  11763. minLength: 1
  11764. pattern: ^[-._a-zA-Z0-9]+$
  11765. type: string
  11766. name:
  11767. description: The name of the Secret resource being referred to.
  11768. maxLength: 253
  11769. minLength: 1
  11770. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11771. type: string
  11772. namespace:
  11773. description: |-
  11774. The namespace of the Secret resource being referred to.
  11775. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11776. maxLength: 63
  11777. minLength: 1
  11778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11779. type: string
  11780. type: object
  11781. type: object
  11782. type: object
  11783. authRef:
  11784. description: A reference to a secret that contains the auth information.
  11785. properties:
  11786. key:
  11787. description: |-
  11788. A key in the referenced Secret.
  11789. Some instances of this field may be defaulted, in others it may be required.
  11790. maxLength: 253
  11791. minLength: 1
  11792. pattern: ^[-._a-zA-Z0-9]+$
  11793. type: string
  11794. name:
  11795. description: The name of the Secret resource being referred to.
  11796. maxLength: 253
  11797. minLength: 1
  11798. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11799. type: string
  11800. namespace:
  11801. description: |-
  11802. The namespace of the Secret resource being referred to.
  11803. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11804. maxLength: 63
  11805. minLength: 1
  11806. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11807. type: string
  11808. type: object
  11809. remoteNamespace:
  11810. default: default
  11811. description: Remote namespace to fetch the secrets from
  11812. maxLength: 63
  11813. minLength: 1
  11814. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11815. type: string
  11816. server:
  11817. description: configures the Kubernetes server Address.
  11818. properties:
  11819. caBundle:
  11820. description: CABundle is a base64-encoded CA certificate
  11821. format: byte
  11822. type: string
  11823. caProvider:
  11824. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  11825. properties:
  11826. key:
  11827. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11828. maxLength: 253
  11829. minLength: 1
  11830. pattern: ^[-._a-zA-Z0-9]+$
  11831. type: string
  11832. name:
  11833. description: The name of the object located at the provider type.
  11834. maxLength: 253
  11835. minLength: 1
  11836. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11837. type: string
  11838. namespace:
  11839. description: |-
  11840. The namespace the Provider type is in.
  11841. Can only be defined when used in a ClusterSecretStore.
  11842. maxLength: 63
  11843. minLength: 1
  11844. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11845. type: string
  11846. type:
  11847. description: The type of provider to use such as "Secret", or "ConfigMap".
  11848. enum:
  11849. - Secret
  11850. - ConfigMap
  11851. type: string
  11852. required:
  11853. - name
  11854. - type
  11855. type: object
  11856. url:
  11857. default: kubernetes.default
  11858. description: configures the Kubernetes server Address.
  11859. type: string
  11860. type: object
  11861. type: object
  11862. onboardbase:
  11863. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  11864. properties:
  11865. apiHost:
  11866. default: https://public.onboardbase.com/api/v1/
  11867. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  11868. type: string
  11869. auth:
  11870. description: Auth configures how the Operator authenticates with the Onboardbase API
  11871. properties:
  11872. apiKeyRef:
  11873. description: |-
  11874. OnboardbaseAPIKey is the APIKey generated by an admin account.
  11875. It is used to recognize and authorize access to a project and environment within onboardbase
  11876. properties:
  11877. key:
  11878. description: |-
  11879. A key in the referenced Secret.
  11880. Some instances of this field may be defaulted, in others it may be required.
  11881. maxLength: 253
  11882. minLength: 1
  11883. pattern: ^[-._a-zA-Z0-9]+$
  11884. type: string
  11885. name:
  11886. description: The name of the Secret resource being referred to.
  11887. maxLength: 253
  11888. minLength: 1
  11889. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11890. type: string
  11891. namespace:
  11892. description: |-
  11893. The namespace of the Secret resource being referred to.
  11894. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11895. maxLength: 63
  11896. minLength: 1
  11897. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11898. type: string
  11899. type: object
  11900. passcodeRef:
  11901. description: OnboardbasePasscode is the passcode attached to the API Key
  11902. properties:
  11903. key:
  11904. description: |-
  11905. A key in the referenced Secret.
  11906. Some instances of this field may be defaulted, in others it may be required.
  11907. maxLength: 253
  11908. minLength: 1
  11909. pattern: ^[-._a-zA-Z0-9]+$
  11910. type: string
  11911. name:
  11912. description: The name of the Secret resource being referred to.
  11913. maxLength: 253
  11914. minLength: 1
  11915. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11916. type: string
  11917. namespace:
  11918. description: |-
  11919. The namespace of the Secret resource being referred to.
  11920. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11921. maxLength: 63
  11922. minLength: 1
  11923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11924. type: string
  11925. type: object
  11926. required:
  11927. - apiKeyRef
  11928. - passcodeRef
  11929. type: object
  11930. environment:
  11931. default: development
  11932. description: Environment is the name of an environmnent within a project to pull the secrets from
  11933. type: string
  11934. project:
  11935. default: development
  11936. description: Project is an onboardbase project that the secrets should be pulled from
  11937. type: string
  11938. required:
  11939. - apiHost
  11940. - auth
  11941. - environment
  11942. - project
  11943. type: object
  11944. onepassword:
  11945. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  11946. properties:
  11947. auth:
  11948. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  11949. properties:
  11950. secretRef:
  11951. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  11952. properties:
  11953. connectTokenSecretRef:
  11954. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  11955. properties:
  11956. key:
  11957. description: |-
  11958. A key in the referenced Secret.
  11959. Some instances of this field may be defaulted, in others it may be required.
  11960. maxLength: 253
  11961. minLength: 1
  11962. pattern: ^[-._a-zA-Z0-9]+$
  11963. type: string
  11964. name:
  11965. description: The name of the Secret resource being referred to.
  11966. maxLength: 253
  11967. minLength: 1
  11968. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11969. type: string
  11970. namespace:
  11971. description: |-
  11972. The namespace of the Secret resource being referred to.
  11973. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11974. maxLength: 63
  11975. minLength: 1
  11976. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11977. type: string
  11978. type: object
  11979. required:
  11980. - connectTokenSecretRef
  11981. type: object
  11982. required:
  11983. - secretRef
  11984. type: object
  11985. connectHost:
  11986. description: ConnectHost defines the OnePassword Connect Server to connect to
  11987. type: string
  11988. vaults:
  11989. additionalProperties:
  11990. type: integer
  11991. description: Vaults defines which OnePassword vaults to search in which order
  11992. type: object
  11993. required:
  11994. - auth
  11995. - connectHost
  11996. - vaults
  11997. type: object
  11998. oracle:
  11999. description: Oracle configures this store to sync secrets using Oracle Vault provider
  12000. properties:
  12001. auth:
  12002. description: |-
  12003. Auth configures how secret-manager authenticates with the Oracle Vault.
  12004. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  12005. properties:
  12006. secretRef:
  12007. description: SecretRef to pass through sensitive information.
  12008. properties:
  12009. fingerprint:
  12010. description: Fingerprint is the fingerprint of the API private key.
  12011. properties:
  12012. key:
  12013. description: |-
  12014. A key in the referenced Secret.
  12015. Some instances of this field may be defaulted, in others it may be required.
  12016. maxLength: 253
  12017. minLength: 1
  12018. pattern: ^[-._a-zA-Z0-9]+$
  12019. type: string
  12020. name:
  12021. description: The name of the Secret resource being referred to.
  12022. maxLength: 253
  12023. minLength: 1
  12024. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12025. type: string
  12026. namespace:
  12027. description: |-
  12028. The namespace of the Secret resource being referred to.
  12029. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12030. maxLength: 63
  12031. minLength: 1
  12032. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12033. type: string
  12034. type: object
  12035. privatekey:
  12036. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  12037. properties:
  12038. key:
  12039. description: |-
  12040. A key in the referenced Secret.
  12041. Some instances of this field may be defaulted, in others it may be required.
  12042. maxLength: 253
  12043. minLength: 1
  12044. pattern: ^[-._a-zA-Z0-9]+$
  12045. type: string
  12046. name:
  12047. description: The name of the Secret resource being referred to.
  12048. maxLength: 253
  12049. minLength: 1
  12050. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12051. type: string
  12052. namespace:
  12053. description: |-
  12054. The namespace of the Secret resource being referred to.
  12055. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12056. maxLength: 63
  12057. minLength: 1
  12058. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12059. type: string
  12060. type: object
  12061. required:
  12062. - fingerprint
  12063. - privatekey
  12064. type: object
  12065. tenancy:
  12066. description: Tenancy is the tenancy OCID where user is located.
  12067. type: string
  12068. user:
  12069. description: User is an access OCID specific to the account.
  12070. type: string
  12071. required:
  12072. - secretRef
  12073. - tenancy
  12074. - user
  12075. type: object
  12076. compartment:
  12077. description: |-
  12078. Compartment is the vault compartment OCID.
  12079. Required for PushSecret
  12080. type: string
  12081. encryptionKey:
  12082. description: |-
  12083. EncryptionKey is the OCID of the encryption key within the vault.
  12084. Required for PushSecret
  12085. type: string
  12086. principalType:
  12087. description: |-
  12088. The type of principal to use for authentication. If left blank, the Auth struct will
  12089. determine the principal type. This optional field must be specified if using
  12090. workload identity.
  12091. enum:
  12092. - ""
  12093. - UserPrincipal
  12094. - InstancePrincipal
  12095. - Workload
  12096. type: string
  12097. region:
  12098. description: Region is the region where vault is located.
  12099. type: string
  12100. serviceAccountRef:
  12101. description: |-
  12102. ServiceAccountRef specified the service account
  12103. that should be used when authenticating with WorkloadIdentity.
  12104. properties:
  12105. audiences:
  12106. description: |-
  12107. Audience specifies the `aud` claim for the service account token
  12108. Some providers automatically extend the audience field based on well-known annotations for workload
  12109. identity (e.g. IRSA or GCP Workload Identity)
  12110. items:
  12111. type: string
  12112. type: array
  12113. name:
  12114. description: The name of the ServiceAccount resource being referred to.
  12115. maxLength: 253
  12116. minLength: 1
  12117. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12118. type: string
  12119. namespace:
  12120. description: |-
  12121. Namespace of the resource being referred to.
  12122. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12123. maxLength: 63
  12124. minLength: 1
  12125. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12126. type: string
  12127. required:
  12128. - name
  12129. type: object
  12130. vault:
  12131. description: Vault is the vault's OCID of the specific vault where secret is located.
  12132. type: string
  12133. required:
  12134. - region
  12135. - vault
  12136. type: object
  12137. passbolt:
  12138. description: PassboltProvider defines configuration for the Passbolt provider.
  12139. properties:
  12140. auth:
  12141. description: Auth defines the information necessary to authenticate against Passbolt Server
  12142. properties:
  12143. passwordSecretRef:
  12144. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  12145. properties:
  12146. key:
  12147. description: |-
  12148. A key in the referenced Secret.
  12149. Some instances of this field may be defaulted, in others it may be required.
  12150. maxLength: 253
  12151. minLength: 1
  12152. pattern: ^[-._a-zA-Z0-9]+$
  12153. type: string
  12154. name:
  12155. description: The name of the Secret resource being referred to.
  12156. maxLength: 253
  12157. minLength: 1
  12158. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12159. type: string
  12160. namespace:
  12161. description: |-
  12162. The namespace of the Secret resource being referred to.
  12163. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12164. maxLength: 63
  12165. minLength: 1
  12166. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12167. type: string
  12168. type: object
  12169. privateKeySecretRef:
  12170. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  12171. properties:
  12172. key:
  12173. description: |-
  12174. A key in the referenced Secret.
  12175. Some instances of this field may be defaulted, in others it may be required.
  12176. maxLength: 253
  12177. minLength: 1
  12178. pattern: ^[-._a-zA-Z0-9]+$
  12179. type: string
  12180. name:
  12181. description: The name of the Secret resource being referred to.
  12182. maxLength: 253
  12183. minLength: 1
  12184. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12185. type: string
  12186. namespace:
  12187. description: |-
  12188. The namespace of the Secret resource being referred to.
  12189. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12190. maxLength: 63
  12191. minLength: 1
  12192. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12193. type: string
  12194. type: object
  12195. required:
  12196. - passwordSecretRef
  12197. - privateKeySecretRef
  12198. type: object
  12199. host:
  12200. description: Host defines the Passbolt Server to connect to
  12201. type: string
  12202. required:
  12203. - auth
  12204. - host
  12205. type: object
  12206. passworddepot:
  12207. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  12208. properties:
  12209. auth:
  12210. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  12211. properties:
  12212. secretRef:
  12213. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  12214. properties:
  12215. credentials:
  12216. description: Username / Password is used for authentication.
  12217. properties:
  12218. key:
  12219. description: |-
  12220. A key in the referenced Secret.
  12221. Some instances of this field may be defaulted, in others it may be required.
  12222. maxLength: 253
  12223. minLength: 1
  12224. pattern: ^[-._a-zA-Z0-9]+$
  12225. type: string
  12226. name:
  12227. description: The name of the Secret resource being referred to.
  12228. maxLength: 253
  12229. minLength: 1
  12230. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12231. type: string
  12232. namespace:
  12233. description: |-
  12234. The namespace of the Secret resource being referred to.
  12235. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12236. maxLength: 63
  12237. minLength: 1
  12238. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12239. type: string
  12240. type: object
  12241. type: object
  12242. required:
  12243. - secretRef
  12244. type: object
  12245. database:
  12246. description: Database to use as source
  12247. type: string
  12248. host:
  12249. description: URL configures the Password Depot instance URL.
  12250. type: string
  12251. required:
  12252. - auth
  12253. - database
  12254. - host
  12255. type: object
  12256. previder:
  12257. description: Previder configures this store to sync secrets using the Previder provider
  12258. properties:
  12259. auth:
  12260. description: PreviderAuth contains a secretRef for credentials.
  12261. properties:
  12262. secretRef:
  12263. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  12264. properties:
  12265. accessToken:
  12266. description: The AccessToken is used for authentication
  12267. properties:
  12268. key:
  12269. description: |-
  12270. A key in the referenced Secret.
  12271. Some instances of this field may be defaulted, in others it may be required.
  12272. maxLength: 253
  12273. minLength: 1
  12274. pattern: ^[-._a-zA-Z0-9]+$
  12275. type: string
  12276. name:
  12277. description: The name of the Secret resource being referred to.
  12278. maxLength: 253
  12279. minLength: 1
  12280. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12281. type: string
  12282. namespace:
  12283. description: |-
  12284. The namespace of the Secret resource being referred to.
  12285. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12286. maxLength: 63
  12287. minLength: 1
  12288. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12289. type: string
  12290. type: object
  12291. required:
  12292. - accessToken
  12293. type: object
  12294. type: object
  12295. baseUri:
  12296. type: string
  12297. required:
  12298. - auth
  12299. type: object
  12300. pulumi:
  12301. description: Pulumi configures this store to sync secrets using the Pulumi provider
  12302. properties:
  12303. accessToken:
  12304. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  12305. properties:
  12306. secretRef:
  12307. description: SecretRef is a reference to a secret containing the Pulumi API token.
  12308. properties:
  12309. key:
  12310. description: |-
  12311. A key in the referenced Secret.
  12312. Some instances of this field may be defaulted, in others it may be required.
  12313. maxLength: 253
  12314. minLength: 1
  12315. pattern: ^[-._a-zA-Z0-9]+$
  12316. type: string
  12317. name:
  12318. description: The name of the Secret resource being referred to.
  12319. maxLength: 253
  12320. minLength: 1
  12321. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12322. type: string
  12323. namespace:
  12324. description: |-
  12325. The namespace of the Secret resource being referred to.
  12326. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12327. maxLength: 63
  12328. minLength: 1
  12329. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12330. type: string
  12331. type: object
  12332. type: object
  12333. apiUrl:
  12334. default: https://api.pulumi.com/api/esc
  12335. description: APIURL is the URL of the Pulumi API.
  12336. type: string
  12337. environment:
  12338. description: |-
  12339. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  12340. dynamically retrieved values from supported providers including all major clouds,
  12341. and other Pulumi ESC environments.
  12342. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  12343. type: string
  12344. organization:
  12345. description: |-
  12346. Organization are a space to collaborate on shared projects and stacks.
  12347. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  12348. type: string
  12349. project:
  12350. description: Project is the name of the Pulumi ESC project the environment belongs to.
  12351. type: string
  12352. required:
  12353. - accessToken
  12354. - environment
  12355. - organization
  12356. - project
  12357. type: object
  12358. scaleway:
  12359. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  12360. properties:
  12361. accessKey:
  12362. description: AccessKey is the non-secret part of the api key.
  12363. properties:
  12364. secretRef:
  12365. description: SecretRef references a key in a secret that will be used as value.
  12366. properties:
  12367. key:
  12368. description: |-
  12369. A key in the referenced Secret.
  12370. Some instances of this field may be defaulted, in others it may be required.
  12371. maxLength: 253
  12372. minLength: 1
  12373. pattern: ^[-._a-zA-Z0-9]+$
  12374. type: string
  12375. name:
  12376. description: The name of the Secret resource being referred to.
  12377. maxLength: 253
  12378. minLength: 1
  12379. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12380. type: string
  12381. namespace:
  12382. description: |-
  12383. The namespace of the Secret resource being referred to.
  12384. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12385. maxLength: 63
  12386. minLength: 1
  12387. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12388. type: string
  12389. type: object
  12390. value:
  12391. description: Value can be specified directly to set a value without using a secret.
  12392. type: string
  12393. type: object
  12394. apiUrl:
  12395. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  12396. type: string
  12397. projectId:
  12398. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  12399. type: string
  12400. region:
  12401. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  12402. type: string
  12403. secretKey:
  12404. description: SecretKey is the non-secret part of the api key.
  12405. properties:
  12406. secretRef:
  12407. description: SecretRef references a key in a secret that will be used as value.
  12408. properties:
  12409. key:
  12410. description: |-
  12411. A key in the referenced Secret.
  12412. Some instances of this field may be defaulted, in others it may be required.
  12413. maxLength: 253
  12414. minLength: 1
  12415. pattern: ^[-._a-zA-Z0-9]+$
  12416. type: string
  12417. name:
  12418. description: The name of the Secret resource being referred to.
  12419. maxLength: 253
  12420. minLength: 1
  12421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12422. type: string
  12423. namespace:
  12424. description: |-
  12425. The namespace of the Secret resource being referred to.
  12426. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12427. maxLength: 63
  12428. minLength: 1
  12429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12430. type: string
  12431. type: object
  12432. value:
  12433. description: Value can be specified directly to set a value without using a secret.
  12434. type: string
  12435. type: object
  12436. required:
  12437. - accessKey
  12438. - projectId
  12439. - region
  12440. - secretKey
  12441. type: object
  12442. secretserver:
  12443. description: |-
  12444. SecretServer configures this store to sync secrets using SecretServer provider
  12445. https://docs.delinea.com/online-help/secret-server/start.htm
  12446. properties:
  12447. password:
  12448. description: Password is the secret server account password.
  12449. properties:
  12450. secretRef:
  12451. description: SecretRef references a key in a secret that will be used as value.
  12452. properties:
  12453. key:
  12454. description: |-
  12455. A key in the referenced Secret.
  12456. Some instances of this field may be defaulted, in others it may be required.
  12457. maxLength: 253
  12458. minLength: 1
  12459. pattern: ^[-._a-zA-Z0-9]+$
  12460. type: string
  12461. name:
  12462. description: The name of the Secret resource being referred to.
  12463. maxLength: 253
  12464. minLength: 1
  12465. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12466. type: string
  12467. namespace:
  12468. description: |-
  12469. The namespace of the Secret resource being referred to.
  12470. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12471. maxLength: 63
  12472. minLength: 1
  12473. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12474. type: string
  12475. type: object
  12476. value:
  12477. description: Value can be specified directly to set a value without using a secret.
  12478. type: string
  12479. type: object
  12480. serverURL:
  12481. description: |-
  12482. ServerURL
  12483. URL to your secret server installation
  12484. type: string
  12485. username:
  12486. description: Username is the secret server account username.
  12487. properties:
  12488. secretRef:
  12489. description: SecretRef references a key in a secret that will be used as value.
  12490. properties:
  12491. key:
  12492. description: |-
  12493. A key in the referenced Secret.
  12494. Some instances of this field may be defaulted, in others it may be required.
  12495. maxLength: 253
  12496. minLength: 1
  12497. pattern: ^[-._a-zA-Z0-9]+$
  12498. type: string
  12499. name:
  12500. description: The name of the Secret resource being referred to.
  12501. maxLength: 253
  12502. minLength: 1
  12503. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12504. type: string
  12505. namespace:
  12506. description: |-
  12507. The namespace of the Secret resource being referred to.
  12508. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12509. maxLength: 63
  12510. minLength: 1
  12511. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12512. type: string
  12513. type: object
  12514. value:
  12515. description: Value can be specified directly to set a value without using a secret.
  12516. type: string
  12517. type: object
  12518. required:
  12519. - password
  12520. - serverURL
  12521. - username
  12522. type: object
  12523. senhasegura:
  12524. description: Senhasegura configures this store to sync secrets using senhasegura provider
  12525. properties:
  12526. auth:
  12527. description: Auth defines parameters to authenticate in senhasegura
  12528. properties:
  12529. clientId:
  12530. type: string
  12531. clientSecretSecretRef:
  12532. description: |-
  12533. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  12534. In some instances, `key` is a required field.
  12535. properties:
  12536. key:
  12537. description: |-
  12538. A key in the referenced Secret.
  12539. Some instances of this field may be defaulted, in others it may be required.
  12540. maxLength: 253
  12541. minLength: 1
  12542. pattern: ^[-._a-zA-Z0-9]+$
  12543. type: string
  12544. name:
  12545. description: The name of the Secret resource being referred to.
  12546. maxLength: 253
  12547. minLength: 1
  12548. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12549. type: string
  12550. namespace:
  12551. description: |-
  12552. The namespace of the Secret resource being referred to.
  12553. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12554. maxLength: 63
  12555. minLength: 1
  12556. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12557. type: string
  12558. type: object
  12559. required:
  12560. - clientId
  12561. - clientSecretSecretRef
  12562. type: object
  12563. ignoreSslCertificate:
  12564. default: false
  12565. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  12566. type: boolean
  12567. module:
  12568. description: Module defines which senhasegura module should be used to get secrets
  12569. type: string
  12570. url:
  12571. description: URL of senhasegura
  12572. type: string
  12573. required:
  12574. - auth
  12575. - module
  12576. - url
  12577. type: object
  12578. vault:
  12579. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  12580. properties:
  12581. auth:
  12582. description: Auth configures how secret-manager authenticates with the Vault server.
  12583. properties:
  12584. appRole:
  12585. description: |-
  12586. AppRole authenticates with Vault using the App Role auth mechanism,
  12587. with the role and secret stored in a Kubernetes Secret resource.
  12588. properties:
  12589. path:
  12590. default: approle
  12591. description: |-
  12592. Path where the App Role authentication backend is mounted
  12593. in Vault, e.g: "approle"
  12594. type: string
  12595. roleId:
  12596. description: |-
  12597. RoleID configured in the App Role authentication backend when setting
  12598. up the authentication backend in Vault.
  12599. type: string
  12600. roleRef:
  12601. description: |-
  12602. Reference to a key in a Secret that contains the App Role ID used
  12603. to authenticate with Vault.
  12604. The `key` field must be specified and denotes which entry within the Secret
  12605. resource is used as the app role id.
  12606. properties:
  12607. key:
  12608. description: |-
  12609. A key in the referenced Secret.
  12610. Some instances of this field may be defaulted, in others it may be required.
  12611. maxLength: 253
  12612. minLength: 1
  12613. pattern: ^[-._a-zA-Z0-9]+$
  12614. type: string
  12615. name:
  12616. description: The name of the Secret resource being referred to.
  12617. maxLength: 253
  12618. minLength: 1
  12619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12620. type: string
  12621. namespace:
  12622. description: |-
  12623. The namespace of the Secret resource being referred to.
  12624. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12625. maxLength: 63
  12626. minLength: 1
  12627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12628. type: string
  12629. type: object
  12630. secretRef:
  12631. description: |-
  12632. Reference to a key in a Secret that contains the App Role secret used
  12633. to authenticate with Vault.
  12634. The `key` field must be specified and denotes which entry within the Secret
  12635. resource is used as the app role secret.
  12636. properties:
  12637. key:
  12638. description: |-
  12639. A key in the referenced Secret.
  12640. Some instances of this field may be defaulted, in others it may be required.
  12641. maxLength: 253
  12642. minLength: 1
  12643. pattern: ^[-._a-zA-Z0-9]+$
  12644. type: string
  12645. name:
  12646. description: The name of the Secret resource being referred to.
  12647. maxLength: 253
  12648. minLength: 1
  12649. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12650. type: string
  12651. namespace:
  12652. description: |-
  12653. The namespace of the Secret resource being referred to.
  12654. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12655. maxLength: 63
  12656. minLength: 1
  12657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12658. type: string
  12659. type: object
  12660. required:
  12661. - path
  12662. - secretRef
  12663. type: object
  12664. cert:
  12665. description: |-
  12666. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  12667. Cert authentication method
  12668. properties:
  12669. clientCert:
  12670. description: |-
  12671. ClientCert is a certificate to authenticate using the Cert Vault
  12672. authentication method
  12673. properties:
  12674. key:
  12675. description: |-
  12676. A key in the referenced Secret.
  12677. Some instances of this field may be defaulted, in others it may be required.
  12678. maxLength: 253
  12679. minLength: 1
  12680. pattern: ^[-._a-zA-Z0-9]+$
  12681. type: string
  12682. name:
  12683. description: The name of the Secret resource being referred to.
  12684. maxLength: 253
  12685. minLength: 1
  12686. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12687. type: string
  12688. namespace:
  12689. description: |-
  12690. The namespace of the Secret resource being referred to.
  12691. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12692. maxLength: 63
  12693. minLength: 1
  12694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12695. type: string
  12696. type: object
  12697. secretRef:
  12698. description: |-
  12699. SecretRef to a key in a Secret resource containing client private key to
  12700. authenticate with Vault using the Cert authentication method
  12701. properties:
  12702. key:
  12703. description: |-
  12704. A key in the referenced Secret.
  12705. Some instances of this field may be defaulted, in others it may be required.
  12706. maxLength: 253
  12707. minLength: 1
  12708. pattern: ^[-._a-zA-Z0-9]+$
  12709. type: string
  12710. name:
  12711. description: The name of the Secret resource being referred to.
  12712. maxLength: 253
  12713. minLength: 1
  12714. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12715. type: string
  12716. namespace:
  12717. description: |-
  12718. The namespace of the Secret resource being referred to.
  12719. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12720. maxLength: 63
  12721. minLength: 1
  12722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12723. type: string
  12724. type: object
  12725. type: object
  12726. iam:
  12727. description: |-
  12728. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  12729. AWS IAM authentication method
  12730. properties:
  12731. externalID:
  12732. description: AWS External ID set on assumed IAM roles
  12733. type: string
  12734. jwt:
  12735. description: Specify a service account with IRSA enabled
  12736. properties:
  12737. serviceAccountRef:
  12738. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  12739. properties:
  12740. audiences:
  12741. description: |-
  12742. Audience specifies the `aud` claim for the service account token
  12743. Some providers automatically extend the audience field based on well-known annotations for workload
  12744. identity (e.g. IRSA or GCP Workload Identity)
  12745. items:
  12746. type: string
  12747. type: array
  12748. name:
  12749. description: The name of the ServiceAccount resource being referred to.
  12750. maxLength: 253
  12751. minLength: 1
  12752. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12753. type: string
  12754. namespace:
  12755. description: |-
  12756. Namespace of the resource being referred to.
  12757. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12758. maxLength: 63
  12759. minLength: 1
  12760. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12761. type: string
  12762. required:
  12763. - name
  12764. type: object
  12765. type: object
  12766. path:
  12767. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  12768. type: string
  12769. region:
  12770. description: AWS region
  12771. type: string
  12772. role:
  12773. description: This is the AWS role to be assumed before talking to vault
  12774. type: string
  12775. secretRef:
  12776. description: Specify credentials in a Secret object
  12777. properties:
  12778. accessKeyIDSecretRef:
  12779. description: The AccessKeyID is used for authentication
  12780. properties:
  12781. key:
  12782. description: |-
  12783. A key in the referenced Secret.
  12784. Some instances of this field may be defaulted, in others it may be required.
  12785. maxLength: 253
  12786. minLength: 1
  12787. pattern: ^[-._a-zA-Z0-9]+$
  12788. type: string
  12789. name:
  12790. description: The name of the Secret resource being referred to.
  12791. maxLength: 253
  12792. minLength: 1
  12793. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12794. type: string
  12795. namespace:
  12796. description: |-
  12797. The namespace of the Secret resource being referred to.
  12798. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12799. maxLength: 63
  12800. minLength: 1
  12801. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12802. type: string
  12803. type: object
  12804. secretAccessKeySecretRef:
  12805. description: The SecretAccessKey is used for authentication
  12806. properties:
  12807. key:
  12808. description: |-
  12809. A key in the referenced Secret.
  12810. Some instances of this field may be defaulted, in others it may be required.
  12811. maxLength: 253
  12812. minLength: 1
  12813. pattern: ^[-._a-zA-Z0-9]+$
  12814. type: string
  12815. name:
  12816. description: The name of the Secret resource being referred to.
  12817. maxLength: 253
  12818. minLength: 1
  12819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12820. type: string
  12821. namespace:
  12822. description: |-
  12823. The namespace of the Secret resource being referred to.
  12824. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12825. maxLength: 63
  12826. minLength: 1
  12827. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12828. type: string
  12829. type: object
  12830. sessionTokenSecretRef:
  12831. description: |-
  12832. The SessionToken used for authentication
  12833. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  12834. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  12835. properties:
  12836. key:
  12837. description: |-
  12838. A key in the referenced Secret.
  12839. Some instances of this field may be defaulted, in others it may be required.
  12840. maxLength: 253
  12841. minLength: 1
  12842. pattern: ^[-._a-zA-Z0-9]+$
  12843. type: string
  12844. name:
  12845. description: The name of the Secret resource being referred to.
  12846. maxLength: 253
  12847. minLength: 1
  12848. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12849. type: string
  12850. namespace:
  12851. description: |-
  12852. The namespace of the Secret resource being referred to.
  12853. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12854. maxLength: 63
  12855. minLength: 1
  12856. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12857. type: string
  12858. type: object
  12859. type: object
  12860. vaultAwsIamServerID:
  12861. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  12862. type: string
  12863. vaultRole:
  12864. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  12865. type: string
  12866. required:
  12867. - vaultRole
  12868. type: object
  12869. jwt:
  12870. description: |-
  12871. Jwt authenticates with Vault by passing role and JWT token using the
  12872. JWT/OIDC authentication method
  12873. properties:
  12874. kubernetesServiceAccountToken:
  12875. description: |-
  12876. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  12877. a token for with the `TokenRequest` API.
  12878. properties:
  12879. audiences:
  12880. description: |-
  12881. Optional audiences field that will be used to request a temporary Kubernetes service
  12882. account token for the service account referenced by `serviceAccountRef`.
  12883. Defaults to a single audience `vault` it not specified.
  12884. Deprecated: use serviceAccountRef.Audiences instead
  12885. items:
  12886. type: string
  12887. type: array
  12888. expirationSeconds:
  12889. description: |-
  12890. Optional expiration time in seconds that will be used to request a temporary
  12891. Kubernetes service account token for the service account referenced by
  12892. `serviceAccountRef`.
  12893. Deprecated: this will be removed in the future.
  12894. Defaults to 10 minutes.
  12895. format: int64
  12896. type: integer
  12897. serviceAccountRef:
  12898. description: Service account field containing the name of a kubernetes ServiceAccount.
  12899. properties:
  12900. audiences:
  12901. description: |-
  12902. Audience specifies the `aud` claim for the service account token
  12903. Some providers automatically extend the audience field based on well-known annotations for workload
  12904. identity (e.g. IRSA or GCP Workload Identity)
  12905. items:
  12906. type: string
  12907. type: array
  12908. name:
  12909. description: The name of the ServiceAccount resource being referred to.
  12910. maxLength: 253
  12911. minLength: 1
  12912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12913. type: string
  12914. namespace:
  12915. description: |-
  12916. Namespace of the resource being referred to.
  12917. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12918. maxLength: 63
  12919. minLength: 1
  12920. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12921. type: string
  12922. required:
  12923. - name
  12924. type: object
  12925. required:
  12926. - serviceAccountRef
  12927. type: object
  12928. path:
  12929. default: jwt
  12930. description: |-
  12931. Path where the JWT authentication backend is mounted
  12932. in Vault, e.g: "jwt"
  12933. type: string
  12934. role:
  12935. description: |-
  12936. Role is a JWT role to authenticate using the JWT/OIDC Vault
  12937. authentication method
  12938. type: string
  12939. secretRef:
  12940. description: |-
  12941. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  12942. authenticate with Vault using the JWT/OIDC authentication method.
  12943. properties:
  12944. key:
  12945. description: |-
  12946. A key in the referenced Secret.
  12947. Some instances of this field may be defaulted, in others it may be required.
  12948. maxLength: 253
  12949. minLength: 1
  12950. pattern: ^[-._a-zA-Z0-9]+$
  12951. type: string
  12952. name:
  12953. description: The name of the Secret resource being referred to.
  12954. maxLength: 253
  12955. minLength: 1
  12956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12957. type: string
  12958. namespace:
  12959. description: |-
  12960. The namespace of the Secret resource being referred to.
  12961. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12962. maxLength: 63
  12963. minLength: 1
  12964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12965. type: string
  12966. type: object
  12967. required:
  12968. - path
  12969. type: object
  12970. kubernetes:
  12971. description: |-
  12972. Kubernetes authenticates with Vault by passing the ServiceAccount
  12973. token stored in the named Secret resource to the Vault server.
  12974. properties:
  12975. mountPath:
  12976. default: kubernetes
  12977. description: |-
  12978. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  12979. "kubernetes"
  12980. type: string
  12981. role:
  12982. description: |-
  12983. A required field containing the Vault Role to assume. A Role binds a
  12984. Kubernetes ServiceAccount with a set of Vault policies.
  12985. type: string
  12986. secretRef:
  12987. description: |-
  12988. Optional secret field containing a Kubernetes ServiceAccount JWT used
  12989. for authenticating with Vault. If a name is specified without a key,
  12990. `token` is the default. If one is not specified, the one bound to
  12991. the controller will be used.
  12992. properties:
  12993. key:
  12994. description: |-
  12995. A key in the referenced Secret.
  12996. Some instances of this field may be defaulted, in others it may be required.
  12997. maxLength: 253
  12998. minLength: 1
  12999. pattern: ^[-._a-zA-Z0-9]+$
  13000. type: string
  13001. name:
  13002. description: The name of the Secret resource being referred to.
  13003. maxLength: 253
  13004. minLength: 1
  13005. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13006. type: string
  13007. namespace:
  13008. description: |-
  13009. The namespace of the Secret resource being referred to.
  13010. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13011. maxLength: 63
  13012. minLength: 1
  13013. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13014. type: string
  13015. type: object
  13016. serviceAccountRef:
  13017. description: |-
  13018. Optional service account field containing the name of a kubernetes ServiceAccount.
  13019. If the service account is specified, the service account secret token JWT will be used
  13020. for authenticating with Vault. If the service account selector is not supplied,
  13021. the secretRef will be used instead.
  13022. properties:
  13023. audiences:
  13024. description: |-
  13025. Audience specifies the `aud` claim for the service account token
  13026. Some providers automatically extend the audience field based on well-known annotations for workload
  13027. identity (e.g. IRSA or GCP Workload Identity)
  13028. items:
  13029. type: string
  13030. type: array
  13031. name:
  13032. description: The name of the ServiceAccount resource being referred to.
  13033. maxLength: 253
  13034. minLength: 1
  13035. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13036. type: string
  13037. namespace:
  13038. description: |-
  13039. Namespace of the resource being referred to.
  13040. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13041. maxLength: 63
  13042. minLength: 1
  13043. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13044. type: string
  13045. required:
  13046. - name
  13047. type: object
  13048. required:
  13049. - mountPath
  13050. - role
  13051. type: object
  13052. ldap:
  13053. description: |-
  13054. Ldap authenticates with Vault by passing username/password pair using
  13055. the LDAP authentication method
  13056. properties:
  13057. path:
  13058. default: ldap
  13059. description: |-
  13060. Path where the LDAP authentication backend is mounted
  13061. in Vault, e.g: "ldap"
  13062. type: string
  13063. secretRef:
  13064. description: |-
  13065. SecretRef to a key in a Secret resource containing password for the LDAP
  13066. user used to authenticate with Vault using the LDAP authentication
  13067. method
  13068. properties:
  13069. key:
  13070. description: |-
  13071. A key in the referenced Secret.
  13072. Some instances of this field may be defaulted, in others it may be required.
  13073. maxLength: 253
  13074. minLength: 1
  13075. pattern: ^[-._a-zA-Z0-9]+$
  13076. type: string
  13077. name:
  13078. description: The name of the Secret resource being referred to.
  13079. maxLength: 253
  13080. minLength: 1
  13081. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13082. type: string
  13083. namespace:
  13084. description: |-
  13085. The namespace of the Secret resource being referred to.
  13086. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13087. maxLength: 63
  13088. minLength: 1
  13089. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13090. type: string
  13091. type: object
  13092. username:
  13093. description: |-
  13094. Username is an LDAP username used to authenticate using the LDAP Vault
  13095. authentication method
  13096. type: string
  13097. required:
  13098. - path
  13099. - username
  13100. type: object
  13101. namespace:
  13102. description: |-
  13103. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  13104. Namespaces is a set of features within Vault Enterprise that allows
  13105. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  13106. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  13107. This will default to Vault.Namespace field if set, or empty otherwise
  13108. type: string
  13109. tokenSecretRef:
  13110. description: TokenSecretRef authenticates with Vault by presenting a token.
  13111. properties:
  13112. key:
  13113. description: |-
  13114. A key in the referenced Secret.
  13115. Some instances of this field may be defaulted, in others it may be required.
  13116. maxLength: 253
  13117. minLength: 1
  13118. pattern: ^[-._a-zA-Z0-9]+$
  13119. type: string
  13120. name:
  13121. description: The name of the Secret resource being referred to.
  13122. maxLength: 253
  13123. minLength: 1
  13124. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13125. type: string
  13126. namespace:
  13127. description: |-
  13128. The namespace of the Secret resource being referred to.
  13129. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13130. maxLength: 63
  13131. minLength: 1
  13132. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13133. type: string
  13134. type: object
  13135. userPass:
  13136. description: UserPass authenticates with Vault by passing username/password pair
  13137. properties:
  13138. path:
  13139. default: userpass
  13140. description: |-
  13141. Path where the UserPassword authentication backend is mounted
  13142. in Vault, e.g: "userpass"
  13143. type: string
  13144. secretRef:
  13145. description: |-
  13146. SecretRef to a key in a Secret resource containing password for the
  13147. user used to authenticate with Vault using the UserPass authentication
  13148. method
  13149. properties:
  13150. key:
  13151. description: |-
  13152. A key in the referenced Secret.
  13153. Some instances of this field may be defaulted, in others it may be required.
  13154. maxLength: 253
  13155. minLength: 1
  13156. pattern: ^[-._a-zA-Z0-9]+$
  13157. type: string
  13158. name:
  13159. description: The name of the Secret resource being referred to.
  13160. maxLength: 253
  13161. minLength: 1
  13162. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13163. type: string
  13164. namespace:
  13165. description: |-
  13166. The namespace of the Secret resource being referred to.
  13167. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13168. maxLength: 63
  13169. minLength: 1
  13170. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13171. type: string
  13172. type: object
  13173. username:
  13174. description: |-
  13175. Username is a username used to authenticate using the UserPass Vault
  13176. authentication method
  13177. type: string
  13178. required:
  13179. - path
  13180. - username
  13181. type: object
  13182. type: object
  13183. caBundle:
  13184. description: |-
  13185. PEM encoded CA bundle used to validate Vault server certificate. Only used
  13186. if the Server URL is using HTTPS protocol. This parameter is ignored for
  13187. plain HTTP protocol connection. If not set the system root certificates
  13188. are used to validate the TLS connection.
  13189. format: byte
  13190. type: string
  13191. caProvider:
  13192. description: The provider for the CA bundle to use to validate Vault server certificate.
  13193. properties:
  13194. key:
  13195. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  13196. maxLength: 253
  13197. minLength: 1
  13198. pattern: ^[-._a-zA-Z0-9]+$
  13199. type: string
  13200. name:
  13201. description: The name of the object located at the provider type.
  13202. maxLength: 253
  13203. minLength: 1
  13204. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13205. type: string
  13206. namespace:
  13207. description: |-
  13208. The namespace the Provider type is in.
  13209. Can only be defined when used in a ClusterSecretStore.
  13210. maxLength: 63
  13211. minLength: 1
  13212. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13213. type: string
  13214. type:
  13215. description: The type of provider to use such as "Secret", or "ConfigMap".
  13216. enum:
  13217. - Secret
  13218. - ConfigMap
  13219. type: string
  13220. required:
  13221. - name
  13222. - type
  13223. type: object
  13224. forwardInconsistent:
  13225. description: |-
  13226. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  13227. leader instead of simply retrying within a loop. This can increase performance if
  13228. the option is enabled serverside.
  13229. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  13230. type: boolean
  13231. headers:
  13232. additionalProperties:
  13233. type: string
  13234. description: Headers to be added in Vault request
  13235. type: object
  13236. namespace:
  13237. description: |-
  13238. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  13239. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  13240. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  13241. type: string
  13242. path:
  13243. description: |-
  13244. Path is the mount path of the Vault KV backend endpoint, e.g:
  13245. "secret". The v2 KV secret engine version specific "/data" path suffix
  13246. for fetching secrets from Vault is optional and will be appended
  13247. if not present in specified path.
  13248. type: string
  13249. readYourWrites:
  13250. description: |-
  13251. ReadYourWrites ensures isolated read-after-write semantics by
  13252. providing discovered cluster replication states in each request.
  13253. More information about eventual consistency in Vault can be found here
  13254. https://www.vaultproject.io/docs/enterprise/consistency
  13255. type: boolean
  13256. server:
  13257. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  13258. type: string
  13259. tls:
  13260. description: |-
  13261. The configuration used for client side related TLS communication, when the Vault server
  13262. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  13263. This parameter is ignored for plain HTTP protocol connection.
  13264. It's worth noting this configuration is different from the "TLS certificates auth method",
  13265. which is available under the `auth.cert` section.
  13266. properties:
  13267. certSecretRef:
  13268. description: |-
  13269. CertSecretRef is a certificate added to the transport layer
  13270. when communicating with the Vault server.
  13271. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  13272. properties:
  13273. key:
  13274. description: |-
  13275. A key in the referenced Secret.
  13276. Some instances of this field may be defaulted, in others it may be required.
  13277. maxLength: 253
  13278. minLength: 1
  13279. pattern: ^[-._a-zA-Z0-9]+$
  13280. type: string
  13281. name:
  13282. description: The name of the Secret resource being referred to.
  13283. maxLength: 253
  13284. minLength: 1
  13285. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13286. type: string
  13287. namespace:
  13288. description: |-
  13289. The namespace of the Secret resource being referred to.
  13290. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13291. maxLength: 63
  13292. minLength: 1
  13293. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13294. type: string
  13295. type: object
  13296. keySecretRef:
  13297. description: |-
  13298. KeySecretRef to a key in a Secret resource containing client private key
  13299. added to the transport layer when communicating with the Vault server.
  13300. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  13301. properties:
  13302. key:
  13303. description: |-
  13304. A key in the referenced Secret.
  13305. Some instances of this field may be defaulted, in others it may be required.
  13306. maxLength: 253
  13307. minLength: 1
  13308. pattern: ^[-._a-zA-Z0-9]+$
  13309. type: string
  13310. name:
  13311. description: The name of the Secret resource being referred to.
  13312. maxLength: 253
  13313. minLength: 1
  13314. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13315. type: string
  13316. namespace:
  13317. description: |-
  13318. The namespace of the Secret resource being referred to.
  13319. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13320. maxLength: 63
  13321. minLength: 1
  13322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13323. type: string
  13324. type: object
  13325. type: object
  13326. version:
  13327. default: v2
  13328. description: |-
  13329. Version is the Vault KV secret engine version. This can be either "v1" or
  13330. "v2". Version defaults to "v2".
  13331. enum:
  13332. - v1
  13333. - v2
  13334. type: string
  13335. required:
  13336. - server
  13337. type: object
  13338. webhook:
  13339. description: Webhook configures this store to sync secrets using a generic templated webhook
  13340. properties:
  13341. auth:
  13342. description: Auth specifies a authorization protocol. Only one protocol may be set.
  13343. maxProperties: 1
  13344. minProperties: 1
  13345. properties:
  13346. ntlm:
  13347. description: NTLMProtocol configures the store to use NTLM for auth
  13348. properties:
  13349. passwordSecret:
  13350. description: |-
  13351. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13352. In some instances, `key` is a required field.
  13353. properties:
  13354. key:
  13355. description: |-
  13356. A key in the referenced Secret.
  13357. Some instances of this field may be defaulted, in others it may be required.
  13358. maxLength: 253
  13359. minLength: 1
  13360. pattern: ^[-._a-zA-Z0-9]+$
  13361. type: string
  13362. name:
  13363. description: The name of the Secret resource being referred to.
  13364. maxLength: 253
  13365. minLength: 1
  13366. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13367. type: string
  13368. namespace:
  13369. description: |-
  13370. The namespace of the Secret resource being referred to.
  13371. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13372. maxLength: 63
  13373. minLength: 1
  13374. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13375. type: string
  13376. type: object
  13377. usernameSecret:
  13378. description: |-
  13379. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13380. In some instances, `key` is a required field.
  13381. properties:
  13382. key:
  13383. description: |-
  13384. A key in the referenced Secret.
  13385. Some instances of this field may be defaulted, in others it may be required.
  13386. maxLength: 253
  13387. minLength: 1
  13388. pattern: ^[-._a-zA-Z0-9]+$
  13389. type: string
  13390. name:
  13391. description: The name of the Secret resource being referred to.
  13392. maxLength: 253
  13393. minLength: 1
  13394. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13395. type: string
  13396. namespace:
  13397. description: |-
  13398. The namespace of the Secret resource being referred to.
  13399. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13400. maxLength: 63
  13401. minLength: 1
  13402. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13403. type: string
  13404. type: object
  13405. required:
  13406. - passwordSecret
  13407. - usernameSecret
  13408. type: object
  13409. type: object
  13410. body:
  13411. description: Body
  13412. type: string
  13413. caBundle:
  13414. description: |-
  13415. PEM encoded CA bundle used to validate webhook server certificate. Only used
  13416. if the Server URL is using HTTPS protocol. This parameter is ignored for
  13417. plain HTTP protocol connection. If not set the system root certificates
  13418. are used to validate the TLS connection.
  13419. format: byte
  13420. type: string
  13421. caProvider:
  13422. description: The provider for the CA bundle to use to validate webhook server certificate.
  13423. properties:
  13424. key:
  13425. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  13426. maxLength: 253
  13427. minLength: 1
  13428. pattern: ^[-._a-zA-Z0-9]+$
  13429. type: string
  13430. name:
  13431. description: The name of the object located at the provider type.
  13432. maxLength: 253
  13433. minLength: 1
  13434. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13435. type: string
  13436. namespace:
  13437. description: The namespace the Provider type is in.
  13438. maxLength: 63
  13439. minLength: 1
  13440. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13441. type: string
  13442. type:
  13443. description: The type of provider to use such as "Secret", or "ConfigMap".
  13444. enum:
  13445. - Secret
  13446. - ConfigMap
  13447. type: string
  13448. required:
  13449. - name
  13450. - type
  13451. type: object
  13452. headers:
  13453. additionalProperties:
  13454. type: string
  13455. description: Headers
  13456. type: object
  13457. method:
  13458. description: Webhook Method
  13459. type: string
  13460. result:
  13461. description: Result formatting
  13462. properties:
  13463. jsonPath:
  13464. description: Json path of return value
  13465. type: string
  13466. type: object
  13467. secrets:
  13468. description: |-
  13469. Secrets to fill in templates
  13470. These secrets will be passed to the templating function as key value pairs under the given name
  13471. items:
  13472. description: WebhookSecret defines a secret to be used in webhook templates.
  13473. properties:
  13474. name:
  13475. description: Name of this secret in templates
  13476. type: string
  13477. secretRef:
  13478. description: Secret ref to fill in credentials
  13479. properties:
  13480. key:
  13481. description: |-
  13482. A key in the referenced Secret.
  13483. Some instances of this field may be defaulted, in others it may be required.
  13484. maxLength: 253
  13485. minLength: 1
  13486. pattern: ^[-._a-zA-Z0-9]+$
  13487. type: string
  13488. name:
  13489. description: The name of the Secret resource being referred to.
  13490. maxLength: 253
  13491. minLength: 1
  13492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13493. type: string
  13494. namespace:
  13495. description: |-
  13496. The namespace of the Secret resource being referred to.
  13497. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13498. maxLength: 63
  13499. minLength: 1
  13500. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13501. type: string
  13502. type: object
  13503. required:
  13504. - name
  13505. - secretRef
  13506. type: object
  13507. type: array
  13508. timeout:
  13509. description: Timeout
  13510. type: string
  13511. url:
  13512. description: Webhook url to call
  13513. type: string
  13514. required:
  13515. - result
  13516. - url
  13517. type: object
  13518. yandexcertificatemanager:
  13519. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  13520. properties:
  13521. apiEndpoint:
  13522. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13523. type: string
  13524. auth:
  13525. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  13526. properties:
  13527. authorizedKeySecretRef:
  13528. description: The authorized key used for authentication
  13529. properties:
  13530. key:
  13531. description: |-
  13532. A key in the referenced Secret.
  13533. Some instances of this field may be defaulted, in others it may be required.
  13534. maxLength: 253
  13535. minLength: 1
  13536. pattern: ^[-._a-zA-Z0-9]+$
  13537. type: string
  13538. name:
  13539. description: The name of the Secret resource being referred to.
  13540. maxLength: 253
  13541. minLength: 1
  13542. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13543. type: string
  13544. namespace:
  13545. description: |-
  13546. The namespace of the Secret resource being referred to.
  13547. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13548. maxLength: 63
  13549. minLength: 1
  13550. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13551. type: string
  13552. type: object
  13553. type: object
  13554. caProvider:
  13555. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13556. properties:
  13557. certSecretRef:
  13558. description: |-
  13559. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13560. In some instances, `key` is a required field.
  13561. properties:
  13562. key:
  13563. description: |-
  13564. A key in the referenced Secret.
  13565. Some instances of this field may be defaulted, in others it may be required.
  13566. maxLength: 253
  13567. minLength: 1
  13568. pattern: ^[-._a-zA-Z0-9]+$
  13569. type: string
  13570. name:
  13571. description: The name of the Secret resource being referred to.
  13572. maxLength: 253
  13573. minLength: 1
  13574. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13575. type: string
  13576. namespace:
  13577. description: |-
  13578. The namespace of the Secret resource being referred to.
  13579. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13580. maxLength: 63
  13581. minLength: 1
  13582. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13583. type: string
  13584. type: object
  13585. type: object
  13586. required:
  13587. - auth
  13588. type: object
  13589. yandexlockbox:
  13590. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  13591. properties:
  13592. apiEndpoint:
  13593. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13594. type: string
  13595. auth:
  13596. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  13597. properties:
  13598. authorizedKeySecretRef:
  13599. description: The authorized key used for authentication
  13600. properties:
  13601. key:
  13602. description: |-
  13603. A key in the referenced Secret.
  13604. Some instances of this field may be defaulted, in others it may be required.
  13605. maxLength: 253
  13606. minLength: 1
  13607. pattern: ^[-._a-zA-Z0-9]+$
  13608. type: string
  13609. name:
  13610. description: The name of the Secret resource being referred to.
  13611. maxLength: 253
  13612. minLength: 1
  13613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13614. type: string
  13615. namespace:
  13616. description: |-
  13617. The namespace of the Secret resource being referred to.
  13618. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13619. maxLength: 63
  13620. minLength: 1
  13621. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13622. type: string
  13623. type: object
  13624. type: object
  13625. caProvider:
  13626. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13627. properties:
  13628. certSecretRef:
  13629. description: |-
  13630. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13631. In some instances, `key` is a required field.
  13632. properties:
  13633. key:
  13634. description: |-
  13635. A key in the referenced Secret.
  13636. Some instances of this field may be defaulted, in others it may be required.
  13637. maxLength: 253
  13638. minLength: 1
  13639. pattern: ^[-._a-zA-Z0-9]+$
  13640. type: string
  13641. name:
  13642. description: The name of the Secret resource being referred to.
  13643. maxLength: 253
  13644. minLength: 1
  13645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13646. type: string
  13647. namespace:
  13648. description: |-
  13649. The namespace of the Secret resource being referred to.
  13650. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13651. maxLength: 63
  13652. minLength: 1
  13653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13654. type: string
  13655. type: object
  13656. type: object
  13657. required:
  13658. - auth
  13659. type: object
  13660. type: object
  13661. refreshInterval:
  13662. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  13663. type: integer
  13664. retrySettings:
  13665. description: Used to configure HTTP retries on failures.
  13666. properties:
  13667. maxRetries:
  13668. description: MaxRetries is the maximum number of retry attempts.
  13669. format: int32
  13670. type: integer
  13671. retryInterval:
  13672. description: RetryInterval is the interval between retry attempts.
  13673. type: string
  13674. type: object
  13675. required:
  13676. - provider
  13677. type: object
  13678. status:
  13679. description: SecretStoreStatus defines the observed state of the SecretStore.
  13680. properties:
  13681. capabilities:
  13682. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  13683. type: string
  13684. conditions:
  13685. items:
  13686. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  13687. properties:
  13688. lastTransitionTime:
  13689. format: date-time
  13690. type: string
  13691. message:
  13692. type: string
  13693. reason:
  13694. type: string
  13695. status:
  13696. type: string
  13697. type:
  13698. description: SecretStoreConditionType represents the condition type of the SecretStore.
  13699. type: string
  13700. required:
  13701. - status
  13702. - type
  13703. type: object
  13704. type: array
  13705. type: object
  13706. type: object
  13707. served: false
  13708. storage: false
  13709. subresources:
  13710. status: {}
  13711. ---
  13712. apiVersion: apiextensions.k8s.io/v1
  13713. kind: CustomResourceDefinition
  13714. metadata:
  13715. annotations:
  13716. controller-gen.kubebuilder.io/version: v0.19.0
  13717. labels:
  13718. external-secrets.io/component: controller
  13719. name: externalsecrets.external-secrets.io
  13720. spec:
  13721. group: external-secrets.io
  13722. names:
  13723. categories:
  13724. - external-secrets
  13725. kind: ExternalSecret
  13726. listKind: ExternalSecretList
  13727. plural: externalsecrets
  13728. shortNames:
  13729. - es
  13730. singular: externalsecret
  13731. scope: Namespaced
  13732. versions:
  13733. - additionalPrinterColumns:
  13734. - jsonPath: .spec.secretStoreRef.kind
  13735. name: StoreType
  13736. type: string
  13737. - jsonPath: .spec.secretStoreRef.name
  13738. name: Store
  13739. type: string
  13740. - jsonPath: .spec.refreshInterval
  13741. name: Refresh Interval
  13742. type: string
  13743. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  13744. name: Status
  13745. type: string
  13746. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  13747. name: Ready
  13748. type: string
  13749. - jsonPath: .status.refreshTime
  13750. name: Last Sync
  13751. type: date
  13752. name: v1
  13753. schema:
  13754. openAPIV3Schema:
  13755. description: |-
  13756. ExternalSecret is the Schema for the external-secrets API.
  13757. It defines how to fetch data from external APIs and make it available as Kubernetes Secrets.
  13758. properties:
  13759. apiVersion:
  13760. description: |-
  13761. APIVersion defines the versioned schema of this representation of an object.
  13762. Servers should convert recognized schemas to the latest internal value, and
  13763. may reject unrecognized values.
  13764. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  13765. type: string
  13766. kind:
  13767. description: |-
  13768. Kind is a string value representing the REST resource this object represents.
  13769. Servers may infer this from the endpoint the client submits requests to.
  13770. Cannot be updated.
  13771. In CamelCase.
  13772. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  13773. type: string
  13774. metadata:
  13775. type: object
  13776. spec:
  13777. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  13778. properties:
  13779. data:
  13780. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  13781. items:
  13782. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  13783. properties:
  13784. remoteRef:
  13785. description: |-
  13786. RemoteRef points to the remote secret and defines
  13787. which secret (version/property/..) to fetch.
  13788. properties:
  13789. conversionStrategy:
  13790. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  13791. enum:
  13792. - Default
  13793. - Unicode
  13794. type: string
  13795. decodingStrategy:
  13796. description: Used to define a decoding Strategy. Defaults to None when omitted.
  13797. enum:
  13798. - Auto
  13799. - Base64
  13800. - Base64URL
  13801. - None
  13802. type: string
  13803. key:
  13804. description: Key is the key used in the Provider, mandatory
  13805. type: string
  13806. metadataPolicy:
  13807. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13808. enum:
  13809. - None
  13810. - Fetch
  13811. type: string
  13812. nullBytePolicy:
  13813. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13814. enum:
  13815. - Ignore
  13816. - Fail
  13817. type: string
  13818. property:
  13819. description: Used to select a specific property of the Provider value (if a map), if supported
  13820. type: string
  13821. version:
  13822. description: Used to select a specific version of the Provider value, if supported
  13823. type: string
  13824. required:
  13825. - key
  13826. type: object
  13827. secretKey:
  13828. description: The key in the Kubernetes Secret to store the value.
  13829. maxLength: 253
  13830. minLength: 1
  13831. pattern: ^[-._a-zA-Z0-9]+$
  13832. type: string
  13833. sourceRef:
  13834. description: |-
  13835. SourceRef allows you to override the source
  13836. from which the value will be pulled.
  13837. maxProperties: 1
  13838. minProperties: 1
  13839. properties:
  13840. generatorRef:
  13841. description: |-
  13842. GeneratorRef points to a generator custom resource.
  13843. Deprecated: The generatorRef is not implemented in .data[].
  13844. this will be removed with v1.
  13845. properties:
  13846. apiVersion:
  13847. default: generators.external-secrets.io/v1alpha1
  13848. description: Specify the apiVersion of the generator resource
  13849. type: string
  13850. kind:
  13851. description: Specify the Kind of the generator resource
  13852. enum:
  13853. - ACRAccessToken
  13854. - BeyondtrustWorkloadCredentialsDynamicSecret
  13855. - ClusterGenerator
  13856. - CloudsmithAccessToken
  13857. - ECRAuthorizationToken
  13858. - Fake
  13859. - GCRAccessToken
  13860. - GithubAccessToken
  13861. - GitlabDeployToken
  13862. - QuayAccessToken
  13863. - Password
  13864. - SSHKey
  13865. - STSSessionToken
  13866. - UUID
  13867. - VaultDynamicSecret
  13868. - Webhook
  13869. - Grafana
  13870. - MFA
  13871. type: string
  13872. name:
  13873. description: Specify the name of the generator resource
  13874. maxLength: 253
  13875. minLength: 1
  13876. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13877. type: string
  13878. required:
  13879. - kind
  13880. - name
  13881. type: object
  13882. storeRef:
  13883. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13884. properties:
  13885. kind:
  13886. description: |-
  13887. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13888. Defaults to `SecretStore`
  13889. enum:
  13890. - SecretStore
  13891. - ClusterSecretStore
  13892. type: string
  13893. name:
  13894. description: Name of the SecretStore resource
  13895. maxLength: 253
  13896. minLength: 1
  13897. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13898. type: string
  13899. type: object
  13900. type: object
  13901. required:
  13902. - remoteRef
  13903. - secretKey
  13904. type: object
  13905. type: array
  13906. dataFrom:
  13907. description: |-
  13908. DataFrom is used to fetch all properties from a specific Provider data
  13909. If multiple entries are specified, the Secret keys are merged in the specified order
  13910. items:
  13911. description: |-
  13912. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  13913. when using DataFrom to fetch multiple values from a Provider.
  13914. properties:
  13915. extract:
  13916. description: |-
  13917. Used to extract multiple key/value pairs from one secret
  13918. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13919. properties:
  13920. conversionStrategy:
  13921. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  13922. enum:
  13923. - Default
  13924. - Unicode
  13925. type: string
  13926. decodingStrategy:
  13927. description: Used to define a decoding Strategy. Defaults to None when omitted.
  13928. enum:
  13929. - Auto
  13930. - Base64
  13931. - Base64URL
  13932. - None
  13933. type: string
  13934. key:
  13935. description: Key is the key used in the Provider, mandatory
  13936. type: string
  13937. metadataPolicy:
  13938. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13939. enum:
  13940. - None
  13941. - Fetch
  13942. type: string
  13943. nullBytePolicy:
  13944. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13945. enum:
  13946. - Ignore
  13947. - Fail
  13948. type: string
  13949. property:
  13950. description: Used to select a specific property of the Provider value (if a map), if supported
  13951. type: string
  13952. version:
  13953. description: Used to select a specific version of the Provider value, if supported
  13954. type: string
  13955. required:
  13956. - key
  13957. type: object
  13958. find:
  13959. description: |-
  13960. Used to find secrets based on tags or regular expressions
  13961. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13962. properties:
  13963. conversionStrategy:
  13964. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  13965. enum:
  13966. - Default
  13967. - Unicode
  13968. type: string
  13969. decodingStrategy:
  13970. description: Used to define a decoding Strategy. Defaults to None when omitted.
  13971. enum:
  13972. - Auto
  13973. - Base64
  13974. - Base64URL
  13975. - None
  13976. type: string
  13977. name:
  13978. description: Finds secrets based on the name.
  13979. properties:
  13980. regexp:
  13981. description: Finds secrets base
  13982. type: string
  13983. type: object
  13984. nullBytePolicy:
  13985. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  13986. enum:
  13987. - Ignore
  13988. - Fail
  13989. type: string
  13990. path:
  13991. description: A root path to start the find operations.
  13992. type: string
  13993. tags:
  13994. additionalProperties:
  13995. type: string
  13996. description: Find secrets based on tags.
  13997. type: object
  13998. type: object
  13999. rewrite:
  14000. description: |-
  14001. Used to rewrite secret Keys after getting them from the secret Provider
  14002. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  14003. items:
  14004. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  14005. maxProperties: 1
  14006. minProperties: 1
  14007. properties:
  14008. merge:
  14009. description: |-
  14010. Used to merge key/values in one single Secret
  14011. The resulting key will contain all values from the specified secrets
  14012. properties:
  14013. conflictPolicy:
  14014. default: Error
  14015. description: Used to define the policy to use in conflict resolution.
  14016. enum:
  14017. - Ignore
  14018. - Error
  14019. type: string
  14020. into:
  14021. default: ""
  14022. description: |-
  14023. Used to define the target key of the merge operation.
  14024. Required if strategy is JSON. Ignored otherwise.
  14025. type: string
  14026. priority:
  14027. description: Used to define key priority in conflict resolution.
  14028. items:
  14029. type: string
  14030. type: array
  14031. priorityPolicy:
  14032. default: Strict
  14033. description: Used to define the policy when a key in the priority list does not exist in the input.
  14034. enum:
  14035. - IgnoreNotFound
  14036. - Strict
  14037. type: string
  14038. strategy:
  14039. default: Extract
  14040. description: Used to define the strategy to use in the merge operation.
  14041. enum:
  14042. - Extract
  14043. - JSON
  14044. type: string
  14045. type: object
  14046. regexp:
  14047. description: |-
  14048. Used to rewrite with regular expressions.
  14049. The resulting key will be the output of a regexp.ReplaceAll operation.
  14050. properties:
  14051. source:
  14052. description: Used to define the regular expression of a re.Compiler.
  14053. type: string
  14054. target:
  14055. description: Used to define the target pattern of a ReplaceAll operation.
  14056. type: string
  14057. required:
  14058. - source
  14059. - target
  14060. type: object
  14061. transform:
  14062. description: |-
  14063. Used to apply string transformation on the secrets.
  14064. The resulting key will be the output of the template applied by the operation.
  14065. properties:
  14066. template:
  14067. description: |-
  14068. Used to define the template to apply on the secret name.
  14069. `.value ` will specify the secret name in the template.
  14070. type: string
  14071. required:
  14072. - template
  14073. type: object
  14074. type: object
  14075. type: array
  14076. sourceRef:
  14077. description: |-
  14078. SourceRef points to a store or generator
  14079. which contains secret values ready to use.
  14080. Use this in combination with Extract or Find pull values out of
  14081. a specific SecretStore.
  14082. When sourceRef points to a generator Extract or Find is not supported.
  14083. The generator returns a static map of values
  14084. maxProperties: 1
  14085. minProperties: 1
  14086. properties:
  14087. generatorRef:
  14088. description: GeneratorRef points to a generator custom resource.
  14089. properties:
  14090. apiVersion:
  14091. default: generators.external-secrets.io/v1alpha1
  14092. description: Specify the apiVersion of the generator resource
  14093. type: string
  14094. kind:
  14095. description: Specify the Kind of the generator resource
  14096. enum:
  14097. - ACRAccessToken
  14098. - BeyondtrustWorkloadCredentialsDynamicSecret
  14099. - ClusterGenerator
  14100. - CloudsmithAccessToken
  14101. - ECRAuthorizationToken
  14102. - Fake
  14103. - GCRAccessToken
  14104. - GithubAccessToken
  14105. - GitlabDeployToken
  14106. - QuayAccessToken
  14107. - Password
  14108. - SSHKey
  14109. - STSSessionToken
  14110. - UUID
  14111. - VaultDynamicSecret
  14112. - Webhook
  14113. - Grafana
  14114. - MFA
  14115. type: string
  14116. name:
  14117. description: Specify the name of the generator resource
  14118. maxLength: 253
  14119. minLength: 1
  14120. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14121. type: string
  14122. required:
  14123. - kind
  14124. - name
  14125. type: object
  14126. storeRef:
  14127. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14128. properties:
  14129. kind:
  14130. description: |-
  14131. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14132. Defaults to `SecretStore`
  14133. enum:
  14134. - SecretStore
  14135. - ClusterSecretStore
  14136. type: string
  14137. name:
  14138. description: Name of the SecretStore resource
  14139. maxLength: 253
  14140. minLength: 1
  14141. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14142. type: string
  14143. type: object
  14144. type: object
  14145. type: object
  14146. type: array
  14147. refreshInterval:
  14148. default: 1h0m0s
  14149. description: |-
  14150. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  14151. specified as Golang Duration strings.
  14152. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  14153. Example values: "1h0m0s", "2h30m0s", "10m0s"
  14154. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  14155. type: string
  14156. refreshPolicy:
  14157. description: |-
  14158. RefreshPolicy determines how the ExternalSecret should be refreshed:
  14159. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  14160. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  14161. No periodic updates occur if refreshInterval is 0.
  14162. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  14163. enum:
  14164. - CreatedOnce
  14165. - Periodic
  14166. - OnChange
  14167. type: string
  14168. secretStoreRef:
  14169. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14170. properties:
  14171. kind:
  14172. description: |-
  14173. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14174. Defaults to `SecretStore`
  14175. enum:
  14176. - SecretStore
  14177. - ClusterSecretStore
  14178. type: string
  14179. name:
  14180. description: Name of the SecretStore resource
  14181. maxLength: 253
  14182. minLength: 1
  14183. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14184. type: string
  14185. type: object
  14186. syncWindows:
  14187. description: |-
  14188. SyncWindows optionally restricts when periodic refreshes may occur.
  14189. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  14190. properties:
  14191. kind:
  14192. description: |-
  14193. Kind applies to every window in the list.
  14194. "allow" -- syncs are permitted only while at least one window is active;
  14195. all other times are blocked.
  14196. "deny" -- syncs are blocked while any window is active;
  14197. all other times are permitted.
  14198. enum:
  14199. - allow
  14200. - deny
  14201. type: string
  14202. windows:
  14203. description: Windows is the list of schedule+duration pairs.
  14204. items:
  14205. description: |-
  14206. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  14207. within a SyncWindows block.
  14208. properties:
  14209. duration:
  14210. description: |-
  14211. Duration specifies how long the window stays open after each Schedule
  14212. firing. Example: "8h".
  14213. type: string
  14214. schedule:
  14215. description: |-
  14216. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  14217. named shorthand such as @daily or @every 1h. It marks the start time of
  14218. each window occurrence.
  14219. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  14220. minLength: 1
  14221. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  14222. type: string
  14223. required:
  14224. - duration
  14225. - schedule
  14226. type: object
  14227. minItems: 1
  14228. type: array
  14229. required:
  14230. - kind
  14231. - windows
  14232. type: object
  14233. target:
  14234. default:
  14235. creationPolicy: Owner
  14236. deletionPolicy: Retain
  14237. description: |-
  14238. ExternalSecretTarget defines the Kubernetes Secret to be created,
  14239. there can be only one target per ExternalSecret.
  14240. properties:
  14241. creationPolicy:
  14242. default: Owner
  14243. description: |-
  14244. CreationPolicy defines rules on how to create the resulting Secret.
  14245. Defaults to "Owner"
  14246. enum:
  14247. - Owner
  14248. - Orphan
  14249. - Merge
  14250. - None
  14251. - CreateOrMerge
  14252. type: string
  14253. deletionPolicy:
  14254. default: Retain
  14255. description: |-
  14256. DeletionPolicy defines rules on how to delete the resulting Secret.
  14257. Defaults to "Retain"
  14258. enum:
  14259. - Delete
  14260. - Merge
  14261. - Retain
  14262. type: string
  14263. immutable:
  14264. description: Immutable defines if the final secret will be immutable
  14265. type: boolean
  14266. manifest:
  14267. description: |-
  14268. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  14269. When specified, ExternalSecret will create the resource type defined here
  14270. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  14271. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  14272. properties:
  14273. apiVersion:
  14274. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  14275. minLength: 1
  14276. type: string
  14277. kind:
  14278. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  14279. minLength: 1
  14280. type: string
  14281. required:
  14282. - apiVersion
  14283. - kind
  14284. type: object
  14285. name:
  14286. description: |-
  14287. The name of the Secret resource to be managed.
  14288. Defaults to the .metadata.name of the ExternalSecret resource
  14289. maxLength: 253
  14290. minLength: 1
  14291. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14292. type: string
  14293. template:
  14294. description: Template defines a blueprint for the created Secret resource.
  14295. properties:
  14296. data:
  14297. additionalProperties:
  14298. type: string
  14299. type: object
  14300. engineVersion:
  14301. default: v2
  14302. description: |-
  14303. EngineVersion specifies the template engine version
  14304. that should be used to compile/execute the
  14305. template specified in .data and .templateFrom[].
  14306. enum:
  14307. - v2
  14308. type: string
  14309. mergePolicy:
  14310. default: Replace
  14311. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  14312. enum:
  14313. - Replace
  14314. - Merge
  14315. type: string
  14316. metadata:
  14317. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14318. properties:
  14319. annotations:
  14320. additionalProperties:
  14321. type: string
  14322. type: object
  14323. finalizers:
  14324. items:
  14325. type: string
  14326. type: array
  14327. labels:
  14328. additionalProperties:
  14329. type: string
  14330. type: object
  14331. type: object
  14332. templateFrom:
  14333. items:
  14334. description: |-
  14335. TemplateFrom specifies a source for templates.
  14336. Each item in the list can either reference a ConfigMap or a Secret resource.
  14337. properties:
  14338. configMap:
  14339. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14340. properties:
  14341. items:
  14342. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14343. items:
  14344. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14345. properties:
  14346. key:
  14347. description: A key in the ConfigMap/Secret
  14348. maxLength: 253
  14349. minLength: 1
  14350. pattern: ^[-._a-zA-Z0-9]+$
  14351. type: string
  14352. templateAs:
  14353. default: Values
  14354. description: TemplateScope specifies how the template keys should be interpreted.
  14355. enum:
  14356. - Values
  14357. - KeysAndValues
  14358. type: string
  14359. required:
  14360. - key
  14361. type: object
  14362. type: array
  14363. name:
  14364. description: The name of the ConfigMap/Secret resource
  14365. maxLength: 253
  14366. minLength: 1
  14367. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14368. type: string
  14369. required:
  14370. - items
  14371. - name
  14372. type: object
  14373. literal:
  14374. type: string
  14375. secret:
  14376. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14377. properties:
  14378. items:
  14379. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14380. items:
  14381. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14382. properties:
  14383. key:
  14384. description: A key in the ConfigMap/Secret
  14385. maxLength: 253
  14386. minLength: 1
  14387. pattern: ^[-._a-zA-Z0-9]+$
  14388. type: string
  14389. templateAs:
  14390. default: Values
  14391. description: TemplateScope specifies how the template keys should be interpreted.
  14392. enum:
  14393. - Values
  14394. - KeysAndValues
  14395. type: string
  14396. required:
  14397. - key
  14398. type: object
  14399. type: array
  14400. name:
  14401. description: The name of the ConfigMap/Secret resource
  14402. maxLength: 253
  14403. minLength: 1
  14404. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14405. type: string
  14406. required:
  14407. - items
  14408. - name
  14409. type: object
  14410. target:
  14411. default: Data
  14412. description: |-
  14413. Target specifies where to place the template result.
  14414. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  14415. any other value is rejected because it would allow writes to privileged Secret fields.
  14416. For custom resources (when spec.target.manifest is set), this supports
  14417. nested paths like "spec.database.config" or "data".
  14418. type: string
  14419. valuesDecodingStrategy:
  14420. description: |-
  14421. Used to define a decoding Strategy for the rendered template values.
  14422. Defaults to None when omitted.
  14423. enum:
  14424. - Auto
  14425. - Base64
  14426. - Base64URL
  14427. - None
  14428. type: string
  14429. type: object
  14430. type: array
  14431. type:
  14432. type: string
  14433. type: object
  14434. type: object
  14435. type: object
  14436. status:
  14437. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  14438. properties:
  14439. binding:
  14440. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  14441. properties:
  14442. name:
  14443. default: ""
  14444. description: |-
  14445. Name of the referent.
  14446. This field is effectively required, but due to backwards compatibility is
  14447. allowed to be empty. Instances of this type with an empty value here are
  14448. almost certainly wrong.
  14449. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  14450. type: string
  14451. type: object
  14452. x-kubernetes-map-type: atomic
  14453. conditions:
  14454. items:
  14455. description: ExternalSecretStatusCondition defines a status condition of an ExternalSecret resource.
  14456. properties:
  14457. lastTransitionTime:
  14458. format: date-time
  14459. type: string
  14460. message:
  14461. type: string
  14462. reason:
  14463. type: string
  14464. status:
  14465. type: string
  14466. type:
  14467. description: ExternalSecretConditionType defines a value type for ExternalSecret conditions.
  14468. enum:
  14469. - Ready
  14470. - Deleted
  14471. type: string
  14472. required:
  14473. - status
  14474. - type
  14475. type: object
  14476. type: array
  14477. refreshTime:
  14478. description: |-
  14479. refreshTime is the time and date the external secret was fetched and
  14480. the target secret updated
  14481. format: date-time
  14482. nullable: true
  14483. type: string
  14484. syncedResourceVersion:
  14485. description: SyncedResourceVersion keeps track of the last synced version
  14486. type: string
  14487. type: object
  14488. type: object
  14489. selectableFields:
  14490. - jsonPath: .spec.secretStoreRef.name
  14491. - jsonPath: .spec.secretStoreRef.kind
  14492. - jsonPath: .spec.target.name
  14493. - jsonPath: .spec.refreshInterval
  14494. served: true
  14495. storage: true
  14496. subresources:
  14497. status: {}
  14498. - additionalPrinterColumns:
  14499. - jsonPath: .spec.secretStoreRef.kind
  14500. name: StoreType
  14501. type: string
  14502. - jsonPath: .spec.secretStoreRef.name
  14503. name: Store
  14504. type: string
  14505. - jsonPath: .spec.refreshInterval
  14506. name: Refresh Interval
  14507. type: string
  14508. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  14509. name: Status
  14510. type: string
  14511. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  14512. name: Ready
  14513. type: string
  14514. - jsonPath: .status.refreshTime
  14515. name: Last Sync
  14516. type: date
  14517. deprecated: true
  14518. name: v1beta1
  14519. schema:
  14520. openAPIV3Schema:
  14521. description: ExternalSecret is the schema for the external-secrets API.
  14522. properties:
  14523. apiVersion:
  14524. description: |-
  14525. APIVersion defines the versioned schema of this representation of an object.
  14526. Servers should convert recognized schemas to the latest internal value, and
  14527. may reject unrecognized values.
  14528. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  14529. type: string
  14530. kind:
  14531. description: |-
  14532. Kind is a string value representing the REST resource this object represents.
  14533. Servers may infer this from the endpoint the client submits requests to.
  14534. Cannot be updated.
  14535. In CamelCase.
  14536. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  14537. type: string
  14538. metadata:
  14539. type: object
  14540. spec:
  14541. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  14542. properties:
  14543. data:
  14544. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  14545. items:
  14546. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  14547. properties:
  14548. remoteRef:
  14549. description: |-
  14550. RemoteRef points to the remote secret and defines
  14551. which secret (version/property/..) to fetch.
  14552. properties:
  14553. conversionStrategy:
  14554. default: Default
  14555. description: Used to define a conversion Strategy
  14556. enum:
  14557. - Default
  14558. - Unicode
  14559. type: string
  14560. decodingStrategy:
  14561. default: None
  14562. description: Used to define a decoding Strategy
  14563. enum:
  14564. - Auto
  14565. - Base64
  14566. - Base64URL
  14567. - None
  14568. type: string
  14569. key:
  14570. description: Key is the key used in the Provider, mandatory
  14571. type: string
  14572. metadataPolicy:
  14573. default: None
  14574. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14575. enum:
  14576. - None
  14577. - Fetch
  14578. type: string
  14579. property:
  14580. description: Used to select a specific property of the Provider value (if a map), if supported
  14581. type: string
  14582. version:
  14583. description: Used to select a specific version of the Provider value, if supported
  14584. type: string
  14585. required:
  14586. - key
  14587. type: object
  14588. secretKey:
  14589. description: The key in the Kubernetes Secret to store the value.
  14590. maxLength: 253
  14591. minLength: 1
  14592. pattern: ^[-._a-zA-Z0-9]+$
  14593. type: string
  14594. sourceRef:
  14595. description: |-
  14596. SourceRef allows you to override the source
  14597. from which the value will be pulled.
  14598. maxProperties: 1
  14599. minProperties: 1
  14600. properties:
  14601. generatorRef:
  14602. description: |-
  14603. GeneratorRef points to a generator custom resource.
  14604. Deprecated: The generatorRef is not implemented in .data[].
  14605. this will be removed with v1.
  14606. properties:
  14607. apiVersion:
  14608. default: generators.external-secrets.io/v1alpha1
  14609. description: Specify the apiVersion of the generator resource
  14610. type: string
  14611. kind:
  14612. description: Specify the Kind of the generator resource
  14613. enum:
  14614. - ACRAccessToken
  14615. - ClusterGenerator
  14616. - ECRAuthorizationToken
  14617. - Fake
  14618. - GCRAccessToken
  14619. - GithubAccessToken
  14620. - QuayAccessToken
  14621. - Password
  14622. - SSHKey
  14623. - STSSessionToken
  14624. - UUID
  14625. - VaultDynamicSecret
  14626. - Webhook
  14627. - Grafana
  14628. type: string
  14629. name:
  14630. description: Specify the name of the generator resource
  14631. maxLength: 253
  14632. minLength: 1
  14633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14634. type: string
  14635. required:
  14636. - kind
  14637. - name
  14638. type: object
  14639. storeRef:
  14640. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14641. properties:
  14642. kind:
  14643. description: |-
  14644. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14645. Defaults to `SecretStore`
  14646. enum:
  14647. - SecretStore
  14648. - ClusterSecretStore
  14649. type: string
  14650. name:
  14651. description: Name of the SecretStore resource
  14652. maxLength: 253
  14653. minLength: 1
  14654. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14655. type: string
  14656. type: object
  14657. type: object
  14658. required:
  14659. - remoteRef
  14660. - secretKey
  14661. type: object
  14662. type: array
  14663. dataFrom:
  14664. description: |-
  14665. DataFrom is used to fetch all properties from a specific Provider data
  14666. If multiple entries are specified, the Secret keys are merged in the specified order
  14667. items:
  14668. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  14669. properties:
  14670. extract:
  14671. description: |-
  14672. Used to extract multiple key/value pairs from one secret
  14673. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14674. properties:
  14675. conversionStrategy:
  14676. default: Default
  14677. description: Used to define a conversion Strategy
  14678. enum:
  14679. - Default
  14680. - Unicode
  14681. type: string
  14682. decodingStrategy:
  14683. default: None
  14684. description: Used to define a decoding Strategy
  14685. enum:
  14686. - Auto
  14687. - Base64
  14688. - Base64URL
  14689. - None
  14690. type: string
  14691. key:
  14692. description: Key is the key used in the Provider, mandatory
  14693. type: string
  14694. metadataPolicy:
  14695. default: None
  14696. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14697. enum:
  14698. - None
  14699. - Fetch
  14700. type: string
  14701. property:
  14702. description: Used to select a specific property of the Provider value (if a map), if supported
  14703. type: string
  14704. version:
  14705. description: Used to select a specific version of the Provider value, if supported
  14706. type: string
  14707. required:
  14708. - key
  14709. type: object
  14710. find:
  14711. description: |-
  14712. Used to find secrets based on tags or regular expressions
  14713. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14714. properties:
  14715. conversionStrategy:
  14716. default: Default
  14717. description: Used to define a conversion Strategy
  14718. enum:
  14719. - Default
  14720. - Unicode
  14721. type: string
  14722. decodingStrategy:
  14723. default: None
  14724. description: Used to define a decoding Strategy
  14725. enum:
  14726. - Auto
  14727. - Base64
  14728. - Base64URL
  14729. - None
  14730. type: string
  14731. name:
  14732. description: Finds secrets based on the name.
  14733. properties:
  14734. regexp:
  14735. description: Finds secrets base
  14736. type: string
  14737. type: object
  14738. path:
  14739. description: A root path to start the find operations.
  14740. type: string
  14741. tags:
  14742. additionalProperties:
  14743. type: string
  14744. description: Find secrets based on tags.
  14745. type: object
  14746. type: object
  14747. rewrite:
  14748. description: |-
  14749. Used to rewrite secret Keys after getting them from the secret Provider
  14750. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  14751. items:
  14752. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  14753. maxProperties: 1
  14754. minProperties: 1
  14755. properties:
  14756. regexp:
  14757. description: |-
  14758. Used to rewrite with regular expressions.
  14759. The resulting key will be the output of a regexp.ReplaceAll operation.
  14760. properties:
  14761. source:
  14762. description: Used to define the regular expression of a re.Compiler.
  14763. type: string
  14764. target:
  14765. description: Used to define the target pattern of a ReplaceAll operation.
  14766. type: string
  14767. required:
  14768. - source
  14769. - target
  14770. type: object
  14771. transform:
  14772. description: |-
  14773. Used to apply string transformation on the secrets.
  14774. The resulting key will be the output of the template applied by the operation.
  14775. properties:
  14776. template:
  14777. description: |-
  14778. Used to define the template to apply on the secret name.
  14779. `.value ` will specify the secret name in the template.
  14780. type: string
  14781. required:
  14782. - template
  14783. type: object
  14784. type: object
  14785. type: array
  14786. sourceRef:
  14787. description: |-
  14788. SourceRef points to a store or generator
  14789. which contains secret values ready to use.
  14790. Use this in combination with Extract or Find pull values out of
  14791. a specific SecretStore.
  14792. When sourceRef points to a generator Extract or Find is not supported.
  14793. The generator returns a static map of values
  14794. maxProperties: 1
  14795. minProperties: 1
  14796. properties:
  14797. generatorRef:
  14798. description: GeneratorRef points to a generator custom resource.
  14799. properties:
  14800. apiVersion:
  14801. default: generators.external-secrets.io/v1alpha1
  14802. description: Specify the apiVersion of the generator resource
  14803. type: string
  14804. kind:
  14805. description: Specify the Kind of the generator resource
  14806. enum:
  14807. - ACRAccessToken
  14808. - ClusterGenerator
  14809. - ECRAuthorizationToken
  14810. - Fake
  14811. - GCRAccessToken
  14812. - GithubAccessToken
  14813. - QuayAccessToken
  14814. - Password
  14815. - SSHKey
  14816. - STSSessionToken
  14817. - UUID
  14818. - VaultDynamicSecret
  14819. - Webhook
  14820. - Grafana
  14821. type: string
  14822. name:
  14823. description: Specify the name of the generator resource
  14824. maxLength: 253
  14825. minLength: 1
  14826. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14827. type: string
  14828. required:
  14829. - kind
  14830. - name
  14831. type: object
  14832. storeRef:
  14833. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14834. properties:
  14835. kind:
  14836. description: |-
  14837. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14838. Defaults to `SecretStore`
  14839. enum:
  14840. - SecretStore
  14841. - ClusterSecretStore
  14842. type: string
  14843. name:
  14844. description: Name of the SecretStore resource
  14845. maxLength: 253
  14846. minLength: 1
  14847. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14848. type: string
  14849. type: object
  14850. type: object
  14851. type: object
  14852. type: array
  14853. refreshInterval:
  14854. default: 1h0m0s
  14855. description: |-
  14856. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  14857. specified as Golang Duration strings.
  14858. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  14859. Example values: "1h0m0s", "2h30m0s", "10m0s"
  14860. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  14861. type: string
  14862. refreshPolicy:
  14863. description: |-
  14864. RefreshPolicy determines how the ExternalSecret should be refreshed:
  14865. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  14866. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  14867. No periodic updates occur if refreshInterval is 0.
  14868. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  14869. enum:
  14870. - CreatedOnce
  14871. - Periodic
  14872. - OnChange
  14873. type: string
  14874. secretStoreRef:
  14875. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14876. properties:
  14877. kind:
  14878. description: |-
  14879. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14880. Defaults to `SecretStore`
  14881. enum:
  14882. - SecretStore
  14883. - ClusterSecretStore
  14884. type: string
  14885. name:
  14886. description: Name of the SecretStore resource
  14887. maxLength: 253
  14888. minLength: 1
  14889. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14890. type: string
  14891. type: object
  14892. target:
  14893. default:
  14894. creationPolicy: Owner
  14895. deletionPolicy: Retain
  14896. description: |-
  14897. ExternalSecretTarget defines the Kubernetes Secret to be created
  14898. There can be only one target per ExternalSecret.
  14899. properties:
  14900. creationPolicy:
  14901. default: Owner
  14902. description: |-
  14903. CreationPolicy defines rules on how to create the resulting Secret.
  14904. Defaults to "Owner"
  14905. enum:
  14906. - Owner
  14907. - Orphan
  14908. - Merge
  14909. - None
  14910. type: string
  14911. deletionPolicy:
  14912. default: Retain
  14913. description: |-
  14914. DeletionPolicy defines rules on how to delete the resulting Secret.
  14915. Defaults to "Retain"
  14916. enum:
  14917. - Delete
  14918. - Merge
  14919. - Retain
  14920. type: string
  14921. immutable:
  14922. description: Immutable defines if the final secret will be immutable
  14923. type: boolean
  14924. name:
  14925. description: |-
  14926. The name of the Secret resource to be managed.
  14927. Defaults to the .metadata.name of the ExternalSecret resource
  14928. maxLength: 253
  14929. minLength: 1
  14930. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14931. type: string
  14932. template:
  14933. description: Template defines a blueprint for the created Secret resource.
  14934. properties:
  14935. data:
  14936. additionalProperties:
  14937. type: string
  14938. type: object
  14939. engineVersion:
  14940. default: v2
  14941. description: |-
  14942. EngineVersion specifies the template engine version
  14943. that should be used to compile/execute the
  14944. template specified in .data and .templateFrom[].
  14945. enum:
  14946. - v2
  14947. type: string
  14948. mergePolicy:
  14949. default: Replace
  14950. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  14951. enum:
  14952. - Replace
  14953. - Merge
  14954. type: string
  14955. metadata:
  14956. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14957. properties:
  14958. annotations:
  14959. additionalProperties:
  14960. type: string
  14961. type: object
  14962. labels:
  14963. additionalProperties:
  14964. type: string
  14965. type: object
  14966. type: object
  14967. templateFrom:
  14968. items:
  14969. description: TemplateFrom defines a source for template data.
  14970. properties:
  14971. configMap:
  14972. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14973. properties:
  14974. items:
  14975. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14976. items:
  14977. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14978. properties:
  14979. key:
  14980. description: A key in the ConfigMap/Secret
  14981. maxLength: 253
  14982. minLength: 1
  14983. pattern: ^[-._a-zA-Z0-9]+$
  14984. type: string
  14985. templateAs:
  14986. default: Values
  14987. description: TemplateScope defines the scope of the template when processing template data.
  14988. enum:
  14989. - Values
  14990. - KeysAndValues
  14991. type: string
  14992. required:
  14993. - key
  14994. type: object
  14995. type: array
  14996. name:
  14997. description: The name of the ConfigMap/Secret resource
  14998. maxLength: 253
  14999. minLength: 1
  15000. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15001. type: string
  15002. required:
  15003. - items
  15004. - name
  15005. type: object
  15006. literal:
  15007. type: string
  15008. secret:
  15009. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  15010. properties:
  15011. items:
  15012. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15013. items:
  15014. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  15015. properties:
  15016. key:
  15017. description: A key in the ConfigMap/Secret
  15018. maxLength: 253
  15019. minLength: 1
  15020. pattern: ^[-._a-zA-Z0-9]+$
  15021. type: string
  15022. templateAs:
  15023. default: Values
  15024. description: TemplateScope defines the scope of the template when processing template data.
  15025. enum:
  15026. - Values
  15027. - KeysAndValues
  15028. type: string
  15029. required:
  15030. - key
  15031. type: object
  15032. type: array
  15033. name:
  15034. description: The name of the ConfigMap/Secret resource
  15035. maxLength: 253
  15036. minLength: 1
  15037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15038. type: string
  15039. required:
  15040. - items
  15041. - name
  15042. type: object
  15043. target:
  15044. default: Data
  15045. description: TemplateTarget defines the target field where the template result will be stored.
  15046. enum:
  15047. - Data
  15048. - Annotations
  15049. - Labels
  15050. type: string
  15051. type: object
  15052. type: array
  15053. type:
  15054. type: string
  15055. type: object
  15056. type: object
  15057. type: object
  15058. status:
  15059. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  15060. properties:
  15061. binding:
  15062. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  15063. properties:
  15064. name:
  15065. default: ""
  15066. description: |-
  15067. Name of the referent.
  15068. This field is effectively required, but due to backwards compatibility is
  15069. allowed to be empty. Instances of this type with an empty value here are
  15070. almost certainly wrong.
  15071. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  15072. type: string
  15073. type: object
  15074. x-kubernetes-map-type: atomic
  15075. conditions:
  15076. items:
  15077. description: ExternalSecretStatusCondition contains condition information for an ExternalSecret.
  15078. properties:
  15079. lastTransitionTime:
  15080. format: date-time
  15081. type: string
  15082. message:
  15083. type: string
  15084. reason:
  15085. type: string
  15086. status:
  15087. type: string
  15088. type:
  15089. description: ExternalSecretConditionType defines the condition type for an ExternalSecret.
  15090. type: string
  15091. required:
  15092. - status
  15093. - type
  15094. type: object
  15095. type: array
  15096. refreshTime:
  15097. description: |-
  15098. refreshTime is the time and date the external secret was fetched and
  15099. the target secret updated
  15100. format: date-time
  15101. nullable: true
  15102. type: string
  15103. syncedResourceVersion:
  15104. description: SyncedResourceVersion keeps track of the last synced version
  15105. type: string
  15106. type: object
  15107. type: object
  15108. served: false
  15109. storage: false
  15110. subresources:
  15111. status: {}
  15112. ---
  15113. apiVersion: apiextensions.k8s.io/v1
  15114. kind: CustomResourceDefinition
  15115. metadata:
  15116. annotations:
  15117. controller-gen.kubebuilder.io/version: v0.19.0
  15118. labels:
  15119. external-secrets.io/component: controller
  15120. name: pushsecrets.external-secrets.io
  15121. spec:
  15122. group: external-secrets.io
  15123. names:
  15124. categories:
  15125. - external-secrets
  15126. kind: PushSecret
  15127. listKind: PushSecretList
  15128. plural: pushsecrets
  15129. shortNames:
  15130. - ps
  15131. singular: pushsecret
  15132. scope: Namespaced
  15133. versions:
  15134. - additionalPrinterColumns:
  15135. - jsonPath: .metadata.creationTimestamp
  15136. name: AGE
  15137. type: date
  15138. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  15139. name: Status
  15140. type: string
  15141. - jsonPath: .status.refreshTime
  15142. name: Last Sync
  15143. type: date
  15144. name: v1alpha1
  15145. schema:
  15146. openAPIV3Schema:
  15147. description: PushSecret is the Schema for the PushSecrets API that enables pushing Kubernetes secrets to external secret providers.
  15148. properties:
  15149. apiVersion:
  15150. description: |-
  15151. APIVersion defines the versioned schema of this representation of an object.
  15152. Servers should convert recognized schemas to the latest internal value, and
  15153. may reject unrecognized values.
  15154. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15155. type: string
  15156. kind:
  15157. description: |-
  15158. Kind is a string value representing the REST resource this object represents.
  15159. Servers may infer this from the endpoint the client submits requests to.
  15160. Cannot be updated.
  15161. In CamelCase.
  15162. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15163. type: string
  15164. metadata:
  15165. type: object
  15166. spec:
  15167. description: PushSecretSpec configures the behavior of the PushSecret.
  15168. properties:
  15169. data:
  15170. description: Secret Data that should be pushed to providers
  15171. items:
  15172. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  15173. properties:
  15174. conversionStrategy:
  15175. default: None
  15176. description: Used to define a conversion Strategy for the secret keys
  15177. enum:
  15178. - None
  15179. - ReverseUnicode
  15180. type: string
  15181. match:
  15182. description: Match a given Secret Key to be pushed to the provider.
  15183. properties:
  15184. remoteRef:
  15185. description: Remote Refs to push to providers.
  15186. properties:
  15187. property:
  15188. description: Name of the property in the resulting secret
  15189. type: string
  15190. remoteKey:
  15191. description: Name of the resulting provider secret.
  15192. type: string
  15193. required:
  15194. - remoteKey
  15195. type: object
  15196. secretKey:
  15197. description: Secret Key to be pushed
  15198. type: string
  15199. required:
  15200. - remoteRef
  15201. type: object
  15202. metadata:
  15203. description: |-
  15204. Metadata is metadata attached to the secret.
  15205. The structure of metadata is provider specific, please look it up in the provider documentation.
  15206. x-kubernetes-preserve-unknown-fields: true
  15207. required:
  15208. - match
  15209. type: object
  15210. type: array
  15211. dataTo:
  15212. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  15213. items:
  15214. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  15215. properties:
  15216. conversionStrategy:
  15217. default: None
  15218. description: Used to define a conversion Strategy for the secret keys
  15219. enum:
  15220. - None
  15221. - ReverseUnicode
  15222. type: string
  15223. match:
  15224. description: |-
  15225. Match pattern for selecting keys from the source Secret.
  15226. If not specified, all keys are selected.
  15227. properties:
  15228. regexp:
  15229. description: |-
  15230. Regexp matches keys by regular expression.
  15231. If not specified, all keys are matched.
  15232. type: string
  15233. type: object
  15234. metadata:
  15235. description: |-
  15236. Metadata is metadata attached to the secret.
  15237. The structure of metadata is provider specific, please look it up in the provider documentation.
  15238. x-kubernetes-preserve-unknown-fields: true
  15239. remoteKey:
  15240. description: |-
  15241. RemoteKey is the name of the single provider secret that will receive ALL
  15242. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  15243. When set, per-key expansion is skipped and a single push is performed.
  15244. The provider's store prefix (if any) is still prepended to this value.
  15245. When not set, each matched key is pushed as its own individual provider secret.
  15246. type: string
  15247. rewrite:
  15248. description: |-
  15249. Rewrite operations to transform keys before pushing to the provider.
  15250. Operations are applied sequentially.
  15251. items:
  15252. description: PushSecretRewrite defines how to transform secret keys before pushing.
  15253. properties:
  15254. regexp:
  15255. description: Used to rewrite with regular expressions.
  15256. properties:
  15257. source:
  15258. description: Used to define the regular expression of a re.Compiler.
  15259. type: string
  15260. target:
  15261. description: Used to define the target pattern of a ReplaceAll operation.
  15262. type: string
  15263. required:
  15264. - source
  15265. - target
  15266. type: object
  15267. transform:
  15268. description: Used to apply string transformation on the secrets.
  15269. properties:
  15270. template:
  15271. description: |-
  15272. Used to define the template to apply on the secret name.
  15273. `.value ` will specify the secret name in the template.
  15274. type: string
  15275. required:
  15276. - template
  15277. type: object
  15278. type: object
  15279. x-kubernetes-validations:
  15280. - message: exactly one of regexp or transform must be set
  15281. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  15282. type: array
  15283. storeRef:
  15284. description: StoreRef specifies which SecretStore to push to. Required.
  15285. properties:
  15286. kind:
  15287. default: SecretStore
  15288. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  15289. enum:
  15290. - SecretStore
  15291. - ClusterSecretStore
  15292. type: string
  15293. labelSelector:
  15294. description: Optionally, sync to secret stores with label selector
  15295. properties:
  15296. matchExpressions:
  15297. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15298. items:
  15299. description: |-
  15300. A label selector requirement is a selector that contains values, a key, and an operator that
  15301. relates the key and values.
  15302. properties:
  15303. key:
  15304. description: key is the label key that the selector applies to.
  15305. type: string
  15306. operator:
  15307. description: |-
  15308. operator represents a key's relationship to a set of values.
  15309. Valid operators are In, NotIn, Exists and DoesNotExist.
  15310. type: string
  15311. values:
  15312. description: |-
  15313. values is an array of string values. If the operator is In or NotIn,
  15314. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15315. the values array must be empty. This array is replaced during a strategic
  15316. merge patch.
  15317. items:
  15318. type: string
  15319. type: array
  15320. x-kubernetes-list-type: atomic
  15321. required:
  15322. - key
  15323. - operator
  15324. type: object
  15325. type: array
  15326. x-kubernetes-list-type: atomic
  15327. matchLabels:
  15328. additionalProperties:
  15329. type: string
  15330. description: |-
  15331. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15332. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15333. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15334. type: object
  15335. type: object
  15336. x-kubernetes-map-type: atomic
  15337. name:
  15338. description: Optionally, sync to the SecretStore of the given name
  15339. maxLength: 253
  15340. minLength: 1
  15341. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15342. type: string
  15343. type: object
  15344. type: object
  15345. x-kubernetes-validations:
  15346. - message: storeRef must specify either name or labelSelector
  15347. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  15348. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  15349. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  15350. type: array
  15351. deletionPolicy:
  15352. default: None
  15353. description: Deletion Policy to handle Secrets in the provider.
  15354. enum:
  15355. - Delete
  15356. - None
  15357. type: string
  15358. refreshInterval:
  15359. default: 1h0m0s
  15360. description: The Interval to which External Secrets will try to push a secret definition
  15361. type: string
  15362. secretStoreRefs:
  15363. items:
  15364. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  15365. properties:
  15366. kind:
  15367. default: SecretStore
  15368. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  15369. enum:
  15370. - SecretStore
  15371. - ClusterSecretStore
  15372. type: string
  15373. labelSelector:
  15374. description: Optionally, sync to secret stores with label selector
  15375. properties:
  15376. matchExpressions:
  15377. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15378. items:
  15379. description: |-
  15380. A label selector requirement is a selector that contains values, a key, and an operator that
  15381. relates the key and values.
  15382. properties:
  15383. key:
  15384. description: key is the label key that the selector applies to.
  15385. type: string
  15386. operator:
  15387. description: |-
  15388. operator represents a key's relationship to a set of values.
  15389. Valid operators are In, NotIn, Exists and DoesNotExist.
  15390. type: string
  15391. values:
  15392. description: |-
  15393. values is an array of string values. If the operator is In or NotIn,
  15394. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15395. the values array must be empty. This array is replaced during a strategic
  15396. merge patch.
  15397. items:
  15398. type: string
  15399. type: array
  15400. x-kubernetes-list-type: atomic
  15401. required:
  15402. - key
  15403. - operator
  15404. type: object
  15405. type: array
  15406. x-kubernetes-list-type: atomic
  15407. matchLabels:
  15408. additionalProperties:
  15409. type: string
  15410. description: |-
  15411. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15412. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15413. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15414. type: object
  15415. type: object
  15416. x-kubernetes-map-type: atomic
  15417. name:
  15418. description: Optionally, sync to the SecretStore of the given name
  15419. maxLength: 253
  15420. minLength: 1
  15421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15422. type: string
  15423. type: object
  15424. type: array
  15425. selector:
  15426. description: The Secret Selector (k8s source) for the Push Secret
  15427. maxProperties: 1
  15428. minProperties: 1
  15429. properties:
  15430. generatorRef:
  15431. description: Point to a generator to create a Secret.
  15432. properties:
  15433. apiVersion:
  15434. default: generators.external-secrets.io/v1alpha1
  15435. description: Specify the apiVersion of the generator resource
  15436. type: string
  15437. kind:
  15438. description: Specify the Kind of the generator resource
  15439. enum:
  15440. - ACRAccessToken
  15441. - BeyondtrustWorkloadCredentialsDynamicSecret
  15442. - ClusterGenerator
  15443. - CloudsmithAccessToken
  15444. - ECRAuthorizationToken
  15445. - Fake
  15446. - GCRAccessToken
  15447. - GithubAccessToken
  15448. - GitlabDeployToken
  15449. - QuayAccessToken
  15450. - Password
  15451. - SSHKey
  15452. - STSSessionToken
  15453. - UUID
  15454. - VaultDynamicSecret
  15455. - Webhook
  15456. - Grafana
  15457. - MFA
  15458. type: string
  15459. name:
  15460. description: Specify the name of the generator resource
  15461. maxLength: 253
  15462. minLength: 1
  15463. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15464. type: string
  15465. required:
  15466. - kind
  15467. - name
  15468. type: object
  15469. secret:
  15470. description: Select a Secret to Push.
  15471. properties:
  15472. name:
  15473. description: |-
  15474. Name of the Secret.
  15475. The Secret must exist in the same namespace as the PushSecret manifest.
  15476. maxLength: 253
  15477. minLength: 1
  15478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15479. type: string
  15480. selector:
  15481. description: Selector chooses secrets using a labelSelector.
  15482. properties:
  15483. matchExpressions:
  15484. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15485. items:
  15486. description: |-
  15487. A label selector requirement is a selector that contains values, a key, and an operator that
  15488. relates the key and values.
  15489. properties:
  15490. key:
  15491. description: key is the label key that the selector applies to.
  15492. type: string
  15493. operator:
  15494. description: |-
  15495. operator represents a key's relationship to a set of values.
  15496. Valid operators are In, NotIn, Exists and DoesNotExist.
  15497. type: string
  15498. values:
  15499. description: |-
  15500. values is an array of string values. If the operator is In or NotIn,
  15501. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15502. the values array must be empty. This array is replaced during a strategic
  15503. merge patch.
  15504. items:
  15505. type: string
  15506. type: array
  15507. x-kubernetes-list-type: atomic
  15508. required:
  15509. - key
  15510. - operator
  15511. type: object
  15512. type: array
  15513. x-kubernetes-list-type: atomic
  15514. matchLabels:
  15515. additionalProperties:
  15516. type: string
  15517. description: |-
  15518. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15519. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15520. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15521. type: object
  15522. type: object
  15523. x-kubernetes-map-type: atomic
  15524. type: object
  15525. type: object
  15526. template:
  15527. description: Template defines a blueprint for the created Secret resource.
  15528. properties:
  15529. data:
  15530. additionalProperties:
  15531. type: string
  15532. type: object
  15533. engineVersion:
  15534. default: v2
  15535. description: |-
  15536. EngineVersion specifies the template engine version
  15537. that should be used to compile/execute the
  15538. template specified in .data and .templateFrom[].
  15539. enum:
  15540. - v2
  15541. type: string
  15542. mergePolicy:
  15543. default: Replace
  15544. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  15545. enum:
  15546. - Replace
  15547. - Merge
  15548. type: string
  15549. metadata:
  15550. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  15551. properties:
  15552. annotations:
  15553. additionalProperties:
  15554. type: string
  15555. type: object
  15556. finalizers:
  15557. items:
  15558. type: string
  15559. type: array
  15560. labels:
  15561. additionalProperties:
  15562. type: string
  15563. type: object
  15564. type: object
  15565. templateFrom:
  15566. items:
  15567. description: |-
  15568. TemplateFrom specifies a source for templates.
  15569. Each item in the list can either reference a ConfigMap or a Secret resource.
  15570. properties:
  15571. configMap:
  15572. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15573. properties:
  15574. items:
  15575. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15576. items:
  15577. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15578. properties:
  15579. key:
  15580. description: A key in the ConfigMap/Secret
  15581. maxLength: 253
  15582. minLength: 1
  15583. pattern: ^[-._a-zA-Z0-9]+$
  15584. type: string
  15585. templateAs:
  15586. default: Values
  15587. description: TemplateScope specifies how the template keys should be interpreted.
  15588. enum:
  15589. - Values
  15590. - KeysAndValues
  15591. type: string
  15592. required:
  15593. - key
  15594. type: object
  15595. type: array
  15596. name:
  15597. description: The name of the ConfigMap/Secret resource
  15598. maxLength: 253
  15599. minLength: 1
  15600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15601. type: string
  15602. required:
  15603. - items
  15604. - name
  15605. type: object
  15606. literal:
  15607. type: string
  15608. secret:
  15609. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15610. properties:
  15611. items:
  15612. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15613. items:
  15614. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15615. properties:
  15616. key:
  15617. description: A key in the ConfigMap/Secret
  15618. maxLength: 253
  15619. minLength: 1
  15620. pattern: ^[-._a-zA-Z0-9]+$
  15621. type: string
  15622. templateAs:
  15623. default: Values
  15624. description: TemplateScope specifies how the template keys should be interpreted.
  15625. enum:
  15626. - Values
  15627. - KeysAndValues
  15628. type: string
  15629. required:
  15630. - key
  15631. type: object
  15632. type: array
  15633. name:
  15634. description: The name of the ConfigMap/Secret resource
  15635. maxLength: 253
  15636. minLength: 1
  15637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15638. type: string
  15639. required:
  15640. - items
  15641. - name
  15642. type: object
  15643. target:
  15644. default: Data
  15645. description: |-
  15646. Target specifies where to place the template result.
  15647. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  15648. any other value is rejected because it would allow writes to privileged Secret fields.
  15649. For custom resources (when spec.target.manifest is set), this supports
  15650. nested paths like "spec.database.config" or "data".
  15651. type: string
  15652. valuesDecodingStrategy:
  15653. description: |-
  15654. Used to define a decoding Strategy for the rendered template values.
  15655. Defaults to None when omitted.
  15656. enum:
  15657. - Auto
  15658. - Base64
  15659. - Base64URL
  15660. - None
  15661. type: string
  15662. type: object
  15663. type: array
  15664. type:
  15665. type: string
  15666. type: object
  15667. updatePolicy:
  15668. default: Replace
  15669. description: UpdatePolicy to handle Secrets in the provider.
  15670. enum:
  15671. - Replace
  15672. - IfNotExists
  15673. type: string
  15674. required:
  15675. - secretStoreRefs
  15676. - selector
  15677. type: object
  15678. status:
  15679. description: PushSecretStatus indicates the history of the status of PushSecret.
  15680. properties:
  15681. conditions:
  15682. items:
  15683. description: PushSecretStatusCondition indicates the status of the PushSecret.
  15684. properties:
  15685. lastTransitionTime:
  15686. format: date-time
  15687. type: string
  15688. message:
  15689. type: string
  15690. reason:
  15691. type: string
  15692. status:
  15693. type: string
  15694. type:
  15695. description: PushSecretConditionType indicates the condition of the PushSecret.
  15696. type: string
  15697. required:
  15698. - status
  15699. - type
  15700. type: object
  15701. type: array
  15702. refreshTime:
  15703. description: |-
  15704. refreshTime is the time and date the external secret was fetched and
  15705. the target secret updated
  15706. format: date-time
  15707. nullable: true
  15708. type: string
  15709. syncedPushSecrets:
  15710. additionalProperties:
  15711. additionalProperties:
  15712. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  15713. properties:
  15714. conversionStrategy:
  15715. default: None
  15716. description: Used to define a conversion Strategy for the secret keys
  15717. enum:
  15718. - None
  15719. - ReverseUnicode
  15720. type: string
  15721. match:
  15722. description: Match a given Secret Key to be pushed to the provider.
  15723. properties:
  15724. remoteRef:
  15725. description: Remote Refs to push to providers.
  15726. properties:
  15727. property:
  15728. description: Name of the property in the resulting secret
  15729. type: string
  15730. remoteKey:
  15731. description: Name of the resulting provider secret.
  15732. type: string
  15733. required:
  15734. - remoteKey
  15735. type: object
  15736. secretKey:
  15737. description: Secret Key to be pushed
  15738. type: string
  15739. required:
  15740. - remoteRef
  15741. type: object
  15742. metadata:
  15743. description: |-
  15744. Metadata is metadata attached to the secret.
  15745. The structure of metadata is provider specific, please look it up in the provider documentation.
  15746. x-kubernetes-preserve-unknown-fields: true
  15747. required:
  15748. - match
  15749. type: object
  15750. type: object
  15751. description: |-
  15752. Synced PushSecrets, including secrets that already exist in provider.
  15753. Matches secret stores to PushSecretData that was stored to that secret store.
  15754. type: object
  15755. syncedResourceVersion:
  15756. description: SyncedResourceVersion keeps track of the last synced version.
  15757. type: string
  15758. type: object
  15759. type: object
  15760. served: true
  15761. storage: true
  15762. subresources:
  15763. status: {}
  15764. ---
  15765. apiVersion: apiextensions.k8s.io/v1
  15766. kind: CustomResourceDefinition
  15767. metadata:
  15768. annotations:
  15769. controller-gen.kubebuilder.io/version: v0.19.0
  15770. labels:
  15771. external-secrets.io/component: controller
  15772. name: secretstores.external-secrets.io
  15773. spec:
  15774. group: external-secrets.io
  15775. names:
  15776. categories:
  15777. - external-secrets
  15778. kind: SecretStore
  15779. listKind: SecretStoreList
  15780. plural: secretstores
  15781. shortNames:
  15782. - ss
  15783. singular: secretstore
  15784. scope: Namespaced
  15785. versions:
  15786. - additionalPrinterColumns:
  15787. - jsonPath: .metadata.creationTimestamp
  15788. name: AGE
  15789. type: date
  15790. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  15791. name: Status
  15792. type: string
  15793. - jsonPath: .status.capabilities
  15794. name: Capabilities
  15795. type: string
  15796. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  15797. name: Ready
  15798. type: string
  15799. name: v1
  15800. schema:
  15801. openAPIV3Schema:
  15802. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  15803. properties:
  15804. apiVersion:
  15805. description: |-
  15806. APIVersion defines the versioned schema of this representation of an object.
  15807. Servers should convert recognized schemas to the latest internal value, and
  15808. may reject unrecognized values.
  15809. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15810. type: string
  15811. kind:
  15812. description: |-
  15813. Kind is a string value representing the REST resource this object represents.
  15814. Servers may infer this from the endpoint the client submits requests to.
  15815. Cannot be updated.
  15816. In CamelCase.
  15817. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15818. type: string
  15819. metadata:
  15820. type: object
  15821. spec:
  15822. description: SecretStoreSpec defines the desired state of SecretStore.
  15823. properties:
  15824. conditions:
  15825. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  15826. items:
  15827. description: |-
  15828. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  15829. for a ClusterSecretStore instance.
  15830. properties:
  15831. namespaceRegexes:
  15832. description: Choose namespaces by using regex matching
  15833. items:
  15834. type: string
  15835. type: array
  15836. namespaceSelector:
  15837. description: Choose namespace using a labelSelector
  15838. properties:
  15839. matchExpressions:
  15840. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15841. items:
  15842. description: |-
  15843. A label selector requirement is a selector that contains values, a key, and an operator that
  15844. relates the key and values.
  15845. properties:
  15846. key:
  15847. description: key is the label key that the selector applies to.
  15848. type: string
  15849. operator:
  15850. description: |-
  15851. operator represents a key's relationship to a set of values.
  15852. Valid operators are In, NotIn, Exists and DoesNotExist.
  15853. type: string
  15854. values:
  15855. description: |-
  15856. values is an array of string values. If the operator is In or NotIn,
  15857. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15858. the values array must be empty. This array is replaced during a strategic
  15859. merge patch.
  15860. items:
  15861. type: string
  15862. type: array
  15863. x-kubernetes-list-type: atomic
  15864. required:
  15865. - key
  15866. - operator
  15867. type: object
  15868. type: array
  15869. x-kubernetes-list-type: atomic
  15870. matchLabels:
  15871. additionalProperties:
  15872. type: string
  15873. description: |-
  15874. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15875. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15876. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15877. type: object
  15878. type: object
  15879. x-kubernetes-map-type: atomic
  15880. namespaces:
  15881. description: Choose namespaces by name
  15882. items:
  15883. maxLength: 63
  15884. minLength: 1
  15885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15886. type: string
  15887. type: array
  15888. type: object
  15889. type: array
  15890. controller:
  15891. description: |-
  15892. Used to select the correct ESO controller (think: ingress.ingressClassName)
  15893. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  15894. type: string
  15895. provider:
  15896. description: Used to configure the provider. Only one provider may be set
  15897. maxProperties: 1
  15898. minProperties: 1
  15899. properties:
  15900. akeyless:
  15901. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  15902. properties:
  15903. akeylessGWApiURL:
  15904. description: Akeyless GW API Url from which the secrets to be fetched from.
  15905. type: string
  15906. authSecretRef:
  15907. description: Auth configures how the operator authenticates with Akeyless.
  15908. properties:
  15909. kubernetesAuth:
  15910. description: |-
  15911. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  15912. token stored in the named Secret resource.
  15913. properties:
  15914. accessID:
  15915. description: the Akeyless Kubernetes auth-method access-id
  15916. type: string
  15917. k8sConfName:
  15918. description: Kubernetes-auth configuration name in Akeyless-Gateway
  15919. type: string
  15920. secretRef:
  15921. description: |-
  15922. Optional secret field containing a Kubernetes ServiceAccount JWT used
  15923. for authenticating with Akeyless. If a name is specified without a key,
  15924. `token` is the default. If one is not specified, the one bound to
  15925. the controller will be used.
  15926. properties:
  15927. key:
  15928. description: |-
  15929. A key in the referenced Secret.
  15930. Some instances of this field may be defaulted, in others it may be required.
  15931. maxLength: 253
  15932. minLength: 1
  15933. pattern: ^[-._a-zA-Z0-9]+$
  15934. type: string
  15935. name:
  15936. description: The name of the Secret resource being referred to.
  15937. maxLength: 253
  15938. minLength: 1
  15939. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15940. type: string
  15941. namespace:
  15942. description: |-
  15943. The namespace of the Secret resource being referred to.
  15944. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15945. maxLength: 63
  15946. minLength: 1
  15947. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15948. type: string
  15949. type: object
  15950. serviceAccountRef:
  15951. description: |-
  15952. Optional service account field containing the name of a kubernetes ServiceAccount.
  15953. If the service account is specified, the service account secret token JWT will be used
  15954. for authenticating with Akeyless. If the service account selector is not supplied,
  15955. the secretRef will be used instead.
  15956. properties:
  15957. audiences:
  15958. description: |-
  15959. Audience specifies the `aud` claim for the service account token
  15960. Some providers automatically extend the audience field based on well-known annotations for workload
  15961. identity (e.g. IRSA or GCP Workload Identity)
  15962. items:
  15963. type: string
  15964. type: array
  15965. name:
  15966. description: The name of the ServiceAccount resource being referred to.
  15967. maxLength: 253
  15968. minLength: 1
  15969. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15970. type: string
  15971. namespace:
  15972. description: |-
  15973. Namespace of the resource being referred to.
  15974. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15975. maxLength: 63
  15976. minLength: 1
  15977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15978. type: string
  15979. required:
  15980. - name
  15981. type: object
  15982. required:
  15983. - accessID
  15984. - k8sConfName
  15985. type: object
  15986. secretRef:
  15987. description: |-
  15988. Reference to a Secret that contains the details
  15989. to authenticate with Akeyless.
  15990. properties:
  15991. accessID:
  15992. description: The SecretAccessID is used for authentication
  15993. properties:
  15994. key:
  15995. description: |-
  15996. A key in the referenced Secret.
  15997. Some instances of this field may be defaulted, in others it may be required.
  15998. maxLength: 253
  15999. minLength: 1
  16000. pattern: ^[-._a-zA-Z0-9]+$
  16001. type: string
  16002. name:
  16003. description: The name of the Secret resource being referred to.
  16004. maxLength: 253
  16005. minLength: 1
  16006. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16007. type: string
  16008. namespace:
  16009. description: |-
  16010. The namespace of the Secret resource being referred to.
  16011. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16012. maxLength: 63
  16013. minLength: 1
  16014. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16015. type: string
  16016. type: object
  16017. accessType:
  16018. description: |-
  16019. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16020. In some instances, `key` is a required field.
  16021. properties:
  16022. key:
  16023. description: |-
  16024. A key in the referenced Secret.
  16025. Some instances of this field may be defaulted, in others it may be required.
  16026. maxLength: 253
  16027. minLength: 1
  16028. pattern: ^[-._a-zA-Z0-9]+$
  16029. type: string
  16030. name:
  16031. description: The name of the Secret resource being referred to.
  16032. maxLength: 253
  16033. minLength: 1
  16034. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16035. type: string
  16036. namespace:
  16037. description: |-
  16038. The namespace of the Secret resource being referred to.
  16039. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16040. maxLength: 63
  16041. minLength: 1
  16042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16043. type: string
  16044. type: object
  16045. accessTypeParam:
  16046. description: |-
  16047. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16048. In some instances, `key` is a required field.
  16049. properties:
  16050. key:
  16051. description: |-
  16052. A key in the referenced Secret.
  16053. Some instances of this field may be defaulted, in others it may be required.
  16054. maxLength: 253
  16055. minLength: 1
  16056. pattern: ^[-._a-zA-Z0-9]+$
  16057. type: string
  16058. name:
  16059. description: The name of the Secret resource being referred to.
  16060. maxLength: 253
  16061. minLength: 1
  16062. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16063. type: string
  16064. namespace:
  16065. description: |-
  16066. The namespace of the Secret resource being referred to.
  16067. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16068. maxLength: 63
  16069. minLength: 1
  16070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16071. type: string
  16072. type: object
  16073. type: object
  16074. serviceAccountRef:
  16075. description: |-
  16076. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  16077. authentication on AKS Workload Identity. The operator obtains a federated
  16078. identity token from this ServiceAccount via the TokenRequest API instead
  16079. of using the ESO controller pod identity. Ignored for other access types.
  16080. properties:
  16081. audiences:
  16082. description: |-
  16083. Audience specifies the `aud` claim for the service account token
  16084. Some providers automatically extend the audience field based on well-known annotations for workload
  16085. identity (e.g. IRSA or GCP Workload Identity)
  16086. items:
  16087. type: string
  16088. type: array
  16089. name:
  16090. description: The name of the ServiceAccount resource being referred to.
  16091. maxLength: 253
  16092. minLength: 1
  16093. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16094. type: string
  16095. namespace:
  16096. description: |-
  16097. Namespace of the resource being referred to.
  16098. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16099. maxLength: 63
  16100. minLength: 1
  16101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16102. type: string
  16103. required:
  16104. - name
  16105. type: object
  16106. type: object
  16107. caBundle:
  16108. description: |-
  16109. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  16110. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  16111. are used to validate the TLS connection.
  16112. format: byte
  16113. type: string
  16114. caProvider:
  16115. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  16116. properties:
  16117. key:
  16118. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16119. maxLength: 253
  16120. minLength: 1
  16121. pattern: ^[-._a-zA-Z0-9]+$
  16122. type: string
  16123. name:
  16124. description: The name of the object located at the provider type.
  16125. maxLength: 253
  16126. minLength: 1
  16127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16128. type: string
  16129. namespace:
  16130. description: |-
  16131. The namespace the Provider type is in.
  16132. Can only be defined when used in a ClusterSecretStore.
  16133. maxLength: 63
  16134. minLength: 1
  16135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16136. type: string
  16137. type:
  16138. description: The type of provider to use such as "Secret", or "ConfigMap".
  16139. enum:
  16140. - Secret
  16141. - ConfigMap
  16142. type: string
  16143. required:
  16144. - name
  16145. - type
  16146. type: object
  16147. ignoreCache:
  16148. description: |-
  16149. IgnoreCache bypasses the Gateway cache for secret reads when true.
  16150. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  16151. type: boolean
  16152. required:
  16153. - akeylessGWApiURL
  16154. - authSecretRef
  16155. type: object
  16156. aws:
  16157. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  16158. properties:
  16159. additionalRoles:
  16160. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  16161. items:
  16162. type: string
  16163. type: array
  16164. auth:
  16165. description: |-
  16166. Auth defines the information necessary to authenticate against AWS
  16167. if not set aws sdk will infer credentials from your environment
  16168. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  16169. properties:
  16170. jwt:
  16171. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  16172. properties:
  16173. serviceAccountRef:
  16174. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  16175. properties:
  16176. audiences:
  16177. description: |-
  16178. Audience specifies the `aud` claim for the service account token
  16179. Some providers automatically extend the audience field based on well-known annotations for workload
  16180. identity (e.g. IRSA or GCP Workload Identity)
  16181. items:
  16182. type: string
  16183. type: array
  16184. name:
  16185. description: The name of the ServiceAccount resource being referred to.
  16186. maxLength: 253
  16187. minLength: 1
  16188. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16189. type: string
  16190. namespace:
  16191. description: |-
  16192. Namespace of the resource being referred to.
  16193. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16194. maxLength: 63
  16195. minLength: 1
  16196. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16197. type: string
  16198. required:
  16199. - name
  16200. type: object
  16201. type: object
  16202. secretRef:
  16203. description: |-
  16204. AWSAuthSecretRef holds secret references for AWS credentials
  16205. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  16206. properties:
  16207. accessKeyIDSecretRef:
  16208. description: The AccessKeyID is used for authentication
  16209. properties:
  16210. key:
  16211. description: |-
  16212. A key in the referenced Secret.
  16213. Some instances of this field may be defaulted, in others it may be required.
  16214. maxLength: 253
  16215. minLength: 1
  16216. pattern: ^[-._a-zA-Z0-9]+$
  16217. type: string
  16218. name:
  16219. description: The name of the Secret resource being referred to.
  16220. maxLength: 253
  16221. minLength: 1
  16222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16223. type: string
  16224. namespace:
  16225. description: |-
  16226. The namespace of the Secret resource being referred to.
  16227. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16228. maxLength: 63
  16229. minLength: 1
  16230. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16231. type: string
  16232. type: object
  16233. secretAccessKeySecretRef:
  16234. description: The SecretAccessKey is used for authentication
  16235. properties:
  16236. key:
  16237. description: |-
  16238. A key in the referenced Secret.
  16239. Some instances of this field may be defaulted, in others it may be required.
  16240. maxLength: 253
  16241. minLength: 1
  16242. pattern: ^[-._a-zA-Z0-9]+$
  16243. type: string
  16244. name:
  16245. description: The name of the Secret resource being referred to.
  16246. maxLength: 253
  16247. minLength: 1
  16248. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16249. type: string
  16250. namespace:
  16251. description: |-
  16252. The namespace of the Secret resource being referred to.
  16253. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16254. maxLength: 63
  16255. minLength: 1
  16256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16257. type: string
  16258. type: object
  16259. sessionTokenSecretRef:
  16260. description: |-
  16261. The SessionToken used for authentication
  16262. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  16263. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  16264. properties:
  16265. key:
  16266. description: |-
  16267. A key in the referenced Secret.
  16268. Some instances of this field may be defaulted, in others it may be required.
  16269. maxLength: 253
  16270. minLength: 1
  16271. pattern: ^[-._a-zA-Z0-9]+$
  16272. type: string
  16273. name:
  16274. description: The name of the Secret resource being referred to.
  16275. maxLength: 253
  16276. minLength: 1
  16277. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16278. type: string
  16279. namespace:
  16280. description: |-
  16281. The namespace of the Secret resource being referred to.
  16282. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16283. maxLength: 63
  16284. minLength: 1
  16285. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16286. type: string
  16287. type: object
  16288. type: object
  16289. type: object
  16290. customSessionTags:
  16291. additionalProperties:
  16292. type: string
  16293. description: |-
  16294. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  16295. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  16296. type: object
  16297. x-kubernetes-validations:
  16298. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  16299. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  16300. externalID:
  16301. description: AWS External ID set on assumed IAM roles
  16302. type: string
  16303. prefix:
  16304. description: Prefix adds a prefix to all retrieved values.
  16305. type: string
  16306. region:
  16307. description: AWS Region to be used for the provider
  16308. type: string
  16309. role:
  16310. description: Role is a Role ARN which the provider will assume
  16311. type: string
  16312. secretsManager:
  16313. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  16314. properties:
  16315. forceDeleteWithoutRecovery:
  16316. description: |-
  16317. Specifies whether to delete the secret without any recovery window. You
  16318. can't use both this parameter and RecoveryWindowInDays in the same call.
  16319. If you don't use either, then by default Secrets Manager uses a 30 day
  16320. recovery window.
  16321. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  16322. type: boolean
  16323. recoveryWindowInDays:
  16324. description: |-
  16325. The number of days from 7 to 30 that Secrets Manager waits before
  16326. permanently deleting the secret. You can't use both this parameter and
  16327. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  16328. then by default Secrets Manager uses a 30-day recovery window.
  16329. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  16330. format: int64
  16331. type: integer
  16332. type: object
  16333. service:
  16334. description: Service defines which service should be used to fetch the secrets
  16335. enum:
  16336. - SecretsManager
  16337. - ParameterStore
  16338. - CertificateManager
  16339. type: string
  16340. sessionTags:
  16341. description: AWS STS assume role session tags
  16342. items:
  16343. description: |-
  16344. Tag is a key-value pair that can be attached to an AWS resource.
  16345. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  16346. properties:
  16347. key:
  16348. type: string
  16349. value:
  16350. type: string
  16351. required:
  16352. - key
  16353. - value
  16354. type: object
  16355. type: array
  16356. sessionTagsPolicy:
  16357. default: None
  16358. description: |-
  16359. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  16360. None (default): no tags are added.
  16361. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  16362. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  16363. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  16364. enum:
  16365. - None
  16366. - Simple
  16367. - Custom
  16368. type: string
  16369. transitiveTagKeys:
  16370. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  16371. items:
  16372. type: string
  16373. type: array
  16374. required:
  16375. - region
  16376. - service
  16377. type: object
  16378. azurekv:
  16379. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  16380. properties:
  16381. authSecretRef:
  16382. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16383. properties:
  16384. clientCertificate:
  16385. description: The Azure ClientCertificate of the service principle used for authentication.
  16386. properties:
  16387. key:
  16388. description: |-
  16389. A key in the referenced Secret.
  16390. Some instances of this field may be defaulted, in others it may be required.
  16391. maxLength: 253
  16392. minLength: 1
  16393. pattern: ^[-._a-zA-Z0-9]+$
  16394. type: string
  16395. name:
  16396. description: The name of the Secret resource being referred to.
  16397. maxLength: 253
  16398. minLength: 1
  16399. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16400. type: string
  16401. namespace:
  16402. description: |-
  16403. The namespace of the Secret resource being referred to.
  16404. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16405. maxLength: 63
  16406. minLength: 1
  16407. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16408. type: string
  16409. type: object
  16410. clientId:
  16411. description: The Azure clientId of the service principle or managed identity used for authentication.
  16412. properties:
  16413. key:
  16414. description: |-
  16415. A key in the referenced Secret.
  16416. Some instances of this field may be defaulted, in others it may be required.
  16417. maxLength: 253
  16418. minLength: 1
  16419. pattern: ^[-._a-zA-Z0-9]+$
  16420. type: string
  16421. name:
  16422. description: The name of the Secret resource being referred to.
  16423. maxLength: 253
  16424. minLength: 1
  16425. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16426. type: string
  16427. namespace:
  16428. description: |-
  16429. The namespace of the Secret resource being referred to.
  16430. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16431. maxLength: 63
  16432. minLength: 1
  16433. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16434. type: string
  16435. type: object
  16436. clientSecret:
  16437. description: The Azure ClientSecret of the service principle used for authentication.
  16438. properties:
  16439. key:
  16440. description: |-
  16441. A key in the referenced Secret.
  16442. Some instances of this field may be defaulted, in others it may be required.
  16443. maxLength: 253
  16444. minLength: 1
  16445. pattern: ^[-._a-zA-Z0-9]+$
  16446. type: string
  16447. name:
  16448. description: The name of the Secret resource being referred to.
  16449. maxLength: 253
  16450. minLength: 1
  16451. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16452. type: string
  16453. namespace:
  16454. description: |-
  16455. The namespace of the Secret resource being referred to.
  16456. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16457. maxLength: 63
  16458. minLength: 1
  16459. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16460. type: string
  16461. type: object
  16462. tenantId:
  16463. description: The Azure tenantId of the managed identity used for authentication.
  16464. properties:
  16465. key:
  16466. description: |-
  16467. A key in the referenced Secret.
  16468. Some instances of this field may be defaulted, in others it may be required.
  16469. maxLength: 253
  16470. minLength: 1
  16471. pattern: ^[-._a-zA-Z0-9]+$
  16472. type: string
  16473. name:
  16474. description: The name of the Secret resource being referred to.
  16475. maxLength: 253
  16476. minLength: 1
  16477. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16478. type: string
  16479. namespace:
  16480. description: |-
  16481. The namespace of the Secret resource being referred to.
  16482. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16483. maxLength: 63
  16484. minLength: 1
  16485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16486. type: string
  16487. type: object
  16488. type: object
  16489. authType:
  16490. default: ServicePrincipal
  16491. description: |-
  16492. Auth type defines how to authenticate to the keyvault service.
  16493. Valid values are:
  16494. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  16495. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  16496. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  16497. enum:
  16498. - ServicePrincipal
  16499. - ManagedIdentity
  16500. - WorkloadIdentity
  16501. type: string
  16502. customCloudConfig:
  16503. description: |-
  16504. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  16505. Required when EnvironmentType is AzureStackCloud.
  16506. Optional for other environment types - useful for Azure China when using Workload Identity
  16507. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  16508. standard China Cloud endpoint (login.chinacloudapi.cn).
  16509. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  16510. configuration is not supported with the legacy go-autorest SDK.
  16511. properties:
  16512. activeDirectoryEndpoint:
  16513. description: |-
  16514. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  16515. Required when using custom cloud configuration
  16516. type: string
  16517. keyVaultDNSSuffix:
  16518. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  16519. type: string
  16520. keyVaultEndpoint:
  16521. description: KeyVaultEndpoint is the Key Vault service endpoint
  16522. type: string
  16523. resourceManagerEndpoint:
  16524. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  16525. type: string
  16526. required:
  16527. - activeDirectoryEndpoint
  16528. type: object
  16529. environmentType:
  16530. default: PublicCloud
  16531. description: |-
  16532. EnvironmentType specifies the Azure cloud environment endpoints to use for
  16533. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  16534. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  16535. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  16536. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  16537. enum:
  16538. - PublicCloud
  16539. - USGovernmentCloud
  16540. - ChinaCloud
  16541. - GermanCloud
  16542. - AzureStackCloud
  16543. type: string
  16544. identityId:
  16545. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  16546. type: string
  16547. serviceAccountRef:
  16548. description: |-
  16549. ServiceAccountRef specified the service account
  16550. that should be used when authenticating with WorkloadIdentity.
  16551. properties:
  16552. audiences:
  16553. description: |-
  16554. Audience specifies the `aud` claim for the service account token
  16555. Some providers automatically extend the audience field based on well-known annotations for workload
  16556. identity (e.g. IRSA or GCP Workload Identity)
  16557. items:
  16558. type: string
  16559. type: array
  16560. name:
  16561. description: The name of the ServiceAccount resource being referred to.
  16562. maxLength: 253
  16563. minLength: 1
  16564. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16565. type: string
  16566. namespace:
  16567. description: |-
  16568. Namespace of the resource being referred to.
  16569. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16570. maxLength: 63
  16571. minLength: 1
  16572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16573. type: string
  16574. required:
  16575. - name
  16576. type: object
  16577. tenantId:
  16578. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16579. type: string
  16580. useAzureSDK:
  16581. default: false
  16582. description: |-
  16583. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  16584. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  16585. type: boolean
  16586. vaultUrl:
  16587. description: Vault Url from which the secrets to be fetched from.
  16588. type: string
  16589. required:
  16590. - vaultUrl
  16591. type: object
  16592. barbican:
  16593. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  16594. properties:
  16595. auth:
  16596. description: BarbicanAuth contains the authentication information for Barbican.
  16597. properties:
  16598. applicationCredentialID:
  16599. description: ID of the application credential used for authentication.
  16600. maxProperties: 1
  16601. minProperties: 1
  16602. properties:
  16603. secretRef:
  16604. description: |-
  16605. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16606. In some instances, `key` is a required field.
  16607. properties:
  16608. key:
  16609. description: |-
  16610. A key in the referenced Secret.
  16611. Some instances of this field may be defaulted, in others it may be required.
  16612. maxLength: 253
  16613. minLength: 1
  16614. pattern: ^[-._a-zA-Z0-9]+$
  16615. type: string
  16616. name:
  16617. description: The name of the Secret resource being referred to.
  16618. maxLength: 253
  16619. minLength: 1
  16620. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16621. type: string
  16622. namespace:
  16623. description: |-
  16624. The namespace of the Secret resource being referred to.
  16625. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16626. maxLength: 63
  16627. minLength: 1
  16628. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16629. type: string
  16630. type: object
  16631. value:
  16632. minLength: 1
  16633. type: string
  16634. type: object
  16635. applicationCredentialSecret:
  16636. description: BarbicanProviderAppCredSecretRef defines a reference to an Application Credential Secret.
  16637. properties:
  16638. secretRef:
  16639. description: |-
  16640. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16641. In some instances, `key` is a required field.
  16642. properties:
  16643. key:
  16644. description: |-
  16645. A key in the referenced Secret.
  16646. Some instances of this field may be defaulted, in others it may be required.
  16647. maxLength: 253
  16648. minLength: 1
  16649. pattern: ^[-._a-zA-Z0-9]+$
  16650. type: string
  16651. name:
  16652. description: The name of the Secret resource being referred to.
  16653. maxLength: 253
  16654. minLength: 1
  16655. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16656. type: string
  16657. namespace:
  16658. description: |-
  16659. The namespace of the Secret resource being referred to.
  16660. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16661. maxLength: 63
  16662. minLength: 1
  16663. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16664. type: string
  16665. type: object
  16666. required:
  16667. - secretRef
  16668. type: object
  16669. authType:
  16670. default: password
  16671. description: |-
  16672. AuthType selects how Barbican authenticates.
  16673. - "password": use username and password.
  16674. - "applicationCredential": use application credential ID and secret.
  16675. Defaults to "password".
  16676. enum:
  16677. - password
  16678. - applicationCredential
  16679. type: string
  16680. password:
  16681. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  16682. properties:
  16683. secretRef:
  16684. description: |-
  16685. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16686. In some instances, `key` is a required field.
  16687. properties:
  16688. key:
  16689. description: |-
  16690. A key in the referenced Secret.
  16691. Some instances of this field may be defaulted, in others it may be required.
  16692. maxLength: 253
  16693. minLength: 1
  16694. pattern: ^[-._a-zA-Z0-9]+$
  16695. type: string
  16696. name:
  16697. description: The name of the Secret resource being referred to.
  16698. maxLength: 253
  16699. minLength: 1
  16700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16701. type: string
  16702. namespace:
  16703. description: |-
  16704. The namespace of the Secret resource being referred to.
  16705. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16706. maxLength: 63
  16707. minLength: 1
  16708. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16709. type: string
  16710. type: object
  16711. required:
  16712. - secretRef
  16713. type: object
  16714. username:
  16715. description: Username / Password authentication fields.
  16716. maxProperties: 1
  16717. minProperties: 1
  16718. properties:
  16719. secretRef:
  16720. description: |-
  16721. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16722. In some instances, `key` is a required field.
  16723. properties:
  16724. key:
  16725. description: |-
  16726. A key in the referenced Secret.
  16727. Some instances of this field may be defaulted, in others it may be required.
  16728. maxLength: 253
  16729. minLength: 1
  16730. pattern: ^[-._a-zA-Z0-9]+$
  16731. type: string
  16732. name:
  16733. description: The name of the Secret resource being referred to.
  16734. maxLength: 253
  16735. minLength: 1
  16736. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16737. type: string
  16738. namespace:
  16739. description: |-
  16740. The namespace of the Secret resource being referred to.
  16741. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16742. maxLength: 63
  16743. minLength: 1
  16744. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16745. type: string
  16746. type: object
  16747. value:
  16748. minLength: 1
  16749. type: string
  16750. type: object
  16751. type: object
  16752. x-kubernetes-validations:
  16753. - message: password auth requires both username and password
  16754. rule: (has(self.authType) && self.authType == 'applicationCredential') || (has(self.username) && has(self.password))
  16755. - message: applicationCredential auth requires both applicationCredentialID and applicationCredentialSecret
  16756. rule: self.authType != 'applicationCredential' || (has(self.applicationCredentialID) && has(self.applicationCredentialSecret))
  16757. - message: password auth should not include applicationCredential fields
  16758. rule: (has(self.authType) && self.authType == 'applicationCredential') || (!has(self.applicationCredentialID) && !has(self.applicationCredentialSecret))
  16759. - message: applicationCredential auth should not include password fields
  16760. rule: self.authType != 'applicationCredential' || (!has(self.username) && !has(self.password))
  16761. authURL:
  16762. type: string
  16763. domainName:
  16764. type: string
  16765. region:
  16766. type: string
  16767. tenantName:
  16768. type: string
  16769. required:
  16770. - auth
  16771. type: object
  16772. beyondtrust:
  16773. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  16774. properties:
  16775. auth:
  16776. description: Auth configures how the operator authenticates with Beyondtrust.
  16777. properties:
  16778. apiKey:
  16779. description: APIKey If not provided then ClientID/ClientSecret become required.
  16780. properties:
  16781. secretRef:
  16782. description: SecretRef references a key in a secret that will be used as value.
  16783. properties:
  16784. key:
  16785. description: |-
  16786. A key in the referenced Secret.
  16787. Some instances of this field may be defaulted, in others it may be required.
  16788. maxLength: 253
  16789. minLength: 1
  16790. pattern: ^[-._a-zA-Z0-9]+$
  16791. type: string
  16792. name:
  16793. description: The name of the Secret resource being referred to.
  16794. maxLength: 253
  16795. minLength: 1
  16796. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16797. type: string
  16798. namespace:
  16799. description: |-
  16800. The namespace of the Secret resource being referred to.
  16801. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16802. maxLength: 63
  16803. minLength: 1
  16804. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16805. type: string
  16806. type: object
  16807. value:
  16808. description: Value can be specified directly to set a value without using a secret.
  16809. type: string
  16810. type: object
  16811. certificate:
  16812. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  16813. properties:
  16814. secretRef:
  16815. description: SecretRef references a key in a secret that will be used as value.
  16816. properties:
  16817. key:
  16818. description: |-
  16819. A key in the referenced Secret.
  16820. Some instances of this field may be defaulted, in others it may be required.
  16821. maxLength: 253
  16822. minLength: 1
  16823. pattern: ^[-._a-zA-Z0-9]+$
  16824. type: string
  16825. name:
  16826. description: The name of the Secret resource being referred to.
  16827. maxLength: 253
  16828. minLength: 1
  16829. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16830. type: string
  16831. namespace:
  16832. description: |-
  16833. The namespace of the Secret resource being referred to.
  16834. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16835. maxLength: 63
  16836. minLength: 1
  16837. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16838. type: string
  16839. type: object
  16840. value:
  16841. description: Value can be specified directly to set a value without using a secret.
  16842. type: string
  16843. type: object
  16844. certificateKey:
  16845. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  16846. properties:
  16847. secretRef:
  16848. description: SecretRef references a key in a secret that will be used as value.
  16849. properties:
  16850. key:
  16851. description: |-
  16852. A key in the referenced Secret.
  16853. Some instances of this field may be defaulted, in others it may be required.
  16854. maxLength: 253
  16855. minLength: 1
  16856. pattern: ^[-._a-zA-Z0-9]+$
  16857. type: string
  16858. name:
  16859. description: The name of the Secret resource being referred to.
  16860. maxLength: 253
  16861. minLength: 1
  16862. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16863. type: string
  16864. namespace:
  16865. description: |-
  16866. The namespace of the Secret resource being referred to.
  16867. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16868. maxLength: 63
  16869. minLength: 1
  16870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16871. type: string
  16872. type: object
  16873. value:
  16874. description: Value can be specified directly to set a value without using a secret.
  16875. type: string
  16876. type: object
  16877. clientId:
  16878. description: ClientID is the API OAuth Client ID.
  16879. properties:
  16880. secretRef:
  16881. description: SecretRef references a key in a secret that will be used as value.
  16882. properties:
  16883. key:
  16884. description: |-
  16885. A key in the referenced Secret.
  16886. Some instances of this field may be defaulted, in others it may be required.
  16887. maxLength: 253
  16888. minLength: 1
  16889. pattern: ^[-._a-zA-Z0-9]+$
  16890. type: string
  16891. name:
  16892. description: The name of the Secret resource being referred to.
  16893. maxLength: 253
  16894. minLength: 1
  16895. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16896. type: string
  16897. namespace:
  16898. description: |-
  16899. The namespace of the Secret resource being referred to.
  16900. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16901. maxLength: 63
  16902. minLength: 1
  16903. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16904. type: string
  16905. type: object
  16906. value:
  16907. description: Value can be specified directly to set a value without using a secret.
  16908. type: string
  16909. type: object
  16910. clientSecret:
  16911. description: ClientSecret is the API OAuth Client Secret.
  16912. properties:
  16913. secretRef:
  16914. description: SecretRef references a key in a secret that will be used as value.
  16915. properties:
  16916. key:
  16917. description: |-
  16918. A key in the referenced Secret.
  16919. Some instances of this field may be defaulted, in others it may be required.
  16920. maxLength: 253
  16921. minLength: 1
  16922. pattern: ^[-._a-zA-Z0-9]+$
  16923. type: string
  16924. name:
  16925. description: The name of the Secret resource being referred to.
  16926. maxLength: 253
  16927. minLength: 1
  16928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16929. type: string
  16930. namespace:
  16931. description: |-
  16932. The namespace of the Secret resource being referred to.
  16933. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16934. maxLength: 63
  16935. minLength: 1
  16936. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16937. type: string
  16938. type: object
  16939. value:
  16940. description: Value can be specified directly to set a value without using a secret.
  16941. type: string
  16942. type: object
  16943. type: object
  16944. server:
  16945. description: Auth configures how API server works.
  16946. properties:
  16947. apiUrl:
  16948. type: string
  16949. apiVersion:
  16950. type: string
  16951. clientTimeOutSeconds:
  16952. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  16953. type: integer
  16954. decrypt:
  16955. default: true
  16956. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  16957. type: boolean
  16958. retrievalType:
  16959. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  16960. type: string
  16961. separator:
  16962. description: A character that separates the folder names.
  16963. type: string
  16964. verifyCA:
  16965. type: boolean
  16966. required:
  16967. - apiUrl
  16968. - verifyCA
  16969. type: object
  16970. required:
  16971. - auth
  16972. - server
  16973. type: object
  16974. beyondtrustworkloadcredentials:
  16975. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  16976. properties:
  16977. auth:
  16978. description: |-
  16979. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  16980. Currently supports API key authentication via Kubernetes secret reference.
  16981. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16982. properties:
  16983. apikey:
  16984. description: |-
  16985. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  16986. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  16987. properties:
  16988. token:
  16989. description: |-
  16990. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  16991. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  16992. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  16993. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16994. properties:
  16995. key:
  16996. description: |-
  16997. A key in the referenced Secret.
  16998. Some instances of this field may be defaulted, in others it may be required.
  16999. maxLength: 253
  17000. minLength: 1
  17001. pattern: ^[-._a-zA-Z0-9]+$
  17002. type: string
  17003. name:
  17004. description: The name of the Secret resource being referred to.
  17005. maxLength: 253
  17006. minLength: 1
  17007. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17008. type: string
  17009. namespace:
  17010. description: |-
  17011. The namespace of the Secret resource being referred to.
  17012. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17013. maxLength: 63
  17014. minLength: 1
  17015. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17016. type: string
  17017. type: object
  17018. required:
  17019. - token
  17020. type: object
  17021. required:
  17022. - apikey
  17023. type: object
  17024. caBundle:
  17025. description: |-
  17026. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  17027. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  17028. If not set, the system's trusted root certificates are used.
  17029. format: byte
  17030. type: string
  17031. caProvider:
  17032. description: |-
  17033. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  17034. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  17035. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  17036. properties:
  17037. key:
  17038. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17039. maxLength: 253
  17040. minLength: 1
  17041. pattern: ^[-._a-zA-Z0-9]+$
  17042. type: string
  17043. name:
  17044. description: The name of the object located at the provider type.
  17045. maxLength: 253
  17046. minLength: 1
  17047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17048. type: string
  17049. namespace:
  17050. description: |-
  17051. The namespace the Provider type is in.
  17052. Can only be defined when used in a ClusterSecretStore.
  17053. maxLength: 63
  17054. minLength: 1
  17055. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17056. type: string
  17057. type:
  17058. description: The type of provider to use such as "Secret", or "ConfigMap".
  17059. enum:
  17060. - Secret
  17061. - ConfigMap
  17062. type: string
  17063. required:
  17064. - name
  17065. - type
  17066. type: object
  17067. folderPath:
  17068. description: |-
  17069. FolderPath specifies the default folder path for secret retrieval.
  17070. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  17071. Example: "production/database" or "dev/api-keys"
  17072. Leave empty to retrieve secrets from the root folder.
  17073. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  17074. type: string
  17075. server:
  17076. description: |-
  17077. Server configures the BeyondTrust Workload Credentials server connection details.
  17078. Includes the API URL and Site ID for your BeyondTrust instance.
  17079. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  17080. properties:
  17081. apiUrl:
  17082. description: |-
  17083. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  17084. This should be the full URL to your BeyondTrust instance.
  17085. Example: https://api.beyondtrust.io/siie
  17086. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  17087. type: string
  17088. siteId:
  17089. description: |-
  17090. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  17091. This identifier is unique to your BeyondTrust Workload Credentials instance.
  17092. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  17093. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  17094. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  17095. type: string
  17096. required:
  17097. - apiUrl
  17098. - siteId
  17099. type: object
  17100. required:
  17101. - auth
  17102. - server
  17103. type: object
  17104. bitwardensecretsmanager:
  17105. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  17106. properties:
  17107. apiURL:
  17108. type: string
  17109. auth:
  17110. description: |-
  17111. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  17112. Make sure that the token being used has permissions on the given secret.
  17113. properties:
  17114. secretRef:
  17115. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  17116. properties:
  17117. credentials:
  17118. description: AccessToken used for the bitwarden instance.
  17119. properties:
  17120. key:
  17121. description: |-
  17122. A key in the referenced Secret.
  17123. Some instances of this field may be defaulted, in others it may be required.
  17124. maxLength: 253
  17125. minLength: 1
  17126. pattern: ^[-._a-zA-Z0-9]+$
  17127. type: string
  17128. name:
  17129. description: The name of the Secret resource being referred to.
  17130. maxLength: 253
  17131. minLength: 1
  17132. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17133. type: string
  17134. namespace:
  17135. description: |-
  17136. The namespace of the Secret resource being referred to.
  17137. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17138. maxLength: 63
  17139. minLength: 1
  17140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17141. type: string
  17142. type: object
  17143. required:
  17144. - credentials
  17145. type: object
  17146. required:
  17147. - secretRef
  17148. type: object
  17149. bitwardenServerSDKURL:
  17150. type: string
  17151. caBundle:
  17152. description: |-
  17153. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  17154. can be performed.
  17155. type: string
  17156. caProvider:
  17157. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  17158. properties:
  17159. key:
  17160. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17161. maxLength: 253
  17162. minLength: 1
  17163. pattern: ^[-._a-zA-Z0-9]+$
  17164. type: string
  17165. name:
  17166. description: The name of the object located at the provider type.
  17167. maxLength: 253
  17168. minLength: 1
  17169. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17170. type: string
  17171. namespace:
  17172. description: |-
  17173. The namespace the Provider type is in.
  17174. Can only be defined when used in a ClusterSecretStore.
  17175. maxLength: 63
  17176. minLength: 1
  17177. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17178. type: string
  17179. type:
  17180. description: The type of provider to use such as "Secret", or "ConfigMap".
  17181. enum:
  17182. - Secret
  17183. - ConfigMap
  17184. type: string
  17185. required:
  17186. - name
  17187. - type
  17188. type: object
  17189. identityURL:
  17190. type: string
  17191. organizationID:
  17192. description: OrganizationID determines which organization this secret store manages.
  17193. type: string
  17194. projectID:
  17195. description: ProjectID determines which project this secret store manages.
  17196. type: string
  17197. required:
  17198. - auth
  17199. - organizationID
  17200. - projectID
  17201. type: object
  17202. chef:
  17203. description: Chef configures this store to sync secrets with chef server
  17204. properties:
  17205. auth:
  17206. description: Auth defines the information necessary to authenticate against chef Server
  17207. properties:
  17208. secretRef:
  17209. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  17210. properties:
  17211. privateKeySecretRef:
  17212. description: SecretKey is the Signing Key in PEM format, used for authentication.
  17213. properties:
  17214. key:
  17215. description: |-
  17216. A key in the referenced Secret.
  17217. Some instances of this field may be defaulted, in others it may be required.
  17218. maxLength: 253
  17219. minLength: 1
  17220. pattern: ^[-._a-zA-Z0-9]+$
  17221. type: string
  17222. name:
  17223. description: The name of the Secret resource being referred to.
  17224. maxLength: 253
  17225. minLength: 1
  17226. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17227. type: string
  17228. namespace:
  17229. description: |-
  17230. The namespace of the Secret resource being referred to.
  17231. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17232. maxLength: 63
  17233. minLength: 1
  17234. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17235. type: string
  17236. type: object
  17237. required:
  17238. - privateKeySecretRef
  17239. type: object
  17240. required:
  17241. - secretRef
  17242. type: object
  17243. serverUrl:
  17244. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  17245. type: string
  17246. username:
  17247. description: UserName should be the user ID on the chef server
  17248. type: string
  17249. required:
  17250. - auth
  17251. - serverUrl
  17252. - username
  17253. type: object
  17254. cloudrusm:
  17255. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  17256. properties:
  17257. auth:
  17258. description: CSMAuth contains a secretRef for credentials.
  17259. properties:
  17260. secretRef:
  17261. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  17262. properties:
  17263. accessKeyIDSecretRef:
  17264. description: The AccessKeyID is used for authentication
  17265. properties:
  17266. key:
  17267. description: |-
  17268. A key in the referenced Secret.
  17269. Some instances of this field may be defaulted, in others it may be required.
  17270. maxLength: 253
  17271. minLength: 1
  17272. pattern: ^[-._a-zA-Z0-9]+$
  17273. type: string
  17274. name:
  17275. description: The name of the Secret resource being referred to.
  17276. maxLength: 253
  17277. minLength: 1
  17278. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17279. type: string
  17280. namespace:
  17281. description: |-
  17282. The namespace of the Secret resource being referred to.
  17283. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17284. maxLength: 63
  17285. minLength: 1
  17286. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17287. type: string
  17288. type: object
  17289. accessKeySecretSecretRef:
  17290. description: The AccessKeySecret is used for authentication
  17291. properties:
  17292. key:
  17293. description: |-
  17294. A key in the referenced Secret.
  17295. Some instances of this field may be defaulted, in others it may be required.
  17296. maxLength: 253
  17297. minLength: 1
  17298. pattern: ^[-._a-zA-Z0-9]+$
  17299. type: string
  17300. name:
  17301. description: The name of the Secret resource being referred to.
  17302. maxLength: 253
  17303. minLength: 1
  17304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17305. type: string
  17306. namespace:
  17307. description: |-
  17308. The namespace of the Secret resource being referred to.
  17309. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17310. maxLength: 63
  17311. minLength: 1
  17312. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17313. type: string
  17314. type: object
  17315. required:
  17316. - accessKeyIDSecretRef
  17317. - accessKeySecretSecretRef
  17318. type: object
  17319. type: object
  17320. projectID:
  17321. description: ProjectID is the project, which the secrets are stored in.
  17322. type: string
  17323. required:
  17324. - auth
  17325. type: object
  17326. conjur:
  17327. description: Conjur configures this store to sync secrets using conjur provider
  17328. properties:
  17329. auth:
  17330. description: Defines authentication settings for connecting to Conjur.
  17331. maxProperties: 1
  17332. minProperties: 1
  17333. properties:
  17334. apikey:
  17335. description: Authenticates with Conjur using an API key.
  17336. properties:
  17337. account:
  17338. description: Account is the Conjur organization account name.
  17339. type: string
  17340. apiKeyRef:
  17341. description: |-
  17342. A reference to a specific 'key' containing the Conjur API key
  17343. within a Secret resource. In some instances, `key` is a required field.
  17344. properties:
  17345. key:
  17346. description: |-
  17347. A key in the referenced Secret.
  17348. Some instances of this field may be defaulted, in others it may be required.
  17349. maxLength: 253
  17350. minLength: 1
  17351. pattern: ^[-._a-zA-Z0-9]+$
  17352. type: string
  17353. name:
  17354. description: The name of the Secret resource being referred to.
  17355. maxLength: 253
  17356. minLength: 1
  17357. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17358. type: string
  17359. namespace:
  17360. description: |-
  17361. The namespace of the Secret resource being referred to.
  17362. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17363. maxLength: 63
  17364. minLength: 1
  17365. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17366. type: string
  17367. type: object
  17368. userRef:
  17369. description: |-
  17370. A reference to a specific 'key' containing the Conjur username
  17371. within a Secret resource. In some instances, `key` is a required field.
  17372. properties:
  17373. key:
  17374. description: |-
  17375. A key in the referenced Secret.
  17376. Some instances of this field may be defaulted, in others it may be required.
  17377. maxLength: 253
  17378. minLength: 1
  17379. pattern: ^[-._a-zA-Z0-9]+$
  17380. type: string
  17381. name:
  17382. description: The name of the Secret resource being referred to.
  17383. maxLength: 253
  17384. minLength: 1
  17385. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17386. type: string
  17387. namespace:
  17388. description: |-
  17389. The namespace of the Secret resource being referred to.
  17390. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17391. maxLength: 63
  17392. minLength: 1
  17393. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17394. type: string
  17395. type: object
  17396. required:
  17397. - account
  17398. - apiKeyRef
  17399. - userRef
  17400. type: object
  17401. cert:
  17402. description: Cert enables certificate-based authentication using a client certificate and key.
  17403. properties:
  17404. account:
  17405. description: Account is the Conjur organization account name.
  17406. type: string
  17407. clientCertRef:
  17408. description: |-
  17409. ClientCertRef is a reference to a specific 'key' containing the client certificate
  17410. within a Secret resource. The certificate must be PEM-encoded.
  17411. properties:
  17412. key:
  17413. description: |-
  17414. A key in the referenced Secret.
  17415. Some instances of this field may be defaulted, in others it may be required.
  17416. maxLength: 253
  17417. minLength: 1
  17418. pattern: ^[-._a-zA-Z0-9]+$
  17419. type: string
  17420. name:
  17421. description: The name of the Secret resource being referred to.
  17422. maxLength: 253
  17423. minLength: 1
  17424. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17425. type: string
  17426. namespace:
  17427. description: |-
  17428. The namespace of the Secret resource being referred to.
  17429. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17430. maxLength: 63
  17431. minLength: 1
  17432. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17433. type: string
  17434. type: object
  17435. clientKeyRef:
  17436. description: |-
  17437. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  17438. within a Secret resource. The key must be PEM-encoded.
  17439. properties:
  17440. key:
  17441. description: |-
  17442. A key in the referenced Secret.
  17443. Some instances of this field may be defaulted, in others it may be required.
  17444. maxLength: 253
  17445. minLength: 1
  17446. pattern: ^[-._a-zA-Z0-9]+$
  17447. type: string
  17448. name:
  17449. description: The name of the Secret resource being referred to.
  17450. maxLength: 253
  17451. minLength: 1
  17452. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17453. type: string
  17454. namespace:
  17455. description: |-
  17456. The namespace of the Secret resource being referred to.
  17457. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17458. maxLength: 63
  17459. minLength: 1
  17460. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17461. type: string
  17462. type: object
  17463. hostId:
  17464. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  17465. type: string
  17466. serviceID:
  17467. description: The conjur authn cert webservice id
  17468. type: string
  17469. required:
  17470. - account
  17471. - clientCertRef
  17472. - clientKeyRef
  17473. - serviceID
  17474. type: object
  17475. jwt:
  17476. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  17477. properties:
  17478. account:
  17479. description: Account is the Conjur organization account name.
  17480. type: string
  17481. hostId:
  17482. description: |-
  17483. Optional HostID for JWT authentication. This may be used depending
  17484. on how the Conjur JWT authenticator policy is configured.
  17485. type: string
  17486. secretRef:
  17487. description: |-
  17488. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  17489. authenticate with Conjur using the JWT authentication method.
  17490. properties:
  17491. key:
  17492. description: |-
  17493. A key in the referenced Secret.
  17494. Some instances of this field may be defaulted, in others it may be required.
  17495. maxLength: 253
  17496. minLength: 1
  17497. pattern: ^[-._a-zA-Z0-9]+$
  17498. type: string
  17499. name:
  17500. description: The name of the Secret resource being referred to.
  17501. maxLength: 253
  17502. minLength: 1
  17503. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17504. type: string
  17505. namespace:
  17506. description: |-
  17507. The namespace of the Secret resource being referred to.
  17508. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17509. maxLength: 63
  17510. minLength: 1
  17511. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17512. type: string
  17513. type: object
  17514. serviceAccountRef:
  17515. description: |-
  17516. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  17517. a token for with the `TokenRequest` API.
  17518. properties:
  17519. audiences:
  17520. description: |-
  17521. Audience specifies the `aud` claim for the service account token
  17522. Some providers automatically extend the audience field based on well-known annotations for workload
  17523. identity (e.g. IRSA or GCP Workload Identity)
  17524. items:
  17525. type: string
  17526. type: array
  17527. name:
  17528. description: The name of the ServiceAccount resource being referred to.
  17529. maxLength: 253
  17530. minLength: 1
  17531. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17532. type: string
  17533. namespace:
  17534. description: |-
  17535. Namespace of the resource being referred to.
  17536. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17537. maxLength: 63
  17538. minLength: 1
  17539. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17540. type: string
  17541. required:
  17542. - name
  17543. type: object
  17544. serviceID:
  17545. description: The conjur authn jwt webservice id
  17546. type: string
  17547. required:
  17548. - account
  17549. - serviceID
  17550. type: object
  17551. type: object
  17552. caBundle:
  17553. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  17554. type: string
  17555. caProvider:
  17556. description: |-
  17557. Used to provide custom certificate authority (CA) certificates
  17558. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  17559. that contains a PEM-encoded certificate.
  17560. properties:
  17561. key:
  17562. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17563. maxLength: 253
  17564. minLength: 1
  17565. pattern: ^[-._a-zA-Z0-9]+$
  17566. type: string
  17567. name:
  17568. description: The name of the object located at the provider type.
  17569. maxLength: 253
  17570. minLength: 1
  17571. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17572. type: string
  17573. namespace:
  17574. description: |-
  17575. The namespace the Provider type is in.
  17576. Can only be defined when used in a ClusterSecretStore.
  17577. maxLength: 63
  17578. minLength: 1
  17579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17580. type: string
  17581. type:
  17582. description: The type of provider to use such as "Secret", or "ConfigMap".
  17583. enum:
  17584. - Secret
  17585. - ConfigMap
  17586. type: string
  17587. required:
  17588. - name
  17589. - type
  17590. type: object
  17591. url:
  17592. description: URL is the endpoint of the Conjur instance.
  17593. type: string
  17594. required:
  17595. - auth
  17596. - url
  17597. type: object
  17598. crd:
  17599. description: |-
  17600. CRD configures this store to sync secrets from arbitrary Kubernetes resources,
  17601. including both custom resources (CRDs) and core API resources. Resources are
  17602. selected by API group, version and kind, where group can be "" (empty string)
  17603. for core resources such as ConfigMap. Reading the core v1 Secret is
  17604. intentionally blocked — use the Kubernetes provider for that.
  17605. properties:
  17606. auth:
  17607. description: |-
  17608. Auth configures authentication to the Kubernetes API, same as the
  17609. Kubernetes provider. Required when Server.URL is set (unless using AuthRef).
  17610. maxProperties: 1
  17611. minProperties: 1
  17612. properties:
  17613. cert:
  17614. description: has both clientCert and clientKey as secretKeySelector
  17615. properties:
  17616. clientCert:
  17617. description: |-
  17618. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17619. In some instances, `key` is a required field.
  17620. properties:
  17621. key:
  17622. description: |-
  17623. A key in the referenced Secret.
  17624. Some instances of this field may be defaulted, in others it may be required.
  17625. maxLength: 253
  17626. minLength: 1
  17627. pattern: ^[-._a-zA-Z0-9]+$
  17628. type: string
  17629. name:
  17630. description: The name of the Secret resource being referred to.
  17631. maxLength: 253
  17632. minLength: 1
  17633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17634. type: string
  17635. namespace:
  17636. description: |-
  17637. The namespace of the Secret resource being referred to.
  17638. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17639. maxLength: 63
  17640. minLength: 1
  17641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17642. type: string
  17643. type: object
  17644. clientKey:
  17645. description: |-
  17646. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17647. In some instances, `key` is a required field.
  17648. properties:
  17649. key:
  17650. description: |-
  17651. A key in the referenced Secret.
  17652. Some instances of this field may be defaulted, in others it may be required.
  17653. maxLength: 253
  17654. minLength: 1
  17655. pattern: ^[-._a-zA-Z0-9]+$
  17656. type: string
  17657. name:
  17658. description: The name of the Secret resource being referred to.
  17659. maxLength: 253
  17660. minLength: 1
  17661. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17662. type: string
  17663. namespace:
  17664. description: |-
  17665. The namespace of the Secret resource being referred to.
  17666. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17667. maxLength: 63
  17668. minLength: 1
  17669. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17670. type: string
  17671. type: object
  17672. required:
  17673. - clientCert
  17674. - clientKey
  17675. type: object
  17676. serviceAccount:
  17677. description: points to a service account that should be used for authentication
  17678. properties:
  17679. audiences:
  17680. description: |-
  17681. Audience specifies the `aud` claim for the service account token
  17682. Some providers automatically extend the audience field based on well-known annotations for workload
  17683. identity (e.g. IRSA or GCP Workload Identity)
  17684. items:
  17685. type: string
  17686. type: array
  17687. name:
  17688. description: The name of the ServiceAccount resource being referred to.
  17689. maxLength: 253
  17690. minLength: 1
  17691. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17692. type: string
  17693. namespace:
  17694. description: |-
  17695. Namespace of the resource being referred to.
  17696. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17697. maxLength: 63
  17698. minLength: 1
  17699. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17700. type: string
  17701. required:
  17702. - name
  17703. type: object
  17704. token:
  17705. description: use static token to authenticate with
  17706. properties:
  17707. bearerToken:
  17708. description: |-
  17709. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17710. In some instances, `key` is a required field.
  17711. properties:
  17712. key:
  17713. description: |-
  17714. A key in the referenced Secret.
  17715. Some instances of this field may be defaulted, in others it may be required.
  17716. maxLength: 253
  17717. minLength: 1
  17718. pattern: ^[-._a-zA-Z0-9]+$
  17719. type: string
  17720. name:
  17721. description: The name of the Secret resource being referred to.
  17722. maxLength: 253
  17723. minLength: 1
  17724. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17725. type: string
  17726. namespace:
  17727. description: |-
  17728. The namespace of the Secret resource being referred to.
  17729. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17730. maxLength: 63
  17731. minLength: 1
  17732. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17733. type: string
  17734. type: object
  17735. required:
  17736. - bearerToken
  17737. type: object
  17738. type: object
  17739. authRef:
  17740. description: |-
  17741. AuthRef references a Secret containing a kubeconfig. Same semantics as the
  17742. Kubernetes provider.
  17743. properties:
  17744. key:
  17745. description: |-
  17746. A key in the referenced Secret.
  17747. Some instances of this field may be defaulted, in others it may be required.
  17748. maxLength: 253
  17749. minLength: 1
  17750. pattern: ^[-._a-zA-Z0-9]+$
  17751. type: string
  17752. name:
  17753. description: The name of the Secret resource being referred to.
  17754. maxLength: 253
  17755. minLength: 1
  17756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17757. type: string
  17758. namespace:
  17759. description: |-
  17760. The namespace of the Secret resource being referred to.
  17761. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17762. maxLength: 63
  17763. minLength: 1
  17764. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17765. type: string
  17766. type: object
  17767. resource:
  17768. description: Resource identifies the CRD by its API group, version and kind.
  17769. properties:
  17770. group:
  17771. description: |-
  17772. Group is the API group of the resource. Use "" (empty string) for core
  17773. Kubernetes resources such as ConfigMap; use e.g. "config.example.io"
  17774. for a CRD. The field is required to be present in the manifest — write
  17775. `group: ""` explicitly for core resources so typos fail at admission
  17776. time rather than later at discovery.
  17777. type: string
  17778. kind:
  17779. description: Kind is the Kubernetes resource kind (e.g. "MyCustomResource").
  17780. minLength: 1
  17781. type: string
  17782. version:
  17783. description: Version is the API version of the resource (e.g. "v1alpha1").
  17784. minLength: 1
  17785. type: string
  17786. required:
  17787. - group
  17788. - kind
  17789. - version
  17790. type: object
  17791. server:
  17792. description: |-
  17793. Server configures the Kubernetes API address and TLS trust, same as the
  17794. Kubernetes provider. When omitted, the URL defaults to the in-cluster API.
  17795. properties:
  17796. caBundle:
  17797. description: CABundle is a base64-encoded CA certificate
  17798. format: byte
  17799. type: string
  17800. caProvider:
  17801. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  17802. properties:
  17803. key:
  17804. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17805. maxLength: 253
  17806. minLength: 1
  17807. pattern: ^[-._a-zA-Z0-9]+$
  17808. type: string
  17809. name:
  17810. description: The name of the object located at the provider type.
  17811. maxLength: 253
  17812. minLength: 1
  17813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17814. type: string
  17815. namespace:
  17816. description: |-
  17817. The namespace the Provider type is in.
  17818. Can only be defined when used in a ClusterSecretStore.
  17819. maxLength: 63
  17820. minLength: 1
  17821. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17822. type: string
  17823. type:
  17824. description: The type of provider to use such as "Secret", or "ConfigMap".
  17825. enum:
  17826. - Secret
  17827. - ConfigMap
  17828. type: string
  17829. required:
  17830. - name
  17831. - type
  17832. type: object
  17833. url:
  17834. default: kubernetes.default
  17835. description: configures the Kubernetes server Address.
  17836. type: string
  17837. type: object
  17838. whitelist:
  17839. description: |-
  17840. Whitelist optionally restricts which object names and requested properties
  17841. are allowed to be read.
  17842. properties:
  17843. rules:
  17844. description: |-
  17845. Rules is a list of allow rules. If rules are set, at least one rule must
  17846. match for a request to be allowed.
  17847. items:
  17848. description: CRDProviderWhitelistRule defines a single allow rule for CRD reads.
  17849. properties:
  17850. name:
  17851. description: |-
  17852. Name is an optional regular expression matched against the bare object name.
  17853. For both SecretStore and ClusterSecretStore this is always the object name
  17854. without any namespace prefix (e.g. "my-db-spec", not "prod/my-db-spec").
  17855. type: string
  17856. namespace:
  17857. description: |-
  17858. Namespace is an optional regular expression matched against the namespace of
  17859. the object. Applies only when a ClusterSecretStore is used; it is ignored
  17860. for SecretStore (where the namespace is fixed to the store namespace).
  17861. type: string
  17862. properties:
  17863. description: |-
  17864. Properties is an optional list of regular expressions matched against
  17865. requested property keys (for example: "spec.secretValue").
  17866. items:
  17867. type: string
  17868. type: array
  17869. type: object
  17870. type: array
  17871. type: object
  17872. required:
  17873. - resource
  17874. type: object
  17875. x-kubernetes-validations:
  17876. - message: one of auth or authRef is required
  17877. rule: has(self.auth) || has(self.authRef)
  17878. - message: at most one of the fields in [auth authRef] may be set
  17879. rule: '[has(self.auth),has(self.authRef)].filter(x,x==true).size() <= 1'
  17880. delinea:
  17881. description: |-
  17882. Delinea DevOps Secrets Vault
  17883. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  17884. properties:
  17885. clientId:
  17886. description: ClientID is the non-secret part of the credential.
  17887. properties:
  17888. secretRef:
  17889. description: SecretRef references a key in a secret that will be used as value.
  17890. properties:
  17891. key:
  17892. description: |-
  17893. A key in the referenced Secret.
  17894. Some instances of this field may be defaulted, in others it may be required.
  17895. maxLength: 253
  17896. minLength: 1
  17897. pattern: ^[-._a-zA-Z0-9]+$
  17898. type: string
  17899. name:
  17900. description: The name of the Secret resource being referred to.
  17901. maxLength: 253
  17902. minLength: 1
  17903. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17904. type: string
  17905. namespace:
  17906. description: |-
  17907. The namespace of the Secret resource being referred to.
  17908. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17909. maxLength: 63
  17910. minLength: 1
  17911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17912. type: string
  17913. type: object
  17914. value:
  17915. description: Value can be specified directly to set a value without using a secret.
  17916. type: string
  17917. type: object
  17918. clientSecret:
  17919. description: ClientSecret is the secret part of the credential.
  17920. properties:
  17921. secretRef:
  17922. description: SecretRef references a key in a secret that will be used as value.
  17923. properties:
  17924. key:
  17925. description: |-
  17926. A key in the referenced Secret.
  17927. Some instances of this field may be defaulted, in others it may be required.
  17928. maxLength: 253
  17929. minLength: 1
  17930. pattern: ^[-._a-zA-Z0-9]+$
  17931. type: string
  17932. name:
  17933. description: The name of the Secret resource being referred to.
  17934. maxLength: 253
  17935. minLength: 1
  17936. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17937. type: string
  17938. namespace:
  17939. description: |-
  17940. The namespace of the Secret resource being referred to.
  17941. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17942. maxLength: 63
  17943. minLength: 1
  17944. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17945. type: string
  17946. type: object
  17947. value:
  17948. description: Value can be specified directly to set a value without using a secret.
  17949. type: string
  17950. type: object
  17951. tenant:
  17952. description: Tenant is the chosen hostname / site name.
  17953. type: string
  17954. tld:
  17955. description: |-
  17956. TLD is based on the server location that was chosen during provisioning.
  17957. If unset, defaults to "com".
  17958. type: string
  17959. urlTemplate:
  17960. description: |-
  17961. URLTemplate
  17962. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  17963. type: string
  17964. required:
  17965. - clientId
  17966. - clientSecret
  17967. - tenant
  17968. type: object
  17969. doppler:
  17970. description: Doppler configures this store to sync secrets using the Doppler provider
  17971. properties:
  17972. auth:
  17973. description: Auth configures how the Operator authenticates with the Doppler API
  17974. properties:
  17975. oidcConfig:
  17976. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  17977. properties:
  17978. expirationSeconds:
  17979. default: 600
  17980. description: |-
  17981. ExpirationSeconds sets the ServiceAccount token validity duration.
  17982. Defaults to 10 minutes.
  17983. format: int64
  17984. type: integer
  17985. identity:
  17986. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  17987. type: string
  17988. serviceAccountRef:
  17989. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  17990. properties:
  17991. audiences:
  17992. description: |-
  17993. Audience specifies the `aud` claim for the service account token
  17994. Some providers automatically extend the audience field based on well-known annotations for workload
  17995. identity (e.g. IRSA or GCP Workload Identity)
  17996. items:
  17997. type: string
  17998. type: array
  17999. name:
  18000. description: The name of the ServiceAccount resource being referred to.
  18001. maxLength: 253
  18002. minLength: 1
  18003. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18004. type: string
  18005. namespace:
  18006. description: |-
  18007. Namespace of the resource being referred to.
  18008. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18009. maxLength: 63
  18010. minLength: 1
  18011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18012. type: string
  18013. required:
  18014. - name
  18015. type: object
  18016. required:
  18017. - identity
  18018. - serviceAccountRef
  18019. type: object
  18020. secretRef:
  18021. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  18022. properties:
  18023. dopplerToken:
  18024. description: |-
  18025. The DopplerToken is used for authentication.
  18026. See https://docs.doppler.com/reference/api#authentication for auth token types.
  18027. The Key attribute defaults to dopplerToken if not specified.
  18028. properties:
  18029. key:
  18030. description: |-
  18031. A key in the referenced Secret.
  18032. Some instances of this field may be defaulted, in others it may be required.
  18033. maxLength: 253
  18034. minLength: 1
  18035. pattern: ^[-._a-zA-Z0-9]+$
  18036. type: string
  18037. name:
  18038. description: The name of the Secret resource being referred to.
  18039. maxLength: 253
  18040. minLength: 1
  18041. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18042. type: string
  18043. namespace:
  18044. description: |-
  18045. The namespace of the Secret resource being referred to.
  18046. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18047. maxLength: 63
  18048. minLength: 1
  18049. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18050. type: string
  18051. type: object
  18052. required:
  18053. - dopplerToken
  18054. type: object
  18055. type: object
  18056. x-kubernetes-validations:
  18057. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  18058. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  18059. config:
  18060. description: Doppler config (required if not using a Service Token)
  18061. type: string
  18062. format:
  18063. description: Format enables the downloading of secrets as a file (string)
  18064. enum:
  18065. - json
  18066. - dotnet-json
  18067. - env
  18068. - yaml
  18069. - docker
  18070. type: string
  18071. nameTransformer:
  18072. description: Environment variable compatible name transforms that change secret names to a different format
  18073. enum:
  18074. - upper-camel
  18075. - camel
  18076. - lower-snake
  18077. - tf-var
  18078. - dotnet-env
  18079. - lower-kebab
  18080. type: string
  18081. project:
  18082. description: Doppler project (required if not using a Service Token)
  18083. type: string
  18084. required:
  18085. - auth
  18086. type: object
  18087. dvls:
  18088. description: DVLS configures this store to sync secrets using Devolutions Server provider
  18089. properties:
  18090. auth:
  18091. description: Auth defines the authentication method to use.
  18092. properties:
  18093. secretRef:
  18094. description: SecretRef contains the Application ID and Application Secret for authentication.
  18095. properties:
  18096. appId:
  18097. description: AppID is the reference to the secret containing the Application ID.
  18098. properties:
  18099. key:
  18100. description: |-
  18101. A key in the referenced Secret.
  18102. Some instances of this field may be defaulted, in others it may be required.
  18103. maxLength: 253
  18104. minLength: 1
  18105. pattern: ^[-._a-zA-Z0-9]+$
  18106. type: string
  18107. name:
  18108. description: The name of the Secret resource being referred to.
  18109. maxLength: 253
  18110. minLength: 1
  18111. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18112. type: string
  18113. namespace:
  18114. description: |-
  18115. The namespace of the Secret resource being referred to.
  18116. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18117. maxLength: 63
  18118. minLength: 1
  18119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18120. type: string
  18121. type: object
  18122. appSecret:
  18123. description: AppSecret is the reference to the secret containing the Application Secret.
  18124. properties:
  18125. key:
  18126. description: |-
  18127. A key in the referenced Secret.
  18128. Some instances of this field may be defaulted, in others it may be required.
  18129. maxLength: 253
  18130. minLength: 1
  18131. pattern: ^[-._a-zA-Z0-9]+$
  18132. type: string
  18133. name:
  18134. description: The name of the Secret resource being referred to.
  18135. maxLength: 253
  18136. minLength: 1
  18137. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18138. type: string
  18139. namespace:
  18140. description: |-
  18141. The namespace of the Secret resource being referred to.
  18142. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18143. maxLength: 63
  18144. minLength: 1
  18145. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18146. type: string
  18147. type: object
  18148. required:
  18149. - appId
  18150. - appSecret
  18151. type: object
  18152. required:
  18153. - secretRef
  18154. type: object
  18155. insecure:
  18156. description: |-
  18157. Insecure allows connecting to DVLS over plain HTTP.
  18158. This is NOT RECOMMENDED for production use.
  18159. Set to true only if you understand the security implications.
  18160. type: boolean
  18161. serverUrl:
  18162. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  18163. type: string
  18164. vault:
  18165. description: |-
  18166. Vault is the name or UUID of the vault to fetch secrets from.
  18167. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  18168. type: string
  18169. required:
  18170. - auth
  18171. - serverUrl
  18172. type: object
  18173. fake:
  18174. description: Fake configures a store with static key/value pairs
  18175. properties:
  18176. data:
  18177. items:
  18178. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  18179. properties:
  18180. key:
  18181. type: string
  18182. value:
  18183. type: string
  18184. version:
  18185. type: string
  18186. required:
  18187. - key
  18188. - value
  18189. type: object
  18190. type: array
  18191. validationResult:
  18192. description: ValidationResult is defined type for the number of validation results.
  18193. type: integer
  18194. required:
  18195. - data
  18196. type: object
  18197. fortanix:
  18198. description: Fortanix configures this store to sync secrets using the Fortanix provider
  18199. properties:
  18200. apiKey:
  18201. description: APIKey is the API token to access SDKMS Applications.
  18202. properties:
  18203. secretRef:
  18204. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  18205. properties:
  18206. key:
  18207. description: |-
  18208. A key in the referenced Secret.
  18209. Some instances of this field may be defaulted, in others it may be required.
  18210. maxLength: 253
  18211. minLength: 1
  18212. pattern: ^[-._a-zA-Z0-9]+$
  18213. type: string
  18214. name:
  18215. description: The name of the Secret resource being referred to.
  18216. maxLength: 253
  18217. minLength: 1
  18218. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18219. type: string
  18220. namespace:
  18221. description: |-
  18222. The namespace of the Secret resource being referred to.
  18223. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18224. maxLength: 63
  18225. minLength: 1
  18226. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18227. type: string
  18228. type: object
  18229. type: object
  18230. apiUrl:
  18231. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  18232. type: string
  18233. type: object
  18234. gcpsm:
  18235. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  18236. properties:
  18237. auth:
  18238. description: Auth defines the information necessary to authenticate against GCP
  18239. properties:
  18240. secretRef:
  18241. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  18242. properties:
  18243. secretAccessKeySecretRef:
  18244. description: The SecretAccessKey is used for authentication
  18245. properties:
  18246. key:
  18247. description: |-
  18248. A key in the referenced Secret.
  18249. Some instances of this field may be defaulted, in others it may be required.
  18250. maxLength: 253
  18251. minLength: 1
  18252. pattern: ^[-._a-zA-Z0-9]+$
  18253. type: string
  18254. name:
  18255. description: The name of the Secret resource being referred to.
  18256. maxLength: 253
  18257. minLength: 1
  18258. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18259. type: string
  18260. namespace:
  18261. description: |-
  18262. The namespace of the Secret resource being referred to.
  18263. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18264. maxLength: 63
  18265. minLength: 1
  18266. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18267. type: string
  18268. type: object
  18269. type: object
  18270. workloadIdentity:
  18271. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  18272. properties:
  18273. clusterLocation:
  18274. description: |-
  18275. ClusterLocation is the location of the cluster
  18276. If not specified, it fetches information from the metadata server
  18277. type: string
  18278. clusterName:
  18279. description: |-
  18280. ClusterName is the name of the cluster
  18281. If not specified, it fetches information from the metadata server
  18282. type: string
  18283. clusterProjectID:
  18284. description: |-
  18285. ClusterProjectID is the project ID of the cluster
  18286. If not specified, it fetches information from the metadata server
  18287. type: string
  18288. serviceAccountRef:
  18289. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  18290. properties:
  18291. audiences:
  18292. description: |-
  18293. Audience specifies the `aud` claim for the service account token
  18294. Some providers automatically extend the audience field based on well-known annotations for workload
  18295. identity (e.g. IRSA or GCP Workload Identity)
  18296. items:
  18297. type: string
  18298. type: array
  18299. name:
  18300. description: The name of the ServiceAccount resource being referred to.
  18301. maxLength: 253
  18302. minLength: 1
  18303. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18304. type: string
  18305. namespace:
  18306. description: |-
  18307. Namespace of the resource being referred to.
  18308. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18309. maxLength: 63
  18310. minLength: 1
  18311. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18312. type: string
  18313. required:
  18314. - name
  18315. type: object
  18316. required:
  18317. - serviceAccountRef
  18318. type: object
  18319. workloadIdentityFederation:
  18320. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  18321. properties:
  18322. audience:
  18323. description: |-
  18324. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  18325. If specified, Audience found in the external account credential config will be overridden with the configured value.
  18326. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  18327. type: string
  18328. awsSecurityCredentials:
  18329. description: |-
  18330. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  18331. when using the AWS metadata server is not an option.
  18332. properties:
  18333. awsCredentialsSecretRef:
  18334. description: |-
  18335. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  18336. Secret should be created with below names for keys
  18337. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  18338. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  18339. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  18340. properties:
  18341. name:
  18342. description: name of the secret.
  18343. maxLength: 253
  18344. minLength: 1
  18345. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18346. type: string
  18347. namespace:
  18348. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  18349. maxLength: 63
  18350. minLength: 1
  18351. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18352. type: string
  18353. required:
  18354. - name
  18355. type: object
  18356. region:
  18357. description: region is for configuring the AWS region to be used.
  18358. example: ap-south-1
  18359. maxLength: 50
  18360. minLength: 1
  18361. pattern: ^[a-z0-9-]+$
  18362. type: string
  18363. required:
  18364. - awsCredentialsSecretRef
  18365. - region
  18366. type: object
  18367. credConfig:
  18368. description: |-
  18369. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  18370. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  18371. serviceAccountRef must be used by providing operators service account details.
  18372. properties:
  18373. key:
  18374. description: key name holding the external account credential config.
  18375. maxLength: 253
  18376. minLength: 1
  18377. pattern: ^[-._a-zA-Z0-9]+$
  18378. type: string
  18379. name:
  18380. description: name of the configmap.
  18381. maxLength: 253
  18382. minLength: 1
  18383. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18384. type: string
  18385. namespace:
  18386. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  18387. maxLength: 63
  18388. minLength: 1
  18389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18390. type: string
  18391. required:
  18392. - key
  18393. - name
  18394. type: object
  18395. externalTokenEndpoint:
  18396. description: |-
  18397. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  18398. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  18399. URL is having the expected value.
  18400. type: string
  18401. gcpServiceAccountEmail:
  18402. description: |-
  18403. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  18404. after Workload Identity Federation. Use this to grant access through the service account's
  18405. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  18406. service_account_impersonation_url in the external account JSON from credConfig;
  18407. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  18408. on that ServiceAccount.
  18409. example: my-gsa@my-project.iam.gserviceaccount.com
  18410. minLength: 1
  18411. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  18412. type: string
  18413. serviceAccountRef:
  18414. description: |-
  18415. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  18416. when Kubernetes is configured as provider in workload identity pool.
  18417. properties:
  18418. audiences:
  18419. description: |-
  18420. Audience specifies the `aud` claim for the service account token
  18421. Some providers automatically extend the audience field based on well-known annotations for workload
  18422. identity (e.g. IRSA or GCP Workload Identity)
  18423. items:
  18424. type: string
  18425. type: array
  18426. name:
  18427. description: The name of the ServiceAccount resource being referred to.
  18428. maxLength: 253
  18429. minLength: 1
  18430. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18431. type: string
  18432. namespace:
  18433. description: |-
  18434. Namespace of the resource being referred to.
  18435. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18436. maxLength: 63
  18437. minLength: 1
  18438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18439. type: string
  18440. required:
  18441. - name
  18442. type: object
  18443. type: object
  18444. type: object
  18445. location:
  18446. description: Location optionally defines a location for a secret
  18447. type: string
  18448. projectID:
  18449. description: ProjectID project where secret is located
  18450. type: string
  18451. secretVersionSelectionPolicy:
  18452. default: LatestOrFail
  18453. description: |-
  18454. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  18455. when "latest" is disabled or destroyed.
  18456. Possible values are:
  18457. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  18458. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  18459. type: string
  18460. type: object
  18461. github:
  18462. description: |-
  18463. Github configures this store to push GitHub Actions or Dependabot secrets using the GitHub API provider.
  18464. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  18465. properties:
  18466. appID:
  18467. description: appID specifies the Github APP that will be used to authenticate the client
  18468. format: int64
  18469. type: integer
  18470. auth:
  18471. description: auth configures how secret-manager authenticates with a Github instance.
  18472. properties:
  18473. privateKey:
  18474. description: |-
  18475. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18476. In some instances, `key` is a required field.
  18477. properties:
  18478. key:
  18479. description: |-
  18480. A key in the referenced Secret.
  18481. Some instances of this field may be defaulted, in others it may be required.
  18482. maxLength: 253
  18483. minLength: 1
  18484. pattern: ^[-._a-zA-Z0-9]+$
  18485. type: string
  18486. name:
  18487. description: The name of the Secret resource being referred to.
  18488. maxLength: 253
  18489. minLength: 1
  18490. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18491. type: string
  18492. namespace:
  18493. description: |-
  18494. The namespace of the Secret resource being referred to.
  18495. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18496. maxLength: 63
  18497. minLength: 1
  18498. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18499. type: string
  18500. type: object
  18501. required:
  18502. - privateKey
  18503. type: object
  18504. environment:
  18505. description: environment will be used to fetch secrets from a particular environment within a github repository
  18506. type: string
  18507. installationID:
  18508. description: installationID specifies the Github APP installation that will be used to authenticate the client
  18509. format: int64
  18510. type: integer
  18511. orgSecretVisibility:
  18512. description: |-
  18513. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  18514. Valid values are "all" or "private".
  18515. When unset, new secrets are created with visibility "all" and existing secrets preserve
  18516. whatever visibility they already have in GitHub.
  18517. enum:
  18518. - all
  18519. - private
  18520. type: string
  18521. organization:
  18522. description: organization will be used to fetch secrets from the Github organization
  18523. type: string
  18524. repository:
  18525. description: repository will be used to fetch secrets from the Github repository within an organization
  18526. type: string
  18527. secretType:
  18528. default: Actions
  18529. description: |-
  18530. secretType specifies which GitHub secret service to use.
  18531. Defaults to Actions for backwards compatibility.
  18532. enum:
  18533. - Actions
  18534. - Dependabot
  18535. type: string
  18536. uploadURL:
  18537. description: Upload URL for enterprise instances. Default to URL.
  18538. type: string
  18539. url:
  18540. default: https://github.com/
  18541. description: URL configures the Github instance URL. Defaults to https://github.com/.
  18542. type: string
  18543. required:
  18544. - appID
  18545. - auth
  18546. - installationID
  18547. - organization
  18548. type: object
  18549. x-kubernetes-validations:
  18550. - message: Dependabot secrets do not support environments
  18551. rule: self.secretType != 'Dependabot' || !has(self.environment) || size(self.environment) == 0
  18552. gitlab:
  18553. description: GitLab configures this store to sync secrets using GitLab Variables provider
  18554. properties:
  18555. auth:
  18556. description: Auth configures how secret-manager authenticates with a GitLab instance.
  18557. properties:
  18558. SecretRef:
  18559. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  18560. properties:
  18561. accessToken:
  18562. description: AccessToken is used for authentication.
  18563. properties:
  18564. key:
  18565. description: |-
  18566. A key in the referenced Secret.
  18567. Some instances of this field may be defaulted, in others it may be required.
  18568. maxLength: 253
  18569. minLength: 1
  18570. pattern: ^[-._a-zA-Z0-9]+$
  18571. type: string
  18572. name:
  18573. description: The name of the Secret resource being referred to.
  18574. maxLength: 253
  18575. minLength: 1
  18576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18577. type: string
  18578. namespace:
  18579. description: |-
  18580. The namespace of the Secret resource being referred to.
  18581. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18582. maxLength: 63
  18583. minLength: 1
  18584. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18585. type: string
  18586. type: object
  18587. type: object
  18588. required:
  18589. - SecretRef
  18590. type: object
  18591. caBundle:
  18592. description: |-
  18593. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  18594. can be performed.
  18595. format: byte
  18596. type: string
  18597. caProvider:
  18598. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  18599. properties:
  18600. key:
  18601. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  18602. maxLength: 253
  18603. minLength: 1
  18604. pattern: ^[-._a-zA-Z0-9]+$
  18605. type: string
  18606. name:
  18607. description: The name of the object located at the provider type.
  18608. maxLength: 253
  18609. minLength: 1
  18610. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18611. type: string
  18612. namespace:
  18613. description: |-
  18614. The namespace the Provider type is in.
  18615. Can only be defined when used in a ClusterSecretStore.
  18616. maxLength: 63
  18617. minLength: 1
  18618. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18619. type: string
  18620. type:
  18621. description: The type of provider to use such as "Secret", or "ConfigMap".
  18622. enum:
  18623. - Secret
  18624. - ConfigMap
  18625. type: string
  18626. required:
  18627. - name
  18628. - type
  18629. type: object
  18630. environment:
  18631. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  18632. type: string
  18633. groupIDs:
  18634. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  18635. items:
  18636. type: string
  18637. type: array
  18638. inheritFromGroups:
  18639. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  18640. type: boolean
  18641. projectID:
  18642. description: ProjectID specifies a project where secrets are located.
  18643. type: string
  18644. url:
  18645. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  18646. type: string
  18647. required:
  18648. - auth
  18649. type: object
  18650. ibm:
  18651. description: IBM configures this store to sync secrets using IBM Cloud provider
  18652. properties:
  18653. auth:
  18654. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  18655. maxProperties: 1
  18656. minProperties: 1
  18657. properties:
  18658. containerAuth:
  18659. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  18660. properties:
  18661. iamEndpoint:
  18662. type: string
  18663. profile:
  18664. description: the IBM Trusted Profile
  18665. type: string
  18666. tokenLocation:
  18667. description: Location the token is mounted on the pod
  18668. type: string
  18669. required:
  18670. - profile
  18671. type: object
  18672. secretRef:
  18673. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  18674. properties:
  18675. iamEndpoint:
  18676. description: The IAM endpoint used to obain a token
  18677. type: string
  18678. secretApiKeySecretRef:
  18679. description: The SecretAccessKey is used for authentication
  18680. properties:
  18681. key:
  18682. description: |-
  18683. A key in the referenced Secret.
  18684. Some instances of this field may be defaulted, in others it may be required.
  18685. maxLength: 253
  18686. minLength: 1
  18687. pattern: ^[-._a-zA-Z0-9]+$
  18688. type: string
  18689. name:
  18690. description: The name of the Secret resource being referred to.
  18691. maxLength: 253
  18692. minLength: 1
  18693. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18694. type: string
  18695. namespace:
  18696. description: |-
  18697. The namespace of the Secret resource being referred to.
  18698. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18699. maxLength: 63
  18700. minLength: 1
  18701. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18702. type: string
  18703. type: object
  18704. type: object
  18705. type: object
  18706. serviceUrl:
  18707. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  18708. type: string
  18709. required:
  18710. - auth
  18711. type: object
  18712. infisical:
  18713. description: Infisical configures this store to sync secrets using the Infisical provider
  18714. properties:
  18715. auth:
  18716. description: Auth configures how the Operator authenticates with the Infisical API
  18717. properties:
  18718. awsAuthCredentials:
  18719. description: AwsAuthCredentials represents the credentials for AWS authentication.
  18720. properties:
  18721. identityId:
  18722. description: |-
  18723. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18724. In some instances, `key` is a required field.
  18725. properties:
  18726. key:
  18727. description: |-
  18728. A key in the referenced Secret.
  18729. Some instances of this field may be defaulted, in others it may be required.
  18730. maxLength: 253
  18731. minLength: 1
  18732. pattern: ^[-._a-zA-Z0-9]+$
  18733. type: string
  18734. name:
  18735. description: The name of the Secret resource being referred to.
  18736. maxLength: 253
  18737. minLength: 1
  18738. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18739. type: string
  18740. namespace:
  18741. description: |-
  18742. The namespace of the Secret resource being referred to.
  18743. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18744. maxLength: 63
  18745. minLength: 1
  18746. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18747. type: string
  18748. type: object
  18749. required:
  18750. - identityId
  18751. type: object
  18752. azureAuthCredentials:
  18753. description: AzureAuthCredentials represents the credentials for Azure authentication.
  18754. properties:
  18755. identityId:
  18756. description: |-
  18757. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18758. In some instances, `key` is a required field.
  18759. properties:
  18760. key:
  18761. description: |-
  18762. A key in the referenced Secret.
  18763. Some instances of this field may be defaulted, in others it may be required.
  18764. maxLength: 253
  18765. minLength: 1
  18766. pattern: ^[-._a-zA-Z0-9]+$
  18767. type: string
  18768. name:
  18769. description: The name of the Secret resource being referred to.
  18770. maxLength: 253
  18771. minLength: 1
  18772. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18773. type: string
  18774. namespace:
  18775. description: |-
  18776. The namespace of the Secret resource being referred to.
  18777. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18778. maxLength: 63
  18779. minLength: 1
  18780. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18781. type: string
  18782. type: object
  18783. resource:
  18784. description: |-
  18785. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18786. In some instances, `key` is a required field.
  18787. properties:
  18788. key:
  18789. description: |-
  18790. A key in the referenced Secret.
  18791. Some instances of this field may be defaulted, in others it may be required.
  18792. maxLength: 253
  18793. minLength: 1
  18794. pattern: ^[-._a-zA-Z0-9]+$
  18795. type: string
  18796. name:
  18797. description: The name of the Secret resource being referred to.
  18798. maxLength: 253
  18799. minLength: 1
  18800. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18801. type: string
  18802. namespace:
  18803. description: |-
  18804. The namespace of the Secret resource being referred to.
  18805. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18806. maxLength: 63
  18807. minLength: 1
  18808. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18809. type: string
  18810. type: object
  18811. required:
  18812. - identityId
  18813. type: object
  18814. gcpIamAuthCredentials:
  18815. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  18816. properties:
  18817. identityId:
  18818. description: |-
  18819. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18820. In some instances, `key` is a required field.
  18821. properties:
  18822. key:
  18823. description: |-
  18824. A key in the referenced Secret.
  18825. Some instances of this field may be defaulted, in others it may be required.
  18826. maxLength: 253
  18827. minLength: 1
  18828. pattern: ^[-._a-zA-Z0-9]+$
  18829. type: string
  18830. name:
  18831. description: The name of the Secret resource being referred to.
  18832. maxLength: 253
  18833. minLength: 1
  18834. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18835. type: string
  18836. namespace:
  18837. description: |-
  18838. The namespace of the Secret resource being referred to.
  18839. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18840. maxLength: 63
  18841. minLength: 1
  18842. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18843. type: string
  18844. type: object
  18845. serviceAccountKeyFilePath:
  18846. description: |-
  18847. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18848. In some instances, `key` is a required field.
  18849. properties:
  18850. key:
  18851. description: |-
  18852. A key in the referenced Secret.
  18853. Some instances of this field may be defaulted, in others it may be required.
  18854. maxLength: 253
  18855. minLength: 1
  18856. pattern: ^[-._a-zA-Z0-9]+$
  18857. type: string
  18858. name:
  18859. description: The name of the Secret resource being referred to.
  18860. maxLength: 253
  18861. minLength: 1
  18862. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18863. type: string
  18864. namespace:
  18865. description: |-
  18866. The namespace of the Secret resource being referred to.
  18867. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18868. maxLength: 63
  18869. minLength: 1
  18870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18871. type: string
  18872. type: object
  18873. required:
  18874. - identityId
  18875. - serviceAccountKeyFilePath
  18876. type: object
  18877. gcpIdTokenAuthCredentials:
  18878. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  18879. properties:
  18880. identityId:
  18881. description: |-
  18882. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18883. In some instances, `key` is a required field.
  18884. properties:
  18885. key:
  18886. description: |-
  18887. A key in the referenced Secret.
  18888. Some instances of this field may be defaulted, in others it may be required.
  18889. maxLength: 253
  18890. minLength: 1
  18891. pattern: ^[-._a-zA-Z0-9]+$
  18892. type: string
  18893. name:
  18894. description: The name of the Secret resource being referred to.
  18895. maxLength: 253
  18896. minLength: 1
  18897. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18898. type: string
  18899. namespace:
  18900. description: |-
  18901. The namespace of the Secret resource being referred to.
  18902. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18903. maxLength: 63
  18904. minLength: 1
  18905. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18906. type: string
  18907. type: object
  18908. required:
  18909. - identityId
  18910. type: object
  18911. jwtAuthCredentials:
  18912. description: JwtAuthCredentials represents the credentials for JWT authentication.
  18913. properties:
  18914. identityId:
  18915. description: |-
  18916. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18917. In some instances, `key` is a required field.
  18918. properties:
  18919. key:
  18920. description: |-
  18921. A key in the referenced Secret.
  18922. Some instances of this field may be defaulted, in others it may be required.
  18923. maxLength: 253
  18924. minLength: 1
  18925. pattern: ^[-._a-zA-Z0-9]+$
  18926. type: string
  18927. name:
  18928. description: The name of the Secret resource being referred to.
  18929. maxLength: 253
  18930. minLength: 1
  18931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18932. type: string
  18933. namespace:
  18934. description: |-
  18935. The namespace of the Secret resource being referred to.
  18936. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18937. maxLength: 63
  18938. minLength: 1
  18939. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18940. type: string
  18941. type: object
  18942. jwt:
  18943. description: |-
  18944. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18945. In some instances, `key` is a required field.
  18946. properties:
  18947. key:
  18948. description: |-
  18949. A key in the referenced Secret.
  18950. Some instances of this field may be defaulted, in others it may be required.
  18951. maxLength: 253
  18952. minLength: 1
  18953. pattern: ^[-._a-zA-Z0-9]+$
  18954. type: string
  18955. name:
  18956. description: The name of the Secret resource being referred to.
  18957. maxLength: 253
  18958. minLength: 1
  18959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18960. type: string
  18961. namespace:
  18962. description: |-
  18963. The namespace of the Secret resource being referred to.
  18964. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18965. maxLength: 63
  18966. minLength: 1
  18967. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18968. type: string
  18969. type: object
  18970. required:
  18971. - identityId
  18972. - jwt
  18973. type: object
  18974. kubernetesAuthCredentials:
  18975. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  18976. properties:
  18977. identityId:
  18978. description: |-
  18979. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18980. In some instances, `key` is a required field.
  18981. properties:
  18982. key:
  18983. description: |-
  18984. A key in the referenced Secret.
  18985. Some instances of this field may be defaulted, in others it may be required.
  18986. maxLength: 253
  18987. minLength: 1
  18988. pattern: ^[-._a-zA-Z0-9]+$
  18989. type: string
  18990. name:
  18991. description: The name of the Secret resource being referred to.
  18992. maxLength: 253
  18993. minLength: 1
  18994. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18995. type: string
  18996. namespace:
  18997. description: |-
  18998. The namespace of the Secret resource being referred to.
  18999. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19000. maxLength: 63
  19001. minLength: 1
  19002. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19003. type: string
  19004. type: object
  19005. serviceAccountTokenPath:
  19006. description: |-
  19007. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19008. In some instances, `key` is a required field.
  19009. properties:
  19010. key:
  19011. description: |-
  19012. A key in the referenced Secret.
  19013. Some instances of this field may be defaulted, in others it may be required.
  19014. maxLength: 253
  19015. minLength: 1
  19016. pattern: ^[-._a-zA-Z0-9]+$
  19017. type: string
  19018. name:
  19019. description: The name of the Secret resource being referred to.
  19020. maxLength: 253
  19021. minLength: 1
  19022. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19023. type: string
  19024. namespace:
  19025. description: |-
  19026. The namespace of the Secret resource being referred to.
  19027. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19028. maxLength: 63
  19029. minLength: 1
  19030. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19031. type: string
  19032. type: object
  19033. required:
  19034. - identityId
  19035. type: object
  19036. ldapAuthCredentials:
  19037. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  19038. properties:
  19039. identityId:
  19040. description: |-
  19041. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19042. In some instances, `key` is a required field.
  19043. properties:
  19044. key:
  19045. description: |-
  19046. A key in the referenced Secret.
  19047. Some instances of this field may be defaulted, in others it may be required.
  19048. maxLength: 253
  19049. minLength: 1
  19050. pattern: ^[-._a-zA-Z0-9]+$
  19051. type: string
  19052. name:
  19053. description: The name of the Secret resource being referred to.
  19054. maxLength: 253
  19055. minLength: 1
  19056. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19057. type: string
  19058. namespace:
  19059. description: |-
  19060. The namespace of the Secret resource being referred to.
  19061. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19062. maxLength: 63
  19063. minLength: 1
  19064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19065. type: string
  19066. type: object
  19067. ldapPassword:
  19068. description: |-
  19069. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19070. In some instances, `key` is a required field.
  19071. properties:
  19072. key:
  19073. description: |-
  19074. A key in the referenced Secret.
  19075. Some instances of this field may be defaulted, in others it may be required.
  19076. maxLength: 253
  19077. minLength: 1
  19078. pattern: ^[-._a-zA-Z0-9]+$
  19079. type: string
  19080. name:
  19081. description: The name of the Secret resource being referred to.
  19082. maxLength: 253
  19083. minLength: 1
  19084. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19085. type: string
  19086. namespace:
  19087. description: |-
  19088. The namespace of the Secret resource being referred to.
  19089. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19090. maxLength: 63
  19091. minLength: 1
  19092. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19093. type: string
  19094. type: object
  19095. ldapUsername:
  19096. description: |-
  19097. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19098. In some instances, `key` is a required field.
  19099. properties:
  19100. key:
  19101. description: |-
  19102. A key in the referenced Secret.
  19103. Some instances of this field may be defaulted, in others it may be required.
  19104. maxLength: 253
  19105. minLength: 1
  19106. pattern: ^[-._a-zA-Z0-9]+$
  19107. type: string
  19108. name:
  19109. description: The name of the Secret resource being referred to.
  19110. maxLength: 253
  19111. minLength: 1
  19112. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19113. type: string
  19114. namespace:
  19115. description: |-
  19116. The namespace of the Secret resource being referred to.
  19117. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19118. maxLength: 63
  19119. minLength: 1
  19120. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19121. type: string
  19122. type: object
  19123. required:
  19124. - identityId
  19125. - ldapPassword
  19126. - ldapUsername
  19127. type: object
  19128. ociAuthCredentials:
  19129. description: OciAuthCredentials represents the credentials for OCI authentication.
  19130. properties:
  19131. fingerprint:
  19132. description: |-
  19133. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19134. In some instances, `key` is a required field.
  19135. properties:
  19136. key:
  19137. description: |-
  19138. A key in the referenced Secret.
  19139. Some instances of this field may be defaulted, in others it may be required.
  19140. maxLength: 253
  19141. minLength: 1
  19142. pattern: ^[-._a-zA-Z0-9]+$
  19143. type: string
  19144. name:
  19145. description: The name of the Secret resource being referred to.
  19146. maxLength: 253
  19147. minLength: 1
  19148. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19149. type: string
  19150. namespace:
  19151. description: |-
  19152. The namespace of the Secret resource being referred to.
  19153. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19154. maxLength: 63
  19155. minLength: 1
  19156. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19157. type: string
  19158. type: object
  19159. identityId:
  19160. description: |-
  19161. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19162. In some instances, `key` is a required field.
  19163. properties:
  19164. key:
  19165. description: |-
  19166. A key in the referenced Secret.
  19167. Some instances of this field may be defaulted, in others it may be required.
  19168. maxLength: 253
  19169. minLength: 1
  19170. pattern: ^[-._a-zA-Z0-9]+$
  19171. type: string
  19172. name:
  19173. description: The name of the Secret resource being referred to.
  19174. maxLength: 253
  19175. minLength: 1
  19176. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19177. type: string
  19178. namespace:
  19179. description: |-
  19180. The namespace of the Secret resource being referred to.
  19181. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19182. maxLength: 63
  19183. minLength: 1
  19184. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19185. type: string
  19186. type: object
  19187. privateKey:
  19188. description: |-
  19189. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19190. In some instances, `key` is a required field.
  19191. properties:
  19192. key:
  19193. description: |-
  19194. A key in the referenced Secret.
  19195. Some instances of this field may be defaulted, in others it may be required.
  19196. maxLength: 253
  19197. minLength: 1
  19198. pattern: ^[-._a-zA-Z0-9]+$
  19199. type: string
  19200. name:
  19201. description: The name of the Secret resource being referred to.
  19202. maxLength: 253
  19203. minLength: 1
  19204. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19205. type: string
  19206. namespace:
  19207. description: |-
  19208. The namespace of the Secret resource being referred to.
  19209. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19210. maxLength: 63
  19211. minLength: 1
  19212. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19213. type: string
  19214. type: object
  19215. privateKeyPassphrase:
  19216. description: |-
  19217. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19218. In some instances, `key` is a required field.
  19219. properties:
  19220. key:
  19221. description: |-
  19222. A key in the referenced Secret.
  19223. Some instances of this field may be defaulted, in others it may be required.
  19224. maxLength: 253
  19225. minLength: 1
  19226. pattern: ^[-._a-zA-Z0-9]+$
  19227. type: string
  19228. name:
  19229. description: The name of the Secret resource being referred to.
  19230. maxLength: 253
  19231. minLength: 1
  19232. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19233. type: string
  19234. namespace:
  19235. description: |-
  19236. The namespace of the Secret resource being referred to.
  19237. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19238. maxLength: 63
  19239. minLength: 1
  19240. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19241. type: string
  19242. type: object
  19243. region:
  19244. description: |-
  19245. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19246. In some instances, `key` is a required field.
  19247. properties:
  19248. key:
  19249. description: |-
  19250. A key in the referenced Secret.
  19251. Some instances of this field may be defaulted, in others it may be required.
  19252. maxLength: 253
  19253. minLength: 1
  19254. pattern: ^[-._a-zA-Z0-9]+$
  19255. type: string
  19256. name:
  19257. description: The name of the Secret resource being referred to.
  19258. maxLength: 253
  19259. minLength: 1
  19260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19261. type: string
  19262. namespace:
  19263. description: |-
  19264. The namespace of the Secret resource being referred to.
  19265. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19266. maxLength: 63
  19267. minLength: 1
  19268. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19269. type: string
  19270. type: object
  19271. tenancyId:
  19272. description: |-
  19273. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19274. In some instances, `key` is a required field.
  19275. properties:
  19276. key:
  19277. description: |-
  19278. A key in the referenced Secret.
  19279. Some instances of this field may be defaulted, in others it may be required.
  19280. maxLength: 253
  19281. minLength: 1
  19282. pattern: ^[-._a-zA-Z0-9]+$
  19283. type: string
  19284. name:
  19285. description: The name of the Secret resource being referred to.
  19286. maxLength: 253
  19287. minLength: 1
  19288. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19289. type: string
  19290. namespace:
  19291. description: |-
  19292. The namespace of the Secret resource being referred to.
  19293. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19294. maxLength: 63
  19295. minLength: 1
  19296. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19297. type: string
  19298. type: object
  19299. userId:
  19300. description: |-
  19301. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19302. In some instances, `key` is a required field.
  19303. properties:
  19304. key:
  19305. description: |-
  19306. A key in the referenced Secret.
  19307. Some instances of this field may be defaulted, in others it may be required.
  19308. maxLength: 253
  19309. minLength: 1
  19310. pattern: ^[-._a-zA-Z0-9]+$
  19311. type: string
  19312. name:
  19313. description: The name of the Secret resource being referred to.
  19314. maxLength: 253
  19315. minLength: 1
  19316. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19317. type: string
  19318. namespace:
  19319. description: |-
  19320. The namespace of the Secret resource being referred to.
  19321. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19322. maxLength: 63
  19323. minLength: 1
  19324. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19325. type: string
  19326. type: object
  19327. required:
  19328. - fingerprint
  19329. - identityId
  19330. - privateKey
  19331. - region
  19332. - tenancyId
  19333. - userId
  19334. type: object
  19335. tokenAuthCredentials:
  19336. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  19337. properties:
  19338. accessToken:
  19339. description: |-
  19340. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19341. In some instances, `key` is a required field.
  19342. properties:
  19343. key:
  19344. description: |-
  19345. A key in the referenced Secret.
  19346. Some instances of this field may be defaulted, in others it may be required.
  19347. maxLength: 253
  19348. minLength: 1
  19349. pattern: ^[-._a-zA-Z0-9]+$
  19350. type: string
  19351. name:
  19352. description: The name of the Secret resource being referred to.
  19353. maxLength: 253
  19354. minLength: 1
  19355. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19356. type: string
  19357. namespace:
  19358. description: |-
  19359. The namespace of the Secret resource being referred to.
  19360. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19361. maxLength: 63
  19362. minLength: 1
  19363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19364. type: string
  19365. type: object
  19366. required:
  19367. - accessToken
  19368. type: object
  19369. universalAuthCredentials:
  19370. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  19371. properties:
  19372. clientId:
  19373. description: |-
  19374. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19375. In some instances, `key` is a required field.
  19376. properties:
  19377. key:
  19378. description: |-
  19379. A key in the referenced Secret.
  19380. Some instances of this field may be defaulted, in others it may be required.
  19381. maxLength: 253
  19382. minLength: 1
  19383. pattern: ^[-._a-zA-Z0-9]+$
  19384. type: string
  19385. name:
  19386. description: The name of the Secret resource being referred to.
  19387. maxLength: 253
  19388. minLength: 1
  19389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19390. type: string
  19391. namespace:
  19392. description: |-
  19393. The namespace of the Secret resource being referred to.
  19394. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19395. maxLength: 63
  19396. minLength: 1
  19397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19398. type: string
  19399. type: object
  19400. clientSecret:
  19401. description: |-
  19402. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19403. In some instances, `key` is a required field.
  19404. properties:
  19405. key:
  19406. description: |-
  19407. A key in the referenced Secret.
  19408. Some instances of this field may be defaulted, in others it may be required.
  19409. maxLength: 253
  19410. minLength: 1
  19411. pattern: ^[-._a-zA-Z0-9]+$
  19412. type: string
  19413. name:
  19414. description: The name of the Secret resource being referred to.
  19415. maxLength: 253
  19416. minLength: 1
  19417. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19418. type: string
  19419. namespace:
  19420. description: |-
  19421. The namespace of the Secret resource being referred to.
  19422. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19423. maxLength: 63
  19424. minLength: 1
  19425. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19426. type: string
  19427. type: object
  19428. required:
  19429. - clientId
  19430. - clientSecret
  19431. type: object
  19432. type: object
  19433. caBundle:
  19434. description: |-
  19435. CABundle is a PEM-encoded CA certificate bundle used to validate
  19436. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  19437. format: byte
  19438. type: string
  19439. caProvider:
  19440. description: |-
  19441. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  19442. The certificate is used to validate the Infisical server's TLS certificate.
  19443. Mutually exclusive with CABundle.
  19444. properties:
  19445. key:
  19446. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19447. maxLength: 253
  19448. minLength: 1
  19449. pattern: ^[-._a-zA-Z0-9]+$
  19450. type: string
  19451. name:
  19452. description: The name of the object located at the provider type.
  19453. maxLength: 253
  19454. minLength: 1
  19455. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19456. type: string
  19457. namespace:
  19458. description: |-
  19459. The namespace the Provider type is in.
  19460. Can only be defined when used in a ClusterSecretStore.
  19461. maxLength: 63
  19462. minLength: 1
  19463. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19464. type: string
  19465. type:
  19466. description: The type of provider to use such as "Secret", or "ConfigMap".
  19467. enum:
  19468. - Secret
  19469. - ConfigMap
  19470. type: string
  19471. required:
  19472. - name
  19473. - type
  19474. type: object
  19475. hostAPI:
  19476. default: https://app.infisical.com/api
  19477. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  19478. type: string
  19479. secretsScope:
  19480. description: SecretsScope defines the scope of the secrets within the workspace
  19481. properties:
  19482. environmentSlug:
  19483. description: EnvironmentSlug is the required slug identifier for the environment.
  19484. type: string
  19485. expandSecretReferences:
  19486. default: true
  19487. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  19488. type: boolean
  19489. includeSecretPath:
  19490. default: false
  19491. description: |-
  19492. IncludeSecretPath indicates whether the secret path should be included as a prefix
  19493. in the secret key. Secrets at the root path (/) are not prefixed.
  19494. type: boolean
  19495. organizationSlug:
  19496. description: |-
  19497. OrganizationSlug is the optional slug that identifies the organization that will be used
  19498. during authentication. Useful for sub-organization setups
  19499. type: string
  19500. projectSlug:
  19501. description: ProjectSlug is the required slug identifier for the project.
  19502. type: string
  19503. recursive:
  19504. default: false
  19505. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  19506. type: boolean
  19507. secretsPath:
  19508. default: /
  19509. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  19510. type: string
  19511. required:
  19512. - environmentSlug
  19513. - projectSlug
  19514. type: object
  19515. required:
  19516. - auth
  19517. - secretsScope
  19518. type: object
  19519. keepersecurity:
  19520. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  19521. properties:
  19522. authRef:
  19523. description: |-
  19524. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19525. In some instances, `key` is a required field.
  19526. properties:
  19527. key:
  19528. description: |-
  19529. A key in the referenced Secret.
  19530. Some instances of this field may be defaulted, in others it may be required.
  19531. maxLength: 253
  19532. minLength: 1
  19533. pattern: ^[-._a-zA-Z0-9]+$
  19534. type: string
  19535. name:
  19536. description: The name of the Secret resource being referred to.
  19537. maxLength: 253
  19538. minLength: 1
  19539. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19540. type: string
  19541. namespace:
  19542. description: |-
  19543. The namespace of the Secret resource being referred to.
  19544. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19545. maxLength: 63
  19546. minLength: 1
  19547. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19548. type: string
  19549. type: object
  19550. folderID:
  19551. type: string
  19552. getByTitleFallback:
  19553. type: boolean
  19554. required:
  19555. - authRef
  19556. type: object
  19557. kubernetes:
  19558. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  19559. properties:
  19560. auth:
  19561. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  19562. maxProperties: 1
  19563. minProperties: 1
  19564. properties:
  19565. cert:
  19566. description: has both clientCert and clientKey as secretKeySelector
  19567. properties:
  19568. clientCert:
  19569. description: |-
  19570. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19571. In some instances, `key` is a required field.
  19572. properties:
  19573. key:
  19574. description: |-
  19575. A key in the referenced Secret.
  19576. Some instances of this field may be defaulted, in others it may be required.
  19577. maxLength: 253
  19578. minLength: 1
  19579. pattern: ^[-._a-zA-Z0-9]+$
  19580. type: string
  19581. name:
  19582. description: The name of the Secret resource being referred to.
  19583. maxLength: 253
  19584. minLength: 1
  19585. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19586. type: string
  19587. namespace:
  19588. description: |-
  19589. The namespace of the Secret resource being referred to.
  19590. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19591. maxLength: 63
  19592. minLength: 1
  19593. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19594. type: string
  19595. type: object
  19596. clientKey:
  19597. description: |-
  19598. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19599. In some instances, `key` is a required field.
  19600. properties:
  19601. key:
  19602. description: |-
  19603. A key in the referenced Secret.
  19604. Some instances of this field may be defaulted, in others it may be required.
  19605. maxLength: 253
  19606. minLength: 1
  19607. pattern: ^[-._a-zA-Z0-9]+$
  19608. type: string
  19609. name:
  19610. description: The name of the Secret resource being referred to.
  19611. maxLength: 253
  19612. minLength: 1
  19613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19614. type: string
  19615. namespace:
  19616. description: |-
  19617. The namespace of the Secret resource being referred to.
  19618. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19619. maxLength: 63
  19620. minLength: 1
  19621. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19622. type: string
  19623. type: object
  19624. required:
  19625. - clientCert
  19626. - clientKey
  19627. type: object
  19628. serviceAccount:
  19629. description: points to a service account that should be used for authentication
  19630. properties:
  19631. audiences:
  19632. description: |-
  19633. Audience specifies the `aud` claim for the service account token
  19634. Some providers automatically extend the audience field based on well-known annotations for workload
  19635. identity (e.g. IRSA or GCP Workload Identity)
  19636. items:
  19637. type: string
  19638. type: array
  19639. name:
  19640. description: The name of the ServiceAccount resource being referred to.
  19641. maxLength: 253
  19642. minLength: 1
  19643. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19644. type: string
  19645. namespace:
  19646. description: |-
  19647. Namespace of the resource being referred to.
  19648. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19649. maxLength: 63
  19650. minLength: 1
  19651. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19652. type: string
  19653. required:
  19654. - name
  19655. type: object
  19656. token:
  19657. description: use static token to authenticate with
  19658. properties:
  19659. bearerToken:
  19660. description: |-
  19661. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19662. In some instances, `key` is a required field.
  19663. properties:
  19664. key:
  19665. description: |-
  19666. A key in the referenced Secret.
  19667. Some instances of this field may be defaulted, in others it may be required.
  19668. maxLength: 253
  19669. minLength: 1
  19670. pattern: ^[-._a-zA-Z0-9]+$
  19671. type: string
  19672. name:
  19673. description: The name of the Secret resource being referred to.
  19674. maxLength: 253
  19675. minLength: 1
  19676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19677. type: string
  19678. namespace:
  19679. description: |-
  19680. The namespace of the Secret resource being referred to.
  19681. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19682. maxLength: 63
  19683. minLength: 1
  19684. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19685. type: string
  19686. type: object
  19687. required:
  19688. - bearerToken
  19689. type: object
  19690. type: object
  19691. authRef:
  19692. description: A reference to a secret that contains the auth information.
  19693. properties:
  19694. key:
  19695. description: |-
  19696. A key in the referenced Secret.
  19697. Some instances of this field may be defaulted, in others it may be required.
  19698. maxLength: 253
  19699. minLength: 1
  19700. pattern: ^[-._a-zA-Z0-9]+$
  19701. type: string
  19702. name:
  19703. description: The name of the Secret resource being referred to.
  19704. maxLength: 253
  19705. minLength: 1
  19706. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19707. type: string
  19708. namespace:
  19709. description: |-
  19710. The namespace of the Secret resource being referred to.
  19711. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19712. maxLength: 63
  19713. minLength: 1
  19714. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19715. type: string
  19716. type: object
  19717. remoteNamespace:
  19718. default: default
  19719. description: Remote namespace to fetch the secrets from
  19720. maxLength: 63
  19721. minLength: 1
  19722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19723. type: string
  19724. server:
  19725. description: configures the Kubernetes server Address.
  19726. properties:
  19727. caBundle:
  19728. description: CABundle is a base64-encoded CA certificate
  19729. format: byte
  19730. type: string
  19731. caProvider:
  19732. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  19733. properties:
  19734. key:
  19735. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19736. maxLength: 253
  19737. minLength: 1
  19738. pattern: ^[-._a-zA-Z0-9]+$
  19739. type: string
  19740. name:
  19741. description: The name of the object located at the provider type.
  19742. maxLength: 253
  19743. minLength: 1
  19744. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19745. type: string
  19746. namespace:
  19747. description: |-
  19748. The namespace the Provider type is in.
  19749. Can only be defined when used in a ClusterSecretStore.
  19750. maxLength: 63
  19751. minLength: 1
  19752. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19753. type: string
  19754. type:
  19755. description: The type of provider to use such as "Secret", or "ConfigMap".
  19756. enum:
  19757. - Secret
  19758. - ConfigMap
  19759. type: string
  19760. required:
  19761. - name
  19762. - type
  19763. type: object
  19764. url:
  19765. default: kubernetes.default
  19766. description: configures the Kubernetes server Address.
  19767. type: string
  19768. type: object
  19769. type: object
  19770. nebiusmysterybox:
  19771. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  19772. properties:
  19773. apiDomain:
  19774. description: NebiusMysterybox API endpoint
  19775. type: string
  19776. auth:
  19777. description: Auth defines parameters to authenticate in MysteryBox
  19778. properties:
  19779. serviceAccountCredsSecretRef:
  19780. description: |-
  19781. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  19782. document with service account credentials used to get an IAM token.
  19783. Expected JSON structure:
  19784. {
  19785. "subject-credentials": {
  19786. "alg": "RS256",
  19787. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  19788. "kid": "<public-key-id>",
  19789. "iss": "<issuer-service-account-id>",
  19790. "sub": "<subject-service-account-id>"
  19791. }
  19792. }
  19793. properties:
  19794. key:
  19795. description: |-
  19796. A key in the referenced Secret.
  19797. Some instances of this field may be defaulted, in others it may be required.
  19798. maxLength: 253
  19799. minLength: 1
  19800. pattern: ^[-._a-zA-Z0-9]+$
  19801. type: string
  19802. name:
  19803. description: The name of the Secret resource being referred to.
  19804. maxLength: 253
  19805. minLength: 1
  19806. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19807. type: string
  19808. namespace:
  19809. description: |-
  19810. The namespace of the Secret resource being referred to.
  19811. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19812. maxLength: 63
  19813. minLength: 1
  19814. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19815. type: string
  19816. type: object
  19817. tokenSecretRef:
  19818. description: Token authenticates with Nebius Mysterybox by presenting a token.
  19819. properties:
  19820. key:
  19821. description: |-
  19822. A key in the referenced Secret.
  19823. Some instances of this field may be defaulted, in others it may be required.
  19824. maxLength: 253
  19825. minLength: 1
  19826. pattern: ^[-._a-zA-Z0-9]+$
  19827. type: string
  19828. name:
  19829. description: The name of the Secret resource being referred to.
  19830. maxLength: 253
  19831. minLength: 1
  19832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19833. type: string
  19834. namespace:
  19835. description: |-
  19836. The namespace of the Secret resource being referred to.
  19837. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19838. maxLength: 63
  19839. minLength: 1
  19840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19841. type: string
  19842. type: object
  19843. workloadIdentity:
  19844. description: WorkloadIdentity defines configuration for workload identity authentication to Nebius IAM.
  19845. properties:
  19846. iamServiceAccountID:
  19847. description: |-
  19848. IAMServiceAccountID is the Nebius IAM service account identifier that the
  19849. federated Kubernetes service account should impersonate during token exchange.
  19850. example: serviceaccount-e00example
  19851. minLength: 1
  19852. pattern: ^serviceaccount-[a-z][a-z0-9]{2}
  19853. type: string
  19854. serviceAccountRef:
  19855. description: |-
  19856. ServiceAccountRef references a Kubernetes ServiceAccount used to request a
  19857. temporary JWT via the TokenRequest API. The JWT is then exchanged for a
  19858. Nebius IAM token using workload federation.
  19859. properties:
  19860. audiences:
  19861. description: |-
  19862. Audience specifies the `aud` claim for the service account token
  19863. Some providers automatically extend the audience field based on well-known annotations for workload
  19864. identity (e.g. IRSA or GCP Workload Identity)
  19865. items:
  19866. type: string
  19867. type: array
  19868. name:
  19869. description: The name of the ServiceAccount resource being referred to.
  19870. maxLength: 253
  19871. minLength: 1
  19872. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19873. type: string
  19874. namespace:
  19875. description: |-
  19876. Namespace of the resource being referred to.
  19877. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19878. maxLength: 63
  19879. minLength: 1
  19880. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19881. type: string
  19882. required:
  19883. - name
  19884. type: object
  19885. required:
  19886. - iamServiceAccountID
  19887. - serviceAccountRef
  19888. type: object
  19889. type: object
  19890. x-kubernetes-validations:
  19891. - message: exactly one of serviceAccountCredsSecretRef, tokenSecretRef, or workloadIdentity must be set
  19892. rule: '(has(self.serviceAccountCredsSecretRef) && has(self.serviceAccountCredsSecretRef.name) && size(self.serviceAccountCredsSecretRef.name) > 0 ? 1 : 0) + (has(self.tokenSecretRef) && has(self.tokenSecretRef.name) && size(self.tokenSecretRef.name) > 0 ? 1 : 0) + (has(self.workloadIdentity) ? 1 : 0) == 1'
  19893. caProvider:
  19894. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  19895. properties:
  19896. certSecretRef:
  19897. description: |-
  19898. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19899. In some instances, `key` is a required field.
  19900. properties:
  19901. key:
  19902. description: |-
  19903. A key in the referenced Secret.
  19904. Some instances of this field may be defaulted, in others it may be required.
  19905. maxLength: 253
  19906. minLength: 1
  19907. pattern: ^[-._a-zA-Z0-9]+$
  19908. type: string
  19909. name:
  19910. description: The name of the Secret resource being referred to.
  19911. maxLength: 253
  19912. minLength: 1
  19913. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19914. type: string
  19915. namespace:
  19916. description: |-
  19917. The namespace of the Secret resource being referred to.
  19918. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19919. maxLength: 63
  19920. minLength: 1
  19921. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19922. type: string
  19923. type: object
  19924. type: object
  19925. required:
  19926. - apiDomain
  19927. - auth
  19928. type: object
  19929. ngrok:
  19930. description: Ngrok configures this store to sync secrets using the ngrok provider.
  19931. properties:
  19932. apiUrl:
  19933. default: https://api.ngrok.com
  19934. description: APIURL is the URL of the ngrok API.
  19935. type: string
  19936. auth:
  19937. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  19938. maxProperties: 1
  19939. minProperties: 1
  19940. properties:
  19941. apiKey:
  19942. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  19943. properties:
  19944. secretRef:
  19945. description: SecretRef is a reference to a secret containing the ngrok API key.
  19946. properties:
  19947. key:
  19948. description: |-
  19949. A key in the referenced Secret.
  19950. Some instances of this field may be defaulted, in others it may be required.
  19951. maxLength: 253
  19952. minLength: 1
  19953. pattern: ^[-._a-zA-Z0-9]+$
  19954. type: string
  19955. name:
  19956. description: The name of the Secret resource being referred to.
  19957. maxLength: 253
  19958. minLength: 1
  19959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19960. type: string
  19961. namespace:
  19962. description: |-
  19963. The namespace of the Secret resource being referred to.
  19964. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19965. maxLength: 63
  19966. minLength: 1
  19967. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19968. type: string
  19969. type: object
  19970. type: object
  19971. type: object
  19972. vault:
  19973. description: Vault configures the ngrok vault to sync secrets with.
  19974. properties:
  19975. name:
  19976. description: Name is the name of the ngrok vault to sync secrets with.
  19977. type: string
  19978. required:
  19979. - name
  19980. type: object
  19981. required:
  19982. - auth
  19983. - vault
  19984. type: object
  19985. onboardbase:
  19986. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  19987. properties:
  19988. apiHost:
  19989. default: https://public.onboardbase.com/api/v1/
  19990. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  19991. type: string
  19992. auth:
  19993. description: Auth configures how the Operator authenticates with the Onboardbase API
  19994. properties:
  19995. apiKeyRef:
  19996. description: |-
  19997. OnboardbaseAPIKey is the APIKey generated by an admin account.
  19998. It is used to recognize and authorize access to a project and environment within onboardbase
  19999. properties:
  20000. key:
  20001. description: |-
  20002. A key in the referenced Secret.
  20003. Some instances of this field may be defaulted, in others it may be required.
  20004. maxLength: 253
  20005. minLength: 1
  20006. pattern: ^[-._a-zA-Z0-9]+$
  20007. type: string
  20008. name:
  20009. description: The name of the Secret resource being referred to.
  20010. maxLength: 253
  20011. minLength: 1
  20012. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20013. type: string
  20014. namespace:
  20015. description: |-
  20016. The namespace of the Secret resource being referred to.
  20017. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20018. maxLength: 63
  20019. minLength: 1
  20020. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20021. type: string
  20022. type: object
  20023. passcodeRef:
  20024. description: OnboardbasePasscode is the passcode attached to the API Key
  20025. properties:
  20026. key:
  20027. description: |-
  20028. A key in the referenced Secret.
  20029. Some instances of this field may be defaulted, in others it may be required.
  20030. maxLength: 253
  20031. minLength: 1
  20032. pattern: ^[-._a-zA-Z0-9]+$
  20033. type: string
  20034. name:
  20035. description: The name of the Secret resource being referred to.
  20036. maxLength: 253
  20037. minLength: 1
  20038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20039. type: string
  20040. namespace:
  20041. description: |-
  20042. The namespace of the Secret resource being referred to.
  20043. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20044. maxLength: 63
  20045. minLength: 1
  20046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20047. type: string
  20048. type: object
  20049. required:
  20050. - apiKeyRef
  20051. - passcodeRef
  20052. type: object
  20053. environment:
  20054. default: development
  20055. description: Environment is the name of an environmnent within a project to pull the secrets from
  20056. type: string
  20057. project:
  20058. default: development
  20059. description: Project is an onboardbase project that the secrets should be pulled from
  20060. type: string
  20061. required:
  20062. - apiHost
  20063. - auth
  20064. - environment
  20065. - project
  20066. type: object
  20067. onepassword:
  20068. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  20069. properties:
  20070. auth:
  20071. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  20072. properties:
  20073. secretRef:
  20074. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  20075. properties:
  20076. connectTokenSecretRef:
  20077. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  20078. properties:
  20079. key:
  20080. description: |-
  20081. A key in the referenced Secret.
  20082. Some instances of this field may be defaulted, in others it may be required.
  20083. maxLength: 253
  20084. minLength: 1
  20085. pattern: ^[-._a-zA-Z0-9]+$
  20086. type: string
  20087. name:
  20088. description: The name of the Secret resource being referred to.
  20089. maxLength: 253
  20090. minLength: 1
  20091. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20092. type: string
  20093. namespace:
  20094. description: |-
  20095. The namespace of the Secret resource being referred to.
  20096. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20097. maxLength: 63
  20098. minLength: 1
  20099. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20100. type: string
  20101. type: object
  20102. required:
  20103. - connectTokenSecretRef
  20104. type: object
  20105. required:
  20106. - secretRef
  20107. type: object
  20108. connectHost:
  20109. description: ConnectHost defines the OnePassword Connect Server to connect to
  20110. type: string
  20111. vaults:
  20112. additionalProperties:
  20113. type: integer
  20114. description: Vaults defines which OnePassword vaults to search in which order
  20115. type: object
  20116. required:
  20117. - auth
  20118. - connectHost
  20119. - vaults
  20120. type: object
  20121. onepasswordSDK:
  20122. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  20123. properties:
  20124. auth:
  20125. description: Auth defines the information necessary to authenticate against OnePassword API.
  20126. properties:
  20127. serviceAccountSecretRef:
  20128. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  20129. properties:
  20130. key:
  20131. description: |-
  20132. A key in the referenced Secret.
  20133. Some instances of this field may be defaulted, in others it may be required.
  20134. maxLength: 253
  20135. minLength: 1
  20136. pattern: ^[-._a-zA-Z0-9]+$
  20137. type: string
  20138. name:
  20139. description: The name of the Secret resource being referred to.
  20140. maxLength: 253
  20141. minLength: 1
  20142. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20143. type: string
  20144. namespace:
  20145. description: |-
  20146. The namespace of the Secret resource being referred to.
  20147. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20148. maxLength: 63
  20149. minLength: 1
  20150. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20151. type: string
  20152. type: object
  20153. required:
  20154. - serviceAccountSecretRef
  20155. type: object
  20156. cache:
  20157. description: |-
  20158. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  20159. When enabled, secrets are cached with the specified TTL.
  20160. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  20161. If omitted, caching is disabled (default).
  20162. cache: {} is a valid option to set.
  20163. properties:
  20164. maxSize:
  20165. default: 100
  20166. description: |-
  20167. MaxSize is the maximum number of secrets to cache.
  20168. When the cache is full, least-recently-used entries are evicted.
  20169. minimum: 1
  20170. type: integer
  20171. ttl:
  20172. default: 5m
  20173. description: |-
  20174. TTL is the time-to-live for cached secrets.
  20175. Format: duration string (e.g., "5m", "1h", "30s")
  20176. type: string
  20177. type: object
  20178. environment:
  20179. description: |-
  20180. Environment defines the 1Password Environment ID to read variables from.
  20181. Environments are read-only: PushSecret, DeleteSecret, and SecretExists return an error when set.
  20182. Mutually exclusive with Vault.
  20183. type: string
  20184. integrationInfo:
  20185. description: |-
  20186. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  20187. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  20188. properties:
  20189. name:
  20190. default: 1Password SDK
  20191. description: Name defaults to "1Password SDK".
  20192. type: string
  20193. version:
  20194. default: v1.0.0
  20195. description: Version defaults to "v1.0.0".
  20196. type: string
  20197. type: object
  20198. vault:
  20199. description: |-
  20200. Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  20201. Mutually exclusive with Environment.
  20202. type: string
  20203. required:
  20204. - auth
  20205. type: object
  20206. x-kubernetes-validations:
  20207. - message: at most one of the fields in [vault environment] may be set
  20208. rule: '[has(self.vault),has(self.environment)].filter(x,x==true).size() <= 1'
  20209. openBao:
  20210. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  20211. properties:
  20212. auth:
  20213. description: Auth configures how secret-manager authenticates with the OpenBao server.
  20214. properties:
  20215. appRole:
  20216. description: |-
  20217. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  20218. with the role and secret stored in a Kubernetes Secret resource.
  20219. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  20220. properties:
  20221. path:
  20222. default: approle
  20223. description: |-
  20224. Path where the App Role authentication backend is mounted
  20225. in OpenBao, e.g: "approle"
  20226. type: string
  20227. roleId:
  20228. description: |-
  20229. RoleID configured in the App Role authentication backend when setting
  20230. up the authentication backend in OpenBao.
  20231. minLength: 1
  20232. type: string
  20233. roleRef:
  20234. description: |-
  20235. Reference to a key in a Secret that contains the App Role ID used
  20236. to authenticate with OpenBao.
  20237. The `key` field must be specified and denotes which entry within the Secret
  20238. resource is used as the app role id.
  20239. properties:
  20240. key:
  20241. description: |-
  20242. A key in the referenced Secret.
  20243. Some instances of this field may be defaulted, in others it may be required.
  20244. maxLength: 253
  20245. minLength: 1
  20246. pattern: ^[-._a-zA-Z0-9]+$
  20247. type: string
  20248. name:
  20249. description: The name of the Secret resource being referred to.
  20250. maxLength: 253
  20251. minLength: 1
  20252. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20253. type: string
  20254. namespace:
  20255. description: |-
  20256. The namespace of the Secret resource being referred to.
  20257. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20258. maxLength: 63
  20259. minLength: 1
  20260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20261. type: string
  20262. type: object
  20263. secretRef:
  20264. description: |-
  20265. Reference to a key in a Secret that contains the App Role secret used
  20266. to authenticate with OpenBao.
  20267. The `key` field must be specified and denotes which entry within the Secret
  20268. resource is used as the app role secret.
  20269. properties:
  20270. key:
  20271. description: |-
  20272. A key in the referenced Secret.
  20273. Some instances of this field may be defaulted, in others it may be required.
  20274. maxLength: 253
  20275. minLength: 1
  20276. pattern: ^[-._a-zA-Z0-9]+$
  20277. type: string
  20278. name:
  20279. description: The name of the Secret resource being referred to.
  20280. maxLength: 253
  20281. minLength: 1
  20282. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20283. type: string
  20284. namespace:
  20285. description: |-
  20286. The namespace of the Secret resource being referred to.
  20287. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20288. maxLength: 63
  20289. minLength: 1
  20290. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20291. type: string
  20292. type: object
  20293. required:
  20294. - path
  20295. - secretRef
  20296. type: object
  20297. x-kubernetes-validations:
  20298. - message: exactly one of the fields in [roleId roleRef] must be set
  20299. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  20300. kubernetes:
  20301. description: |-
  20302. Kubernetes authenticates with OpenBao by passing a ServiceAccount
  20303. token to the [Kubernetes auth mechanism].
  20304. [Kubernetes auth mechanism]: https://openbao.org/docs/auth/kubernetes/
  20305. properties:
  20306. path:
  20307. default: kubernetes
  20308. description: |-
  20309. Path where the Kubernetes authentication backend is mounted in OpenBao, e.g:
  20310. "kubernetes"
  20311. type: string
  20312. role:
  20313. description: |-
  20314. A required field containing the OpenBao Role to assume. A Role binds a
  20315. Kubernetes ServiceAccount with a set of OpenBao policies.
  20316. minLength: 1
  20317. type: string
  20318. secretRef:
  20319. description: |-
  20320. Optional secret field containing a Kubernetes ServiceAccount JWT used
  20321. for authenticating with OpenBao. If a name is specified without a key,
  20322. `token` is the default.
  20323. properties:
  20324. key:
  20325. description: |-
  20326. A key in the referenced Secret.
  20327. Some instances of this field may be defaulted, in others it may be required.
  20328. maxLength: 253
  20329. minLength: 1
  20330. pattern: ^[-._a-zA-Z0-9]+$
  20331. type: string
  20332. name:
  20333. description: The name of the Secret resource being referred to.
  20334. maxLength: 253
  20335. minLength: 1
  20336. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20337. type: string
  20338. namespace:
  20339. description: |-
  20340. The namespace of the Secret resource being referred to.
  20341. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20342. maxLength: 63
  20343. minLength: 1
  20344. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20345. type: string
  20346. type: object
  20347. serviceAccountRef:
  20348. description: |-
  20349. Optional service account field containing the name of a Kubernetes ServiceAccount.
  20350. If the service account is specified, a token will be requested from the Kubernetes
  20351. TokenRequest API for authenticating with OpenBao.
  20352. Any configured audiences will be passed to the TokenRequest as-is.
  20353. properties:
  20354. audiences:
  20355. description: |-
  20356. Audience specifies the `aud` claim for the service account token
  20357. Some providers automatically extend the audience field based on well-known annotations for workload
  20358. identity (e.g. IRSA or GCP Workload Identity)
  20359. items:
  20360. type: string
  20361. type: array
  20362. name:
  20363. description: The name of the ServiceAccount resource being referred to.
  20364. maxLength: 253
  20365. minLength: 1
  20366. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20367. type: string
  20368. namespace:
  20369. description: |-
  20370. Namespace of the resource being referred to.
  20371. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20372. maxLength: 63
  20373. minLength: 1
  20374. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20375. type: string
  20376. required:
  20377. - name
  20378. type: object
  20379. required:
  20380. - path
  20381. - role
  20382. type: object
  20383. x-kubernetes-validations:
  20384. - message: exactly one of the fields in [serviceAccountRef secretRef] must be set
  20385. rule: '[has(self.serviceAccountRef),has(self.secretRef)].filter(x,x==true).size() == 1'
  20386. namespace:
  20387. description: |-
  20388. Name of the [OpenBao Namespace] to authenticate to. This can be different
  20389. than the namespace your secret is in. Namespaces is a set of features
  20390. within OpenBao that allows OpenBao environments to support secure
  20391. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  20392. if set, or empty otherwise
  20393. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  20394. type: string
  20395. tokenSecretRef:
  20396. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  20397. properties:
  20398. key:
  20399. description: |-
  20400. A key in the referenced Secret.
  20401. Some instances of this field may be defaulted, in others it may be required.
  20402. maxLength: 253
  20403. minLength: 1
  20404. pattern: ^[-._a-zA-Z0-9]+$
  20405. type: string
  20406. name:
  20407. description: The name of the Secret resource being referred to.
  20408. maxLength: 253
  20409. minLength: 1
  20410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20411. type: string
  20412. namespace:
  20413. description: |-
  20414. The namespace of the Secret resource being referred to.
  20415. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20416. maxLength: 63
  20417. minLength: 1
  20418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20419. type: string
  20420. type: object
  20421. userPass:
  20422. description: UserPass authenticates with OpenBao by passing a username/password pair
  20423. properties:
  20424. path:
  20425. default: userpass
  20426. description: |-
  20427. Path where the UserPassword authentication backend is mounted
  20428. in OpenBao, e.g: "userpass"
  20429. type: string
  20430. secretRef:
  20431. description: |-
  20432. SecretRef to a key in a Secret resource containing password for the user
  20433. used to authenticate with OpenBao using the [UserPass authentication
  20434. method]
  20435. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  20436. properties:
  20437. key:
  20438. description: |-
  20439. A key in the referenced Secret.
  20440. Some instances of this field may be defaulted, in others it may be required.
  20441. maxLength: 253
  20442. minLength: 1
  20443. pattern: ^[-._a-zA-Z0-9]+$
  20444. type: string
  20445. name:
  20446. description: The name of the Secret resource being referred to.
  20447. maxLength: 253
  20448. minLength: 1
  20449. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20450. type: string
  20451. namespace:
  20452. description: |-
  20453. The namespace of the Secret resource being referred to.
  20454. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20455. maxLength: 63
  20456. minLength: 1
  20457. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20458. type: string
  20459. type: object
  20460. username:
  20461. description: |-
  20462. Username is a username used to authenticate using the [UserPass
  20463. authentication method]
  20464. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  20465. type: string
  20466. required:
  20467. - path
  20468. - username
  20469. type: object
  20470. type: object
  20471. x-kubernetes-validations:
  20472. - message: exactly one of the fields in [appRole tokenSecretRef userPass kubernetes] must be set
  20473. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass),has(self.kubernetes)].filter(x,x==true).size() == 1'
  20474. caBundle:
  20475. description: |-
  20476. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  20477. this and `caProvider` are not set the system root certificates are used
  20478. to validate the TLS connection.
  20479. format: byte
  20480. type: string
  20481. caProvider:
  20482. description: |-
  20483. The provider for the CA bundle to use to validate OpenBao server
  20484. certificate. If this and `caBundle` are not set the system root
  20485. certificates are used to validate the TLS connection.
  20486. properties:
  20487. key:
  20488. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20489. maxLength: 253
  20490. minLength: 1
  20491. pattern: ^[-._a-zA-Z0-9]+$
  20492. type: string
  20493. name:
  20494. description: The name of the object located at the provider type.
  20495. maxLength: 253
  20496. minLength: 1
  20497. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20498. type: string
  20499. namespace:
  20500. description: |-
  20501. The namespace the Provider type is in.
  20502. Can only be defined when used in a ClusterSecretStore.
  20503. maxLength: 63
  20504. minLength: 1
  20505. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20506. type: string
  20507. type:
  20508. description: The type of provider to use such as "Secret", or "ConfigMap".
  20509. enum:
  20510. - Secret
  20511. - ConfigMap
  20512. type: string
  20513. required:
  20514. - name
  20515. - type
  20516. type: object
  20517. namespace:
  20518. description: |-
  20519. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  20520. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  20521. e.g: "ns1".
  20522. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  20523. type: string
  20524. path:
  20525. description: |-
  20526. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  20527. "secret". The v2 KV secret engine version specific "/data" path suffix
  20528. for fetching secrets from OpenBao is optional and will be appended
  20529. if not present in specified path.
  20530. type: string
  20531. server:
  20532. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  20533. type: string
  20534. version:
  20535. default: v2
  20536. description: |-
  20537. Version is the OpenBao KV secret engine version. This can be either "v1" or
  20538. "v2". Version defaults to "v2".
  20539. enum:
  20540. - v1
  20541. - v2
  20542. type: string
  20543. required:
  20544. - server
  20545. type: object
  20546. x-kubernetes-validations:
  20547. - message: at most one of the fields in [caBundle caProvider] may be set
  20548. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  20549. oracle:
  20550. description: Oracle configures this store to sync secrets using Oracle Vault provider
  20551. properties:
  20552. auth:
  20553. description: |-
  20554. Auth configures how secret-manager authenticates with the Oracle Vault.
  20555. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  20556. properties:
  20557. secretRef:
  20558. description: SecretRef to pass through sensitive information.
  20559. properties:
  20560. fingerprint:
  20561. description: Fingerprint is the fingerprint of the API private key.
  20562. properties:
  20563. key:
  20564. description: |-
  20565. A key in the referenced Secret.
  20566. Some instances of this field may be defaulted, in others it may be required.
  20567. maxLength: 253
  20568. minLength: 1
  20569. pattern: ^[-._a-zA-Z0-9]+$
  20570. type: string
  20571. name:
  20572. description: The name of the Secret resource being referred to.
  20573. maxLength: 253
  20574. minLength: 1
  20575. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20576. type: string
  20577. namespace:
  20578. description: |-
  20579. The namespace of the Secret resource being referred to.
  20580. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20581. maxLength: 63
  20582. minLength: 1
  20583. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20584. type: string
  20585. type: object
  20586. privatekey:
  20587. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  20588. properties:
  20589. key:
  20590. description: |-
  20591. A key in the referenced Secret.
  20592. Some instances of this field may be defaulted, in others it may be required.
  20593. maxLength: 253
  20594. minLength: 1
  20595. pattern: ^[-._a-zA-Z0-9]+$
  20596. type: string
  20597. name:
  20598. description: The name of the Secret resource being referred to.
  20599. maxLength: 253
  20600. minLength: 1
  20601. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20602. type: string
  20603. namespace:
  20604. description: |-
  20605. The namespace of the Secret resource being referred to.
  20606. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20607. maxLength: 63
  20608. minLength: 1
  20609. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20610. type: string
  20611. type: object
  20612. required:
  20613. - fingerprint
  20614. - privatekey
  20615. type: object
  20616. tenancy:
  20617. description: Tenancy is the tenancy OCID where user is located.
  20618. type: string
  20619. user:
  20620. description: User is an access OCID specific to the account.
  20621. type: string
  20622. required:
  20623. - secretRef
  20624. - tenancy
  20625. - user
  20626. type: object
  20627. compartment:
  20628. description: |-
  20629. Compartment is the vault compartment OCID.
  20630. Required for PushSecret
  20631. type: string
  20632. encryptionKey:
  20633. description: |-
  20634. EncryptionKey is the OCID of the encryption key within the vault.
  20635. Required for PushSecret
  20636. type: string
  20637. principalType:
  20638. description: |-
  20639. The type of principal to use for authentication. If left blank, the Auth struct will
  20640. determine the principal type. This optional field must be specified if using
  20641. workload identity.
  20642. enum:
  20643. - ""
  20644. - UserPrincipal
  20645. - InstancePrincipal
  20646. - Workload
  20647. type: string
  20648. region:
  20649. description: Region is the region where vault is located.
  20650. type: string
  20651. serviceAccountRef:
  20652. description: |-
  20653. ServiceAccountRef specified the service account
  20654. that should be used when authenticating with WorkloadIdentity.
  20655. properties:
  20656. audiences:
  20657. description: |-
  20658. Audience specifies the `aud` claim for the service account token
  20659. Some providers automatically extend the audience field based on well-known annotations for workload
  20660. identity (e.g. IRSA or GCP Workload Identity)
  20661. items:
  20662. type: string
  20663. type: array
  20664. name:
  20665. description: The name of the ServiceAccount resource being referred to.
  20666. maxLength: 253
  20667. minLength: 1
  20668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20669. type: string
  20670. namespace:
  20671. description: |-
  20672. Namespace of the resource being referred to.
  20673. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20674. maxLength: 63
  20675. minLength: 1
  20676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20677. type: string
  20678. required:
  20679. - name
  20680. type: object
  20681. vault:
  20682. description: Vault is the vault's OCID of the specific vault where secret is located.
  20683. type: string
  20684. required:
  20685. - region
  20686. - vault
  20687. type: object
  20688. ovh:
  20689. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  20690. properties:
  20691. auth:
  20692. description: Authentication method (mtls or token).
  20693. properties:
  20694. mtls:
  20695. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  20696. properties:
  20697. caBundle:
  20698. format: byte
  20699. type: string
  20700. caProvider:
  20701. description: |-
  20702. CAProvider provides a custom certificate authority for accessing the provider's store.
  20703. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  20704. properties:
  20705. key:
  20706. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20707. maxLength: 253
  20708. minLength: 1
  20709. pattern: ^[-._a-zA-Z0-9]+$
  20710. type: string
  20711. name:
  20712. description: The name of the object located at the provider type.
  20713. maxLength: 253
  20714. minLength: 1
  20715. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20716. type: string
  20717. namespace:
  20718. description: |-
  20719. The namespace the Provider type is in.
  20720. Can only be defined when used in a ClusterSecretStore.
  20721. maxLength: 63
  20722. minLength: 1
  20723. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20724. type: string
  20725. type:
  20726. description: The type of provider to use such as "Secret", or "ConfigMap".
  20727. enum:
  20728. - Secret
  20729. - ConfigMap
  20730. type: string
  20731. required:
  20732. - name
  20733. - type
  20734. type: object
  20735. certSecretRef:
  20736. description: |-
  20737. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20738. In some instances, `key` is a required field.
  20739. properties:
  20740. key:
  20741. description: |-
  20742. A key in the referenced Secret.
  20743. Some instances of this field may be defaulted, in others it may be required.
  20744. maxLength: 253
  20745. minLength: 1
  20746. pattern: ^[-._a-zA-Z0-9]+$
  20747. type: string
  20748. name:
  20749. description: The name of the Secret resource being referred to.
  20750. maxLength: 253
  20751. minLength: 1
  20752. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20753. type: string
  20754. namespace:
  20755. description: |-
  20756. The namespace of the Secret resource being referred to.
  20757. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20758. maxLength: 63
  20759. minLength: 1
  20760. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20761. type: string
  20762. type: object
  20763. keySecretRef:
  20764. description: |-
  20765. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20766. In some instances, `key` is a required field.
  20767. properties:
  20768. key:
  20769. description: |-
  20770. A key in the referenced Secret.
  20771. Some instances of this field may be defaulted, in others it may be required.
  20772. maxLength: 253
  20773. minLength: 1
  20774. pattern: ^[-._a-zA-Z0-9]+$
  20775. type: string
  20776. name:
  20777. description: The name of the Secret resource being referred to.
  20778. maxLength: 253
  20779. minLength: 1
  20780. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20781. type: string
  20782. namespace:
  20783. description: |-
  20784. The namespace of the Secret resource being referred to.
  20785. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20786. maxLength: 63
  20787. minLength: 1
  20788. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20789. type: string
  20790. type: object
  20791. required:
  20792. - certSecretRef
  20793. - keySecretRef
  20794. type: object
  20795. token:
  20796. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  20797. properties:
  20798. tokenSecretRef:
  20799. description: |-
  20800. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20801. In some instances, `key` is a required field.
  20802. properties:
  20803. key:
  20804. description: |-
  20805. A key in the referenced Secret.
  20806. Some instances of this field may be defaulted, in others it may be required.
  20807. maxLength: 253
  20808. minLength: 1
  20809. pattern: ^[-._a-zA-Z0-9]+$
  20810. type: string
  20811. name:
  20812. description: The name of the Secret resource being referred to.
  20813. maxLength: 253
  20814. minLength: 1
  20815. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20816. type: string
  20817. namespace:
  20818. description: |-
  20819. The namespace of the Secret resource being referred to.
  20820. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20821. maxLength: 63
  20822. minLength: 1
  20823. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20824. type: string
  20825. type: object
  20826. required:
  20827. - tokenSecretRef
  20828. type: object
  20829. type: object
  20830. casRequired:
  20831. description: 'Enables or disables check-and-set (CAS) (default: false).'
  20832. type: boolean
  20833. okmsTimeout:
  20834. default: 30
  20835. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  20836. format: int32
  20837. minimum: 1
  20838. type: integer
  20839. okmsid:
  20840. description: specifies the OKMS ID.
  20841. type: string
  20842. server:
  20843. description: specifies the OKMS server endpoint.
  20844. type: string
  20845. required:
  20846. - auth
  20847. - okmsid
  20848. - server
  20849. type: object
  20850. passbolt:
  20851. description: |-
  20852. PassboltProvider provides access to Passbolt secrets manager.
  20853. See: https://www.passbolt.com.
  20854. properties:
  20855. auth:
  20856. description: Auth defines the information necessary to authenticate against Passbolt Server
  20857. properties:
  20858. passwordSecretRef:
  20859. description: |-
  20860. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20861. In some instances, `key` is a required field.
  20862. properties:
  20863. key:
  20864. description: |-
  20865. A key in the referenced Secret.
  20866. Some instances of this field may be defaulted, in others it may be required.
  20867. maxLength: 253
  20868. minLength: 1
  20869. pattern: ^[-._a-zA-Z0-9]+$
  20870. type: string
  20871. name:
  20872. description: The name of the Secret resource being referred to.
  20873. maxLength: 253
  20874. minLength: 1
  20875. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20876. type: string
  20877. namespace:
  20878. description: |-
  20879. The namespace of the Secret resource being referred to.
  20880. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20881. maxLength: 63
  20882. minLength: 1
  20883. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20884. type: string
  20885. type: object
  20886. privateKeySecretRef:
  20887. description: |-
  20888. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20889. In some instances, `key` is a required field.
  20890. properties:
  20891. key:
  20892. description: |-
  20893. A key in the referenced Secret.
  20894. Some instances of this field may be defaulted, in others it may be required.
  20895. maxLength: 253
  20896. minLength: 1
  20897. pattern: ^[-._a-zA-Z0-9]+$
  20898. type: string
  20899. name:
  20900. description: The name of the Secret resource being referred to.
  20901. maxLength: 253
  20902. minLength: 1
  20903. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20904. type: string
  20905. namespace:
  20906. description: |-
  20907. The namespace of the Secret resource being referred to.
  20908. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20909. maxLength: 63
  20910. minLength: 1
  20911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20912. type: string
  20913. type: object
  20914. required:
  20915. - passwordSecretRef
  20916. - privateKeySecretRef
  20917. type: object
  20918. caBundle:
  20919. description: |-
  20920. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  20921. if the Host URL is using HTTPS protocol. If not set the system root certificates
  20922. are used to validate the TLS connection.
  20923. format: byte
  20924. type: string
  20925. caProvider:
  20926. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  20927. properties:
  20928. key:
  20929. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20930. maxLength: 253
  20931. minLength: 1
  20932. pattern: ^[-._a-zA-Z0-9]+$
  20933. type: string
  20934. name:
  20935. description: The name of the object located at the provider type.
  20936. maxLength: 253
  20937. minLength: 1
  20938. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20939. type: string
  20940. namespace:
  20941. description: |-
  20942. The namespace the Provider type is in.
  20943. Can only be defined when used in a ClusterSecretStore.
  20944. maxLength: 63
  20945. minLength: 1
  20946. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20947. type: string
  20948. type:
  20949. description: The type of provider to use such as "Secret", or "ConfigMap".
  20950. enum:
  20951. - Secret
  20952. - ConfigMap
  20953. type: string
  20954. required:
  20955. - name
  20956. - type
  20957. type: object
  20958. host:
  20959. description: Host defines the Passbolt Server to connect to
  20960. type: string
  20961. required:
  20962. - auth
  20963. - host
  20964. type: object
  20965. passworddepot:
  20966. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  20967. properties:
  20968. auth:
  20969. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  20970. properties:
  20971. secretRef:
  20972. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  20973. properties:
  20974. credentials:
  20975. description: Username / Password is used for authentication.
  20976. properties:
  20977. key:
  20978. description: |-
  20979. A key in the referenced Secret.
  20980. Some instances of this field may be defaulted, in others it may be required.
  20981. maxLength: 253
  20982. minLength: 1
  20983. pattern: ^[-._a-zA-Z0-9]+$
  20984. type: string
  20985. name:
  20986. description: The name of the Secret resource being referred to.
  20987. maxLength: 253
  20988. minLength: 1
  20989. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20990. type: string
  20991. namespace:
  20992. description: |-
  20993. The namespace of the Secret resource being referred to.
  20994. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20995. maxLength: 63
  20996. minLength: 1
  20997. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20998. type: string
  20999. type: object
  21000. type: object
  21001. required:
  21002. - secretRef
  21003. type: object
  21004. database:
  21005. description: Database to use as source
  21006. type: string
  21007. host:
  21008. description: URL configures the Password Depot instance URL.
  21009. type: string
  21010. required:
  21011. - auth
  21012. - database
  21013. - host
  21014. type: object
  21015. previder:
  21016. description: Previder configures this store to sync secrets using the Previder provider
  21017. properties:
  21018. auth:
  21019. description: PreviderAuth contains a secretRef for credentials.
  21020. properties:
  21021. secretRef:
  21022. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  21023. properties:
  21024. accessToken:
  21025. description: The AccessToken is used for authentication
  21026. properties:
  21027. key:
  21028. description: |-
  21029. A key in the referenced Secret.
  21030. Some instances of this field may be defaulted, in others it may be required.
  21031. maxLength: 253
  21032. minLength: 1
  21033. pattern: ^[-._a-zA-Z0-9]+$
  21034. type: string
  21035. name:
  21036. description: The name of the Secret resource being referred to.
  21037. maxLength: 253
  21038. minLength: 1
  21039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21040. type: string
  21041. namespace:
  21042. description: |-
  21043. The namespace of the Secret resource being referred to.
  21044. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21045. maxLength: 63
  21046. minLength: 1
  21047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21048. type: string
  21049. type: object
  21050. required:
  21051. - accessToken
  21052. type: object
  21053. type: object
  21054. baseUri:
  21055. type: string
  21056. required:
  21057. - auth
  21058. type: object
  21059. pulumi:
  21060. description: Pulumi configures this store to sync secrets using the Pulumi provider
  21061. properties:
  21062. accessToken:
  21063. description: |-
  21064. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  21065. Deprecated: Use auth.accessToken instead.
  21066. properties:
  21067. secretRef:
  21068. description: SecretRef is a reference to a secret containing the Pulumi API token.
  21069. properties:
  21070. key:
  21071. description: |-
  21072. A key in the referenced Secret.
  21073. Some instances of this field may be defaulted, in others it may be required.
  21074. maxLength: 253
  21075. minLength: 1
  21076. pattern: ^[-._a-zA-Z0-9]+$
  21077. type: string
  21078. name:
  21079. description: The name of the Secret resource being referred to.
  21080. maxLength: 253
  21081. minLength: 1
  21082. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21083. type: string
  21084. namespace:
  21085. description: |-
  21086. The namespace of the Secret resource being referred to.
  21087. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21088. maxLength: 63
  21089. minLength: 1
  21090. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21091. type: string
  21092. type: object
  21093. type: object
  21094. apiUrl:
  21095. default: https://api.pulumi.com/api/esc
  21096. description: APIURL is the URL of the Pulumi API.
  21097. type: string
  21098. auth:
  21099. description: |-
  21100. Auth configures how the Operator authenticates with the Pulumi API.
  21101. Either auth or the deprecated accessToken field must be specified.
  21102. properties:
  21103. accessToken:
  21104. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  21105. properties:
  21106. secretRef:
  21107. description: SecretRef is a reference to a secret containing the Pulumi API token.
  21108. properties:
  21109. key:
  21110. description: |-
  21111. A key in the referenced Secret.
  21112. Some instances of this field may be defaulted, in others it may be required.
  21113. maxLength: 253
  21114. minLength: 1
  21115. pattern: ^[-._a-zA-Z0-9]+$
  21116. type: string
  21117. name:
  21118. description: The name of the Secret resource being referred to.
  21119. maxLength: 253
  21120. minLength: 1
  21121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21122. type: string
  21123. namespace:
  21124. description: |-
  21125. The namespace of the Secret resource being referred to.
  21126. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21127. maxLength: 63
  21128. minLength: 1
  21129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21130. type: string
  21131. type: object
  21132. type: object
  21133. oidcConfig:
  21134. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  21135. properties:
  21136. expirationSeconds:
  21137. default: 600
  21138. description: |-
  21139. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  21140. Defaults to 10 minutes.
  21141. format: int64
  21142. minimum: 600
  21143. type: integer
  21144. organization:
  21145. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  21146. type: string
  21147. serviceAccountRef:
  21148. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  21149. properties:
  21150. audiences:
  21151. description: |-
  21152. Audience specifies the `aud` claim for the service account token
  21153. Some providers automatically extend the audience field based on well-known annotations for workload
  21154. identity (e.g. IRSA or GCP Workload Identity)
  21155. items:
  21156. type: string
  21157. type: array
  21158. name:
  21159. description: The name of the ServiceAccount resource being referred to.
  21160. maxLength: 253
  21161. minLength: 1
  21162. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21163. type: string
  21164. namespace:
  21165. description: |-
  21166. Namespace of the resource being referred to.
  21167. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21168. maxLength: 63
  21169. minLength: 1
  21170. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21171. type: string
  21172. required:
  21173. - name
  21174. type: object
  21175. required:
  21176. - organization
  21177. - serviceAccountRef
  21178. type: object
  21179. type: object
  21180. x-kubernetes-validations:
  21181. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  21182. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  21183. environment:
  21184. description: |-
  21185. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  21186. dynamically retrieved values from supported providers including all major clouds,
  21187. and other Pulumi ESC environments.
  21188. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  21189. type: string
  21190. organization:
  21191. description: |-
  21192. Organization are a space to collaborate on shared projects and stacks.
  21193. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  21194. type: string
  21195. project:
  21196. description: Project is the name of the Pulumi ESC project the environment belongs to.
  21197. type: string
  21198. required:
  21199. - environment
  21200. - organization
  21201. - project
  21202. type: object
  21203. x-kubernetes-validations:
  21204. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  21205. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  21206. scaleway:
  21207. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  21208. properties:
  21209. accessKey:
  21210. description: AccessKey is the non-secret part of the api key.
  21211. properties:
  21212. secretRef:
  21213. description: SecretRef references a key in a secret that will be used as value.
  21214. properties:
  21215. key:
  21216. description: |-
  21217. A key in the referenced Secret.
  21218. Some instances of this field may be defaulted, in others it may be required.
  21219. maxLength: 253
  21220. minLength: 1
  21221. pattern: ^[-._a-zA-Z0-9]+$
  21222. type: string
  21223. name:
  21224. description: The name of the Secret resource being referred to.
  21225. maxLength: 253
  21226. minLength: 1
  21227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21228. type: string
  21229. namespace:
  21230. description: |-
  21231. The namespace of the Secret resource being referred to.
  21232. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21233. maxLength: 63
  21234. minLength: 1
  21235. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21236. type: string
  21237. type: object
  21238. value:
  21239. description: Value can be specified directly to set a value without using a secret.
  21240. type: string
  21241. type: object
  21242. apiUrl:
  21243. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  21244. type: string
  21245. projectId:
  21246. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  21247. type: string
  21248. region:
  21249. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  21250. type: string
  21251. secretKey:
  21252. description: SecretKey is the non-secret part of the api key.
  21253. properties:
  21254. secretRef:
  21255. description: SecretRef references a key in a secret that will be used as value.
  21256. properties:
  21257. key:
  21258. description: |-
  21259. A key in the referenced Secret.
  21260. Some instances of this field may be defaulted, in others it may be required.
  21261. maxLength: 253
  21262. minLength: 1
  21263. pattern: ^[-._a-zA-Z0-9]+$
  21264. type: string
  21265. name:
  21266. description: The name of the Secret resource being referred to.
  21267. maxLength: 253
  21268. minLength: 1
  21269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21270. type: string
  21271. namespace:
  21272. description: |-
  21273. The namespace of the Secret resource being referred to.
  21274. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21275. maxLength: 63
  21276. minLength: 1
  21277. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21278. type: string
  21279. type: object
  21280. value:
  21281. description: Value can be specified directly to set a value without using a secret.
  21282. type: string
  21283. type: object
  21284. required:
  21285. - accessKey
  21286. - projectId
  21287. - region
  21288. - secretKey
  21289. type: object
  21290. secretserver:
  21291. description: |-
  21292. SecretServer configures this store to sync secrets using SecretServer provider
  21293. https://docs.delinea.com/online-help/secret-server/start.htm
  21294. properties:
  21295. caBundle:
  21296. description: |-
  21297. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  21298. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  21299. are used to validate the TLS connection.
  21300. format: byte
  21301. type: string
  21302. caProvider:
  21303. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  21304. properties:
  21305. key:
  21306. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  21307. maxLength: 253
  21308. minLength: 1
  21309. pattern: ^[-._a-zA-Z0-9]+$
  21310. type: string
  21311. name:
  21312. description: The name of the object located at the provider type.
  21313. maxLength: 253
  21314. minLength: 1
  21315. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21316. type: string
  21317. namespace:
  21318. description: |-
  21319. The namespace the Provider type is in.
  21320. Can only be defined when used in a ClusterSecretStore.
  21321. maxLength: 63
  21322. minLength: 1
  21323. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21324. type: string
  21325. type:
  21326. description: The type of provider to use such as "Secret", or "ConfigMap".
  21327. enum:
  21328. - Secret
  21329. - ConfigMap
  21330. type: string
  21331. required:
  21332. - name
  21333. - type
  21334. type: object
  21335. disableSiteIDValidation:
  21336. description: |-
  21337. DisableSiteIDValidation permits a missing site ID for new secrets.
  21338. The provider sends 0 if no site ID is set.
  21339. type: boolean
  21340. domain:
  21341. description: Domain is the secret server domain.
  21342. type: string
  21343. password:
  21344. description: |-
  21345. Password is the secret server account password.
  21346. Required unless Token is set.
  21347. properties:
  21348. secretRef:
  21349. description: SecretRef references a key in a secret that will be used as value.
  21350. properties:
  21351. key:
  21352. description: |-
  21353. A key in the referenced Secret.
  21354. Some instances of this field may be defaulted, in others it may be required.
  21355. maxLength: 253
  21356. minLength: 1
  21357. pattern: ^[-._a-zA-Z0-9]+$
  21358. type: string
  21359. name:
  21360. description: The name of the Secret resource being referred to.
  21361. maxLength: 253
  21362. minLength: 1
  21363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21364. type: string
  21365. namespace:
  21366. description: |-
  21367. The namespace of the Secret resource being referred to.
  21368. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21369. maxLength: 63
  21370. minLength: 1
  21371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21372. type: string
  21373. type: object
  21374. value:
  21375. description: Value can be specified directly to set a value without using a secret.
  21376. minLength: 1
  21377. type: string
  21378. type: object
  21379. x-kubernetes-validations:
  21380. - message: exactly one of value or secretRef must be set
  21381. rule: has(self.value) != has(self.secretRef)
  21382. serverURL:
  21383. description: |-
  21384. ServerURL
  21385. URL to your secret server installation
  21386. type: string
  21387. siteId:
  21388. description: |-
  21389. SiteID is the ID of the Secret Server site for new secrets.
  21390. PushSecret metadata can override this value for one secret.
  21391. The provider uses 1 if this field is not set.
  21392. minimum: 1
  21393. type: integer
  21394. token:
  21395. description: |-
  21396. Token is an access token used to authenticate to the secret server,
  21397. as an alternative to Username and Password. When set, Username and
  21398. Password are not required and are ignored.
  21399. properties:
  21400. secretRef:
  21401. description: SecretRef references a key in a secret that will be used as value.
  21402. properties:
  21403. key:
  21404. description: |-
  21405. A key in the referenced Secret.
  21406. Some instances of this field may be defaulted, in others it may be required.
  21407. maxLength: 253
  21408. minLength: 1
  21409. pattern: ^[-._a-zA-Z0-9]+$
  21410. type: string
  21411. name:
  21412. description: The name of the Secret resource being referred to.
  21413. maxLength: 253
  21414. minLength: 1
  21415. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21416. type: string
  21417. namespace:
  21418. description: |-
  21419. The namespace of the Secret resource being referred to.
  21420. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21421. maxLength: 63
  21422. minLength: 1
  21423. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21424. type: string
  21425. type: object
  21426. value:
  21427. description: Value can be specified directly to set a value without using a secret.
  21428. minLength: 1
  21429. type: string
  21430. type: object
  21431. x-kubernetes-validations:
  21432. - message: exactly one of value or secretRef must be set
  21433. rule: has(self.value) != has(self.secretRef)
  21434. username:
  21435. description: |-
  21436. Username is the secret server account username.
  21437. Required unless Token is set.
  21438. properties:
  21439. secretRef:
  21440. description: SecretRef references a key in a secret that will be used as value.
  21441. properties:
  21442. key:
  21443. description: |-
  21444. A key in the referenced Secret.
  21445. Some instances of this field may be defaulted, in others it may be required.
  21446. maxLength: 253
  21447. minLength: 1
  21448. pattern: ^[-._a-zA-Z0-9]+$
  21449. type: string
  21450. name:
  21451. description: The name of the Secret resource being referred to.
  21452. maxLength: 253
  21453. minLength: 1
  21454. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21455. type: string
  21456. namespace:
  21457. description: |-
  21458. The namespace of the Secret resource being referred to.
  21459. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21460. maxLength: 63
  21461. minLength: 1
  21462. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21463. type: string
  21464. type: object
  21465. value:
  21466. description: Value can be specified directly to set a value without using a secret.
  21467. minLength: 1
  21468. type: string
  21469. type: object
  21470. x-kubernetes-validations:
  21471. - message: exactly one of value or secretRef must be set
  21472. rule: has(self.value) != has(self.secretRef)
  21473. required:
  21474. - serverURL
  21475. type: object
  21476. x-kubernetes-validations:
  21477. - message: either token, or both username and password, must be set
  21478. rule: has(self.token) || (has(self.username) && has(self.password))
  21479. senhasegura:
  21480. description: Senhasegura configures this store to sync secrets using senhasegura provider
  21481. properties:
  21482. auth:
  21483. description: Auth defines parameters to authenticate in senhasegura
  21484. properties:
  21485. clientId:
  21486. type: string
  21487. clientSecretSecretRef:
  21488. description: |-
  21489. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  21490. In some instances, `key` is a required field.
  21491. properties:
  21492. key:
  21493. description: |-
  21494. A key in the referenced Secret.
  21495. Some instances of this field may be defaulted, in others it may be required.
  21496. maxLength: 253
  21497. minLength: 1
  21498. pattern: ^[-._a-zA-Z0-9]+$
  21499. type: string
  21500. name:
  21501. description: The name of the Secret resource being referred to.
  21502. maxLength: 253
  21503. minLength: 1
  21504. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21505. type: string
  21506. namespace:
  21507. description: |-
  21508. The namespace of the Secret resource being referred to.
  21509. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21510. maxLength: 63
  21511. minLength: 1
  21512. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21513. type: string
  21514. type: object
  21515. required:
  21516. - clientId
  21517. - clientSecretSecretRef
  21518. type: object
  21519. ignoreSslCertificate:
  21520. default: false
  21521. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  21522. type: boolean
  21523. module:
  21524. description: Module defines which senhasegura module should be used to get secrets
  21525. type: string
  21526. url:
  21527. description: URL of senhasegura
  21528. type: string
  21529. required:
  21530. - auth
  21531. - module
  21532. - url
  21533. type: object
  21534. vault:
  21535. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  21536. properties:
  21537. auth:
  21538. description: Auth configures how secret-manager authenticates with the Vault server.
  21539. properties:
  21540. appRole:
  21541. description: |-
  21542. AppRole authenticates with Vault using the App Role auth mechanism,
  21543. with the role and secret stored in a Kubernetes Secret resource.
  21544. properties:
  21545. path:
  21546. default: approle
  21547. description: |-
  21548. Path where the App Role authentication backend is mounted
  21549. in Vault, e.g: "approle"
  21550. type: string
  21551. roleId:
  21552. description: |-
  21553. RoleID configured in the App Role authentication backend when setting
  21554. up the authentication backend in Vault.
  21555. type: string
  21556. roleRef:
  21557. description: |-
  21558. Reference to a key in a Secret that contains the App Role ID used
  21559. to authenticate with Vault.
  21560. The `key` field must be specified and denotes which entry within the Secret
  21561. resource is used as the app role id.
  21562. properties:
  21563. key:
  21564. description: |-
  21565. A key in the referenced Secret.
  21566. Some instances of this field may be defaulted, in others it may be required.
  21567. maxLength: 253
  21568. minLength: 1
  21569. pattern: ^[-._a-zA-Z0-9]+$
  21570. type: string
  21571. name:
  21572. description: The name of the Secret resource being referred to.
  21573. maxLength: 253
  21574. minLength: 1
  21575. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21576. type: string
  21577. namespace:
  21578. description: |-
  21579. The namespace of the Secret resource being referred to.
  21580. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21581. maxLength: 63
  21582. minLength: 1
  21583. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21584. type: string
  21585. type: object
  21586. secretRef:
  21587. description: |-
  21588. Reference to a key in a Secret that contains the App Role secret used
  21589. to authenticate with Vault.
  21590. The `key` field must be specified and denotes which entry within the Secret
  21591. resource is used as the app role secret.
  21592. properties:
  21593. key:
  21594. description: |-
  21595. A key in the referenced Secret.
  21596. Some instances of this field may be defaulted, in others it may be required.
  21597. maxLength: 253
  21598. minLength: 1
  21599. pattern: ^[-._a-zA-Z0-9]+$
  21600. type: string
  21601. name:
  21602. description: The name of the Secret resource being referred to.
  21603. maxLength: 253
  21604. minLength: 1
  21605. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21606. type: string
  21607. namespace:
  21608. description: |-
  21609. The namespace of the Secret resource being referred to.
  21610. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21611. maxLength: 63
  21612. minLength: 1
  21613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21614. type: string
  21615. type: object
  21616. required:
  21617. - path
  21618. - secretRef
  21619. type: object
  21620. cert:
  21621. description: |-
  21622. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  21623. Cert authentication method
  21624. properties:
  21625. clientCert:
  21626. description: |-
  21627. ClientCert is a certificate to authenticate using the Cert Vault
  21628. authentication method
  21629. properties:
  21630. key:
  21631. description: |-
  21632. A key in the referenced Secret.
  21633. Some instances of this field may be defaulted, in others it may be required.
  21634. maxLength: 253
  21635. minLength: 1
  21636. pattern: ^[-._a-zA-Z0-9]+$
  21637. type: string
  21638. name:
  21639. description: The name of the Secret resource being referred to.
  21640. maxLength: 253
  21641. minLength: 1
  21642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21643. type: string
  21644. namespace:
  21645. description: |-
  21646. The namespace of the Secret resource being referred to.
  21647. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21648. maxLength: 63
  21649. minLength: 1
  21650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21651. type: string
  21652. type: object
  21653. path:
  21654. default: cert
  21655. description: |-
  21656. Path where the Certificate authentication backend is mounted
  21657. in Vault, e.g: "cert"
  21658. type: string
  21659. secretRef:
  21660. description: |-
  21661. SecretRef to a key in a Secret resource containing client private key to
  21662. authenticate with Vault using the Cert authentication method
  21663. properties:
  21664. key:
  21665. description: |-
  21666. A key in the referenced Secret.
  21667. Some instances of this field may be defaulted, in others it may be required.
  21668. maxLength: 253
  21669. minLength: 1
  21670. pattern: ^[-._a-zA-Z0-9]+$
  21671. type: string
  21672. name:
  21673. description: The name of the Secret resource being referred to.
  21674. maxLength: 253
  21675. minLength: 1
  21676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21677. type: string
  21678. namespace:
  21679. description: |-
  21680. The namespace of the Secret resource being referred to.
  21681. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21682. maxLength: 63
  21683. minLength: 1
  21684. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21685. type: string
  21686. type: object
  21687. vaultRole:
  21688. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  21689. type: string
  21690. type: object
  21691. gcp:
  21692. description: |-
  21693. Gcp authenticates with Vault using Google Cloud Platform authentication method
  21694. GCP authentication method
  21695. properties:
  21696. location:
  21697. description: Location optionally defines a location/region for the secret
  21698. type: string
  21699. path:
  21700. default: gcp
  21701. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  21702. type: string
  21703. projectID:
  21704. description: Project ID of the Google Cloud Platform project
  21705. type: string
  21706. role:
  21707. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  21708. type: string
  21709. secretRef:
  21710. description: Specify credentials in a Secret object
  21711. properties:
  21712. secretAccessKeySecretRef:
  21713. description: The SecretAccessKey is used for authentication
  21714. properties:
  21715. key:
  21716. description: |-
  21717. A key in the referenced Secret.
  21718. Some instances of this field may be defaulted, in others it may be required.
  21719. maxLength: 253
  21720. minLength: 1
  21721. pattern: ^[-._a-zA-Z0-9]+$
  21722. type: string
  21723. name:
  21724. description: The name of the Secret resource being referred to.
  21725. maxLength: 253
  21726. minLength: 1
  21727. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21728. type: string
  21729. namespace:
  21730. description: |-
  21731. The namespace of the Secret resource being referred to.
  21732. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21733. maxLength: 63
  21734. minLength: 1
  21735. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21736. type: string
  21737. type: object
  21738. type: object
  21739. serviceAccountRef:
  21740. description: ServiceAccountRef to a service account for impersonation
  21741. properties:
  21742. audiences:
  21743. description: |-
  21744. Audience specifies the `aud` claim for the service account token
  21745. Some providers automatically extend the audience field based on well-known annotations for workload
  21746. identity (e.g. IRSA or GCP Workload Identity)
  21747. items:
  21748. type: string
  21749. type: array
  21750. name:
  21751. description: The name of the ServiceAccount resource being referred to.
  21752. maxLength: 253
  21753. minLength: 1
  21754. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21755. type: string
  21756. namespace:
  21757. description: |-
  21758. Namespace of the resource being referred to.
  21759. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21760. maxLength: 63
  21761. minLength: 1
  21762. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21763. type: string
  21764. required:
  21765. - name
  21766. type: object
  21767. workloadIdentity:
  21768. description: Specify a service account with Workload Identity
  21769. properties:
  21770. clusterLocation:
  21771. description: |-
  21772. ClusterLocation is the location of the cluster
  21773. If not specified, it fetches information from the metadata server
  21774. type: string
  21775. clusterName:
  21776. description: |-
  21777. ClusterName is the name of the cluster
  21778. If not specified, it fetches information from the metadata server
  21779. type: string
  21780. clusterProjectID:
  21781. description: |-
  21782. ClusterProjectID is the project ID of the cluster
  21783. If not specified, it fetches information from the metadata server
  21784. type: string
  21785. serviceAccountRef:
  21786. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  21787. properties:
  21788. audiences:
  21789. description: |-
  21790. Audience specifies the `aud` claim for the service account token
  21791. Some providers automatically extend the audience field based on well-known annotations for workload
  21792. identity (e.g. IRSA or GCP Workload Identity)
  21793. items:
  21794. type: string
  21795. type: array
  21796. name:
  21797. description: The name of the ServiceAccount resource being referred to.
  21798. maxLength: 253
  21799. minLength: 1
  21800. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21801. type: string
  21802. namespace:
  21803. description: |-
  21804. Namespace of the resource being referred to.
  21805. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21806. maxLength: 63
  21807. minLength: 1
  21808. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21809. type: string
  21810. required:
  21811. - name
  21812. type: object
  21813. required:
  21814. - serviceAccountRef
  21815. type: object
  21816. required:
  21817. - role
  21818. type: object
  21819. iam:
  21820. description: |-
  21821. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  21822. AWS IAM authentication method
  21823. properties:
  21824. externalID:
  21825. description: AWS External ID set on assumed IAM roles
  21826. type: string
  21827. jwt:
  21828. description: Specify a service account with IRSA enabled
  21829. properties:
  21830. serviceAccountRef:
  21831. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  21832. properties:
  21833. audiences:
  21834. description: |-
  21835. Audience specifies the `aud` claim for the service account token
  21836. Some providers automatically extend the audience field based on well-known annotations for workload
  21837. identity (e.g. IRSA or GCP Workload Identity)
  21838. items:
  21839. type: string
  21840. type: array
  21841. name:
  21842. description: The name of the ServiceAccount resource being referred to.
  21843. maxLength: 253
  21844. minLength: 1
  21845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21846. type: string
  21847. namespace:
  21848. description: |-
  21849. Namespace of the resource being referred to.
  21850. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21851. maxLength: 63
  21852. minLength: 1
  21853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21854. type: string
  21855. required:
  21856. - name
  21857. type: object
  21858. type: object
  21859. path:
  21860. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  21861. type: string
  21862. region:
  21863. description: AWS region
  21864. type: string
  21865. role:
  21866. description: This is the AWS role to be assumed before talking to vault
  21867. type: string
  21868. secretRef:
  21869. description: Specify credentials in a Secret object
  21870. properties:
  21871. accessKeyIDSecretRef:
  21872. description: The AccessKeyID is used for authentication
  21873. properties:
  21874. key:
  21875. description: |-
  21876. A key in the referenced Secret.
  21877. Some instances of this field may be defaulted, in others it may be required.
  21878. maxLength: 253
  21879. minLength: 1
  21880. pattern: ^[-._a-zA-Z0-9]+$
  21881. type: string
  21882. name:
  21883. description: The name of the Secret resource being referred to.
  21884. maxLength: 253
  21885. minLength: 1
  21886. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21887. type: string
  21888. namespace:
  21889. description: |-
  21890. The namespace of the Secret resource being referred to.
  21891. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21892. maxLength: 63
  21893. minLength: 1
  21894. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21895. type: string
  21896. type: object
  21897. secretAccessKeySecretRef:
  21898. description: The SecretAccessKey is used for authentication
  21899. properties:
  21900. key:
  21901. description: |-
  21902. A key in the referenced Secret.
  21903. Some instances of this field may be defaulted, in others it may be required.
  21904. maxLength: 253
  21905. minLength: 1
  21906. pattern: ^[-._a-zA-Z0-9]+$
  21907. type: string
  21908. name:
  21909. description: The name of the Secret resource being referred to.
  21910. maxLength: 253
  21911. minLength: 1
  21912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21913. type: string
  21914. namespace:
  21915. description: |-
  21916. The namespace of the Secret resource being referred to.
  21917. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21918. maxLength: 63
  21919. minLength: 1
  21920. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21921. type: string
  21922. type: object
  21923. sessionTokenSecretRef:
  21924. description: |-
  21925. The SessionToken used for authentication
  21926. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  21927. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  21928. properties:
  21929. key:
  21930. description: |-
  21931. A key in the referenced Secret.
  21932. Some instances of this field may be defaulted, in others it may be required.
  21933. maxLength: 253
  21934. minLength: 1
  21935. pattern: ^[-._a-zA-Z0-9]+$
  21936. type: string
  21937. name:
  21938. description: The name of the Secret resource being referred to.
  21939. maxLength: 253
  21940. minLength: 1
  21941. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21942. type: string
  21943. namespace:
  21944. description: |-
  21945. The namespace of the Secret resource being referred to.
  21946. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21947. maxLength: 63
  21948. minLength: 1
  21949. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21950. type: string
  21951. type: object
  21952. type: object
  21953. vaultAwsIamServerID:
  21954. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  21955. type: string
  21956. vaultRole:
  21957. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  21958. type: string
  21959. required:
  21960. - vaultRole
  21961. type: object
  21962. jwt:
  21963. description: |-
  21964. Jwt authenticates with Vault by passing role and JWT token using the
  21965. JWT/OIDC authentication method
  21966. properties:
  21967. kubernetesServiceAccountToken:
  21968. description: |-
  21969. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  21970. a token for with the `TokenRequest` API.
  21971. properties:
  21972. audiences:
  21973. description: |-
  21974. Optional audiences field that will be used to request a temporary Kubernetes service
  21975. account token for the service account referenced by `serviceAccountRef`.
  21976. Defaults to a single audience `vault` it not specified.
  21977. Deprecated: use serviceAccountRef.Audiences instead
  21978. items:
  21979. type: string
  21980. type: array
  21981. expirationSeconds:
  21982. description: |-
  21983. Optional expiration time in seconds that will be used to request a temporary
  21984. Kubernetes service account token for the service account referenced by
  21985. `serviceAccountRef`.
  21986. Deprecated: this will be removed in the future.
  21987. Defaults to 10 minutes.
  21988. format: int64
  21989. type: integer
  21990. serviceAccountRef:
  21991. description: Service account field containing the name of a kubernetes ServiceAccount.
  21992. properties:
  21993. audiences:
  21994. description: |-
  21995. Audience specifies the `aud` claim for the service account token
  21996. Some providers automatically extend the audience field based on well-known annotations for workload
  21997. identity (e.g. IRSA or GCP Workload Identity)
  21998. items:
  21999. type: string
  22000. type: array
  22001. name:
  22002. description: The name of the ServiceAccount resource being referred to.
  22003. maxLength: 253
  22004. minLength: 1
  22005. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22006. type: string
  22007. namespace:
  22008. description: |-
  22009. Namespace of the resource being referred to.
  22010. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22011. maxLength: 63
  22012. minLength: 1
  22013. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22014. type: string
  22015. required:
  22016. - name
  22017. type: object
  22018. required:
  22019. - serviceAccountRef
  22020. type: object
  22021. path:
  22022. default: jwt
  22023. description: |-
  22024. Path where the JWT authentication backend is mounted
  22025. in Vault, e.g: "jwt"
  22026. type: string
  22027. role:
  22028. description: |-
  22029. Role is a JWT role to authenticate using the JWT/OIDC Vault
  22030. authentication method
  22031. type: string
  22032. secretRef:
  22033. description: |-
  22034. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  22035. authenticate with Vault using the JWT/OIDC authentication method.
  22036. properties:
  22037. key:
  22038. description: |-
  22039. A key in the referenced Secret.
  22040. Some instances of this field may be defaulted, in others it may be required.
  22041. maxLength: 253
  22042. minLength: 1
  22043. pattern: ^[-._a-zA-Z0-9]+$
  22044. type: string
  22045. name:
  22046. description: The name of the Secret resource being referred to.
  22047. maxLength: 253
  22048. minLength: 1
  22049. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22050. type: string
  22051. namespace:
  22052. description: |-
  22053. The namespace of the Secret resource being referred to.
  22054. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22055. maxLength: 63
  22056. minLength: 1
  22057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22058. type: string
  22059. type: object
  22060. required:
  22061. - path
  22062. type: object
  22063. kubernetes:
  22064. description: |-
  22065. Kubernetes authenticates with Vault by passing the ServiceAccount
  22066. token stored in the named Secret resource to the Vault server.
  22067. properties:
  22068. mountPath:
  22069. default: kubernetes
  22070. description: |-
  22071. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  22072. "kubernetes"
  22073. type: string
  22074. role:
  22075. description: |-
  22076. A required field containing the Vault Role to assume. A Role binds a
  22077. Kubernetes ServiceAccount with a set of Vault policies.
  22078. type: string
  22079. secretRef:
  22080. description: |-
  22081. Optional secret field containing a Kubernetes ServiceAccount JWT used
  22082. for authenticating with Vault. If a name is specified without a key,
  22083. `token` is the default. If one is not specified, the one bound to
  22084. the controller will be used.
  22085. properties:
  22086. key:
  22087. description: |-
  22088. A key in the referenced Secret.
  22089. Some instances of this field may be defaulted, in others it may be required.
  22090. maxLength: 253
  22091. minLength: 1
  22092. pattern: ^[-._a-zA-Z0-9]+$
  22093. type: string
  22094. name:
  22095. description: The name of the Secret resource being referred to.
  22096. maxLength: 253
  22097. minLength: 1
  22098. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22099. type: string
  22100. namespace:
  22101. description: |-
  22102. The namespace of the Secret resource being referred to.
  22103. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22104. maxLength: 63
  22105. minLength: 1
  22106. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22107. type: string
  22108. type: object
  22109. serviceAccountRef:
  22110. description: |-
  22111. Optional service account field containing the name of a kubernetes ServiceAccount.
  22112. If the service account is specified, the service account secret token JWT will be used
  22113. for authenticating with Vault. If the service account selector is not supplied,
  22114. the secretRef will be used instead.
  22115. properties:
  22116. audiences:
  22117. description: |-
  22118. Audience specifies the `aud` claim for the service account token
  22119. Some providers automatically extend the audience field based on well-known annotations for workload
  22120. identity (e.g. IRSA or GCP Workload Identity)
  22121. items:
  22122. type: string
  22123. type: array
  22124. name:
  22125. description: The name of the ServiceAccount resource being referred to.
  22126. maxLength: 253
  22127. minLength: 1
  22128. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22129. type: string
  22130. namespace:
  22131. description: |-
  22132. Namespace of the resource being referred to.
  22133. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22134. maxLength: 63
  22135. minLength: 1
  22136. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22137. type: string
  22138. required:
  22139. - name
  22140. type: object
  22141. required:
  22142. - mountPath
  22143. - role
  22144. type: object
  22145. ldap:
  22146. description: |-
  22147. Ldap authenticates with Vault by passing username/password pair using
  22148. the LDAP authentication method
  22149. properties:
  22150. path:
  22151. default: ldap
  22152. description: |-
  22153. Path where the LDAP authentication backend is mounted
  22154. in Vault, e.g: "ldap"
  22155. type: string
  22156. secretRef:
  22157. description: |-
  22158. SecretRef to a key in a Secret resource containing password for the LDAP
  22159. user used to authenticate with Vault using the LDAP authentication
  22160. method
  22161. properties:
  22162. key:
  22163. description: |-
  22164. A key in the referenced Secret.
  22165. Some instances of this field may be defaulted, in others it may be required.
  22166. maxLength: 253
  22167. minLength: 1
  22168. pattern: ^[-._a-zA-Z0-9]+$
  22169. type: string
  22170. name:
  22171. description: The name of the Secret resource being referred to.
  22172. maxLength: 253
  22173. minLength: 1
  22174. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22175. type: string
  22176. namespace:
  22177. description: |-
  22178. The namespace of the Secret resource being referred to.
  22179. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22180. maxLength: 63
  22181. minLength: 1
  22182. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22183. type: string
  22184. type: object
  22185. username:
  22186. description: |-
  22187. Username is an LDAP username used to authenticate using the LDAP Vault
  22188. authentication method
  22189. type: string
  22190. required:
  22191. - path
  22192. - username
  22193. type: object
  22194. namespace:
  22195. description: |-
  22196. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  22197. Namespaces is a set of features within Vault Enterprise that allows
  22198. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  22199. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  22200. This will default to Vault.Namespace field if set, or empty otherwise
  22201. type: string
  22202. tokenSecretRef:
  22203. description: TokenSecretRef authenticates with Vault by presenting a token.
  22204. properties:
  22205. key:
  22206. description: |-
  22207. A key in the referenced Secret.
  22208. Some instances of this field may be defaulted, in others it may be required.
  22209. maxLength: 253
  22210. minLength: 1
  22211. pattern: ^[-._a-zA-Z0-9]+$
  22212. type: string
  22213. name:
  22214. description: The name of the Secret resource being referred to.
  22215. maxLength: 253
  22216. minLength: 1
  22217. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22218. type: string
  22219. namespace:
  22220. description: |-
  22221. The namespace of the Secret resource being referred to.
  22222. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22223. maxLength: 63
  22224. minLength: 1
  22225. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22226. type: string
  22227. type: object
  22228. userPass:
  22229. description: UserPass authenticates with Vault by passing username/password pair
  22230. properties:
  22231. path:
  22232. default: userpass
  22233. description: |-
  22234. Path where the UserPassword authentication backend is mounted
  22235. in Vault, e.g: "userpass"
  22236. type: string
  22237. secretRef:
  22238. description: |-
  22239. SecretRef to a key in a Secret resource containing password for the
  22240. user used to authenticate with Vault using the UserPass authentication
  22241. method
  22242. properties:
  22243. key:
  22244. description: |-
  22245. A key in the referenced Secret.
  22246. Some instances of this field may be defaulted, in others it may be required.
  22247. maxLength: 253
  22248. minLength: 1
  22249. pattern: ^[-._a-zA-Z0-9]+$
  22250. type: string
  22251. name:
  22252. description: The name of the Secret resource being referred to.
  22253. maxLength: 253
  22254. minLength: 1
  22255. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22256. type: string
  22257. namespace:
  22258. description: |-
  22259. The namespace of the Secret resource being referred to.
  22260. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22261. maxLength: 63
  22262. minLength: 1
  22263. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22264. type: string
  22265. type: object
  22266. username:
  22267. description: |-
  22268. Username is a username used to authenticate using the UserPass Vault
  22269. authentication method
  22270. type: string
  22271. required:
  22272. - path
  22273. - username
  22274. type: object
  22275. type: object
  22276. caBundle:
  22277. description: |-
  22278. PEM encoded CA bundle used to validate Vault server certificate. Only used
  22279. if the Server URL is using HTTPS protocol. This parameter is ignored for
  22280. plain HTTP protocol connection. If not set the system root certificates
  22281. are used to validate the TLS connection.
  22282. format: byte
  22283. type: string
  22284. caProvider:
  22285. description: The provider for the CA bundle to use to validate Vault server certificate.
  22286. properties:
  22287. key:
  22288. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22289. maxLength: 253
  22290. minLength: 1
  22291. pattern: ^[-._a-zA-Z0-9]+$
  22292. type: string
  22293. name:
  22294. description: The name of the object located at the provider type.
  22295. maxLength: 253
  22296. minLength: 1
  22297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22298. type: string
  22299. namespace:
  22300. description: |-
  22301. The namespace the Provider type is in.
  22302. Can only be defined when used in a ClusterSecretStore.
  22303. maxLength: 63
  22304. minLength: 1
  22305. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22306. type: string
  22307. type:
  22308. description: The type of provider to use such as "Secret", or "ConfigMap".
  22309. enum:
  22310. - Secret
  22311. - ConfigMap
  22312. type: string
  22313. required:
  22314. - name
  22315. - type
  22316. type: object
  22317. checkAndSet:
  22318. description: |-
  22319. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  22320. Only applies to Vault KV v2 stores. When enabled, write operations must include
  22321. the current version of the secret to prevent unintentional overwrites.
  22322. properties:
  22323. required:
  22324. description: |-
  22325. Required when true, all write operations must include a check-and-set parameter.
  22326. This helps prevent unintentional overwrites of secrets.
  22327. type: boolean
  22328. type: object
  22329. forwardInconsistent:
  22330. description: |-
  22331. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  22332. leader instead of simply retrying within a loop. This can increase performance if
  22333. the option is enabled serverside.
  22334. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  22335. type: boolean
  22336. headers:
  22337. additionalProperties:
  22338. type: string
  22339. description: Headers to be added in Vault request
  22340. type: object
  22341. namespace:
  22342. description: |-
  22343. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  22344. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  22345. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  22346. type: string
  22347. path:
  22348. description: |-
  22349. Path is the mount path of the Vault KV backend endpoint, e.g:
  22350. "secret". The v2 KV secret engine version specific "/data" path suffix
  22351. for fetching secrets from Vault is optional and will be appended
  22352. if not present in specified path.
  22353. type: string
  22354. readYourWrites:
  22355. description: |-
  22356. ReadYourWrites ensures isolated read-after-write semantics by
  22357. providing discovered cluster replication states in each request.
  22358. More information about eventual consistency in Vault can be found here
  22359. https://www.vaultproject.io/docs/enterprise/consistency
  22360. type: boolean
  22361. server:
  22362. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  22363. type: string
  22364. tls:
  22365. description: |-
  22366. The configuration used for client side related TLS communication, when the Vault server
  22367. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  22368. This parameter is ignored for plain HTTP protocol connection.
  22369. It's worth noting this configuration is different from the "TLS certificates auth method",
  22370. which is available under the `auth.cert` section.
  22371. properties:
  22372. certSecretRef:
  22373. description: |-
  22374. CertSecretRef is a certificate added to the transport layer
  22375. when communicating with the Vault server.
  22376. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  22377. properties:
  22378. key:
  22379. description: |-
  22380. A key in the referenced Secret.
  22381. Some instances of this field may be defaulted, in others it may be required.
  22382. maxLength: 253
  22383. minLength: 1
  22384. pattern: ^[-._a-zA-Z0-9]+$
  22385. type: string
  22386. name:
  22387. description: The name of the Secret resource being referred to.
  22388. maxLength: 253
  22389. minLength: 1
  22390. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22391. type: string
  22392. namespace:
  22393. description: |-
  22394. The namespace of the Secret resource being referred to.
  22395. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22396. maxLength: 63
  22397. minLength: 1
  22398. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22399. type: string
  22400. type: object
  22401. keySecretRef:
  22402. description: |-
  22403. KeySecretRef to a key in a Secret resource containing client private key
  22404. added to the transport layer when communicating with the Vault server.
  22405. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  22406. properties:
  22407. key:
  22408. description: |-
  22409. A key in the referenced Secret.
  22410. Some instances of this field may be defaulted, in others it may be required.
  22411. maxLength: 253
  22412. minLength: 1
  22413. pattern: ^[-._a-zA-Z0-9]+$
  22414. type: string
  22415. name:
  22416. description: The name of the Secret resource being referred to.
  22417. maxLength: 253
  22418. minLength: 1
  22419. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22420. type: string
  22421. namespace:
  22422. description: |-
  22423. The namespace of the Secret resource being referred to.
  22424. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22425. maxLength: 63
  22426. minLength: 1
  22427. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22428. type: string
  22429. type: object
  22430. type: object
  22431. version:
  22432. default: v2
  22433. description: |-
  22434. Version is the Vault KV secret engine version. This can be either "v1" or
  22435. "v2". Version defaults to "v2".
  22436. enum:
  22437. - v1
  22438. - v2
  22439. type: string
  22440. required:
  22441. - server
  22442. type: object
  22443. volcengine:
  22444. description: Volcengine configures this store to sync secrets using the Volcengine provider
  22445. properties:
  22446. auth:
  22447. description: |-
  22448. Auth defines the authentication method to use.
  22449. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  22450. properties:
  22451. secretRef:
  22452. description: |-
  22453. SecretRef defines the static credentials to use for authentication.
  22454. If not set, IRSA is used.
  22455. properties:
  22456. accessKeyID:
  22457. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  22458. properties:
  22459. key:
  22460. description: |-
  22461. A key in the referenced Secret.
  22462. Some instances of this field may be defaulted, in others it may be required.
  22463. maxLength: 253
  22464. minLength: 1
  22465. pattern: ^[-._a-zA-Z0-9]+$
  22466. type: string
  22467. name:
  22468. description: The name of the Secret resource being referred to.
  22469. maxLength: 253
  22470. minLength: 1
  22471. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22472. type: string
  22473. namespace:
  22474. description: |-
  22475. The namespace of the Secret resource being referred to.
  22476. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22477. maxLength: 63
  22478. minLength: 1
  22479. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22480. type: string
  22481. type: object
  22482. secretAccessKey:
  22483. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  22484. properties:
  22485. key:
  22486. description: |-
  22487. A key in the referenced Secret.
  22488. Some instances of this field may be defaulted, in others it may be required.
  22489. maxLength: 253
  22490. minLength: 1
  22491. pattern: ^[-._a-zA-Z0-9]+$
  22492. type: string
  22493. name:
  22494. description: The name of the Secret resource being referred to.
  22495. maxLength: 253
  22496. minLength: 1
  22497. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22498. type: string
  22499. namespace:
  22500. description: |-
  22501. The namespace of the Secret resource being referred to.
  22502. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22503. maxLength: 63
  22504. minLength: 1
  22505. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22506. type: string
  22507. type: object
  22508. token:
  22509. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  22510. properties:
  22511. key:
  22512. description: |-
  22513. A key in the referenced Secret.
  22514. Some instances of this field may be defaulted, in others it may be required.
  22515. maxLength: 253
  22516. minLength: 1
  22517. pattern: ^[-._a-zA-Z0-9]+$
  22518. type: string
  22519. name:
  22520. description: The name of the Secret resource being referred to.
  22521. maxLength: 253
  22522. minLength: 1
  22523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22524. type: string
  22525. namespace:
  22526. description: |-
  22527. The namespace of the Secret resource being referred to.
  22528. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22529. maxLength: 63
  22530. minLength: 1
  22531. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22532. type: string
  22533. type: object
  22534. required:
  22535. - accessKeyID
  22536. - secretAccessKey
  22537. type: object
  22538. type: object
  22539. region:
  22540. description: Region specifies the Volcengine region to connect to.
  22541. type: string
  22542. required:
  22543. - region
  22544. type: object
  22545. webhook:
  22546. description: Webhook configures this store to sync secrets using a generic templated webhook
  22547. properties:
  22548. auth:
  22549. description: Auth specifies a authorization protocol. Only one protocol may be set.
  22550. maxProperties: 1
  22551. minProperties: 1
  22552. properties:
  22553. ntlm:
  22554. description: NTLMProtocol configures the store to use NTLM for auth
  22555. properties:
  22556. passwordSecret:
  22557. description: |-
  22558. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22559. In some instances, `key` is a required field.
  22560. properties:
  22561. key:
  22562. description: |-
  22563. A key in the referenced Secret.
  22564. Some instances of this field may be defaulted, in others it may be required.
  22565. maxLength: 253
  22566. minLength: 1
  22567. pattern: ^[-._a-zA-Z0-9]+$
  22568. type: string
  22569. name:
  22570. description: The name of the Secret resource being referred to.
  22571. maxLength: 253
  22572. minLength: 1
  22573. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22574. type: string
  22575. namespace:
  22576. description: |-
  22577. The namespace of the Secret resource being referred to.
  22578. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22579. maxLength: 63
  22580. minLength: 1
  22581. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22582. type: string
  22583. type: object
  22584. usernameSecret:
  22585. description: |-
  22586. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22587. In some instances, `key` is a required field.
  22588. properties:
  22589. key:
  22590. description: |-
  22591. A key in the referenced Secret.
  22592. Some instances of this field may be defaulted, in others it may be required.
  22593. maxLength: 253
  22594. minLength: 1
  22595. pattern: ^[-._a-zA-Z0-9]+$
  22596. type: string
  22597. name:
  22598. description: The name of the Secret resource being referred to.
  22599. maxLength: 253
  22600. minLength: 1
  22601. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22602. type: string
  22603. namespace:
  22604. description: |-
  22605. The namespace of the Secret resource being referred to.
  22606. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22607. maxLength: 63
  22608. minLength: 1
  22609. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22610. type: string
  22611. type: object
  22612. required:
  22613. - passwordSecret
  22614. - usernameSecret
  22615. type: object
  22616. type: object
  22617. body:
  22618. description: Body
  22619. type: string
  22620. caBundle:
  22621. description: |-
  22622. PEM encoded CA bundle used to validate webhook server certificate. Only used
  22623. if the Server URL is using HTTPS protocol. This parameter is ignored for
  22624. plain HTTP protocol connection. If not set the system root certificates
  22625. are used to validate the TLS connection.
  22626. format: byte
  22627. type: string
  22628. caProvider:
  22629. description: The provider for the CA bundle to use to validate webhook server certificate.
  22630. properties:
  22631. key:
  22632. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22633. maxLength: 253
  22634. minLength: 1
  22635. pattern: ^[-._a-zA-Z0-9]+$
  22636. type: string
  22637. name:
  22638. description: The name of the object located at the provider type.
  22639. maxLength: 253
  22640. minLength: 1
  22641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22642. type: string
  22643. namespace:
  22644. description: The namespace the Provider type is in.
  22645. maxLength: 63
  22646. minLength: 1
  22647. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22648. type: string
  22649. type:
  22650. description: The type of provider to use such as "Secret", or "ConfigMap".
  22651. enum:
  22652. - Secret
  22653. - ConfigMap
  22654. type: string
  22655. required:
  22656. - name
  22657. - type
  22658. type: object
  22659. headers:
  22660. additionalProperties:
  22661. type: string
  22662. description: Headers
  22663. type: object
  22664. method:
  22665. description: Webhook Method
  22666. type: string
  22667. result:
  22668. description: Result formatting
  22669. properties:
  22670. jsonPath:
  22671. description: Json path of return value
  22672. type: string
  22673. type: object
  22674. secrets:
  22675. description: |-
  22676. Secrets to fill in templates
  22677. These secrets will be passed to the templating function as key value pairs under the given name
  22678. items:
  22679. description: WebhookSecret defines a secret that will be passed to the webhook request.
  22680. properties:
  22681. name:
  22682. description: Name of this secret in templates
  22683. type: string
  22684. secretRef:
  22685. description: Secret ref to fill in credentials
  22686. properties:
  22687. key:
  22688. description: |-
  22689. A key in the referenced Secret.
  22690. Some instances of this field may be defaulted, in others it may be required.
  22691. maxLength: 253
  22692. minLength: 1
  22693. pattern: ^[-._a-zA-Z0-9]+$
  22694. type: string
  22695. name:
  22696. description: The name of the Secret resource being referred to.
  22697. maxLength: 253
  22698. minLength: 1
  22699. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22700. type: string
  22701. namespace:
  22702. description: |-
  22703. The namespace of the Secret resource being referred to.
  22704. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22705. maxLength: 63
  22706. minLength: 1
  22707. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22708. type: string
  22709. type: object
  22710. required:
  22711. - name
  22712. - secretRef
  22713. type: object
  22714. type: array
  22715. timeout:
  22716. description: Timeout
  22717. type: string
  22718. url:
  22719. description: Webhook url to call
  22720. type: string
  22721. required:
  22722. - url
  22723. type: object
  22724. yandexcertificatemanager:
  22725. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  22726. properties:
  22727. apiEndpoint:
  22728. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  22729. type: string
  22730. auth:
  22731. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  22732. properties:
  22733. authorizedKeySecretRef:
  22734. description: The authorized key used for authentication
  22735. properties:
  22736. key:
  22737. description: |-
  22738. A key in the referenced Secret.
  22739. Some instances of this field may be defaulted, in others it may be required.
  22740. maxLength: 253
  22741. minLength: 1
  22742. pattern: ^[-._a-zA-Z0-9]+$
  22743. type: string
  22744. name:
  22745. description: The name of the Secret resource being referred to.
  22746. maxLength: 253
  22747. minLength: 1
  22748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22749. type: string
  22750. namespace:
  22751. description: |-
  22752. The namespace of the Secret resource being referred to.
  22753. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22754. maxLength: 63
  22755. minLength: 1
  22756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22757. type: string
  22758. type: object
  22759. type: object
  22760. caProvider:
  22761. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  22762. properties:
  22763. certSecretRef:
  22764. description: |-
  22765. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22766. In some instances, `key` is a required field.
  22767. properties:
  22768. key:
  22769. description: |-
  22770. A key in the referenced Secret.
  22771. Some instances of this field may be defaulted, in others it may be required.
  22772. maxLength: 253
  22773. minLength: 1
  22774. pattern: ^[-._a-zA-Z0-9]+$
  22775. type: string
  22776. name:
  22777. description: The name of the Secret resource being referred to.
  22778. maxLength: 253
  22779. minLength: 1
  22780. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22781. type: string
  22782. namespace:
  22783. description: |-
  22784. The namespace of the Secret resource being referred to.
  22785. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22786. maxLength: 63
  22787. minLength: 1
  22788. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22789. type: string
  22790. type: object
  22791. type: object
  22792. fetching:
  22793. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  22794. maxProperties: 1
  22795. minProperties: 1
  22796. properties:
  22797. byID:
  22798. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  22799. type: object
  22800. byName:
  22801. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  22802. properties:
  22803. folderID:
  22804. description: The folder to fetch secrets from
  22805. type: string
  22806. required:
  22807. - folderID
  22808. type: object
  22809. type: object
  22810. required:
  22811. - auth
  22812. type: object
  22813. yandexlockbox:
  22814. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  22815. properties:
  22816. apiEndpoint:
  22817. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  22818. type: string
  22819. auth:
  22820. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  22821. properties:
  22822. authorizedKeySecretRef:
  22823. description: The authorized key used for authentication
  22824. properties:
  22825. key:
  22826. description: |-
  22827. A key in the referenced Secret.
  22828. Some instances of this field may be defaulted, in others it may be required.
  22829. maxLength: 253
  22830. minLength: 1
  22831. pattern: ^[-._a-zA-Z0-9]+$
  22832. type: string
  22833. name:
  22834. description: The name of the Secret resource being referred to.
  22835. maxLength: 253
  22836. minLength: 1
  22837. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22838. type: string
  22839. namespace:
  22840. description: |-
  22841. The namespace of the Secret resource being referred to.
  22842. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22843. maxLength: 63
  22844. minLength: 1
  22845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22846. type: string
  22847. type: object
  22848. type: object
  22849. caProvider:
  22850. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  22851. properties:
  22852. certSecretRef:
  22853. description: |-
  22854. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22855. In some instances, `key` is a required field.
  22856. properties:
  22857. key:
  22858. description: |-
  22859. A key in the referenced Secret.
  22860. Some instances of this field may be defaulted, in others it may be required.
  22861. maxLength: 253
  22862. minLength: 1
  22863. pattern: ^[-._a-zA-Z0-9]+$
  22864. type: string
  22865. name:
  22866. description: The name of the Secret resource being referred to.
  22867. maxLength: 253
  22868. minLength: 1
  22869. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22870. type: string
  22871. namespace:
  22872. description: |-
  22873. The namespace of the Secret resource being referred to.
  22874. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22875. maxLength: 63
  22876. minLength: 1
  22877. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22878. type: string
  22879. type: object
  22880. type: object
  22881. fetching:
  22882. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  22883. maxProperties: 1
  22884. minProperties: 1
  22885. properties:
  22886. byID:
  22887. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  22888. type: object
  22889. byName:
  22890. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  22891. properties:
  22892. folderID:
  22893. description: The folder to fetch secrets from
  22894. type: string
  22895. required:
  22896. - folderID
  22897. type: object
  22898. type: object
  22899. required:
  22900. - auth
  22901. type: object
  22902. type: object
  22903. refreshInterval:
  22904. anyOf:
  22905. - type: integer
  22906. - type: string
  22907. description: |-
  22908. Used to configure store refresh interval. Accepts either an integer number
  22909. of seconds (legacy) or a Go duration string such as "1h" or "5m". Empty or
  22910. 0 will default to the controller config.
  22911. x-kubernetes-int-or-string: true
  22912. retrySettings:
  22913. description: Used to configure HTTP retries on failures.
  22914. properties:
  22915. maxRetries:
  22916. format: int32
  22917. type: integer
  22918. retryInterval:
  22919. type: string
  22920. type: object
  22921. required:
  22922. - provider
  22923. type: object
  22924. status:
  22925. description: SecretStoreStatus defines the observed state of the SecretStore.
  22926. properties:
  22927. capabilities:
  22928. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  22929. type: string
  22930. conditions:
  22931. items:
  22932. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  22933. properties:
  22934. lastTransitionTime:
  22935. format: date-time
  22936. type: string
  22937. message:
  22938. type: string
  22939. reason:
  22940. type: string
  22941. status:
  22942. type: string
  22943. type:
  22944. description: SecretStoreConditionType represents the condition of the SecretStore.
  22945. type: string
  22946. required:
  22947. - status
  22948. - type
  22949. type: object
  22950. type: array
  22951. type: object
  22952. type: object
  22953. served: true
  22954. storage: true
  22955. subresources:
  22956. status: {}
  22957. - additionalPrinterColumns:
  22958. - jsonPath: .metadata.creationTimestamp
  22959. name: AGE
  22960. type: date
  22961. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  22962. name: Status
  22963. type: string
  22964. - jsonPath: .status.capabilities
  22965. name: Capabilities
  22966. type: string
  22967. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  22968. name: Ready
  22969. type: string
  22970. deprecated: true
  22971. name: v1beta1
  22972. schema:
  22973. openAPIV3Schema:
  22974. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  22975. properties:
  22976. apiVersion:
  22977. description: |-
  22978. APIVersion defines the versioned schema of this representation of an object.
  22979. Servers should convert recognized schemas to the latest internal value, and
  22980. may reject unrecognized values.
  22981. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  22982. type: string
  22983. kind:
  22984. description: |-
  22985. Kind is a string value representing the REST resource this object represents.
  22986. Servers may infer this from the endpoint the client submits requests to.
  22987. Cannot be updated.
  22988. In CamelCase.
  22989. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  22990. type: string
  22991. metadata:
  22992. type: object
  22993. spec:
  22994. description: SecretStoreSpec defines the desired state of SecretStore.
  22995. properties:
  22996. conditions:
  22997. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  22998. items:
  22999. description: |-
  23000. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  23001. for a ClusterSecretStore instance.
  23002. properties:
  23003. namespaceRegexes:
  23004. description: Choose namespaces by using regex matching
  23005. items:
  23006. type: string
  23007. type: array
  23008. namespaceSelector:
  23009. description: Choose namespace using a labelSelector
  23010. properties:
  23011. matchExpressions:
  23012. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  23013. items:
  23014. description: |-
  23015. A label selector requirement is a selector that contains values, a key, and an operator that
  23016. relates the key and values.
  23017. properties:
  23018. key:
  23019. description: key is the label key that the selector applies to.
  23020. type: string
  23021. operator:
  23022. description: |-
  23023. operator represents a key's relationship to a set of values.
  23024. Valid operators are In, NotIn, Exists and DoesNotExist.
  23025. type: string
  23026. values:
  23027. description: |-
  23028. values is an array of string values. If the operator is In or NotIn,
  23029. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  23030. the values array must be empty. This array is replaced during a strategic
  23031. merge patch.
  23032. items:
  23033. type: string
  23034. type: array
  23035. x-kubernetes-list-type: atomic
  23036. required:
  23037. - key
  23038. - operator
  23039. type: object
  23040. type: array
  23041. x-kubernetes-list-type: atomic
  23042. matchLabels:
  23043. additionalProperties:
  23044. type: string
  23045. description: |-
  23046. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  23047. map is equivalent to an element of matchExpressions, whose key field is "key", the
  23048. operator is "In", and the values array contains only "value". The requirements are ANDed.
  23049. type: object
  23050. type: object
  23051. x-kubernetes-map-type: atomic
  23052. namespaces:
  23053. description: Choose namespaces by name
  23054. items:
  23055. maxLength: 63
  23056. minLength: 1
  23057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23058. type: string
  23059. type: array
  23060. type: object
  23061. type: array
  23062. controller:
  23063. description: |-
  23064. Used to select the correct ESO controller (think: ingress.ingressClassName)
  23065. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  23066. type: string
  23067. provider:
  23068. description: Used to configure the provider. Only one provider may be set
  23069. maxProperties: 1
  23070. minProperties: 1
  23071. properties:
  23072. akeyless:
  23073. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  23074. properties:
  23075. akeylessGWApiURL:
  23076. description: Akeyless GW API Url from which the secrets to be fetched from.
  23077. type: string
  23078. authSecretRef:
  23079. description: Auth configures how the operator authenticates with Akeyless.
  23080. properties:
  23081. kubernetesAuth:
  23082. description: |-
  23083. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  23084. token stored in the named Secret resource.
  23085. properties:
  23086. accessID:
  23087. description: the Akeyless Kubernetes auth-method access-id
  23088. type: string
  23089. k8sConfName:
  23090. description: Kubernetes-auth configuration name in Akeyless-Gateway
  23091. type: string
  23092. secretRef:
  23093. description: |-
  23094. Optional secret field containing a Kubernetes ServiceAccount JWT used
  23095. for authenticating with Akeyless. If a name is specified without a key,
  23096. `token` is the default. If one is not specified, the one bound to
  23097. the controller will be used.
  23098. properties:
  23099. key:
  23100. description: |-
  23101. A key in the referenced Secret.
  23102. Some instances of this field may be defaulted, in others it may be required.
  23103. maxLength: 253
  23104. minLength: 1
  23105. pattern: ^[-._a-zA-Z0-9]+$
  23106. type: string
  23107. name:
  23108. description: The name of the Secret resource being referred to.
  23109. maxLength: 253
  23110. minLength: 1
  23111. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23112. type: string
  23113. namespace:
  23114. description: |-
  23115. The namespace of the Secret resource being referred to.
  23116. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23117. maxLength: 63
  23118. minLength: 1
  23119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23120. type: string
  23121. type: object
  23122. serviceAccountRef:
  23123. description: |-
  23124. Optional service account field containing the name of a kubernetes ServiceAccount.
  23125. If the service account is specified, the service account secret token JWT will be used
  23126. for authenticating with Akeyless. If the service account selector is not supplied,
  23127. the secretRef will be used instead.
  23128. properties:
  23129. audiences:
  23130. description: |-
  23131. Audience specifies the `aud` claim for the service account token
  23132. Some providers automatically extend the audience field based on well-known annotations for workload
  23133. identity (e.g. IRSA or GCP Workload Identity)
  23134. items:
  23135. type: string
  23136. type: array
  23137. name:
  23138. description: The name of the ServiceAccount resource being referred to.
  23139. maxLength: 253
  23140. minLength: 1
  23141. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23142. type: string
  23143. namespace:
  23144. description: |-
  23145. Namespace of the resource being referred to.
  23146. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23147. maxLength: 63
  23148. minLength: 1
  23149. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23150. type: string
  23151. required:
  23152. - name
  23153. type: object
  23154. required:
  23155. - accessID
  23156. - k8sConfName
  23157. type: object
  23158. secretRef:
  23159. description: |-
  23160. Reference to a Secret that contains the details
  23161. to authenticate with Akeyless.
  23162. properties:
  23163. accessID:
  23164. description: The SecretAccessID is used for authentication
  23165. properties:
  23166. key:
  23167. description: |-
  23168. A key in the referenced Secret.
  23169. Some instances of this field may be defaulted, in others it may be required.
  23170. maxLength: 253
  23171. minLength: 1
  23172. pattern: ^[-._a-zA-Z0-9]+$
  23173. type: string
  23174. name:
  23175. description: The name of the Secret resource being referred to.
  23176. maxLength: 253
  23177. minLength: 1
  23178. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23179. type: string
  23180. namespace:
  23181. description: |-
  23182. The namespace of the Secret resource being referred to.
  23183. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23184. maxLength: 63
  23185. minLength: 1
  23186. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23187. type: string
  23188. type: object
  23189. accessType:
  23190. description: |-
  23191. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23192. In some instances, `key` is a required field.
  23193. properties:
  23194. key:
  23195. description: |-
  23196. A key in the referenced Secret.
  23197. Some instances of this field may be defaulted, in others it may be required.
  23198. maxLength: 253
  23199. minLength: 1
  23200. pattern: ^[-._a-zA-Z0-9]+$
  23201. type: string
  23202. name:
  23203. description: The name of the Secret resource being referred to.
  23204. maxLength: 253
  23205. minLength: 1
  23206. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23207. type: string
  23208. namespace:
  23209. description: |-
  23210. The namespace of the Secret resource being referred to.
  23211. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23212. maxLength: 63
  23213. minLength: 1
  23214. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23215. type: string
  23216. type: object
  23217. accessTypeParam:
  23218. description: |-
  23219. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23220. In some instances, `key` is a required field.
  23221. properties:
  23222. key:
  23223. description: |-
  23224. A key in the referenced Secret.
  23225. Some instances of this field may be defaulted, in others it may be required.
  23226. maxLength: 253
  23227. minLength: 1
  23228. pattern: ^[-._a-zA-Z0-9]+$
  23229. type: string
  23230. name:
  23231. description: The name of the Secret resource being referred to.
  23232. maxLength: 253
  23233. minLength: 1
  23234. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23235. type: string
  23236. namespace:
  23237. description: |-
  23238. The namespace of the Secret resource being referred to.
  23239. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23240. maxLength: 63
  23241. minLength: 1
  23242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23243. type: string
  23244. type: object
  23245. type: object
  23246. type: object
  23247. caBundle:
  23248. description: |-
  23249. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  23250. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  23251. are used to validate the TLS connection.
  23252. format: byte
  23253. type: string
  23254. caProvider:
  23255. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  23256. properties:
  23257. key:
  23258. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23259. maxLength: 253
  23260. minLength: 1
  23261. pattern: ^[-._a-zA-Z0-9]+$
  23262. type: string
  23263. name:
  23264. description: The name of the object located at the provider type.
  23265. maxLength: 253
  23266. minLength: 1
  23267. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23268. type: string
  23269. namespace:
  23270. description: |-
  23271. The namespace the Provider type is in.
  23272. Can only be defined when used in a ClusterSecretStore.
  23273. maxLength: 63
  23274. minLength: 1
  23275. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23276. type: string
  23277. type:
  23278. description: The type of provider to use such as "Secret", or "ConfigMap".
  23279. enum:
  23280. - Secret
  23281. - ConfigMap
  23282. type: string
  23283. required:
  23284. - name
  23285. - type
  23286. type: object
  23287. required:
  23288. - akeylessGWApiURL
  23289. - authSecretRef
  23290. type: object
  23291. alibaba:
  23292. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  23293. properties:
  23294. auth:
  23295. description: AlibabaAuth contains a secretRef for credentials.
  23296. properties:
  23297. rrsa:
  23298. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  23299. properties:
  23300. oidcProviderArn:
  23301. type: string
  23302. oidcTokenFilePath:
  23303. type: string
  23304. roleArn:
  23305. type: string
  23306. sessionName:
  23307. type: string
  23308. required:
  23309. - oidcProviderArn
  23310. - oidcTokenFilePath
  23311. - roleArn
  23312. - sessionName
  23313. type: object
  23314. secretRef:
  23315. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  23316. properties:
  23317. accessKeyIDSecretRef:
  23318. description: The AccessKeyID is used for authentication
  23319. properties:
  23320. key:
  23321. description: |-
  23322. A key in the referenced Secret.
  23323. Some instances of this field may be defaulted, in others it may be required.
  23324. maxLength: 253
  23325. minLength: 1
  23326. pattern: ^[-._a-zA-Z0-9]+$
  23327. type: string
  23328. name:
  23329. description: The name of the Secret resource being referred to.
  23330. maxLength: 253
  23331. minLength: 1
  23332. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23333. type: string
  23334. namespace:
  23335. description: |-
  23336. The namespace of the Secret resource being referred to.
  23337. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23338. maxLength: 63
  23339. minLength: 1
  23340. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23341. type: string
  23342. type: object
  23343. accessKeySecretSecretRef:
  23344. description: The AccessKeySecret is used for authentication
  23345. properties:
  23346. key:
  23347. description: |-
  23348. A key in the referenced Secret.
  23349. Some instances of this field may be defaulted, in others it may be required.
  23350. maxLength: 253
  23351. minLength: 1
  23352. pattern: ^[-._a-zA-Z0-9]+$
  23353. type: string
  23354. name:
  23355. description: The name of the Secret resource being referred to.
  23356. maxLength: 253
  23357. minLength: 1
  23358. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23359. type: string
  23360. namespace:
  23361. description: |-
  23362. The namespace of the Secret resource being referred to.
  23363. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23364. maxLength: 63
  23365. minLength: 1
  23366. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23367. type: string
  23368. type: object
  23369. required:
  23370. - accessKeyIDSecretRef
  23371. - accessKeySecretSecretRef
  23372. type: object
  23373. type: object
  23374. regionID:
  23375. description: Alibaba Region to be used for the provider
  23376. type: string
  23377. required:
  23378. - auth
  23379. - regionID
  23380. type: object
  23381. aws:
  23382. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  23383. properties:
  23384. additionalRoles:
  23385. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  23386. items:
  23387. type: string
  23388. type: array
  23389. auth:
  23390. description: |-
  23391. Auth defines the information necessary to authenticate against AWS
  23392. if not set aws sdk will infer credentials from your environment
  23393. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  23394. properties:
  23395. jwt:
  23396. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  23397. properties:
  23398. serviceAccountRef:
  23399. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  23400. properties:
  23401. audiences:
  23402. description: |-
  23403. Audience specifies the `aud` claim for the service account token
  23404. Some providers automatically extend the audience field based on well-known annotations for workload
  23405. identity (e.g. IRSA or GCP Workload Identity)
  23406. items:
  23407. type: string
  23408. type: array
  23409. name:
  23410. description: The name of the ServiceAccount resource being referred to.
  23411. maxLength: 253
  23412. minLength: 1
  23413. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23414. type: string
  23415. namespace:
  23416. description: |-
  23417. Namespace of the resource being referred to.
  23418. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23419. maxLength: 63
  23420. minLength: 1
  23421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23422. type: string
  23423. required:
  23424. - name
  23425. type: object
  23426. type: object
  23427. secretRef:
  23428. description: |-
  23429. AWSAuthSecretRef holds secret references for AWS credentials
  23430. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  23431. properties:
  23432. accessKeyIDSecretRef:
  23433. description: The AccessKeyID is used for authentication
  23434. properties:
  23435. key:
  23436. description: |-
  23437. A key in the referenced Secret.
  23438. Some instances of this field may be defaulted, in others it may be required.
  23439. maxLength: 253
  23440. minLength: 1
  23441. pattern: ^[-._a-zA-Z0-9]+$
  23442. type: string
  23443. name:
  23444. description: The name of the Secret resource being referred to.
  23445. maxLength: 253
  23446. minLength: 1
  23447. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23448. type: string
  23449. namespace:
  23450. description: |-
  23451. The namespace of the Secret resource being referred to.
  23452. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23453. maxLength: 63
  23454. minLength: 1
  23455. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23456. type: string
  23457. type: object
  23458. secretAccessKeySecretRef:
  23459. description: The SecretAccessKey is used for authentication
  23460. properties:
  23461. key:
  23462. description: |-
  23463. A key in the referenced Secret.
  23464. Some instances of this field may be defaulted, in others it may be required.
  23465. maxLength: 253
  23466. minLength: 1
  23467. pattern: ^[-._a-zA-Z0-9]+$
  23468. type: string
  23469. name:
  23470. description: The name of the Secret resource being referred to.
  23471. maxLength: 253
  23472. minLength: 1
  23473. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23474. type: string
  23475. namespace:
  23476. description: |-
  23477. The namespace of the Secret resource being referred to.
  23478. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23479. maxLength: 63
  23480. minLength: 1
  23481. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23482. type: string
  23483. type: object
  23484. sessionTokenSecretRef:
  23485. description: |-
  23486. The SessionToken used for authentication
  23487. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  23488. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  23489. properties:
  23490. key:
  23491. description: |-
  23492. A key in the referenced Secret.
  23493. Some instances of this field may be defaulted, in others it may be required.
  23494. maxLength: 253
  23495. minLength: 1
  23496. pattern: ^[-._a-zA-Z0-9]+$
  23497. type: string
  23498. name:
  23499. description: The name of the Secret resource being referred to.
  23500. maxLength: 253
  23501. minLength: 1
  23502. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23503. type: string
  23504. namespace:
  23505. description: |-
  23506. The namespace of the Secret resource being referred to.
  23507. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23508. maxLength: 63
  23509. minLength: 1
  23510. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23511. type: string
  23512. type: object
  23513. type: object
  23514. type: object
  23515. externalID:
  23516. description: AWS External ID set on assumed IAM roles
  23517. type: string
  23518. prefix:
  23519. description: Prefix adds a prefix to all retrieved values.
  23520. type: string
  23521. region:
  23522. description: AWS Region to be used for the provider
  23523. type: string
  23524. role:
  23525. description: Role is a Role ARN which the provider will assume
  23526. type: string
  23527. secretsManager:
  23528. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  23529. properties:
  23530. forceDeleteWithoutRecovery:
  23531. description: |-
  23532. Specifies whether to delete the secret without any recovery window. You
  23533. can't use both this parameter and RecoveryWindowInDays in the same call.
  23534. If you don't use either, then by default Secrets Manager uses a 30 day
  23535. recovery window.
  23536. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  23537. type: boolean
  23538. recoveryWindowInDays:
  23539. description: |-
  23540. The number of days from 7 to 30 that Secrets Manager waits before
  23541. permanently deleting the secret. You can't use both this parameter and
  23542. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  23543. then by default Secrets Manager uses a 30 day recovery window.
  23544. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  23545. format: int64
  23546. type: integer
  23547. type: object
  23548. service:
  23549. description: Service defines which service should be used to fetch the secrets
  23550. enum:
  23551. - SecretsManager
  23552. - ParameterStore
  23553. type: string
  23554. sessionTags:
  23555. description: AWS STS assume role session tags
  23556. items:
  23557. description: Tag defines a tag key and value for AWS resources.
  23558. properties:
  23559. key:
  23560. type: string
  23561. value:
  23562. type: string
  23563. required:
  23564. - key
  23565. - value
  23566. type: object
  23567. type: array
  23568. transitiveTagKeys:
  23569. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  23570. items:
  23571. type: string
  23572. type: array
  23573. required:
  23574. - region
  23575. - service
  23576. type: object
  23577. azurekv:
  23578. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  23579. properties:
  23580. authSecretRef:
  23581. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  23582. properties:
  23583. clientCertificate:
  23584. description: The Azure ClientCertificate of the service principle used for authentication.
  23585. properties:
  23586. key:
  23587. description: |-
  23588. A key in the referenced Secret.
  23589. Some instances of this field may be defaulted, in others it may be required.
  23590. maxLength: 253
  23591. minLength: 1
  23592. pattern: ^[-._a-zA-Z0-9]+$
  23593. type: string
  23594. name:
  23595. description: The name of the Secret resource being referred to.
  23596. maxLength: 253
  23597. minLength: 1
  23598. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23599. type: string
  23600. namespace:
  23601. description: |-
  23602. The namespace of the Secret resource being referred to.
  23603. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23604. maxLength: 63
  23605. minLength: 1
  23606. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23607. type: string
  23608. type: object
  23609. clientId:
  23610. description: The Azure clientId of the service principle or managed identity used for authentication.
  23611. properties:
  23612. key:
  23613. description: |-
  23614. A key in the referenced Secret.
  23615. Some instances of this field may be defaulted, in others it may be required.
  23616. maxLength: 253
  23617. minLength: 1
  23618. pattern: ^[-._a-zA-Z0-9]+$
  23619. type: string
  23620. name:
  23621. description: The name of the Secret resource being referred to.
  23622. maxLength: 253
  23623. minLength: 1
  23624. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23625. type: string
  23626. namespace:
  23627. description: |-
  23628. The namespace of the Secret resource being referred to.
  23629. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23630. maxLength: 63
  23631. minLength: 1
  23632. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23633. type: string
  23634. type: object
  23635. clientSecret:
  23636. description: The Azure ClientSecret of the service principle used for authentication.
  23637. properties:
  23638. key:
  23639. description: |-
  23640. A key in the referenced Secret.
  23641. Some instances of this field may be defaulted, in others it may be required.
  23642. maxLength: 253
  23643. minLength: 1
  23644. pattern: ^[-._a-zA-Z0-9]+$
  23645. type: string
  23646. name:
  23647. description: The name of the Secret resource being referred to.
  23648. maxLength: 253
  23649. minLength: 1
  23650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23651. type: string
  23652. namespace:
  23653. description: |-
  23654. The namespace of the Secret resource being referred to.
  23655. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23656. maxLength: 63
  23657. minLength: 1
  23658. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23659. type: string
  23660. type: object
  23661. tenantId:
  23662. description: The Azure tenantId of the managed identity used for authentication.
  23663. properties:
  23664. key:
  23665. description: |-
  23666. A key in the referenced Secret.
  23667. Some instances of this field may be defaulted, in others it may be required.
  23668. maxLength: 253
  23669. minLength: 1
  23670. pattern: ^[-._a-zA-Z0-9]+$
  23671. type: string
  23672. name:
  23673. description: The name of the Secret resource being referred to.
  23674. maxLength: 253
  23675. minLength: 1
  23676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23677. type: string
  23678. namespace:
  23679. description: |-
  23680. The namespace of the Secret resource being referred to.
  23681. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23682. maxLength: 63
  23683. minLength: 1
  23684. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23685. type: string
  23686. type: object
  23687. type: object
  23688. authType:
  23689. default: ServicePrincipal
  23690. description: |-
  23691. Auth type defines how to authenticate to the keyvault service.
  23692. Valid values are:
  23693. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  23694. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  23695. enum:
  23696. - ServicePrincipal
  23697. - ManagedIdentity
  23698. - WorkloadIdentity
  23699. type: string
  23700. environmentType:
  23701. default: PublicCloud
  23702. description: |-
  23703. EnvironmentType specifies the Azure cloud environment endpoints to use for
  23704. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  23705. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  23706. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  23707. enum:
  23708. - PublicCloud
  23709. - USGovernmentCloud
  23710. - ChinaCloud
  23711. - GermanCloud
  23712. type: string
  23713. identityId:
  23714. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  23715. type: string
  23716. serviceAccountRef:
  23717. description: |-
  23718. ServiceAccountRef specified the service account
  23719. that should be used when authenticating with WorkloadIdentity.
  23720. properties:
  23721. audiences:
  23722. description: |-
  23723. Audience specifies the `aud` claim for the service account token
  23724. Some providers automatically extend the audience field based on well-known annotations for workload
  23725. identity (e.g. IRSA or GCP Workload Identity)
  23726. items:
  23727. type: string
  23728. type: array
  23729. name:
  23730. description: The name of the ServiceAccount resource being referred to.
  23731. maxLength: 253
  23732. minLength: 1
  23733. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23734. type: string
  23735. namespace:
  23736. description: |-
  23737. Namespace of the resource being referred to.
  23738. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23739. maxLength: 63
  23740. minLength: 1
  23741. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23742. type: string
  23743. required:
  23744. - name
  23745. type: object
  23746. tenantId:
  23747. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  23748. type: string
  23749. vaultUrl:
  23750. description: Vault Url from which the secrets to be fetched from.
  23751. type: string
  23752. required:
  23753. - vaultUrl
  23754. type: object
  23755. beyondtrust:
  23756. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  23757. properties:
  23758. auth:
  23759. description: Auth configures how the operator authenticates with Beyondtrust.
  23760. properties:
  23761. apiKey:
  23762. description: APIKey If not provided then ClientID/ClientSecret become required.
  23763. properties:
  23764. secretRef:
  23765. description: SecretRef references a key in a secret that will be used as value.
  23766. properties:
  23767. key:
  23768. description: |-
  23769. A key in the referenced Secret.
  23770. Some instances of this field may be defaulted, in others it may be required.
  23771. maxLength: 253
  23772. minLength: 1
  23773. pattern: ^[-._a-zA-Z0-9]+$
  23774. type: string
  23775. name:
  23776. description: The name of the Secret resource being referred to.
  23777. maxLength: 253
  23778. minLength: 1
  23779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23780. type: string
  23781. namespace:
  23782. description: |-
  23783. The namespace of the Secret resource being referred to.
  23784. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23785. maxLength: 63
  23786. minLength: 1
  23787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23788. type: string
  23789. type: object
  23790. value:
  23791. description: Value can be specified directly to set a value without using a secret.
  23792. type: string
  23793. type: object
  23794. certificate:
  23795. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  23796. properties:
  23797. secretRef:
  23798. description: SecretRef references a key in a secret that will be used as value.
  23799. properties:
  23800. key:
  23801. description: |-
  23802. A key in the referenced Secret.
  23803. Some instances of this field may be defaulted, in others it may be required.
  23804. maxLength: 253
  23805. minLength: 1
  23806. pattern: ^[-._a-zA-Z0-9]+$
  23807. type: string
  23808. name:
  23809. description: The name of the Secret resource being referred to.
  23810. maxLength: 253
  23811. minLength: 1
  23812. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23813. type: string
  23814. namespace:
  23815. description: |-
  23816. The namespace of the Secret resource being referred to.
  23817. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23818. maxLength: 63
  23819. minLength: 1
  23820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23821. type: string
  23822. type: object
  23823. value:
  23824. description: Value can be specified directly to set a value without using a secret.
  23825. type: string
  23826. type: object
  23827. certificateKey:
  23828. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  23829. properties:
  23830. secretRef:
  23831. description: SecretRef references a key in a secret that will be used as value.
  23832. properties:
  23833. key:
  23834. description: |-
  23835. A key in the referenced Secret.
  23836. Some instances of this field may be defaulted, in others it may be required.
  23837. maxLength: 253
  23838. minLength: 1
  23839. pattern: ^[-._a-zA-Z0-9]+$
  23840. type: string
  23841. name:
  23842. description: The name of the Secret resource being referred to.
  23843. maxLength: 253
  23844. minLength: 1
  23845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23846. type: string
  23847. namespace:
  23848. description: |-
  23849. The namespace of the Secret resource being referred to.
  23850. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23851. maxLength: 63
  23852. minLength: 1
  23853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23854. type: string
  23855. type: object
  23856. value:
  23857. description: Value can be specified directly to set a value without using a secret.
  23858. type: string
  23859. type: object
  23860. clientId:
  23861. description: ClientID is the API OAuth Client ID.
  23862. properties:
  23863. secretRef:
  23864. description: SecretRef references a key in a secret that will be used as value.
  23865. properties:
  23866. key:
  23867. description: |-
  23868. A key in the referenced Secret.
  23869. Some instances of this field may be defaulted, in others it may be required.
  23870. maxLength: 253
  23871. minLength: 1
  23872. pattern: ^[-._a-zA-Z0-9]+$
  23873. type: string
  23874. name:
  23875. description: The name of the Secret resource being referred to.
  23876. maxLength: 253
  23877. minLength: 1
  23878. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23879. type: string
  23880. namespace:
  23881. description: |-
  23882. The namespace of the Secret resource being referred to.
  23883. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23884. maxLength: 63
  23885. minLength: 1
  23886. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23887. type: string
  23888. type: object
  23889. value:
  23890. description: Value can be specified directly to set a value without using a secret.
  23891. type: string
  23892. type: object
  23893. clientSecret:
  23894. description: ClientSecret is the API OAuth Client Secret.
  23895. properties:
  23896. secretRef:
  23897. description: SecretRef references a key in a secret that will be used as value.
  23898. properties:
  23899. key:
  23900. description: |-
  23901. A key in the referenced Secret.
  23902. Some instances of this field may be defaulted, in others it may be required.
  23903. maxLength: 253
  23904. minLength: 1
  23905. pattern: ^[-._a-zA-Z0-9]+$
  23906. type: string
  23907. name:
  23908. description: The name of the Secret resource being referred to.
  23909. maxLength: 253
  23910. minLength: 1
  23911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23912. type: string
  23913. namespace:
  23914. description: |-
  23915. The namespace of the Secret resource being referred to.
  23916. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23917. maxLength: 63
  23918. minLength: 1
  23919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23920. type: string
  23921. type: object
  23922. value:
  23923. description: Value can be specified directly to set a value without using a secret.
  23924. type: string
  23925. type: object
  23926. type: object
  23927. server:
  23928. description: Auth configures how API server works.
  23929. properties:
  23930. apiUrl:
  23931. type: string
  23932. apiVersion:
  23933. type: string
  23934. clientTimeOutSeconds:
  23935. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  23936. type: integer
  23937. decrypt:
  23938. default: true
  23939. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  23940. type: boolean
  23941. retrievalType:
  23942. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  23943. type: string
  23944. separator:
  23945. description: A character that separates the folder names.
  23946. type: string
  23947. verifyCA:
  23948. type: boolean
  23949. required:
  23950. - apiUrl
  23951. - verifyCA
  23952. type: object
  23953. required:
  23954. - auth
  23955. - server
  23956. type: object
  23957. bitwardensecretsmanager:
  23958. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  23959. properties:
  23960. apiURL:
  23961. type: string
  23962. auth:
  23963. description: |-
  23964. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  23965. Make sure that the token being used has permissions on the given secret.
  23966. properties:
  23967. secretRef:
  23968. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  23969. properties:
  23970. credentials:
  23971. description: AccessToken used for the bitwarden instance.
  23972. properties:
  23973. key:
  23974. description: |-
  23975. A key in the referenced Secret.
  23976. Some instances of this field may be defaulted, in others it may be required.
  23977. maxLength: 253
  23978. minLength: 1
  23979. pattern: ^[-._a-zA-Z0-9]+$
  23980. type: string
  23981. name:
  23982. description: The name of the Secret resource being referred to.
  23983. maxLength: 253
  23984. minLength: 1
  23985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23986. type: string
  23987. namespace:
  23988. description: |-
  23989. The namespace of the Secret resource being referred to.
  23990. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23991. maxLength: 63
  23992. minLength: 1
  23993. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23994. type: string
  23995. type: object
  23996. required:
  23997. - credentials
  23998. type: object
  23999. required:
  24000. - secretRef
  24001. type: object
  24002. bitwardenServerSDKURL:
  24003. type: string
  24004. caBundle:
  24005. description: |-
  24006. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  24007. can be performed.
  24008. type: string
  24009. caProvider:
  24010. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  24011. properties:
  24012. key:
  24013. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24014. maxLength: 253
  24015. minLength: 1
  24016. pattern: ^[-._a-zA-Z0-9]+$
  24017. type: string
  24018. name:
  24019. description: The name of the object located at the provider type.
  24020. maxLength: 253
  24021. minLength: 1
  24022. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24023. type: string
  24024. namespace:
  24025. description: |-
  24026. The namespace the Provider type is in.
  24027. Can only be defined when used in a ClusterSecretStore.
  24028. maxLength: 63
  24029. minLength: 1
  24030. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24031. type: string
  24032. type:
  24033. description: The type of provider to use such as "Secret", or "ConfigMap".
  24034. enum:
  24035. - Secret
  24036. - ConfigMap
  24037. type: string
  24038. required:
  24039. - name
  24040. - type
  24041. type: object
  24042. identityURL:
  24043. type: string
  24044. organizationID:
  24045. description: OrganizationID determines which organization this secret store manages.
  24046. type: string
  24047. projectID:
  24048. description: ProjectID determines which project this secret store manages.
  24049. type: string
  24050. required:
  24051. - auth
  24052. - organizationID
  24053. - projectID
  24054. type: object
  24055. chef:
  24056. description: Chef configures this store to sync secrets with chef server
  24057. properties:
  24058. auth:
  24059. description: Auth defines the information necessary to authenticate against chef Server
  24060. properties:
  24061. secretRef:
  24062. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  24063. properties:
  24064. privateKeySecretRef:
  24065. description: SecretKey is the Signing Key in PEM format, used for authentication.
  24066. properties:
  24067. key:
  24068. description: |-
  24069. A key in the referenced Secret.
  24070. Some instances of this field may be defaulted, in others it may be required.
  24071. maxLength: 253
  24072. minLength: 1
  24073. pattern: ^[-._a-zA-Z0-9]+$
  24074. type: string
  24075. name:
  24076. description: The name of the Secret resource being referred to.
  24077. maxLength: 253
  24078. minLength: 1
  24079. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24080. type: string
  24081. namespace:
  24082. description: |-
  24083. The namespace of the Secret resource being referred to.
  24084. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24085. maxLength: 63
  24086. minLength: 1
  24087. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24088. type: string
  24089. type: object
  24090. required:
  24091. - privateKeySecretRef
  24092. type: object
  24093. required:
  24094. - secretRef
  24095. type: object
  24096. serverUrl:
  24097. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  24098. type: string
  24099. username:
  24100. description: UserName should be the user ID on the chef server
  24101. type: string
  24102. required:
  24103. - auth
  24104. - serverUrl
  24105. - username
  24106. type: object
  24107. cloudrusm:
  24108. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  24109. properties:
  24110. auth:
  24111. description: CSMAuth contains a secretRef for credentials.
  24112. properties:
  24113. secretRef:
  24114. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  24115. properties:
  24116. accessKeyIDSecretRef:
  24117. description: The AccessKeyID is used for authentication
  24118. properties:
  24119. key:
  24120. description: |-
  24121. A key in the referenced Secret.
  24122. Some instances of this field may be defaulted, in others it may be required.
  24123. maxLength: 253
  24124. minLength: 1
  24125. pattern: ^[-._a-zA-Z0-9]+$
  24126. type: string
  24127. name:
  24128. description: The name of the Secret resource being referred to.
  24129. maxLength: 253
  24130. minLength: 1
  24131. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24132. type: string
  24133. namespace:
  24134. description: |-
  24135. The namespace of the Secret resource being referred to.
  24136. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24137. maxLength: 63
  24138. minLength: 1
  24139. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24140. type: string
  24141. type: object
  24142. accessKeySecretSecretRef:
  24143. description: The AccessKeySecret is used for authentication
  24144. properties:
  24145. key:
  24146. description: |-
  24147. A key in the referenced Secret.
  24148. Some instances of this field may be defaulted, in others it may be required.
  24149. maxLength: 253
  24150. minLength: 1
  24151. pattern: ^[-._a-zA-Z0-9]+$
  24152. type: string
  24153. name:
  24154. description: The name of the Secret resource being referred to.
  24155. maxLength: 253
  24156. minLength: 1
  24157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24158. type: string
  24159. namespace:
  24160. description: |-
  24161. The namespace of the Secret resource being referred to.
  24162. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24163. maxLength: 63
  24164. minLength: 1
  24165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24166. type: string
  24167. type: object
  24168. required:
  24169. - accessKeyIDSecretRef
  24170. - accessKeySecretSecretRef
  24171. type: object
  24172. type: object
  24173. projectID:
  24174. description: ProjectID is the project, which the secrets are stored in.
  24175. type: string
  24176. required:
  24177. - auth
  24178. type: object
  24179. conjur:
  24180. description: Conjur configures this store to sync secrets using conjur provider
  24181. properties:
  24182. auth:
  24183. description: Defines authentication settings for connecting to Conjur.
  24184. properties:
  24185. apikey:
  24186. description: Authenticates with Conjur using an API key.
  24187. properties:
  24188. account:
  24189. description: Account is the Conjur organization account name.
  24190. type: string
  24191. apiKeyRef:
  24192. description: |-
  24193. A reference to a specific 'key' containing the Conjur API key
  24194. within a Secret resource. In some instances, `key` is a required field.
  24195. properties:
  24196. key:
  24197. description: |-
  24198. A key in the referenced Secret.
  24199. Some instances of this field may be defaulted, in others it may be required.
  24200. maxLength: 253
  24201. minLength: 1
  24202. pattern: ^[-._a-zA-Z0-9]+$
  24203. type: string
  24204. name:
  24205. description: The name of the Secret resource being referred to.
  24206. maxLength: 253
  24207. minLength: 1
  24208. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24209. type: string
  24210. namespace:
  24211. description: |-
  24212. The namespace of the Secret resource being referred to.
  24213. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24214. maxLength: 63
  24215. minLength: 1
  24216. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24217. type: string
  24218. type: object
  24219. userRef:
  24220. description: |-
  24221. A reference to a specific 'key' containing the Conjur username
  24222. within a Secret resource. In some instances, `key` is a required field.
  24223. properties:
  24224. key:
  24225. description: |-
  24226. A key in the referenced Secret.
  24227. Some instances of this field may be defaulted, in others it may be required.
  24228. maxLength: 253
  24229. minLength: 1
  24230. pattern: ^[-._a-zA-Z0-9]+$
  24231. type: string
  24232. name:
  24233. description: The name of the Secret resource being referred to.
  24234. maxLength: 253
  24235. minLength: 1
  24236. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24237. type: string
  24238. namespace:
  24239. description: |-
  24240. The namespace of the Secret resource being referred to.
  24241. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24242. maxLength: 63
  24243. minLength: 1
  24244. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24245. type: string
  24246. type: object
  24247. required:
  24248. - account
  24249. - apiKeyRef
  24250. - userRef
  24251. type: object
  24252. jwt:
  24253. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  24254. properties:
  24255. account:
  24256. description: Account is the Conjur organization account name.
  24257. type: string
  24258. hostId:
  24259. description: |-
  24260. Optional HostID for JWT authentication. This may be used depending
  24261. on how the Conjur JWT authenticator policy is configured.
  24262. type: string
  24263. secretRef:
  24264. description: |-
  24265. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  24266. authenticate with Conjur using the JWT authentication method.
  24267. properties:
  24268. key:
  24269. description: |-
  24270. A key in the referenced Secret.
  24271. Some instances of this field may be defaulted, in others it may be required.
  24272. maxLength: 253
  24273. minLength: 1
  24274. pattern: ^[-._a-zA-Z0-9]+$
  24275. type: string
  24276. name:
  24277. description: The name of the Secret resource being referred to.
  24278. maxLength: 253
  24279. minLength: 1
  24280. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24281. type: string
  24282. namespace:
  24283. description: |-
  24284. The namespace of the Secret resource being referred to.
  24285. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24286. maxLength: 63
  24287. minLength: 1
  24288. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24289. type: string
  24290. type: object
  24291. serviceAccountRef:
  24292. description: |-
  24293. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  24294. a token for with the `TokenRequest` API.
  24295. properties:
  24296. audiences:
  24297. description: |-
  24298. Audience specifies the `aud` claim for the service account token
  24299. Some providers automatically extend the audience field based on well-known annotations for workload
  24300. identity (e.g. IRSA or GCP Workload Identity)
  24301. items:
  24302. type: string
  24303. type: array
  24304. name:
  24305. description: The name of the ServiceAccount resource being referred to.
  24306. maxLength: 253
  24307. minLength: 1
  24308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24309. type: string
  24310. namespace:
  24311. description: |-
  24312. Namespace of the resource being referred to.
  24313. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24314. maxLength: 63
  24315. minLength: 1
  24316. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24317. type: string
  24318. required:
  24319. - name
  24320. type: object
  24321. serviceID:
  24322. description: The conjur authn jwt webservice id
  24323. type: string
  24324. required:
  24325. - account
  24326. - serviceID
  24327. type: object
  24328. type: object
  24329. caBundle:
  24330. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  24331. type: string
  24332. caProvider:
  24333. description: |-
  24334. Used to provide custom certificate authority (CA) certificates
  24335. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  24336. that contains a PEM-encoded certificate.
  24337. properties:
  24338. key:
  24339. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24340. maxLength: 253
  24341. minLength: 1
  24342. pattern: ^[-._a-zA-Z0-9]+$
  24343. type: string
  24344. name:
  24345. description: The name of the object located at the provider type.
  24346. maxLength: 253
  24347. minLength: 1
  24348. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24349. type: string
  24350. namespace:
  24351. description: |-
  24352. The namespace the Provider type is in.
  24353. Can only be defined when used in a ClusterSecretStore.
  24354. maxLength: 63
  24355. minLength: 1
  24356. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24357. type: string
  24358. type:
  24359. description: The type of provider to use such as "Secret", or "ConfigMap".
  24360. enum:
  24361. - Secret
  24362. - ConfigMap
  24363. type: string
  24364. required:
  24365. - name
  24366. - type
  24367. type: object
  24368. url:
  24369. description: URL is the endpoint of the Conjur instance.
  24370. type: string
  24371. required:
  24372. - auth
  24373. - url
  24374. type: object
  24375. delinea:
  24376. description: |-
  24377. Delinea DevOps Secrets Vault
  24378. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  24379. properties:
  24380. clientId:
  24381. description: ClientID is the non-secret part of the credential.
  24382. properties:
  24383. secretRef:
  24384. description: SecretRef references a key in a secret that will be used as value.
  24385. properties:
  24386. key:
  24387. description: |-
  24388. A key in the referenced Secret.
  24389. Some instances of this field may be defaulted, in others it may be required.
  24390. maxLength: 253
  24391. minLength: 1
  24392. pattern: ^[-._a-zA-Z0-9]+$
  24393. type: string
  24394. name:
  24395. description: The name of the Secret resource being referred to.
  24396. maxLength: 253
  24397. minLength: 1
  24398. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24399. type: string
  24400. namespace:
  24401. description: |-
  24402. The namespace of the Secret resource being referred to.
  24403. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24404. maxLength: 63
  24405. minLength: 1
  24406. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24407. type: string
  24408. type: object
  24409. value:
  24410. description: Value can be specified directly to set a value without using a secret.
  24411. type: string
  24412. type: object
  24413. clientSecret:
  24414. description: ClientSecret is the secret part of the credential.
  24415. properties:
  24416. secretRef:
  24417. description: SecretRef references a key in a secret that will be used as value.
  24418. properties:
  24419. key:
  24420. description: |-
  24421. A key in the referenced Secret.
  24422. Some instances of this field may be defaulted, in others it may be required.
  24423. maxLength: 253
  24424. minLength: 1
  24425. pattern: ^[-._a-zA-Z0-9]+$
  24426. type: string
  24427. name:
  24428. description: The name of the Secret resource being referred to.
  24429. maxLength: 253
  24430. minLength: 1
  24431. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24432. type: string
  24433. namespace:
  24434. description: |-
  24435. The namespace of the Secret resource being referred to.
  24436. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24437. maxLength: 63
  24438. minLength: 1
  24439. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24440. type: string
  24441. type: object
  24442. value:
  24443. description: Value can be specified directly to set a value without using a secret.
  24444. type: string
  24445. type: object
  24446. tenant:
  24447. description: Tenant is the chosen hostname / site name.
  24448. type: string
  24449. tld:
  24450. description: |-
  24451. TLD is based on the server location that was chosen during provisioning.
  24452. If unset, defaults to "com".
  24453. type: string
  24454. urlTemplate:
  24455. description: |-
  24456. URLTemplate
  24457. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  24458. type: string
  24459. required:
  24460. - clientId
  24461. - clientSecret
  24462. - tenant
  24463. type: object
  24464. device42:
  24465. description: Device42 configures this store to sync secrets using the Device42 provider
  24466. properties:
  24467. auth:
  24468. description: Auth configures how secret-manager authenticates with a Device42 instance.
  24469. properties:
  24470. secretRef:
  24471. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  24472. properties:
  24473. credentials:
  24474. description: Username / Password is used for authentication.
  24475. properties:
  24476. key:
  24477. description: |-
  24478. A key in the referenced Secret.
  24479. Some instances of this field may be defaulted, in others it may be required.
  24480. maxLength: 253
  24481. minLength: 1
  24482. pattern: ^[-._a-zA-Z0-9]+$
  24483. type: string
  24484. name:
  24485. description: The name of the Secret resource being referred to.
  24486. maxLength: 253
  24487. minLength: 1
  24488. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24489. type: string
  24490. namespace:
  24491. description: |-
  24492. The namespace of the Secret resource being referred to.
  24493. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24494. maxLength: 63
  24495. minLength: 1
  24496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24497. type: string
  24498. type: object
  24499. type: object
  24500. required:
  24501. - secretRef
  24502. type: object
  24503. host:
  24504. description: URL configures the Device42 instance URL.
  24505. type: string
  24506. required:
  24507. - auth
  24508. - host
  24509. type: object
  24510. doppler:
  24511. description: Doppler configures this store to sync secrets using the Doppler provider
  24512. properties:
  24513. auth:
  24514. description: Auth configures how the Operator authenticates with the Doppler API
  24515. properties:
  24516. secretRef:
  24517. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  24518. properties:
  24519. dopplerToken:
  24520. description: |-
  24521. The DopplerToken is used for authentication.
  24522. See https://docs.doppler.com/reference/api#authentication for auth token types.
  24523. The Key attribute defaults to dopplerToken if not specified.
  24524. properties:
  24525. key:
  24526. description: |-
  24527. A key in the referenced Secret.
  24528. Some instances of this field may be defaulted, in others it may be required.
  24529. maxLength: 253
  24530. minLength: 1
  24531. pattern: ^[-._a-zA-Z0-9]+$
  24532. type: string
  24533. name:
  24534. description: The name of the Secret resource being referred to.
  24535. maxLength: 253
  24536. minLength: 1
  24537. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24538. type: string
  24539. namespace:
  24540. description: |-
  24541. The namespace of the Secret resource being referred to.
  24542. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24543. maxLength: 63
  24544. minLength: 1
  24545. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24546. type: string
  24547. type: object
  24548. required:
  24549. - dopplerToken
  24550. type: object
  24551. required:
  24552. - secretRef
  24553. type: object
  24554. config:
  24555. description: Doppler config (required if not using a Service Token)
  24556. type: string
  24557. format:
  24558. description: Format enables the downloading of secrets as a file (string)
  24559. enum:
  24560. - json
  24561. - dotnet-json
  24562. - env
  24563. - yaml
  24564. - docker
  24565. type: string
  24566. nameTransformer:
  24567. description: Environment variable compatible name transforms that change secret names to a different format
  24568. enum:
  24569. - upper-camel
  24570. - camel
  24571. - lower-snake
  24572. - tf-var
  24573. - dotnet-env
  24574. - lower-kebab
  24575. type: string
  24576. project:
  24577. description: Doppler project (required if not using a Service Token)
  24578. type: string
  24579. required:
  24580. - auth
  24581. type: object
  24582. fake:
  24583. description: Fake configures a store with static key/value pairs
  24584. properties:
  24585. data:
  24586. items:
  24587. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  24588. properties:
  24589. key:
  24590. type: string
  24591. value:
  24592. type: string
  24593. version:
  24594. type: string
  24595. required:
  24596. - key
  24597. - value
  24598. type: object
  24599. type: array
  24600. required:
  24601. - data
  24602. type: object
  24603. fortanix:
  24604. description: Fortanix configures this store to sync secrets using the Fortanix provider
  24605. properties:
  24606. apiKey:
  24607. description: APIKey is the API token to access SDKMS Applications.
  24608. properties:
  24609. secretRef:
  24610. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  24611. properties:
  24612. key:
  24613. description: |-
  24614. A key in the referenced Secret.
  24615. Some instances of this field may be defaulted, in others it may be required.
  24616. maxLength: 253
  24617. minLength: 1
  24618. pattern: ^[-._a-zA-Z0-9]+$
  24619. type: string
  24620. name:
  24621. description: The name of the Secret resource being referred to.
  24622. maxLength: 253
  24623. minLength: 1
  24624. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24625. type: string
  24626. namespace:
  24627. description: |-
  24628. The namespace of the Secret resource being referred to.
  24629. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24630. maxLength: 63
  24631. minLength: 1
  24632. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24633. type: string
  24634. type: object
  24635. type: object
  24636. apiUrl:
  24637. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  24638. type: string
  24639. type: object
  24640. gcpsm:
  24641. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  24642. properties:
  24643. auth:
  24644. description: Auth defines the information necessary to authenticate against GCP
  24645. properties:
  24646. secretRef:
  24647. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  24648. properties:
  24649. secretAccessKeySecretRef:
  24650. description: The SecretAccessKey is used for authentication
  24651. properties:
  24652. key:
  24653. description: |-
  24654. A key in the referenced Secret.
  24655. Some instances of this field may be defaulted, in others it may be required.
  24656. maxLength: 253
  24657. minLength: 1
  24658. pattern: ^[-._a-zA-Z0-9]+$
  24659. type: string
  24660. name:
  24661. description: The name of the Secret resource being referred to.
  24662. maxLength: 253
  24663. minLength: 1
  24664. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24665. type: string
  24666. namespace:
  24667. description: |-
  24668. The namespace of the Secret resource being referred to.
  24669. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24670. maxLength: 63
  24671. minLength: 1
  24672. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24673. type: string
  24674. type: object
  24675. type: object
  24676. workloadIdentity:
  24677. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  24678. properties:
  24679. clusterLocation:
  24680. description: |-
  24681. ClusterLocation is the location of the cluster
  24682. If not specified, it fetches information from the metadata server
  24683. type: string
  24684. clusterName:
  24685. description: |-
  24686. ClusterName is the name of the cluster
  24687. If not specified, it fetches information from the metadata server
  24688. type: string
  24689. clusterProjectID:
  24690. description: |-
  24691. ClusterProjectID is the project ID of the cluster
  24692. If not specified, it fetches information from the metadata server
  24693. type: string
  24694. serviceAccountRef:
  24695. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  24696. properties:
  24697. audiences:
  24698. description: |-
  24699. Audience specifies the `aud` claim for the service account token
  24700. Some providers automatically extend the audience field based on well-known annotations for workload
  24701. identity (e.g. IRSA or GCP Workload Identity)
  24702. items:
  24703. type: string
  24704. type: array
  24705. name:
  24706. description: The name of the ServiceAccount resource being referred to.
  24707. maxLength: 253
  24708. minLength: 1
  24709. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24710. type: string
  24711. namespace:
  24712. description: |-
  24713. Namespace of the resource being referred to.
  24714. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24715. maxLength: 63
  24716. minLength: 1
  24717. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24718. type: string
  24719. required:
  24720. - name
  24721. type: object
  24722. required:
  24723. - serviceAccountRef
  24724. type: object
  24725. type: object
  24726. location:
  24727. description: Location optionally defines a location for a secret
  24728. type: string
  24729. projectID:
  24730. description: ProjectID project where secret is located
  24731. type: string
  24732. type: object
  24733. github:
  24734. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  24735. properties:
  24736. appID:
  24737. description: appID specifies the Github APP that will be used to authenticate the client
  24738. format: int64
  24739. type: integer
  24740. auth:
  24741. description: auth configures how secret-manager authenticates with a Github instance.
  24742. properties:
  24743. privateKey:
  24744. description: |-
  24745. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24746. In some instances, `key` is a required field.
  24747. properties:
  24748. key:
  24749. description: |-
  24750. A key in the referenced Secret.
  24751. Some instances of this field may be defaulted, in others it may be required.
  24752. maxLength: 253
  24753. minLength: 1
  24754. pattern: ^[-._a-zA-Z0-9]+$
  24755. type: string
  24756. name:
  24757. description: The name of the Secret resource being referred to.
  24758. maxLength: 253
  24759. minLength: 1
  24760. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24761. type: string
  24762. namespace:
  24763. description: |-
  24764. The namespace of the Secret resource being referred to.
  24765. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24766. maxLength: 63
  24767. minLength: 1
  24768. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24769. type: string
  24770. type: object
  24771. required:
  24772. - privateKey
  24773. type: object
  24774. environment:
  24775. description: environment will be used to fetch secrets from a particular environment within a github repository
  24776. type: string
  24777. installationID:
  24778. description: installationID specifies the Github APP installation that will be used to authenticate the client
  24779. format: int64
  24780. type: integer
  24781. organization:
  24782. description: organization will be used to fetch secrets from the Github organization
  24783. type: string
  24784. repository:
  24785. description: repository will be used to fetch secrets from the Github repository within an organization
  24786. type: string
  24787. uploadURL:
  24788. description: Upload URL for enterprise instances. Default to URL.
  24789. type: string
  24790. url:
  24791. default: https://github.com/
  24792. description: URL configures the Github instance URL. Defaults to https://github.com/.
  24793. type: string
  24794. required:
  24795. - appID
  24796. - auth
  24797. - installationID
  24798. - organization
  24799. type: object
  24800. gitlab:
  24801. description: GitLab configures this store to sync secrets using GitLab Variables provider
  24802. properties:
  24803. auth:
  24804. description: Auth configures how secret-manager authenticates with a GitLab instance.
  24805. properties:
  24806. SecretRef:
  24807. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  24808. properties:
  24809. accessToken:
  24810. description: AccessToken is used for authentication.
  24811. properties:
  24812. key:
  24813. description: |-
  24814. A key in the referenced Secret.
  24815. Some instances of this field may be defaulted, in others it may be required.
  24816. maxLength: 253
  24817. minLength: 1
  24818. pattern: ^[-._a-zA-Z0-9]+$
  24819. type: string
  24820. name:
  24821. description: The name of the Secret resource being referred to.
  24822. maxLength: 253
  24823. minLength: 1
  24824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24825. type: string
  24826. namespace:
  24827. description: |-
  24828. The namespace of the Secret resource being referred to.
  24829. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24830. maxLength: 63
  24831. minLength: 1
  24832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24833. type: string
  24834. type: object
  24835. type: object
  24836. required:
  24837. - SecretRef
  24838. type: object
  24839. caBundle:
  24840. description: |-
  24841. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  24842. can be performed.
  24843. format: byte
  24844. type: string
  24845. caProvider:
  24846. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  24847. properties:
  24848. key:
  24849. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24850. maxLength: 253
  24851. minLength: 1
  24852. pattern: ^[-._a-zA-Z0-9]+$
  24853. type: string
  24854. name:
  24855. description: The name of the object located at the provider type.
  24856. maxLength: 253
  24857. minLength: 1
  24858. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24859. type: string
  24860. namespace:
  24861. description: |-
  24862. The namespace the Provider type is in.
  24863. Can only be defined when used in a ClusterSecretStore.
  24864. maxLength: 63
  24865. minLength: 1
  24866. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24867. type: string
  24868. type:
  24869. description: The type of provider to use such as "Secret", or "ConfigMap".
  24870. enum:
  24871. - Secret
  24872. - ConfigMap
  24873. type: string
  24874. required:
  24875. - name
  24876. - type
  24877. type: object
  24878. environment:
  24879. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  24880. type: string
  24881. groupIDs:
  24882. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  24883. items:
  24884. type: string
  24885. type: array
  24886. inheritFromGroups:
  24887. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  24888. type: boolean
  24889. projectID:
  24890. description: ProjectID specifies a project where secrets are located.
  24891. type: string
  24892. url:
  24893. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  24894. type: string
  24895. required:
  24896. - auth
  24897. type: object
  24898. ibm:
  24899. description: IBM configures this store to sync secrets using IBM Cloud provider
  24900. properties:
  24901. auth:
  24902. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  24903. maxProperties: 1
  24904. minProperties: 1
  24905. properties:
  24906. containerAuth:
  24907. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  24908. properties:
  24909. iamEndpoint:
  24910. type: string
  24911. profile:
  24912. description: the IBM Trusted Profile
  24913. type: string
  24914. tokenLocation:
  24915. description: Location the token is mounted on the pod
  24916. type: string
  24917. required:
  24918. - profile
  24919. type: object
  24920. secretRef:
  24921. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  24922. properties:
  24923. secretApiKeySecretRef:
  24924. description: The SecretAccessKey is used for authentication
  24925. properties:
  24926. key:
  24927. description: |-
  24928. A key in the referenced Secret.
  24929. Some instances of this field may be defaulted, in others it may be required.
  24930. maxLength: 253
  24931. minLength: 1
  24932. pattern: ^[-._a-zA-Z0-9]+$
  24933. type: string
  24934. name:
  24935. description: The name of the Secret resource being referred to.
  24936. maxLength: 253
  24937. minLength: 1
  24938. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24939. type: string
  24940. namespace:
  24941. description: |-
  24942. The namespace of the Secret resource being referred to.
  24943. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24944. maxLength: 63
  24945. minLength: 1
  24946. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24947. type: string
  24948. type: object
  24949. type: object
  24950. type: object
  24951. serviceUrl:
  24952. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  24953. type: string
  24954. required:
  24955. - auth
  24956. type: object
  24957. infisical:
  24958. description: Infisical configures this store to sync secrets using the Infisical provider
  24959. properties:
  24960. auth:
  24961. description: Auth configures how the Operator authenticates with the Infisical API
  24962. properties:
  24963. universalAuthCredentials:
  24964. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  24965. properties:
  24966. clientId:
  24967. description: |-
  24968. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24969. In some instances, `key` is a required field.
  24970. properties:
  24971. key:
  24972. description: |-
  24973. A key in the referenced Secret.
  24974. Some instances of this field may be defaulted, in others it may be required.
  24975. maxLength: 253
  24976. minLength: 1
  24977. pattern: ^[-._a-zA-Z0-9]+$
  24978. type: string
  24979. name:
  24980. description: The name of the Secret resource being referred to.
  24981. maxLength: 253
  24982. minLength: 1
  24983. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24984. type: string
  24985. namespace:
  24986. description: |-
  24987. The namespace of the Secret resource being referred to.
  24988. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24989. maxLength: 63
  24990. minLength: 1
  24991. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24992. type: string
  24993. type: object
  24994. clientSecret:
  24995. description: |-
  24996. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24997. In some instances, `key` is a required field.
  24998. properties:
  24999. key:
  25000. description: |-
  25001. A key in the referenced Secret.
  25002. Some instances of this field may be defaulted, in others it may be required.
  25003. maxLength: 253
  25004. minLength: 1
  25005. pattern: ^[-._a-zA-Z0-9]+$
  25006. type: string
  25007. name:
  25008. description: The name of the Secret resource being referred to.
  25009. maxLength: 253
  25010. minLength: 1
  25011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25012. type: string
  25013. namespace:
  25014. description: |-
  25015. The namespace of the Secret resource being referred to.
  25016. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25017. maxLength: 63
  25018. minLength: 1
  25019. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25020. type: string
  25021. type: object
  25022. required:
  25023. - clientId
  25024. - clientSecret
  25025. type: object
  25026. type: object
  25027. hostAPI:
  25028. default: https://app.infisical.com/api
  25029. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  25030. type: string
  25031. secretsScope:
  25032. description: SecretsScope defines the scope of the secrets within the workspace
  25033. properties:
  25034. environmentSlug:
  25035. description: EnvironmentSlug is the required slug identifier for the environment.
  25036. type: string
  25037. expandSecretReferences:
  25038. default: true
  25039. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  25040. type: boolean
  25041. projectSlug:
  25042. description: ProjectSlug is the required slug identifier for the project.
  25043. type: string
  25044. recursive:
  25045. default: false
  25046. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  25047. type: boolean
  25048. secretsPath:
  25049. default: /
  25050. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  25051. type: string
  25052. required:
  25053. - environmentSlug
  25054. - projectSlug
  25055. type: object
  25056. required:
  25057. - auth
  25058. - secretsScope
  25059. type: object
  25060. keepersecurity:
  25061. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  25062. properties:
  25063. authRef:
  25064. description: |-
  25065. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25066. In some instances, `key` is a required field.
  25067. properties:
  25068. key:
  25069. description: |-
  25070. A key in the referenced Secret.
  25071. Some instances of this field may be defaulted, in others it may be required.
  25072. maxLength: 253
  25073. minLength: 1
  25074. pattern: ^[-._a-zA-Z0-9]+$
  25075. type: string
  25076. name:
  25077. description: The name of the Secret resource being referred to.
  25078. maxLength: 253
  25079. minLength: 1
  25080. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25081. type: string
  25082. namespace:
  25083. description: |-
  25084. The namespace of the Secret resource being referred to.
  25085. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25086. maxLength: 63
  25087. minLength: 1
  25088. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25089. type: string
  25090. type: object
  25091. folderID:
  25092. type: string
  25093. required:
  25094. - authRef
  25095. - folderID
  25096. type: object
  25097. kubernetes:
  25098. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  25099. properties:
  25100. auth:
  25101. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  25102. maxProperties: 1
  25103. minProperties: 1
  25104. properties:
  25105. cert:
  25106. description: has both clientCert and clientKey as secretKeySelector
  25107. properties:
  25108. clientCert:
  25109. description: |-
  25110. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25111. In some instances, `key` is a required field.
  25112. properties:
  25113. key:
  25114. description: |-
  25115. A key in the referenced Secret.
  25116. Some instances of this field may be defaulted, in others it may be required.
  25117. maxLength: 253
  25118. minLength: 1
  25119. pattern: ^[-._a-zA-Z0-9]+$
  25120. type: string
  25121. name:
  25122. description: The name of the Secret resource being referred to.
  25123. maxLength: 253
  25124. minLength: 1
  25125. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25126. type: string
  25127. namespace:
  25128. description: |-
  25129. The namespace of the Secret resource being referred to.
  25130. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25131. maxLength: 63
  25132. minLength: 1
  25133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25134. type: string
  25135. type: object
  25136. clientKey:
  25137. description: |-
  25138. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25139. In some instances, `key` is a required field.
  25140. properties:
  25141. key:
  25142. description: |-
  25143. A key in the referenced Secret.
  25144. Some instances of this field may be defaulted, in others it may be required.
  25145. maxLength: 253
  25146. minLength: 1
  25147. pattern: ^[-._a-zA-Z0-9]+$
  25148. type: string
  25149. name:
  25150. description: The name of the Secret resource being referred to.
  25151. maxLength: 253
  25152. minLength: 1
  25153. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25154. type: string
  25155. namespace:
  25156. description: |-
  25157. The namespace of the Secret resource being referred to.
  25158. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25159. maxLength: 63
  25160. minLength: 1
  25161. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25162. type: string
  25163. type: object
  25164. type: object
  25165. serviceAccount:
  25166. description: points to a service account that should be used for authentication
  25167. properties:
  25168. audiences:
  25169. description: |-
  25170. Audience specifies the `aud` claim for the service account token
  25171. Some providers automatically extend the audience field based on well-known annotations for workload
  25172. identity (e.g. IRSA or GCP Workload Identity)
  25173. items:
  25174. type: string
  25175. type: array
  25176. name:
  25177. description: The name of the ServiceAccount resource being referred to.
  25178. maxLength: 253
  25179. minLength: 1
  25180. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25181. type: string
  25182. namespace:
  25183. description: |-
  25184. Namespace of the resource being referred to.
  25185. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25186. maxLength: 63
  25187. minLength: 1
  25188. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25189. type: string
  25190. required:
  25191. - name
  25192. type: object
  25193. token:
  25194. description: use static token to authenticate with
  25195. properties:
  25196. bearerToken:
  25197. description: |-
  25198. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25199. In some instances, `key` is a required field.
  25200. properties:
  25201. key:
  25202. description: |-
  25203. A key in the referenced Secret.
  25204. Some instances of this field may be defaulted, in others it may be required.
  25205. maxLength: 253
  25206. minLength: 1
  25207. pattern: ^[-._a-zA-Z0-9]+$
  25208. type: string
  25209. name:
  25210. description: The name of the Secret resource being referred to.
  25211. maxLength: 253
  25212. minLength: 1
  25213. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25214. type: string
  25215. namespace:
  25216. description: |-
  25217. The namespace of the Secret resource being referred to.
  25218. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25219. maxLength: 63
  25220. minLength: 1
  25221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25222. type: string
  25223. type: object
  25224. type: object
  25225. type: object
  25226. authRef:
  25227. description: A reference to a secret that contains the auth information.
  25228. properties:
  25229. key:
  25230. description: |-
  25231. A key in the referenced Secret.
  25232. Some instances of this field may be defaulted, in others it may be required.
  25233. maxLength: 253
  25234. minLength: 1
  25235. pattern: ^[-._a-zA-Z0-9]+$
  25236. type: string
  25237. name:
  25238. description: The name of the Secret resource being referred to.
  25239. maxLength: 253
  25240. minLength: 1
  25241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25242. type: string
  25243. namespace:
  25244. description: |-
  25245. The namespace of the Secret resource being referred to.
  25246. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25247. maxLength: 63
  25248. minLength: 1
  25249. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25250. type: string
  25251. type: object
  25252. remoteNamespace:
  25253. default: default
  25254. description: Remote namespace to fetch the secrets from
  25255. maxLength: 63
  25256. minLength: 1
  25257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25258. type: string
  25259. server:
  25260. description: configures the Kubernetes server Address.
  25261. properties:
  25262. caBundle:
  25263. description: CABundle is a base64-encoded CA certificate
  25264. format: byte
  25265. type: string
  25266. caProvider:
  25267. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  25268. properties:
  25269. key:
  25270. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  25271. maxLength: 253
  25272. minLength: 1
  25273. pattern: ^[-._a-zA-Z0-9]+$
  25274. type: string
  25275. name:
  25276. description: The name of the object located at the provider type.
  25277. maxLength: 253
  25278. minLength: 1
  25279. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25280. type: string
  25281. namespace:
  25282. description: |-
  25283. The namespace the Provider type is in.
  25284. Can only be defined when used in a ClusterSecretStore.
  25285. maxLength: 63
  25286. minLength: 1
  25287. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25288. type: string
  25289. type:
  25290. description: The type of provider to use such as "Secret", or "ConfigMap".
  25291. enum:
  25292. - Secret
  25293. - ConfigMap
  25294. type: string
  25295. required:
  25296. - name
  25297. - type
  25298. type: object
  25299. url:
  25300. default: kubernetes.default
  25301. description: configures the Kubernetes server Address.
  25302. type: string
  25303. type: object
  25304. type: object
  25305. onboardbase:
  25306. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  25307. properties:
  25308. apiHost:
  25309. default: https://public.onboardbase.com/api/v1/
  25310. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  25311. type: string
  25312. auth:
  25313. description: Auth configures how the Operator authenticates with the Onboardbase API
  25314. properties:
  25315. apiKeyRef:
  25316. description: |-
  25317. OnboardbaseAPIKey is the APIKey generated by an admin account.
  25318. It is used to recognize and authorize access to a project and environment within onboardbase
  25319. properties:
  25320. key:
  25321. description: |-
  25322. A key in the referenced Secret.
  25323. Some instances of this field may be defaulted, in others it may be required.
  25324. maxLength: 253
  25325. minLength: 1
  25326. pattern: ^[-._a-zA-Z0-9]+$
  25327. type: string
  25328. name:
  25329. description: The name of the Secret resource being referred to.
  25330. maxLength: 253
  25331. minLength: 1
  25332. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25333. type: string
  25334. namespace:
  25335. description: |-
  25336. The namespace of the Secret resource being referred to.
  25337. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25338. maxLength: 63
  25339. minLength: 1
  25340. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25341. type: string
  25342. type: object
  25343. passcodeRef:
  25344. description: OnboardbasePasscode is the passcode attached to the API Key
  25345. properties:
  25346. key:
  25347. description: |-
  25348. A key in the referenced Secret.
  25349. Some instances of this field may be defaulted, in others it may be required.
  25350. maxLength: 253
  25351. minLength: 1
  25352. pattern: ^[-._a-zA-Z0-9]+$
  25353. type: string
  25354. name:
  25355. description: The name of the Secret resource being referred to.
  25356. maxLength: 253
  25357. minLength: 1
  25358. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25359. type: string
  25360. namespace:
  25361. description: |-
  25362. The namespace of the Secret resource being referred to.
  25363. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25364. maxLength: 63
  25365. minLength: 1
  25366. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25367. type: string
  25368. type: object
  25369. required:
  25370. - apiKeyRef
  25371. - passcodeRef
  25372. type: object
  25373. environment:
  25374. default: development
  25375. description: Environment is the name of an environmnent within a project to pull the secrets from
  25376. type: string
  25377. project:
  25378. default: development
  25379. description: Project is an onboardbase project that the secrets should be pulled from
  25380. type: string
  25381. required:
  25382. - apiHost
  25383. - auth
  25384. - environment
  25385. - project
  25386. type: object
  25387. onepassword:
  25388. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  25389. properties:
  25390. auth:
  25391. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  25392. properties:
  25393. secretRef:
  25394. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  25395. properties:
  25396. connectTokenSecretRef:
  25397. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  25398. properties:
  25399. key:
  25400. description: |-
  25401. A key in the referenced Secret.
  25402. Some instances of this field may be defaulted, in others it may be required.
  25403. maxLength: 253
  25404. minLength: 1
  25405. pattern: ^[-._a-zA-Z0-9]+$
  25406. type: string
  25407. name:
  25408. description: The name of the Secret resource being referred to.
  25409. maxLength: 253
  25410. minLength: 1
  25411. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25412. type: string
  25413. namespace:
  25414. description: |-
  25415. The namespace of the Secret resource being referred to.
  25416. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25417. maxLength: 63
  25418. minLength: 1
  25419. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25420. type: string
  25421. type: object
  25422. required:
  25423. - connectTokenSecretRef
  25424. type: object
  25425. required:
  25426. - secretRef
  25427. type: object
  25428. connectHost:
  25429. description: ConnectHost defines the OnePassword Connect Server to connect to
  25430. type: string
  25431. vaults:
  25432. additionalProperties:
  25433. type: integer
  25434. description: Vaults defines which OnePassword vaults to search in which order
  25435. type: object
  25436. required:
  25437. - auth
  25438. - connectHost
  25439. - vaults
  25440. type: object
  25441. oracle:
  25442. description: Oracle configures this store to sync secrets using Oracle Vault provider
  25443. properties:
  25444. auth:
  25445. description: |-
  25446. Auth configures how secret-manager authenticates with the Oracle Vault.
  25447. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  25448. properties:
  25449. secretRef:
  25450. description: SecretRef to pass through sensitive information.
  25451. properties:
  25452. fingerprint:
  25453. description: Fingerprint is the fingerprint of the API private key.
  25454. properties:
  25455. key:
  25456. description: |-
  25457. A key in the referenced Secret.
  25458. Some instances of this field may be defaulted, in others it may be required.
  25459. maxLength: 253
  25460. minLength: 1
  25461. pattern: ^[-._a-zA-Z0-9]+$
  25462. type: string
  25463. name:
  25464. description: The name of the Secret resource being referred to.
  25465. maxLength: 253
  25466. minLength: 1
  25467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25468. type: string
  25469. namespace:
  25470. description: |-
  25471. The namespace of the Secret resource being referred to.
  25472. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25473. maxLength: 63
  25474. minLength: 1
  25475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25476. type: string
  25477. type: object
  25478. privatekey:
  25479. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  25480. properties:
  25481. key:
  25482. description: |-
  25483. A key in the referenced Secret.
  25484. Some instances of this field may be defaulted, in others it may be required.
  25485. maxLength: 253
  25486. minLength: 1
  25487. pattern: ^[-._a-zA-Z0-9]+$
  25488. type: string
  25489. name:
  25490. description: The name of the Secret resource being referred to.
  25491. maxLength: 253
  25492. minLength: 1
  25493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25494. type: string
  25495. namespace:
  25496. description: |-
  25497. The namespace of the Secret resource being referred to.
  25498. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25499. maxLength: 63
  25500. minLength: 1
  25501. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25502. type: string
  25503. type: object
  25504. required:
  25505. - fingerprint
  25506. - privatekey
  25507. type: object
  25508. tenancy:
  25509. description: Tenancy is the tenancy OCID where user is located.
  25510. type: string
  25511. user:
  25512. description: User is an access OCID specific to the account.
  25513. type: string
  25514. required:
  25515. - secretRef
  25516. - tenancy
  25517. - user
  25518. type: object
  25519. compartment:
  25520. description: |-
  25521. Compartment is the vault compartment OCID.
  25522. Required for PushSecret
  25523. type: string
  25524. encryptionKey:
  25525. description: |-
  25526. EncryptionKey is the OCID of the encryption key within the vault.
  25527. Required for PushSecret
  25528. type: string
  25529. principalType:
  25530. description: |-
  25531. The type of principal to use for authentication. If left blank, the Auth struct will
  25532. determine the principal type. This optional field must be specified if using
  25533. workload identity.
  25534. enum:
  25535. - ""
  25536. - UserPrincipal
  25537. - InstancePrincipal
  25538. - Workload
  25539. type: string
  25540. region:
  25541. description: Region is the region where vault is located.
  25542. type: string
  25543. serviceAccountRef:
  25544. description: |-
  25545. ServiceAccountRef specified the service account
  25546. that should be used when authenticating with WorkloadIdentity.
  25547. properties:
  25548. audiences:
  25549. description: |-
  25550. Audience specifies the `aud` claim for the service account token
  25551. Some providers automatically extend the audience field based on well-known annotations for workload
  25552. identity (e.g. IRSA or GCP Workload Identity)
  25553. items:
  25554. type: string
  25555. type: array
  25556. name:
  25557. description: The name of the ServiceAccount resource being referred to.
  25558. maxLength: 253
  25559. minLength: 1
  25560. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25561. type: string
  25562. namespace:
  25563. description: |-
  25564. Namespace of the resource being referred to.
  25565. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25566. maxLength: 63
  25567. minLength: 1
  25568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25569. type: string
  25570. required:
  25571. - name
  25572. type: object
  25573. vault:
  25574. description: Vault is the vault's OCID of the specific vault where secret is located.
  25575. type: string
  25576. required:
  25577. - region
  25578. - vault
  25579. type: object
  25580. passbolt:
  25581. description: PassboltProvider defines configuration for the Passbolt provider.
  25582. properties:
  25583. auth:
  25584. description: Auth defines the information necessary to authenticate against Passbolt Server
  25585. properties:
  25586. passwordSecretRef:
  25587. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  25588. properties:
  25589. key:
  25590. description: |-
  25591. A key in the referenced Secret.
  25592. Some instances of this field may be defaulted, in others it may be required.
  25593. maxLength: 253
  25594. minLength: 1
  25595. pattern: ^[-._a-zA-Z0-9]+$
  25596. type: string
  25597. name:
  25598. description: The name of the Secret resource being referred to.
  25599. maxLength: 253
  25600. minLength: 1
  25601. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25602. type: string
  25603. namespace:
  25604. description: |-
  25605. The namespace of the Secret resource being referred to.
  25606. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25607. maxLength: 63
  25608. minLength: 1
  25609. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25610. type: string
  25611. type: object
  25612. privateKeySecretRef:
  25613. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  25614. properties:
  25615. key:
  25616. description: |-
  25617. A key in the referenced Secret.
  25618. Some instances of this field may be defaulted, in others it may be required.
  25619. maxLength: 253
  25620. minLength: 1
  25621. pattern: ^[-._a-zA-Z0-9]+$
  25622. type: string
  25623. name:
  25624. description: The name of the Secret resource being referred to.
  25625. maxLength: 253
  25626. minLength: 1
  25627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25628. type: string
  25629. namespace:
  25630. description: |-
  25631. The namespace of the Secret resource being referred to.
  25632. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25633. maxLength: 63
  25634. minLength: 1
  25635. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25636. type: string
  25637. type: object
  25638. required:
  25639. - passwordSecretRef
  25640. - privateKeySecretRef
  25641. type: object
  25642. host:
  25643. description: Host defines the Passbolt Server to connect to
  25644. type: string
  25645. required:
  25646. - auth
  25647. - host
  25648. type: object
  25649. passworddepot:
  25650. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  25651. properties:
  25652. auth:
  25653. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  25654. properties:
  25655. secretRef:
  25656. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  25657. properties:
  25658. credentials:
  25659. description: Username / Password is used for authentication.
  25660. properties:
  25661. key:
  25662. description: |-
  25663. A key in the referenced Secret.
  25664. Some instances of this field may be defaulted, in others it may be required.
  25665. maxLength: 253
  25666. minLength: 1
  25667. pattern: ^[-._a-zA-Z0-9]+$
  25668. type: string
  25669. name:
  25670. description: The name of the Secret resource being referred to.
  25671. maxLength: 253
  25672. minLength: 1
  25673. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25674. type: string
  25675. namespace:
  25676. description: |-
  25677. The namespace of the Secret resource being referred to.
  25678. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25679. maxLength: 63
  25680. minLength: 1
  25681. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25682. type: string
  25683. type: object
  25684. type: object
  25685. required:
  25686. - secretRef
  25687. type: object
  25688. database:
  25689. description: Database to use as source
  25690. type: string
  25691. host:
  25692. description: URL configures the Password Depot instance URL.
  25693. type: string
  25694. required:
  25695. - auth
  25696. - database
  25697. - host
  25698. type: object
  25699. previder:
  25700. description: Previder configures this store to sync secrets using the Previder provider
  25701. properties:
  25702. auth:
  25703. description: PreviderAuth contains a secretRef for credentials.
  25704. properties:
  25705. secretRef:
  25706. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  25707. properties:
  25708. accessToken:
  25709. description: The AccessToken is used for authentication
  25710. properties:
  25711. key:
  25712. description: |-
  25713. A key in the referenced Secret.
  25714. Some instances of this field may be defaulted, in others it may be required.
  25715. maxLength: 253
  25716. minLength: 1
  25717. pattern: ^[-._a-zA-Z0-9]+$
  25718. type: string
  25719. name:
  25720. description: The name of the Secret resource being referred to.
  25721. maxLength: 253
  25722. minLength: 1
  25723. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25724. type: string
  25725. namespace:
  25726. description: |-
  25727. The namespace of the Secret resource being referred to.
  25728. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25729. maxLength: 63
  25730. minLength: 1
  25731. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25732. type: string
  25733. type: object
  25734. required:
  25735. - accessToken
  25736. type: object
  25737. type: object
  25738. baseUri:
  25739. type: string
  25740. required:
  25741. - auth
  25742. type: object
  25743. pulumi:
  25744. description: Pulumi configures this store to sync secrets using the Pulumi provider
  25745. properties:
  25746. accessToken:
  25747. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  25748. properties:
  25749. secretRef:
  25750. description: SecretRef is a reference to a secret containing the Pulumi API token.
  25751. properties:
  25752. key:
  25753. description: |-
  25754. A key in the referenced Secret.
  25755. Some instances of this field may be defaulted, in others it may be required.
  25756. maxLength: 253
  25757. minLength: 1
  25758. pattern: ^[-._a-zA-Z0-9]+$
  25759. type: string
  25760. name:
  25761. description: The name of the Secret resource being referred to.
  25762. maxLength: 253
  25763. minLength: 1
  25764. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25765. type: string
  25766. namespace:
  25767. description: |-
  25768. The namespace of the Secret resource being referred to.
  25769. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25770. maxLength: 63
  25771. minLength: 1
  25772. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25773. type: string
  25774. type: object
  25775. type: object
  25776. apiUrl:
  25777. default: https://api.pulumi.com/api/esc
  25778. description: APIURL is the URL of the Pulumi API.
  25779. type: string
  25780. environment:
  25781. description: |-
  25782. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  25783. dynamically retrieved values from supported providers including all major clouds,
  25784. and other Pulumi ESC environments.
  25785. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  25786. type: string
  25787. organization:
  25788. description: |-
  25789. Organization are a space to collaborate on shared projects and stacks.
  25790. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  25791. type: string
  25792. project:
  25793. description: Project is the name of the Pulumi ESC project the environment belongs to.
  25794. type: string
  25795. required:
  25796. - accessToken
  25797. - environment
  25798. - organization
  25799. - project
  25800. type: object
  25801. scaleway:
  25802. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  25803. properties:
  25804. accessKey:
  25805. description: AccessKey is the non-secret part of the api key.
  25806. properties:
  25807. secretRef:
  25808. description: SecretRef references a key in a secret that will be used as value.
  25809. properties:
  25810. key:
  25811. description: |-
  25812. A key in the referenced Secret.
  25813. Some instances of this field may be defaulted, in others it may be required.
  25814. maxLength: 253
  25815. minLength: 1
  25816. pattern: ^[-._a-zA-Z0-9]+$
  25817. type: string
  25818. name:
  25819. description: The name of the Secret resource being referred to.
  25820. maxLength: 253
  25821. minLength: 1
  25822. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25823. type: string
  25824. namespace:
  25825. description: |-
  25826. The namespace of the Secret resource being referred to.
  25827. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25828. maxLength: 63
  25829. minLength: 1
  25830. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25831. type: string
  25832. type: object
  25833. value:
  25834. description: Value can be specified directly to set a value without using a secret.
  25835. type: string
  25836. type: object
  25837. apiUrl:
  25838. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  25839. type: string
  25840. projectId:
  25841. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  25842. type: string
  25843. region:
  25844. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  25845. type: string
  25846. secretKey:
  25847. description: SecretKey is the non-secret part of the api key.
  25848. properties:
  25849. secretRef:
  25850. description: SecretRef references a key in a secret that will be used as value.
  25851. properties:
  25852. key:
  25853. description: |-
  25854. A key in the referenced Secret.
  25855. Some instances of this field may be defaulted, in others it may be required.
  25856. maxLength: 253
  25857. minLength: 1
  25858. pattern: ^[-._a-zA-Z0-9]+$
  25859. type: string
  25860. name:
  25861. description: The name of the Secret resource being referred to.
  25862. maxLength: 253
  25863. minLength: 1
  25864. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25865. type: string
  25866. namespace:
  25867. description: |-
  25868. The namespace of the Secret resource being referred to.
  25869. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25870. maxLength: 63
  25871. minLength: 1
  25872. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25873. type: string
  25874. type: object
  25875. value:
  25876. description: Value can be specified directly to set a value without using a secret.
  25877. type: string
  25878. type: object
  25879. required:
  25880. - accessKey
  25881. - projectId
  25882. - region
  25883. - secretKey
  25884. type: object
  25885. secretserver:
  25886. description: |-
  25887. SecretServer configures this store to sync secrets using SecretServer provider
  25888. https://docs.delinea.com/online-help/secret-server/start.htm
  25889. properties:
  25890. password:
  25891. description: Password is the secret server account password.
  25892. properties:
  25893. secretRef:
  25894. description: SecretRef references a key in a secret that will be used as value.
  25895. properties:
  25896. key:
  25897. description: |-
  25898. A key in the referenced Secret.
  25899. Some instances of this field may be defaulted, in others it may be required.
  25900. maxLength: 253
  25901. minLength: 1
  25902. pattern: ^[-._a-zA-Z0-9]+$
  25903. type: string
  25904. name:
  25905. description: The name of the Secret resource being referred to.
  25906. maxLength: 253
  25907. minLength: 1
  25908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25909. type: string
  25910. namespace:
  25911. description: |-
  25912. The namespace of the Secret resource being referred to.
  25913. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25914. maxLength: 63
  25915. minLength: 1
  25916. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25917. type: string
  25918. type: object
  25919. value:
  25920. description: Value can be specified directly to set a value without using a secret.
  25921. type: string
  25922. type: object
  25923. serverURL:
  25924. description: |-
  25925. ServerURL
  25926. URL to your secret server installation
  25927. type: string
  25928. username:
  25929. description: Username is the secret server account username.
  25930. properties:
  25931. secretRef:
  25932. description: SecretRef references a key in a secret that will be used as value.
  25933. properties:
  25934. key:
  25935. description: |-
  25936. A key in the referenced Secret.
  25937. Some instances of this field may be defaulted, in others it may be required.
  25938. maxLength: 253
  25939. minLength: 1
  25940. pattern: ^[-._a-zA-Z0-9]+$
  25941. type: string
  25942. name:
  25943. description: The name of the Secret resource being referred to.
  25944. maxLength: 253
  25945. minLength: 1
  25946. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25947. type: string
  25948. namespace:
  25949. description: |-
  25950. The namespace of the Secret resource being referred to.
  25951. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25952. maxLength: 63
  25953. minLength: 1
  25954. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25955. type: string
  25956. type: object
  25957. value:
  25958. description: Value can be specified directly to set a value without using a secret.
  25959. type: string
  25960. type: object
  25961. required:
  25962. - password
  25963. - serverURL
  25964. - username
  25965. type: object
  25966. senhasegura:
  25967. description: Senhasegura configures this store to sync secrets using senhasegura provider
  25968. properties:
  25969. auth:
  25970. description: Auth defines parameters to authenticate in senhasegura
  25971. properties:
  25972. clientId:
  25973. type: string
  25974. clientSecretSecretRef:
  25975. description: |-
  25976. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25977. In some instances, `key` is a required field.
  25978. properties:
  25979. key:
  25980. description: |-
  25981. A key in the referenced Secret.
  25982. Some instances of this field may be defaulted, in others it may be required.
  25983. maxLength: 253
  25984. minLength: 1
  25985. pattern: ^[-._a-zA-Z0-9]+$
  25986. type: string
  25987. name:
  25988. description: The name of the Secret resource being referred to.
  25989. maxLength: 253
  25990. minLength: 1
  25991. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25992. type: string
  25993. namespace:
  25994. description: |-
  25995. The namespace of the Secret resource being referred to.
  25996. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25997. maxLength: 63
  25998. minLength: 1
  25999. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26000. type: string
  26001. type: object
  26002. required:
  26003. - clientId
  26004. - clientSecretSecretRef
  26005. type: object
  26006. ignoreSslCertificate:
  26007. default: false
  26008. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  26009. type: boolean
  26010. module:
  26011. description: Module defines which senhasegura module should be used to get secrets
  26012. type: string
  26013. url:
  26014. description: URL of senhasegura
  26015. type: string
  26016. required:
  26017. - auth
  26018. - module
  26019. - url
  26020. type: object
  26021. vault:
  26022. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  26023. properties:
  26024. auth:
  26025. description: Auth configures how secret-manager authenticates with the Vault server.
  26026. properties:
  26027. appRole:
  26028. description: |-
  26029. AppRole authenticates with Vault using the App Role auth mechanism,
  26030. with the role and secret stored in a Kubernetes Secret resource.
  26031. properties:
  26032. path:
  26033. default: approle
  26034. description: |-
  26035. Path where the App Role authentication backend is mounted
  26036. in Vault, e.g: "approle"
  26037. type: string
  26038. roleId:
  26039. description: |-
  26040. RoleID configured in the App Role authentication backend when setting
  26041. up the authentication backend in Vault.
  26042. type: string
  26043. roleRef:
  26044. description: |-
  26045. Reference to a key in a Secret that contains the App Role ID used
  26046. to authenticate with Vault.
  26047. The `key` field must be specified and denotes which entry within the Secret
  26048. resource is used as the app role id.
  26049. properties:
  26050. key:
  26051. description: |-
  26052. A key in the referenced Secret.
  26053. Some instances of this field may be defaulted, in others it may be required.
  26054. maxLength: 253
  26055. minLength: 1
  26056. pattern: ^[-._a-zA-Z0-9]+$
  26057. type: string
  26058. name:
  26059. description: The name of the Secret resource being referred to.
  26060. maxLength: 253
  26061. minLength: 1
  26062. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26063. type: string
  26064. namespace:
  26065. description: |-
  26066. The namespace of the Secret resource being referred to.
  26067. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26068. maxLength: 63
  26069. minLength: 1
  26070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26071. type: string
  26072. type: object
  26073. secretRef:
  26074. description: |-
  26075. Reference to a key in a Secret that contains the App Role secret used
  26076. to authenticate with Vault.
  26077. The `key` field must be specified and denotes which entry within the Secret
  26078. resource is used as the app role secret.
  26079. properties:
  26080. key:
  26081. description: |-
  26082. A key in the referenced Secret.
  26083. Some instances of this field may be defaulted, in others it may be required.
  26084. maxLength: 253
  26085. minLength: 1
  26086. pattern: ^[-._a-zA-Z0-9]+$
  26087. type: string
  26088. name:
  26089. description: The name of the Secret resource being referred to.
  26090. maxLength: 253
  26091. minLength: 1
  26092. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26093. type: string
  26094. namespace:
  26095. description: |-
  26096. The namespace of the Secret resource being referred to.
  26097. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26098. maxLength: 63
  26099. minLength: 1
  26100. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26101. type: string
  26102. type: object
  26103. required:
  26104. - path
  26105. - secretRef
  26106. type: object
  26107. cert:
  26108. description: |-
  26109. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  26110. Cert authentication method
  26111. properties:
  26112. clientCert:
  26113. description: |-
  26114. ClientCert is a certificate to authenticate using the Cert Vault
  26115. authentication method
  26116. properties:
  26117. key:
  26118. description: |-
  26119. A key in the referenced Secret.
  26120. Some instances of this field may be defaulted, in others it may be required.
  26121. maxLength: 253
  26122. minLength: 1
  26123. pattern: ^[-._a-zA-Z0-9]+$
  26124. type: string
  26125. name:
  26126. description: The name of the Secret resource being referred to.
  26127. maxLength: 253
  26128. minLength: 1
  26129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26130. type: string
  26131. namespace:
  26132. description: |-
  26133. The namespace of the Secret resource being referred to.
  26134. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26135. maxLength: 63
  26136. minLength: 1
  26137. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26138. type: string
  26139. type: object
  26140. secretRef:
  26141. description: |-
  26142. SecretRef to a key in a Secret resource containing client private key to
  26143. authenticate with Vault using the Cert authentication method
  26144. properties:
  26145. key:
  26146. description: |-
  26147. A key in the referenced Secret.
  26148. Some instances of this field may be defaulted, in others it may be required.
  26149. maxLength: 253
  26150. minLength: 1
  26151. pattern: ^[-._a-zA-Z0-9]+$
  26152. type: string
  26153. name:
  26154. description: The name of the Secret resource being referred to.
  26155. maxLength: 253
  26156. minLength: 1
  26157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26158. type: string
  26159. namespace:
  26160. description: |-
  26161. The namespace of the Secret resource being referred to.
  26162. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26163. maxLength: 63
  26164. minLength: 1
  26165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26166. type: string
  26167. type: object
  26168. type: object
  26169. iam:
  26170. description: |-
  26171. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  26172. AWS IAM authentication method
  26173. properties:
  26174. externalID:
  26175. description: AWS External ID set on assumed IAM roles
  26176. type: string
  26177. jwt:
  26178. description: Specify a service account with IRSA enabled
  26179. properties:
  26180. serviceAccountRef:
  26181. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  26182. properties:
  26183. audiences:
  26184. description: |-
  26185. Audience specifies the `aud` claim for the service account token
  26186. Some providers automatically extend the audience field based on well-known annotations for workload
  26187. identity (e.g. IRSA or GCP Workload Identity)
  26188. items:
  26189. type: string
  26190. type: array
  26191. name:
  26192. description: The name of the ServiceAccount resource being referred to.
  26193. maxLength: 253
  26194. minLength: 1
  26195. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26196. type: string
  26197. namespace:
  26198. description: |-
  26199. Namespace of the resource being referred to.
  26200. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26201. maxLength: 63
  26202. minLength: 1
  26203. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26204. type: string
  26205. required:
  26206. - name
  26207. type: object
  26208. type: object
  26209. path:
  26210. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  26211. type: string
  26212. region:
  26213. description: AWS region
  26214. type: string
  26215. role:
  26216. description: This is the AWS role to be assumed before talking to vault
  26217. type: string
  26218. secretRef:
  26219. description: Specify credentials in a Secret object
  26220. properties:
  26221. accessKeyIDSecretRef:
  26222. description: The AccessKeyID is used for authentication
  26223. properties:
  26224. key:
  26225. description: |-
  26226. A key in the referenced Secret.
  26227. Some instances of this field may be defaulted, in others it may be required.
  26228. maxLength: 253
  26229. minLength: 1
  26230. pattern: ^[-._a-zA-Z0-9]+$
  26231. type: string
  26232. name:
  26233. description: The name of the Secret resource being referred to.
  26234. maxLength: 253
  26235. minLength: 1
  26236. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26237. type: string
  26238. namespace:
  26239. description: |-
  26240. The namespace of the Secret resource being referred to.
  26241. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26242. maxLength: 63
  26243. minLength: 1
  26244. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26245. type: string
  26246. type: object
  26247. secretAccessKeySecretRef:
  26248. description: The SecretAccessKey is used for authentication
  26249. properties:
  26250. key:
  26251. description: |-
  26252. A key in the referenced Secret.
  26253. Some instances of this field may be defaulted, in others it may be required.
  26254. maxLength: 253
  26255. minLength: 1
  26256. pattern: ^[-._a-zA-Z0-9]+$
  26257. type: string
  26258. name:
  26259. description: The name of the Secret resource being referred to.
  26260. maxLength: 253
  26261. minLength: 1
  26262. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26263. type: string
  26264. namespace:
  26265. description: |-
  26266. The namespace of the Secret resource being referred to.
  26267. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26268. maxLength: 63
  26269. minLength: 1
  26270. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26271. type: string
  26272. type: object
  26273. sessionTokenSecretRef:
  26274. description: |-
  26275. The SessionToken used for authentication
  26276. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  26277. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  26278. properties:
  26279. key:
  26280. description: |-
  26281. A key in the referenced Secret.
  26282. Some instances of this field may be defaulted, in others it may be required.
  26283. maxLength: 253
  26284. minLength: 1
  26285. pattern: ^[-._a-zA-Z0-9]+$
  26286. type: string
  26287. name:
  26288. description: The name of the Secret resource being referred to.
  26289. maxLength: 253
  26290. minLength: 1
  26291. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26292. type: string
  26293. namespace:
  26294. description: |-
  26295. The namespace of the Secret resource being referred to.
  26296. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26297. maxLength: 63
  26298. minLength: 1
  26299. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26300. type: string
  26301. type: object
  26302. type: object
  26303. vaultAwsIamServerID:
  26304. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  26305. type: string
  26306. vaultRole:
  26307. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  26308. type: string
  26309. required:
  26310. - vaultRole
  26311. type: object
  26312. jwt:
  26313. description: |-
  26314. Jwt authenticates with Vault by passing role and JWT token using the
  26315. JWT/OIDC authentication method
  26316. properties:
  26317. kubernetesServiceAccountToken:
  26318. description: |-
  26319. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  26320. a token for with the `TokenRequest` API.
  26321. properties:
  26322. audiences:
  26323. description: |-
  26324. Optional audiences field that will be used to request a temporary Kubernetes service
  26325. account token for the service account referenced by `serviceAccountRef`.
  26326. Defaults to a single audience `vault` it not specified.
  26327. Deprecated: use serviceAccountRef.Audiences instead
  26328. items:
  26329. type: string
  26330. type: array
  26331. expirationSeconds:
  26332. description: |-
  26333. Optional expiration time in seconds that will be used to request a temporary
  26334. Kubernetes service account token for the service account referenced by
  26335. `serviceAccountRef`.
  26336. Deprecated: this will be removed in the future.
  26337. Defaults to 10 minutes.
  26338. format: int64
  26339. type: integer
  26340. serviceAccountRef:
  26341. description: Service account field containing the name of a kubernetes ServiceAccount.
  26342. properties:
  26343. audiences:
  26344. description: |-
  26345. Audience specifies the `aud` claim for the service account token
  26346. Some providers automatically extend the audience field based on well-known annotations for workload
  26347. identity (e.g. IRSA or GCP Workload Identity)
  26348. items:
  26349. type: string
  26350. type: array
  26351. name:
  26352. description: The name of the ServiceAccount resource being referred to.
  26353. maxLength: 253
  26354. minLength: 1
  26355. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26356. type: string
  26357. namespace:
  26358. description: |-
  26359. Namespace of the resource being referred to.
  26360. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26361. maxLength: 63
  26362. minLength: 1
  26363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26364. type: string
  26365. required:
  26366. - name
  26367. type: object
  26368. required:
  26369. - serviceAccountRef
  26370. type: object
  26371. path:
  26372. default: jwt
  26373. description: |-
  26374. Path where the JWT authentication backend is mounted
  26375. in Vault, e.g: "jwt"
  26376. type: string
  26377. role:
  26378. description: |-
  26379. Role is a JWT role to authenticate using the JWT/OIDC Vault
  26380. authentication method
  26381. type: string
  26382. secretRef:
  26383. description: |-
  26384. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  26385. authenticate with Vault using the JWT/OIDC authentication method.
  26386. properties:
  26387. key:
  26388. description: |-
  26389. A key in the referenced Secret.
  26390. Some instances of this field may be defaulted, in others it may be required.
  26391. maxLength: 253
  26392. minLength: 1
  26393. pattern: ^[-._a-zA-Z0-9]+$
  26394. type: string
  26395. name:
  26396. description: The name of the Secret resource being referred to.
  26397. maxLength: 253
  26398. minLength: 1
  26399. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26400. type: string
  26401. namespace:
  26402. description: |-
  26403. The namespace of the Secret resource being referred to.
  26404. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26405. maxLength: 63
  26406. minLength: 1
  26407. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26408. type: string
  26409. type: object
  26410. required:
  26411. - path
  26412. type: object
  26413. kubernetes:
  26414. description: |-
  26415. Kubernetes authenticates with Vault by passing the ServiceAccount
  26416. token stored in the named Secret resource to the Vault server.
  26417. properties:
  26418. mountPath:
  26419. default: kubernetes
  26420. description: |-
  26421. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  26422. "kubernetes"
  26423. type: string
  26424. role:
  26425. description: |-
  26426. A required field containing the Vault Role to assume. A Role binds a
  26427. Kubernetes ServiceAccount with a set of Vault policies.
  26428. type: string
  26429. secretRef:
  26430. description: |-
  26431. Optional secret field containing a Kubernetes ServiceAccount JWT used
  26432. for authenticating with Vault. If a name is specified without a key,
  26433. `token` is the default. If one is not specified, the one bound to
  26434. the controller will be used.
  26435. properties:
  26436. key:
  26437. description: |-
  26438. A key in the referenced Secret.
  26439. Some instances of this field may be defaulted, in others it may be required.
  26440. maxLength: 253
  26441. minLength: 1
  26442. pattern: ^[-._a-zA-Z0-9]+$
  26443. type: string
  26444. name:
  26445. description: The name of the Secret resource being referred to.
  26446. maxLength: 253
  26447. minLength: 1
  26448. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26449. type: string
  26450. namespace:
  26451. description: |-
  26452. The namespace of the Secret resource being referred to.
  26453. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26454. maxLength: 63
  26455. minLength: 1
  26456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26457. type: string
  26458. type: object
  26459. serviceAccountRef:
  26460. description: |-
  26461. Optional service account field containing the name of a kubernetes ServiceAccount.
  26462. If the service account is specified, the service account secret token JWT will be used
  26463. for authenticating with Vault. If the service account selector is not supplied,
  26464. the secretRef will be used instead.
  26465. properties:
  26466. audiences:
  26467. description: |-
  26468. Audience specifies the `aud` claim for the service account token
  26469. Some providers automatically extend the audience field based on well-known annotations for workload
  26470. identity (e.g. IRSA or GCP Workload Identity)
  26471. items:
  26472. type: string
  26473. type: array
  26474. name:
  26475. description: The name of the ServiceAccount resource being referred to.
  26476. maxLength: 253
  26477. minLength: 1
  26478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26479. type: string
  26480. namespace:
  26481. description: |-
  26482. Namespace of the resource being referred to.
  26483. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26484. maxLength: 63
  26485. minLength: 1
  26486. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26487. type: string
  26488. required:
  26489. - name
  26490. type: object
  26491. required:
  26492. - mountPath
  26493. - role
  26494. type: object
  26495. ldap:
  26496. description: |-
  26497. Ldap authenticates with Vault by passing username/password pair using
  26498. the LDAP authentication method
  26499. properties:
  26500. path:
  26501. default: ldap
  26502. description: |-
  26503. Path where the LDAP authentication backend is mounted
  26504. in Vault, e.g: "ldap"
  26505. type: string
  26506. secretRef:
  26507. description: |-
  26508. SecretRef to a key in a Secret resource containing password for the LDAP
  26509. user used to authenticate with Vault using the LDAP authentication
  26510. method
  26511. properties:
  26512. key:
  26513. description: |-
  26514. A key in the referenced Secret.
  26515. Some instances of this field may be defaulted, in others it may be required.
  26516. maxLength: 253
  26517. minLength: 1
  26518. pattern: ^[-._a-zA-Z0-9]+$
  26519. type: string
  26520. name:
  26521. description: The name of the Secret resource being referred to.
  26522. maxLength: 253
  26523. minLength: 1
  26524. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26525. type: string
  26526. namespace:
  26527. description: |-
  26528. The namespace of the Secret resource being referred to.
  26529. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26530. maxLength: 63
  26531. minLength: 1
  26532. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26533. type: string
  26534. type: object
  26535. username:
  26536. description: |-
  26537. Username is an LDAP username used to authenticate using the LDAP Vault
  26538. authentication method
  26539. type: string
  26540. required:
  26541. - path
  26542. - username
  26543. type: object
  26544. namespace:
  26545. description: |-
  26546. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  26547. Namespaces is a set of features within Vault Enterprise that allows
  26548. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  26549. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  26550. This will default to Vault.Namespace field if set, or empty otherwise
  26551. type: string
  26552. tokenSecretRef:
  26553. description: TokenSecretRef authenticates with Vault by presenting a token.
  26554. properties:
  26555. key:
  26556. description: |-
  26557. A key in the referenced Secret.
  26558. Some instances of this field may be defaulted, in others it may be required.
  26559. maxLength: 253
  26560. minLength: 1
  26561. pattern: ^[-._a-zA-Z0-9]+$
  26562. type: string
  26563. name:
  26564. description: The name of the Secret resource being referred to.
  26565. maxLength: 253
  26566. minLength: 1
  26567. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26568. type: string
  26569. namespace:
  26570. description: |-
  26571. The namespace of the Secret resource being referred to.
  26572. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26573. maxLength: 63
  26574. minLength: 1
  26575. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26576. type: string
  26577. type: object
  26578. userPass:
  26579. description: UserPass authenticates with Vault by passing username/password pair
  26580. properties:
  26581. path:
  26582. default: userpass
  26583. description: |-
  26584. Path where the UserPassword authentication backend is mounted
  26585. in Vault, e.g: "userpass"
  26586. type: string
  26587. secretRef:
  26588. description: |-
  26589. SecretRef to a key in a Secret resource containing password for the
  26590. user used to authenticate with Vault using the UserPass authentication
  26591. method
  26592. properties:
  26593. key:
  26594. description: |-
  26595. A key in the referenced Secret.
  26596. Some instances of this field may be defaulted, in others it may be required.
  26597. maxLength: 253
  26598. minLength: 1
  26599. pattern: ^[-._a-zA-Z0-9]+$
  26600. type: string
  26601. name:
  26602. description: The name of the Secret resource being referred to.
  26603. maxLength: 253
  26604. minLength: 1
  26605. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26606. type: string
  26607. namespace:
  26608. description: |-
  26609. The namespace of the Secret resource being referred to.
  26610. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26611. maxLength: 63
  26612. minLength: 1
  26613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26614. type: string
  26615. type: object
  26616. username:
  26617. description: |-
  26618. Username is a username used to authenticate using the UserPass Vault
  26619. authentication method
  26620. type: string
  26621. required:
  26622. - path
  26623. - username
  26624. type: object
  26625. type: object
  26626. caBundle:
  26627. description: |-
  26628. PEM encoded CA bundle used to validate Vault server certificate. Only used
  26629. if the Server URL is using HTTPS protocol. This parameter is ignored for
  26630. plain HTTP protocol connection. If not set the system root certificates
  26631. are used to validate the TLS connection.
  26632. format: byte
  26633. type: string
  26634. caProvider:
  26635. description: The provider for the CA bundle to use to validate Vault server certificate.
  26636. properties:
  26637. key:
  26638. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26639. maxLength: 253
  26640. minLength: 1
  26641. pattern: ^[-._a-zA-Z0-9]+$
  26642. type: string
  26643. name:
  26644. description: The name of the object located at the provider type.
  26645. maxLength: 253
  26646. minLength: 1
  26647. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26648. type: string
  26649. namespace:
  26650. description: |-
  26651. The namespace the Provider type is in.
  26652. Can only be defined when used in a ClusterSecretStore.
  26653. maxLength: 63
  26654. minLength: 1
  26655. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26656. type: string
  26657. type:
  26658. description: The type of provider to use such as "Secret", or "ConfigMap".
  26659. enum:
  26660. - Secret
  26661. - ConfigMap
  26662. type: string
  26663. required:
  26664. - name
  26665. - type
  26666. type: object
  26667. forwardInconsistent:
  26668. description: |-
  26669. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  26670. leader instead of simply retrying within a loop. This can increase performance if
  26671. the option is enabled serverside.
  26672. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  26673. type: boolean
  26674. headers:
  26675. additionalProperties:
  26676. type: string
  26677. description: Headers to be added in Vault request
  26678. type: object
  26679. namespace:
  26680. description: |-
  26681. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  26682. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  26683. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  26684. type: string
  26685. path:
  26686. description: |-
  26687. Path is the mount path of the Vault KV backend endpoint, e.g:
  26688. "secret". The v2 KV secret engine version specific "/data" path suffix
  26689. for fetching secrets from Vault is optional and will be appended
  26690. if not present in specified path.
  26691. type: string
  26692. readYourWrites:
  26693. description: |-
  26694. ReadYourWrites ensures isolated read-after-write semantics by
  26695. providing discovered cluster replication states in each request.
  26696. More information about eventual consistency in Vault can be found here
  26697. https://www.vaultproject.io/docs/enterprise/consistency
  26698. type: boolean
  26699. server:
  26700. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  26701. type: string
  26702. tls:
  26703. description: |-
  26704. The configuration used for client side related TLS communication, when the Vault server
  26705. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  26706. This parameter is ignored for plain HTTP protocol connection.
  26707. It's worth noting this configuration is different from the "TLS certificates auth method",
  26708. which is available under the `auth.cert` section.
  26709. properties:
  26710. certSecretRef:
  26711. description: |-
  26712. CertSecretRef is a certificate added to the transport layer
  26713. when communicating with the Vault server.
  26714. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  26715. properties:
  26716. key:
  26717. description: |-
  26718. A key in the referenced Secret.
  26719. Some instances of this field may be defaulted, in others it may be required.
  26720. maxLength: 253
  26721. minLength: 1
  26722. pattern: ^[-._a-zA-Z0-9]+$
  26723. type: string
  26724. name:
  26725. description: The name of the Secret resource being referred to.
  26726. maxLength: 253
  26727. minLength: 1
  26728. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26729. type: string
  26730. namespace:
  26731. description: |-
  26732. The namespace of the Secret resource being referred to.
  26733. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26734. maxLength: 63
  26735. minLength: 1
  26736. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26737. type: string
  26738. type: object
  26739. keySecretRef:
  26740. description: |-
  26741. KeySecretRef to a key in a Secret resource containing client private key
  26742. added to the transport layer when communicating with the Vault server.
  26743. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  26744. properties:
  26745. key:
  26746. description: |-
  26747. A key in the referenced Secret.
  26748. Some instances of this field may be defaulted, in others it may be required.
  26749. maxLength: 253
  26750. minLength: 1
  26751. pattern: ^[-._a-zA-Z0-9]+$
  26752. type: string
  26753. name:
  26754. description: The name of the Secret resource being referred to.
  26755. maxLength: 253
  26756. minLength: 1
  26757. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26758. type: string
  26759. namespace:
  26760. description: |-
  26761. The namespace of the Secret resource being referred to.
  26762. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26763. maxLength: 63
  26764. minLength: 1
  26765. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26766. type: string
  26767. type: object
  26768. type: object
  26769. version:
  26770. default: v2
  26771. description: |-
  26772. Version is the Vault KV secret engine version. This can be either "v1" or
  26773. "v2". Version defaults to "v2".
  26774. enum:
  26775. - v1
  26776. - v2
  26777. type: string
  26778. required:
  26779. - server
  26780. type: object
  26781. webhook:
  26782. description: Webhook configures this store to sync secrets using a generic templated webhook
  26783. properties:
  26784. auth:
  26785. description: Auth specifies a authorization protocol. Only one protocol may be set.
  26786. maxProperties: 1
  26787. minProperties: 1
  26788. properties:
  26789. ntlm:
  26790. description: NTLMProtocol configures the store to use NTLM for auth
  26791. properties:
  26792. passwordSecret:
  26793. description: |-
  26794. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26795. In some instances, `key` is a required field.
  26796. properties:
  26797. key:
  26798. description: |-
  26799. A key in the referenced Secret.
  26800. Some instances of this field may be defaulted, in others it may be required.
  26801. maxLength: 253
  26802. minLength: 1
  26803. pattern: ^[-._a-zA-Z0-9]+$
  26804. type: string
  26805. name:
  26806. description: The name of the Secret resource being referred to.
  26807. maxLength: 253
  26808. minLength: 1
  26809. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26810. type: string
  26811. namespace:
  26812. description: |-
  26813. The namespace of the Secret resource being referred to.
  26814. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26815. maxLength: 63
  26816. minLength: 1
  26817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26818. type: string
  26819. type: object
  26820. usernameSecret:
  26821. description: |-
  26822. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26823. In some instances, `key` is a required field.
  26824. properties:
  26825. key:
  26826. description: |-
  26827. A key in the referenced Secret.
  26828. Some instances of this field may be defaulted, in others it may be required.
  26829. maxLength: 253
  26830. minLength: 1
  26831. pattern: ^[-._a-zA-Z0-9]+$
  26832. type: string
  26833. name:
  26834. description: The name of the Secret resource being referred to.
  26835. maxLength: 253
  26836. minLength: 1
  26837. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26838. type: string
  26839. namespace:
  26840. description: |-
  26841. The namespace of the Secret resource being referred to.
  26842. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26843. maxLength: 63
  26844. minLength: 1
  26845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26846. type: string
  26847. type: object
  26848. required:
  26849. - passwordSecret
  26850. - usernameSecret
  26851. type: object
  26852. type: object
  26853. body:
  26854. description: Body
  26855. type: string
  26856. caBundle:
  26857. description: |-
  26858. PEM encoded CA bundle used to validate webhook server certificate. Only used
  26859. if the Server URL is using HTTPS protocol. This parameter is ignored for
  26860. plain HTTP protocol connection. If not set the system root certificates
  26861. are used to validate the TLS connection.
  26862. format: byte
  26863. type: string
  26864. caProvider:
  26865. description: The provider for the CA bundle to use to validate webhook server certificate.
  26866. properties:
  26867. key:
  26868. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26869. maxLength: 253
  26870. minLength: 1
  26871. pattern: ^[-._a-zA-Z0-9]+$
  26872. type: string
  26873. name:
  26874. description: The name of the object located at the provider type.
  26875. maxLength: 253
  26876. minLength: 1
  26877. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26878. type: string
  26879. namespace:
  26880. description: The namespace the Provider type is in.
  26881. maxLength: 63
  26882. minLength: 1
  26883. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26884. type: string
  26885. type:
  26886. description: The type of provider to use such as "Secret", or "ConfigMap".
  26887. enum:
  26888. - Secret
  26889. - ConfigMap
  26890. type: string
  26891. required:
  26892. - name
  26893. - type
  26894. type: object
  26895. headers:
  26896. additionalProperties:
  26897. type: string
  26898. description: Headers
  26899. type: object
  26900. method:
  26901. description: Webhook Method
  26902. type: string
  26903. result:
  26904. description: Result formatting
  26905. properties:
  26906. jsonPath:
  26907. description: Json path of return value
  26908. type: string
  26909. type: object
  26910. secrets:
  26911. description: |-
  26912. Secrets to fill in templates
  26913. These secrets will be passed to the templating function as key value pairs under the given name
  26914. items:
  26915. description: WebhookSecret defines a secret to be used in webhook templates.
  26916. properties:
  26917. name:
  26918. description: Name of this secret in templates
  26919. type: string
  26920. secretRef:
  26921. description: Secret ref to fill in credentials
  26922. properties:
  26923. key:
  26924. description: |-
  26925. A key in the referenced Secret.
  26926. Some instances of this field may be defaulted, in others it may be required.
  26927. maxLength: 253
  26928. minLength: 1
  26929. pattern: ^[-._a-zA-Z0-9]+$
  26930. type: string
  26931. name:
  26932. description: The name of the Secret resource being referred to.
  26933. maxLength: 253
  26934. minLength: 1
  26935. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26936. type: string
  26937. namespace:
  26938. description: |-
  26939. The namespace of the Secret resource being referred to.
  26940. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26941. maxLength: 63
  26942. minLength: 1
  26943. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26944. type: string
  26945. type: object
  26946. required:
  26947. - name
  26948. - secretRef
  26949. type: object
  26950. type: array
  26951. timeout:
  26952. description: Timeout
  26953. type: string
  26954. url:
  26955. description: Webhook url to call
  26956. type: string
  26957. required:
  26958. - result
  26959. - url
  26960. type: object
  26961. yandexcertificatemanager:
  26962. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  26963. properties:
  26964. apiEndpoint:
  26965. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  26966. type: string
  26967. auth:
  26968. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  26969. properties:
  26970. authorizedKeySecretRef:
  26971. description: The authorized key used for authentication
  26972. properties:
  26973. key:
  26974. description: |-
  26975. A key in the referenced Secret.
  26976. Some instances of this field may be defaulted, in others it may be required.
  26977. maxLength: 253
  26978. minLength: 1
  26979. pattern: ^[-._a-zA-Z0-9]+$
  26980. type: string
  26981. name:
  26982. description: The name of the Secret resource being referred to.
  26983. maxLength: 253
  26984. minLength: 1
  26985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26986. type: string
  26987. namespace:
  26988. description: |-
  26989. The namespace of the Secret resource being referred to.
  26990. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26991. maxLength: 63
  26992. minLength: 1
  26993. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26994. type: string
  26995. type: object
  26996. type: object
  26997. caProvider:
  26998. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  26999. properties:
  27000. certSecretRef:
  27001. description: |-
  27002. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  27003. In some instances, `key` is a required field.
  27004. properties:
  27005. key:
  27006. description: |-
  27007. A key in the referenced Secret.
  27008. Some instances of this field may be defaulted, in others it may be required.
  27009. maxLength: 253
  27010. minLength: 1
  27011. pattern: ^[-._a-zA-Z0-9]+$
  27012. type: string
  27013. name:
  27014. description: The name of the Secret resource being referred to.
  27015. maxLength: 253
  27016. minLength: 1
  27017. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27018. type: string
  27019. namespace:
  27020. description: |-
  27021. The namespace of the Secret resource being referred to.
  27022. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27023. maxLength: 63
  27024. minLength: 1
  27025. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27026. type: string
  27027. type: object
  27028. type: object
  27029. required:
  27030. - auth
  27031. type: object
  27032. yandexlockbox:
  27033. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  27034. properties:
  27035. apiEndpoint:
  27036. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  27037. type: string
  27038. auth:
  27039. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  27040. properties:
  27041. authorizedKeySecretRef:
  27042. description: The authorized key used for authentication
  27043. properties:
  27044. key:
  27045. description: |-
  27046. A key in the referenced Secret.
  27047. Some instances of this field may be defaulted, in others it may be required.
  27048. maxLength: 253
  27049. minLength: 1
  27050. pattern: ^[-._a-zA-Z0-9]+$
  27051. type: string
  27052. name:
  27053. description: The name of the Secret resource being referred to.
  27054. maxLength: 253
  27055. minLength: 1
  27056. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27057. type: string
  27058. namespace:
  27059. description: |-
  27060. The namespace of the Secret resource being referred to.
  27061. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27062. maxLength: 63
  27063. minLength: 1
  27064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27065. type: string
  27066. type: object
  27067. type: object
  27068. caProvider:
  27069. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  27070. properties:
  27071. certSecretRef:
  27072. description: |-
  27073. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  27074. In some instances, `key` is a required field.
  27075. properties:
  27076. key:
  27077. description: |-
  27078. A key in the referenced Secret.
  27079. Some instances of this field may be defaulted, in others it may be required.
  27080. maxLength: 253
  27081. minLength: 1
  27082. pattern: ^[-._a-zA-Z0-9]+$
  27083. type: string
  27084. name:
  27085. description: The name of the Secret resource being referred to.
  27086. maxLength: 253
  27087. minLength: 1
  27088. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27089. type: string
  27090. namespace:
  27091. description: |-
  27092. The namespace of the Secret resource being referred to.
  27093. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27094. maxLength: 63
  27095. minLength: 1
  27096. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27097. type: string
  27098. type: object
  27099. type: object
  27100. required:
  27101. - auth
  27102. type: object
  27103. type: object
  27104. refreshInterval:
  27105. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  27106. type: integer
  27107. retrySettings:
  27108. description: Used to configure HTTP retries on failures.
  27109. properties:
  27110. maxRetries:
  27111. description: MaxRetries is the maximum number of retry attempts.
  27112. format: int32
  27113. type: integer
  27114. retryInterval:
  27115. description: RetryInterval is the interval between retry attempts.
  27116. type: string
  27117. type: object
  27118. required:
  27119. - provider
  27120. type: object
  27121. status:
  27122. description: SecretStoreStatus defines the observed state of the SecretStore.
  27123. properties:
  27124. capabilities:
  27125. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  27126. type: string
  27127. conditions:
  27128. items:
  27129. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  27130. properties:
  27131. lastTransitionTime:
  27132. format: date-time
  27133. type: string
  27134. message:
  27135. type: string
  27136. reason:
  27137. type: string
  27138. status:
  27139. type: string
  27140. type:
  27141. description: SecretStoreConditionType represents the condition type of the SecretStore.
  27142. type: string
  27143. required:
  27144. - status
  27145. - type
  27146. type: object
  27147. type: array
  27148. type: object
  27149. type: object
  27150. served: false
  27151. storage: false
  27152. subresources:
  27153. status: {}
  27154. ---
  27155. apiVersion: apiextensions.k8s.io/v1
  27156. kind: CustomResourceDefinition
  27157. metadata:
  27158. annotations:
  27159. controller-gen.kubebuilder.io/version: v0.19.0
  27160. labels:
  27161. external-secrets.io/component: controller
  27162. name: acraccesstokens.generators.external-secrets.io
  27163. spec:
  27164. group: generators.external-secrets.io
  27165. names:
  27166. categories:
  27167. - external-secrets
  27168. - external-secrets-generators
  27169. kind: ACRAccessToken
  27170. listKind: ACRAccessTokenList
  27171. plural: acraccesstokens
  27172. singular: acraccesstoken
  27173. scope: Namespaced
  27174. versions:
  27175. - name: v1alpha1
  27176. schema:
  27177. openAPIV3Schema:
  27178. description: |-
  27179. ACRAccessToken returns an Azure Container Registry token
  27180. that can be used for pushing/pulling images.
  27181. Note: by default it will return an ACR Refresh Token with full access
  27182. (depending on the identity).
  27183. This can be scoped down to the repository level using .spec.scope.
  27184. In case scope is defined it will return an ACR Access Token.
  27185. See docs: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md
  27186. properties:
  27187. apiVersion:
  27188. description: |-
  27189. APIVersion defines the versioned schema of this representation of an object.
  27190. Servers should convert recognized schemas to the latest internal value, and
  27191. may reject unrecognized values.
  27192. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27193. type: string
  27194. kind:
  27195. description: |-
  27196. Kind is a string value representing the REST resource this object represents.
  27197. Servers may infer this from the endpoint the client submits requests to.
  27198. Cannot be updated.
  27199. In CamelCase.
  27200. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27201. type: string
  27202. metadata:
  27203. type: object
  27204. spec:
  27205. description: |-
  27206. ACRAccessTokenSpec defines how to generate the access token
  27207. e.g. how to authenticate and which registry to use.
  27208. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  27209. properties:
  27210. auth:
  27211. description: ACRAuth defines the authentication methods for Azure Container Registry.
  27212. properties:
  27213. managedIdentity:
  27214. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  27215. properties:
  27216. identityId:
  27217. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  27218. type: string
  27219. type: object
  27220. servicePrincipal:
  27221. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  27222. properties:
  27223. secretRef:
  27224. description: |-
  27225. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  27226. It uses static credentials stored in a Kind=Secret.
  27227. properties:
  27228. clientId:
  27229. description: The Azure clientId of the service principle used for authentication.
  27230. properties:
  27231. key:
  27232. description: |-
  27233. A key in the referenced Secret.
  27234. Some instances of this field may be defaulted, in others it may be required.
  27235. maxLength: 253
  27236. minLength: 1
  27237. pattern: ^[-._a-zA-Z0-9]+$
  27238. type: string
  27239. name:
  27240. description: The name of the Secret resource being referred to.
  27241. maxLength: 253
  27242. minLength: 1
  27243. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27244. type: string
  27245. namespace:
  27246. description: |-
  27247. The namespace of the Secret resource being referred to.
  27248. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27249. maxLength: 63
  27250. minLength: 1
  27251. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27252. type: string
  27253. type: object
  27254. clientSecret:
  27255. description: The Azure ClientSecret of the service principle used for authentication.
  27256. properties:
  27257. key:
  27258. description: |-
  27259. A key in the referenced Secret.
  27260. Some instances of this field may be defaulted, in others it may be required.
  27261. maxLength: 253
  27262. minLength: 1
  27263. pattern: ^[-._a-zA-Z0-9]+$
  27264. type: string
  27265. name:
  27266. description: The name of the Secret resource being referred to.
  27267. maxLength: 253
  27268. minLength: 1
  27269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27270. type: string
  27271. namespace:
  27272. description: |-
  27273. The namespace of the Secret resource being referred to.
  27274. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27275. maxLength: 63
  27276. minLength: 1
  27277. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27278. type: string
  27279. type: object
  27280. type: object
  27281. required:
  27282. - secretRef
  27283. type: object
  27284. workloadIdentity:
  27285. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  27286. properties:
  27287. serviceAccountRef:
  27288. description: |-
  27289. ServiceAccountRef specified the service account
  27290. that should be used when authenticating with WorkloadIdentity.
  27291. properties:
  27292. audiences:
  27293. description: |-
  27294. Audience specifies the `aud` claim for the service account token
  27295. Some providers automatically extend the audience field based on well-known annotations for workload
  27296. identity (e.g. IRSA or GCP Workload Identity)
  27297. items:
  27298. type: string
  27299. type: array
  27300. name:
  27301. description: The name of the ServiceAccount resource being referred to.
  27302. maxLength: 253
  27303. minLength: 1
  27304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27305. type: string
  27306. namespace:
  27307. description: |-
  27308. Namespace of the resource being referred to.
  27309. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27310. maxLength: 63
  27311. minLength: 1
  27312. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27313. type: string
  27314. required:
  27315. - name
  27316. type: object
  27317. type: object
  27318. type: object
  27319. environmentType:
  27320. default: PublicCloud
  27321. description: |-
  27322. EnvironmentType specifies the Azure cloud environment endpoints to use for
  27323. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  27324. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  27325. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  27326. enum:
  27327. - PublicCloud
  27328. - USGovernmentCloud
  27329. - ChinaCloud
  27330. - GermanCloud
  27331. - AzureStackCloud
  27332. type: string
  27333. registry:
  27334. description: |-
  27335. the domain name of the ACR registry
  27336. e.g. foobarexample.azurecr.io
  27337. type: string
  27338. scope:
  27339. description: |-
  27340. Define the scope for the access token, e.g. pull/push access for a repository.
  27341. if not provided it will return a refresh token that has full scope.
  27342. Note: you need to pin it down to the repository level, there is no wildcard available.
  27343. examples:
  27344. repository:my-repository:pull,push
  27345. repository:my-repository:pull
  27346. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  27347. type: string
  27348. tenantId:
  27349. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  27350. type: string
  27351. required:
  27352. - auth
  27353. - registry
  27354. type: object
  27355. type: object
  27356. served: true
  27357. storage: true
  27358. subresources:
  27359. status: {}
  27360. ---
  27361. apiVersion: apiextensions.k8s.io/v1
  27362. kind: CustomResourceDefinition
  27363. metadata:
  27364. annotations:
  27365. controller-gen.kubebuilder.io/version: v0.19.0
  27366. labels:
  27367. external-secrets.io/component: controller
  27368. name: beyondtrustworkloadcredentialsdynamicsecrets.generators.external-secrets.io
  27369. spec:
  27370. group: generators.external-secrets.io
  27371. names:
  27372. categories:
  27373. - external-secrets
  27374. - external-secrets-generators
  27375. kind: BeyondtrustWorkloadCredentialsDynamicSecret
  27376. listKind: BeyondtrustWorkloadCredentialsDynamicSecretList
  27377. plural: beyondtrustworkloadcredentialsdynamicsecrets
  27378. singular: beyondtrustworkloadcredentialsdynamicsecret
  27379. scope: Namespaced
  27380. versions:
  27381. - name: v1alpha1
  27382. schema:
  27383. openAPIV3Schema:
  27384. description: |-
  27385. BeyondtrustWorkloadCredentialsDynamicSecret represents a generator that requests dynamic credentials from BeyondTrust Workload Credentials.
  27386. This generator calls the BeyondTrust Workload Credentials API to generate fresh, temporary credentials
  27387. (such as AWS STS credentials) each time an ExternalSecret is refreshed.
  27388. Dynamic secret definitions must be created in BeyondTrust Workload Credentials before they can be referenced.
  27389. For complete documentation, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27390. properties:
  27391. apiVersion:
  27392. description: |-
  27393. APIVersion defines the versioned schema of this representation of an object.
  27394. Servers should convert recognized schemas to the latest internal value, and
  27395. may reject unrecognized values.
  27396. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27397. type: string
  27398. kind:
  27399. description: |-
  27400. Kind is a string value representing the REST resource this object represents.
  27401. Servers may infer this from the endpoint the client submits requests to.
  27402. Cannot be updated.
  27403. In CamelCase.
  27404. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27405. type: string
  27406. metadata:
  27407. type: object
  27408. spec:
  27409. description: |-
  27410. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  27411. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  27412. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27413. properties:
  27414. controller:
  27415. description: |-
  27416. Controller selects the controller that should handle this generator.
  27417. Leave empty to use the default controller.
  27418. type: string
  27419. provider:
  27420. description: |-
  27421. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  27422. server connection details, and the folder path to the dynamic secret definition.
  27423. The folderPath should point to a dynamic secret definition that has been created in
  27424. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  27425. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27426. properties:
  27427. auth:
  27428. description: |-
  27429. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  27430. Currently supports API key authentication via Kubernetes secret reference.
  27431. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27432. properties:
  27433. apikey:
  27434. description: |-
  27435. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  27436. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  27437. properties:
  27438. token:
  27439. description: |-
  27440. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  27441. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  27442. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  27443. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27444. properties:
  27445. key:
  27446. description: |-
  27447. A key in the referenced Secret.
  27448. Some instances of this field may be defaulted, in others it may be required.
  27449. maxLength: 253
  27450. minLength: 1
  27451. pattern: ^[-._a-zA-Z0-9]+$
  27452. type: string
  27453. name:
  27454. description: The name of the Secret resource being referred to.
  27455. maxLength: 253
  27456. minLength: 1
  27457. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27458. type: string
  27459. namespace:
  27460. description: |-
  27461. The namespace of the Secret resource being referred to.
  27462. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27463. maxLength: 63
  27464. minLength: 1
  27465. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27466. type: string
  27467. type: object
  27468. required:
  27469. - token
  27470. type: object
  27471. required:
  27472. - apikey
  27473. type: object
  27474. caBundle:
  27475. description: |-
  27476. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27477. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  27478. If not set, the system's trusted root certificates are used.
  27479. format: byte
  27480. type: string
  27481. caProvider:
  27482. description: |-
  27483. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  27484. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27485. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  27486. properties:
  27487. key:
  27488. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  27489. maxLength: 253
  27490. minLength: 1
  27491. pattern: ^[-._a-zA-Z0-9]+$
  27492. type: string
  27493. name:
  27494. description: The name of the object located at the provider type.
  27495. maxLength: 253
  27496. minLength: 1
  27497. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27498. type: string
  27499. namespace:
  27500. description: |-
  27501. The namespace the Provider type is in.
  27502. Can only be defined when used in a ClusterSecretStore.
  27503. maxLength: 63
  27504. minLength: 1
  27505. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27506. type: string
  27507. type:
  27508. description: The type of provider to use such as "Secret", or "ConfigMap".
  27509. enum:
  27510. - Secret
  27511. - ConfigMap
  27512. type: string
  27513. required:
  27514. - name
  27515. - type
  27516. type: object
  27517. folderPath:
  27518. description: |-
  27519. FolderPath specifies the default folder path for secret retrieval.
  27520. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  27521. Example: "production/database" or "dev/api-keys"
  27522. Leave empty to retrieve secrets from the root folder.
  27523. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  27524. type: string
  27525. server:
  27526. description: |-
  27527. Server configures the BeyondTrust Workload Credentials server connection details.
  27528. Includes the API URL and Site ID for your BeyondTrust instance.
  27529. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27530. properties:
  27531. apiUrl:
  27532. description: |-
  27533. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  27534. This should be the full URL to your BeyondTrust instance.
  27535. Example: https://api.beyondtrust.io/siie
  27536. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  27537. type: string
  27538. siteId:
  27539. description: |-
  27540. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  27541. This identifier is unique to your BeyondTrust Workload Credentials instance.
  27542. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  27543. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  27544. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27545. type: string
  27546. required:
  27547. - apiUrl
  27548. - siteId
  27549. type: object
  27550. required:
  27551. - auth
  27552. - server
  27553. type: object
  27554. retrySettings:
  27555. description: |-
  27556. RetrySettings configures exponential backoff for failed API requests.
  27557. If not specified, uses the default retry settings.
  27558. properties:
  27559. maxRetries:
  27560. format: int32
  27561. type: integer
  27562. retryInterval:
  27563. type: string
  27564. type: object
  27565. required:
  27566. - provider
  27567. type: object
  27568. type: object
  27569. served: true
  27570. storage: true
  27571. subresources:
  27572. status: {}
  27573. ---
  27574. apiVersion: apiextensions.k8s.io/v1
  27575. kind: CustomResourceDefinition
  27576. metadata:
  27577. annotations:
  27578. controller-gen.kubebuilder.io/version: v0.19.0
  27579. labels:
  27580. external-secrets.io/component: controller
  27581. name: cloudsmithaccesstokens.generators.external-secrets.io
  27582. spec:
  27583. group: generators.external-secrets.io
  27584. names:
  27585. categories:
  27586. - external-secrets
  27587. - external-secrets-generators
  27588. kind: CloudsmithAccessToken
  27589. listKind: CloudsmithAccessTokenList
  27590. plural: cloudsmithaccesstokens
  27591. singular: cloudsmithaccesstoken
  27592. scope: Namespaced
  27593. versions:
  27594. - name: v1alpha1
  27595. schema:
  27596. openAPIV3Schema:
  27597. description: CloudsmithAccessToken generates Cloudsmith access token using OIDC authentication
  27598. properties:
  27599. apiVersion:
  27600. description: |-
  27601. APIVersion defines the versioned schema of this representation of an object.
  27602. Servers should convert recognized schemas to the latest internal value, and
  27603. may reject unrecognized values.
  27604. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27605. type: string
  27606. kind:
  27607. description: |-
  27608. Kind is a string value representing the REST resource this object represents.
  27609. Servers may infer this from the endpoint the client submits requests to.
  27610. Cannot be updated.
  27611. In CamelCase.
  27612. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27613. type: string
  27614. metadata:
  27615. type: object
  27616. spec:
  27617. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  27618. properties:
  27619. apiUrl:
  27620. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  27621. type: string
  27622. orgSlug:
  27623. description: OrgSlug is the organization slug in Cloudsmith
  27624. type: string
  27625. serviceAccountRef:
  27626. description: Name of the service account you are federating with
  27627. properties:
  27628. audiences:
  27629. description: |-
  27630. Audience specifies the `aud` claim for the service account token
  27631. Some providers automatically extend the audience field based on well-known annotations for workload
  27632. identity (e.g. IRSA or GCP Workload Identity)
  27633. items:
  27634. type: string
  27635. type: array
  27636. name:
  27637. description: The name of the ServiceAccount resource being referred to.
  27638. maxLength: 253
  27639. minLength: 1
  27640. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27641. type: string
  27642. namespace:
  27643. description: |-
  27644. Namespace of the resource being referred to.
  27645. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27646. maxLength: 63
  27647. minLength: 1
  27648. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27649. type: string
  27650. required:
  27651. - name
  27652. type: object
  27653. serviceSlug:
  27654. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  27655. type: string
  27656. required:
  27657. - orgSlug
  27658. - serviceAccountRef
  27659. - serviceSlug
  27660. type: object
  27661. type: object
  27662. served: true
  27663. storage: true
  27664. subresources:
  27665. status: {}
  27666. ---
  27667. apiVersion: apiextensions.k8s.io/v1
  27668. kind: CustomResourceDefinition
  27669. metadata:
  27670. annotations:
  27671. controller-gen.kubebuilder.io/version: v0.19.0
  27672. labels:
  27673. external-secrets.io/component: controller
  27674. name: clustergenerators.generators.external-secrets.io
  27675. spec:
  27676. group: generators.external-secrets.io
  27677. names:
  27678. categories:
  27679. - external-secrets
  27680. - external-secrets-generators
  27681. kind: ClusterGenerator
  27682. listKind: ClusterGeneratorList
  27683. plural: clustergenerators
  27684. singular: clustergenerator
  27685. scope: Cluster
  27686. versions:
  27687. - name: v1alpha1
  27688. schema:
  27689. openAPIV3Schema:
  27690. description: ClusterGenerator represents a cluster-wide generator which can be referenced as part of `generatorRef` fields.
  27691. properties:
  27692. apiVersion:
  27693. description: |-
  27694. APIVersion defines the versioned schema of this representation of an object.
  27695. Servers should convert recognized schemas to the latest internal value, and
  27696. may reject unrecognized values.
  27697. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27698. type: string
  27699. kind:
  27700. description: |-
  27701. Kind is a string value representing the REST resource this object represents.
  27702. Servers may infer this from the endpoint the client submits requests to.
  27703. Cannot be updated.
  27704. In CamelCase.
  27705. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27706. type: string
  27707. metadata:
  27708. type: object
  27709. spec:
  27710. description: ClusterGeneratorSpec defines the desired state of a ClusterGenerator.
  27711. properties:
  27712. generator:
  27713. description: Generator the spec for this generator, must match the kind.
  27714. maxProperties: 1
  27715. minProperties: 1
  27716. properties:
  27717. acrAccessTokenSpec:
  27718. description: |-
  27719. ACRAccessTokenSpec defines how to generate the access token
  27720. e.g. how to authenticate and which registry to use.
  27721. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  27722. properties:
  27723. auth:
  27724. description: ACRAuth defines the authentication methods for Azure Container Registry.
  27725. properties:
  27726. managedIdentity:
  27727. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  27728. properties:
  27729. identityId:
  27730. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  27731. type: string
  27732. type: object
  27733. servicePrincipal:
  27734. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  27735. properties:
  27736. secretRef:
  27737. description: |-
  27738. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  27739. It uses static credentials stored in a Kind=Secret.
  27740. properties:
  27741. clientId:
  27742. description: The Azure clientId of the service principle used for authentication.
  27743. properties:
  27744. key:
  27745. description: |-
  27746. A key in the referenced Secret.
  27747. Some instances of this field may be defaulted, in others it may be required.
  27748. maxLength: 253
  27749. minLength: 1
  27750. pattern: ^[-._a-zA-Z0-9]+$
  27751. type: string
  27752. name:
  27753. description: The name of the Secret resource being referred to.
  27754. maxLength: 253
  27755. minLength: 1
  27756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27757. type: string
  27758. namespace:
  27759. description: |-
  27760. The namespace of the Secret resource being referred to.
  27761. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27762. maxLength: 63
  27763. minLength: 1
  27764. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27765. type: string
  27766. type: object
  27767. clientSecret:
  27768. description: The Azure ClientSecret of the service principle used for authentication.
  27769. properties:
  27770. key:
  27771. description: |-
  27772. A key in the referenced Secret.
  27773. Some instances of this field may be defaulted, in others it may be required.
  27774. maxLength: 253
  27775. minLength: 1
  27776. pattern: ^[-._a-zA-Z0-9]+$
  27777. type: string
  27778. name:
  27779. description: The name of the Secret resource being referred to.
  27780. maxLength: 253
  27781. minLength: 1
  27782. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27783. type: string
  27784. namespace:
  27785. description: |-
  27786. The namespace of the Secret resource being referred to.
  27787. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27788. maxLength: 63
  27789. minLength: 1
  27790. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27791. type: string
  27792. type: object
  27793. type: object
  27794. required:
  27795. - secretRef
  27796. type: object
  27797. workloadIdentity:
  27798. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  27799. properties:
  27800. serviceAccountRef:
  27801. description: |-
  27802. ServiceAccountRef specified the service account
  27803. that should be used when authenticating with WorkloadIdentity.
  27804. properties:
  27805. audiences:
  27806. description: |-
  27807. Audience specifies the `aud` claim for the service account token
  27808. Some providers automatically extend the audience field based on well-known annotations for workload
  27809. identity (e.g. IRSA or GCP Workload Identity)
  27810. items:
  27811. type: string
  27812. type: array
  27813. name:
  27814. description: The name of the ServiceAccount resource being referred to.
  27815. maxLength: 253
  27816. minLength: 1
  27817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27818. type: string
  27819. namespace:
  27820. description: |-
  27821. Namespace of the resource being referred to.
  27822. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27823. maxLength: 63
  27824. minLength: 1
  27825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27826. type: string
  27827. required:
  27828. - name
  27829. type: object
  27830. type: object
  27831. type: object
  27832. environmentType:
  27833. default: PublicCloud
  27834. description: |-
  27835. EnvironmentType specifies the Azure cloud environment endpoints to use for
  27836. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  27837. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  27838. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  27839. enum:
  27840. - PublicCloud
  27841. - USGovernmentCloud
  27842. - ChinaCloud
  27843. - GermanCloud
  27844. - AzureStackCloud
  27845. type: string
  27846. registry:
  27847. description: |-
  27848. the domain name of the ACR registry
  27849. e.g. foobarexample.azurecr.io
  27850. type: string
  27851. scope:
  27852. description: |-
  27853. Define the scope for the access token, e.g. pull/push access for a repository.
  27854. if not provided it will return a refresh token that has full scope.
  27855. Note: you need to pin it down to the repository level, there is no wildcard available.
  27856. examples:
  27857. repository:my-repository:pull,push
  27858. repository:my-repository:pull
  27859. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  27860. type: string
  27861. tenantId:
  27862. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  27863. type: string
  27864. required:
  27865. - auth
  27866. - registry
  27867. type: object
  27868. beyondtrustWorkloadCredentialsDynamicSecretSpec:
  27869. description: |-
  27870. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  27871. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  27872. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27873. properties:
  27874. controller:
  27875. description: |-
  27876. Controller selects the controller that should handle this generator.
  27877. Leave empty to use the default controller.
  27878. type: string
  27879. provider:
  27880. description: |-
  27881. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  27882. server connection details, and the folder path to the dynamic secret definition.
  27883. The folderPath should point to a dynamic secret definition that has been created in
  27884. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  27885. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27886. properties:
  27887. auth:
  27888. description: |-
  27889. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  27890. Currently supports API key authentication via Kubernetes secret reference.
  27891. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27892. properties:
  27893. apikey:
  27894. description: |-
  27895. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  27896. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  27897. properties:
  27898. token:
  27899. description: |-
  27900. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  27901. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  27902. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  27903. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27904. properties:
  27905. key:
  27906. description: |-
  27907. A key in the referenced Secret.
  27908. Some instances of this field may be defaulted, in others it may be required.
  27909. maxLength: 253
  27910. minLength: 1
  27911. pattern: ^[-._a-zA-Z0-9]+$
  27912. type: string
  27913. name:
  27914. description: The name of the Secret resource being referred to.
  27915. maxLength: 253
  27916. minLength: 1
  27917. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27918. type: string
  27919. namespace:
  27920. description: |-
  27921. The namespace of the Secret resource being referred to.
  27922. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27923. maxLength: 63
  27924. minLength: 1
  27925. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27926. type: string
  27927. type: object
  27928. required:
  27929. - token
  27930. type: object
  27931. required:
  27932. - apikey
  27933. type: object
  27934. caBundle:
  27935. description: |-
  27936. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27937. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  27938. If not set, the system's trusted root certificates are used.
  27939. format: byte
  27940. type: string
  27941. caProvider:
  27942. description: |-
  27943. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  27944. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27945. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  27946. properties:
  27947. key:
  27948. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  27949. maxLength: 253
  27950. minLength: 1
  27951. pattern: ^[-._a-zA-Z0-9]+$
  27952. type: string
  27953. name:
  27954. description: The name of the object located at the provider type.
  27955. maxLength: 253
  27956. minLength: 1
  27957. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27958. type: string
  27959. namespace:
  27960. description: |-
  27961. The namespace the Provider type is in.
  27962. Can only be defined when used in a ClusterSecretStore.
  27963. maxLength: 63
  27964. minLength: 1
  27965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27966. type: string
  27967. type:
  27968. description: The type of provider to use such as "Secret", or "ConfigMap".
  27969. enum:
  27970. - Secret
  27971. - ConfigMap
  27972. type: string
  27973. required:
  27974. - name
  27975. - type
  27976. type: object
  27977. folderPath:
  27978. description: |-
  27979. FolderPath specifies the default folder path for secret retrieval.
  27980. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  27981. Example: "production/database" or "dev/api-keys"
  27982. Leave empty to retrieve secrets from the root folder.
  27983. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  27984. type: string
  27985. server:
  27986. description: |-
  27987. Server configures the BeyondTrust Workload Credentials server connection details.
  27988. Includes the API URL and Site ID for your BeyondTrust instance.
  27989. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27990. properties:
  27991. apiUrl:
  27992. description: |-
  27993. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  27994. This should be the full URL to your BeyondTrust instance.
  27995. Example: https://api.beyondtrust.io/siie
  27996. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  27997. type: string
  27998. siteId:
  27999. description: |-
  28000. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  28001. This identifier is unique to your BeyondTrust Workload Credentials instance.
  28002. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  28003. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  28004. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  28005. type: string
  28006. required:
  28007. - apiUrl
  28008. - siteId
  28009. type: object
  28010. required:
  28011. - auth
  28012. - server
  28013. type: object
  28014. retrySettings:
  28015. description: |-
  28016. RetrySettings configures exponential backoff for failed API requests.
  28017. If not specified, uses the default retry settings.
  28018. properties:
  28019. maxRetries:
  28020. format: int32
  28021. type: integer
  28022. retryInterval:
  28023. type: string
  28024. type: object
  28025. required:
  28026. - provider
  28027. type: object
  28028. cloudsmithAccessTokenSpec:
  28029. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  28030. properties:
  28031. apiUrl:
  28032. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  28033. type: string
  28034. orgSlug:
  28035. description: OrgSlug is the organization slug in Cloudsmith
  28036. type: string
  28037. serviceAccountRef:
  28038. description: Name of the service account you are federating with
  28039. properties:
  28040. audiences:
  28041. description: |-
  28042. Audience specifies the `aud` claim for the service account token
  28043. Some providers automatically extend the audience field based on well-known annotations for workload
  28044. identity (e.g. IRSA or GCP Workload Identity)
  28045. items:
  28046. type: string
  28047. type: array
  28048. name:
  28049. description: The name of the ServiceAccount resource being referred to.
  28050. maxLength: 253
  28051. minLength: 1
  28052. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28053. type: string
  28054. namespace:
  28055. description: |-
  28056. Namespace of the resource being referred to.
  28057. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28058. maxLength: 63
  28059. minLength: 1
  28060. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28061. type: string
  28062. required:
  28063. - name
  28064. type: object
  28065. serviceSlug:
  28066. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  28067. type: string
  28068. required:
  28069. - orgSlug
  28070. - serviceAccountRef
  28071. - serviceSlug
  28072. type: object
  28073. ecrAuthorizationTokenSpec:
  28074. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  28075. properties:
  28076. auth:
  28077. description: Auth defines how to authenticate with AWS
  28078. properties:
  28079. jwt:
  28080. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  28081. properties:
  28082. serviceAccountRef:
  28083. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28084. properties:
  28085. audiences:
  28086. description: |-
  28087. Audience specifies the `aud` claim for the service account token
  28088. Some providers automatically extend the audience field based on well-known annotations for workload
  28089. identity (e.g. IRSA or GCP Workload Identity)
  28090. items:
  28091. type: string
  28092. type: array
  28093. name:
  28094. description: The name of the ServiceAccount resource being referred to.
  28095. maxLength: 253
  28096. minLength: 1
  28097. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28098. type: string
  28099. namespace:
  28100. description: |-
  28101. Namespace of the resource being referred to.
  28102. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28103. maxLength: 63
  28104. minLength: 1
  28105. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28106. type: string
  28107. required:
  28108. - name
  28109. type: object
  28110. type: object
  28111. secretRef:
  28112. description: |-
  28113. AWSAuthSecretRef holds secret references for AWS credentials
  28114. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  28115. properties:
  28116. accessKeyIDSecretRef:
  28117. description: The AccessKeyID is used for authentication
  28118. properties:
  28119. key:
  28120. description: |-
  28121. A key in the referenced Secret.
  28122. Some instances of this field may be defaulted, in others it may be required.
  28123. maxLength: 253
  28124. minLength: 1
  28125. pattern: ^[-._a-zA-Z0-9]+$
  28126. type: string
  28127. name:
  28128. description: The name of the Secret resource being referred to.
  28129. maxLength: 253
  28130. minLength: 1
  28131. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28132. type: string
  28133. namespace:
  28134. description: |-
  28135. The namespace of the Secret resource being referred to.
  28136. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28137. maxLength: 63
  28138. minLength: 1
  28139. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28140. type: string
  28141. type: object
  28142. secretAccessKeySecretRef:
  28143. description: The SecretAccessKey is used for authentication
  28144. properties:
  28145. key:
  28146. description: |-
  28147. A key in the referenced Secret.
  28148. Some instances of this field may be defaulted, in others it may be required.
  28149. maxLength: 253
  28150. minLength: 1
  28151. pattern: ^[-._a-zA-Z0-9]+$
  28152. type: string
  28153. name:
  28154. description: The name of the Secret resource being referred to.
  28155. maxLength: 253
  28156. minLength: 1
  28157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28158. type: string
  28159. namespace:
  28160. description: |-
  28161. The namespace of the Secret resource being referred to.
  28162. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28163. maxLength: 63
  28164. minLength: 1
  28165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28166. type: string
  28167. type: object
  28168. sessionTokenSecretRef:
  28169. description: |-
  28170. The SessionToken used for authentication
  28171. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28172. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28173. properties:
  28174. key:
  28175. description: |-
  28176. A key in the referenced Secret.
  28177. Some instances of this field may be defaulted, in others it may be required.
  28178. maxLength: 253
  28179. minLength: 1
  28180. pattern: ^[-._a-zA-Z0-9]+$
  28181. type: string
  28182. name:
  28183. description: The name of the Secret resource being referred to.
  28184. maxLength: 253
  28185. minLength: 1
  28186. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28187. type: string
  28188. namespace:
  28189. description: |-
  28190. The namespace of the Secret resource being referred to.
  28191. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28192. maxLength: 63
  28193. minLength: 1
  28194. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28195. type: string
  28196. type: object
  28197. type: object
  28198. type: object
  28199. region:
  28200. description: Region specifies the region to operate in.
  28201. type: string
  28202. role:
  28203. description: |-
  28204. You can assume a role before making calls to the
  28205. desired AWS service.
  28206. type: string
  28207. scope:
  28208. description: |-
  28209. Scope specifies the ECR service scope.
  28210. Valid options are private and public.
  28211. type: string
  28212. required:
  28213. - region
  28214. type: object
  28215. fakeSpec:
  28216. description: FakeSpec contains the static data.
  28217. properties:
  28218. controller:
  28219. description: |-
  28220. Used to select the correct ESO controller (think: ingress.ingressClassName)
  28221. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  28222. type: string
  28223. data:
  28224. additionalProperties:
  28225. type: string
  28226. description: |-
  28227. Data defines the static data returned
  28228. by this generator.
  28229. type: object
  28230. type: object
  28231. gcrAccessTokenSpec:
  28232. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  28233. properties:
  28234. auth:
  28235. description: Auth defines the means for authenticating with GCP
  28236. properties:
  28237. secretRef:
  28238. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  28239. properties:
  28240. secretAccessKeySecretRef:
  28241. description: The SecretAccessKey is used for authentication
  28242. properties:
  28243. key:
  28244. description: |-
  28245. A key in the referenced Secret.
  28246. Some instances of this field may be defaulted, in others it may be required.
  28247. maxLength: 253
  28248. minLength: 1
  28249. pattern: ^[-._a-zA-Z0-9]+$
  28250. type: string
  28251. name:
  28252. description: The name of the Secret resource being referred to.
  28253. maxLength: 253
  28254. minLength: 1
  28255. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28256. type: string
  28257. namespace:
  28258. description: |-
  28259. The namespace of the Secret resource being referred to.
  28260. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28261. maxLength: 63
  28262. minLength: 1
  28263. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28264. type: string
  28265. type: object
  28266. type: object
  28267. workloadIdentity:
  28268. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  28269. properties:
  28270. clusterLocation:
  28271. type: string
  28272. clusterName:
  28273. type: string
  28274. clusterProjectID:
  28275. type: string
  28276. serviceAccountRef:
  28277. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28278. properties:
  28279. audiences:
  28280. description: |-
  28281. Audience specifies the `aud` claim for the service account token
  28282. Some providers automatically extend the audience field based on well-known annotations for workload
  28283. identity (e.g. IRSA or GCP Workload Identity)
  28284. items:
  28285. type: string
  28286. type: array
  28287. name:
  28288. description: The name of the ServiceAccount resource being referred to.
  28289. maxLength: 253
  28290. minLength: 1
  28291. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28292. type: string
  28293. namespace:
  28294. description: |-
  28295. Namespace of the resource being referred to.
  28296. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28297. maxLength: 63
  28298. minLength: 1
  28299. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28300. type: string
  28301. required:
  28302. - name
  28303. type: object
  28304. required:
  28305. - clusterLocation
  28306. - clusterName
  28307. - serviceAccountRef
  28308. type: object
  28309. workloadIdentityFederation:
  28310. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  28311. properties:
  28312. audience:
  28313. description: |-
  28314. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  28315. If specified, Audience found in the external account credential config will be overridden with the configured value.
  28316. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  28317. type: string
  28318. awsSecurityCredentials:
  28319. description: |-
  28320. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  28321. when using the AWS metadata server is not an option.
  28322. properties:
  28323. awsCredentialsSecretRef:
  28324. description: |-
  28325. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  28326. Secret should be created with below names for keys
  28327. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  28328. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  28329. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  28330. properties:
  28331. name:
  28332. description: name of the secret.
  28333. maxLength: 253
  28334. minLength: 1
  28335. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28336. type: string
  28337. namespace:
  28338. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  28339. maxLength: 63
  28340. minLength: 1
  28341. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28342. type: string
  28343. required:
  28344. - name
  28345. type: object
  28346. region:
  28347. description: region is for configuring the AWS region to be used.
  28348. example: ap-south-1
  28349. maxLength: 50
  28350. minLength: 1
  28351. pattern: ^[a-z0-9-]+$
  28352. type: string
  28353. required:
  28354. - awsCredentialsSecretRef
  28355. - region
  28356. type: object
  28357. credConfig:
  28358. description: |-
  28359. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  28360. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  28361. serviceAccountRef must be used by providing operators service account details.
  28362. properties:
  28363. key:
  28364. description: key name holding the external account credential config.
  28365. maxLength: 253
  28366. minLength: 1
  28367. pattern: ^[-._a-zA-Z0-9]+$
  28368. type: string
  28369. name:
  28370. description: name of the configmap.
  28371. maxLength: 253
  28372. minLength: 1
  28373. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28374. type: string
  28375. namespace:
  28376. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  28377. maxLength: 63
  28378. minLength: 1
  28379. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28380. type: string
  28381. required:
  28382. - key
  28383. - name
  28384. type: object
  28385. externalTokenEndpoint:
  28386. description: |-
  28387. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  28388. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  28389. URL is having the expected value.
  28390. type: string
  28391. gcpServiceAccountEmail:
  28392. description: |-
  28393. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  28394. after Workload Identity Federation. Use this to grant access through the service account's
  28395. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  28396. service_account_impersonation_url in the external account JSON from credConfig;
  28397. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  28398. on that ServiceAccount.
  28399. example: my-gsa@my-project.iam.gserviceaccount.com
  28400. minLength: 1
  28401. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  28402. type: string
  28403. serviceAccountRef:
  28404. description: |-
  28405. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  28406. when Kubernetes is configured as provider in workload identity pool.
  28407. properties:
  28408. audiences:
  28409. description: |-
  28410. Audience specifies the `aud` claim for the service account token
  28411. Some providers automatically extend the audience field based on well-known annotations for workload
  28412. identity (e.g. IRSA or GCP Workload Identity)
  28413. items:
  28414. type: string
  28415. type: array
  28416. name:
  28417. description: The name of the ServiceAccount resource being referred to.
  28418. maxLength: 253
  28419. minLength: 1
  28420. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28421. type: string
  28422. namespace:
  28423. description: |-
  28424. Namespace of the resource being referred to.
  28425. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28426. maxLength: 63
  28427. minLength: 1
  28428. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28429. type: string
  28430. required:
  28431. - name
  28432. type: object
  28433. type: object
  28434. type: object
  28435. projectID:
  28436. description: ProjectID defines which project to use to authenticate with
  28437. type: string
  28438. required:
  28439. - auth
  28440. - projectID
  28441. type: object
  28442. githubAccessTokenSpec:
  28443. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  28444. properties:
  28445. appID:
  28446. type: string
  28447. auth:
  28448. description: Auth configures how ESO authenticates with a Github instance.
  28449. properties:
  28450. privateKey:
  28451. description: GithubSecretRef references a secret containing GitHub credentials.
  28452. properties:
  28453. secretRef:
  28454. description: |-
  28455. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28456. In some instances, `key` is a required field.
  28457. properties:
  28458. key:
  28459. description: |-
  28460. A key in the referenced Secret.
  28461. Some instances of this field may be defaulted, in others it may be required.
  28462. maxLength: 253
  28463. minLength: 1
  28464. pattern: ^[-._a-zA-Z0-9]+$
  28465. type: string
  28466. name:
  28467. description: The name of the Secret resource being referred to.
  28468. maxLength: 253
  28469. minLength: 1
  28470. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28471. type: string
  28472. namespace:
  28473. description: |-
  28474. The namespace of the Secret resource being referred to.
  28475. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28476. maxLength: 63
  28477. minLength: 1
  28478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28479. type: string
  28480. type: object
  28481. required:
  28482. - secretRef
  28483. type: object
  28484. required:
  28485. - privateKey
  28486. type: object
  28487. installID:
  28488. type: string
  28489. permissions:
  28490. additionalProperties:
  28491. type: string
  28492. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  28493. type: object
  28494. repositories:
  28495. description: |-
  28496. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  28497. is installed to.
  28498. items:
  28499. type: string
  28500. type: array
  28501. url:
  28502. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  28503. type: string
  28504. required:
  28505. - appID
  28506. - auth
  28507. - installID
  28508. type: object
  28509. gitlabDeployTokenSpec:
  28510. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  28511. properties:
  28512. auth:
  28513. description: Auth configures how ESO authenticates with the GitLab API.
  28514. properties:
  28515. token:
  28516. description: |-
  28517. Token references a secret containing a GitLab access token (personal, group, or
  28518. project) with the api scope and at least the Maintainer role on the target.
  28519. properties:
  28520. secretRef:
  28521. description: |-
  28522. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28523. In some instances, `key` is a required field.
  28524. properties:
  28525. key:
  28526. description: |-
  28527. A key in the referenced Secret.
  28528. Some instances of this field may be defaulted, in others it may be required.
  28529. maxLength: 253
  28530. minLength: 1
  28531. pattern: ^[-._a-zA-Z0-9]+$
  28532. type: string
  28533. name:
  28534. description: The name of the Secret resource being referred to.
  28535. maxLength: 253
  28536. minLength: 1
  28537. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28538. type: string
  28539. namespace:
  28540. description: |-
  28541. The namespace of the Secret resource being referred to.
  28542. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28543. maxLength: 63
  28544. minLength: 1
  28545. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28546. type: string
  28547. type: object
  28548. required:
  28549. - secretRef
  28550. type: object
  28551. required:
  28552. - token
  28553. type: object
  28554. expiresAt:
  28555. description: |-
  28556. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  28557. not expire on the GitLab side and is revoked only when the generator state is
  28558. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  28559. format: date-time
  28560. type: string
  28561. groupID:
  28562. description: |-
  28563. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  28564. create the deploy token in. The generator URL-escapes paths before calling the
  28565. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  28566. minLength: 1
  28567. type: string
  28568. name:
  28569. description: Name of the deploy token.
  28570. minLength: 1
  28571. type: string
  28572. projectID:
  28573. description: |-
  28574. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  28575. project to create the deploy token in. The generator URL-escapes paths before
  28576. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  28577. minLength: 1
  28578. type: string
  28579. scopes:
  28580. description: Scopes granted to the deploy token. At least one scope is required.
  28581. items:
  28582. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  28583. enum:
  28584. - read_repository
  28585. - read_registry
  28586. - write_registry
  28587. - read_package_registry
  28588. - write_package_registry
  28589. - read_virtual_registry
  28590. - write_virtual_registry
  28591. type: string
  28592. minItems: 1
  28593. type: array
  28594. url:
  28595. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  28596. type: string
  28597. username:
  28598. description: |-
  28599. Username is an optional username for the deploy token. GitLab defaults it to
  28600. gitlab+deploy-token-{n} when omitted.
  28601. type: string
  28602. required:
  28603. - auth
  28604. - name
  28605. - scopes
  28606. type: object
  28607. x-kubernetes-validations:
  28608. - message: exactly one of projectID or groupID must be set
  28609. rule: has(self.projectID) != has(self.groupID)
  28610. grafanaSpec:
  28611. description: GrafanaSpec controls the behavior of the grafana generator.
  28612. properties:
  28613. auth:
  28614. description: |-
  28615. Auth is the authentication configuration to authenticate
  28616. against the Grafana instance.
  28617. properties:
  28618. basic:
  28619. description: |-
  28620. Basic auth credentials used to authenticate against the Grafana instance.
  28621. Note: you need a token which has elevated permissions to create service accounts.
  28622. See here for the documentation on basic roles offered by Grafana:
  28623. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28624. properties:
  28625. password:
  28626. description: A basic auth password used to authenticate against the Grafana instance.
  28627. properties:
  28628. key:
  28629. description: The key where the token is found.
  28630. maxLength: 253
  28631. minLength: 1
  28632. pattern: ^[-._a-zA-Z0-9]+$
  28633. type: string
  28634. name:
  28635. description: The name of the Secret resource being referred to.
  28636. maxLength: 253
  28637. minLength: 1
  28638. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28639. type: string
  28640. type: object
  28641. username:
  28642. description: A basic auth username used to authenticate against the Grafana instance.
  28643. type: string
  28644. required:
  28645. - password
  28646. - username
  28647. type: object
  28648. token:
  28649. description: |-
  28650. A service account token used to authenticate against the Grafana instance.
  28651. Note: you need a token which has elevated permissions to create service accounts.
  28652. See here for the documentation on basic roles offered by Grafana:
  28653. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28654. properties:
  28655. key:
  28656. description: The key where the token is found.
  28657. maxLength: 253
  28658. minLength: 1
  28659. pattern: ^[-._a-zA-Z0-9]+$
  28660. type: string
  28661. name:
  28662. description: The name of the Secret resource being referred to.
  28663. maxLength: 253
  28664. minLength: 1
  28665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28666. type: string
  28667. type: object
  28668. type: object
  28669. serviceAccount:
  28670. description: |-
  28671. ServiceAccount is the configuration for the service account that
  28672. is supposed to be generated by the generator.
  28673. properties:
  28674. name:
  28675. description: Name is the name of the service account that will be created by ESO.
  28676. type: string
  28677. role:
  28678. description: |-
  28679. Role is the role of the service account.
  28680. See here for the documentation on basic roles offered by Grafana:
  28681. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28682. type: string
  28683. secondsToLive:
  28684. description: |-
  28685. SecondsToLive is the number of seconds before the generated service account token will expire.
  28686. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  28687. format: int64
  28688. minimum: 1
  28689. type: integer
  28690. required:
  28691. - name
  28692. - role
  28693. type: object
  28694. url:
  28695. description: URL is the URL of the Grafana instance.
  28696. type: string
  28697. required:
  28698. - auth
  28699. - serviceAccount
  28700. - url
  28701. type: object
  28702. mfaSpec:
  28703. description: MFASpec controls the behavior of the mfa generator.
  28704. properties:
  28705. algorithm:
  28706. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  28707. type: string
  28708. length:
  28709. description: Length defines the token length. Defaults to 6 characters.
  28710. type: integer
  28711. secret:
  28712. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  28713. properties:
  28714. key:
  28715. description: |-
  28716. A key in the referenced Secret.
  28717. Some instances of this field may be defaulted, in others it may be required.
  28718. maxLength: 253
  28719. minLength: 1
  28720. pattern: ^[-._a-zA-Z0-9]+$
  28721. type: string
  28722. name:
  28723. description: The name of the Secret resource being referred to.
  28724. maxLength: 253
  28725. minLength: 1
  28726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28727. type: string
  28728. namespace:
  28729. description: |-
  28730. The namespace of the Secret resource being referred to.
  28731. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28732. maxLength: 63
  28733. minLength: 1
  28734. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28735. type: string
  28736. type: object
  28737. timePeriod:
  28738. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  28739. type: integer
  28740. when:
  28741. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  28742. format: date-time
  28743. type: string
  28744. required:
  28745. - secret
  28746. type: object
  28747. passwordSpec:
  28748. description: PasswordSpec controls the behavior of the password generator.
  28749. properties:
  28750. allowRepeat:
  28751. default: false
  28752. description: set AllowRepeat to true to allow repeating characters.
  28753. type: boolean
  28754. digits:
  28755. description: |-
  28756. Digits specifies the number of digits in the generated
  28757. password. If omitted it defaults to 25% of the length of the password
  28758. type: integer
  28759. encoding:
  28760. default: raw
  28761. description: |-
  28762. Encoding specifies the encoding of the generated password.
  28763. Valid values are:
  28764. - "raw" (default): no encoding
  28765. - "base64": standard base64 encoding
  28766. - "base64url": base64url encoding
  28767. - "base32": base32 encoding
  28768. - "hex": hexadecimal encoding
  28769. enum:
  28770. - base64
  28771. - base64url
  28772. - base32
  28773. - hex
  28774. - raw
  28775. type: string
  28776. length:
  28777. default: 24
  28778. description: |-
  28779. Length of the password to be generated.
  28780. Defaults to 24
  28781. type: integer
  28782. noUpper:
  28783. default: false
  28784. description: Set NoUpper to disable uppercase characters
  28785. type: boolean
  28786. secretKeys:
  28787. description: |-
  28788. SecretKeys defines the keys that will be populated with generated passwords.
  28789. Defaults to "password" when not set.
  28790. items:
  28791. type: string
  28792. minItems: 1
  28793. type: array
  28794. symbolCharacters:
  28795. description: |-
  28796. SymbolCharacters specifies the special characters that should be used
  28797. in the generated password.
  28798. type: string
  28799. symbols:
  28800. description: |-
  28801. Symbols specifies the number of symbol characters in the generated
  28802. password. If omitted it defaults to 25% of the length of the password
  28803. type: integer
  28804. required:
  28805. - allowRepeat
  28806. - length
  28807. - noUpper
  28808. type: object
  28809. quayAccessTokenSpec:
  28810. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  28811. properties:
  28812. robotAccount:
  28813. description: Name of the robot account you are federating with
  28814. type: string
  28815. serviceAccountRef:
  28816. description: Name of the service account you are federating with
  28817. properties:
  28818. audiences:
  28819. description: |-
  28820. Audience specifies the `aud` claim for the service account token
  28821. Some providers automatically extend the audience field based on well-known annotations for workload
  28822. identity (e.g. IRSA or GCP Workload Identity)
  28823. items:
  28824. type: string
  28825. type: array
  28826. name:
  28827. description: The name of the ServiceAccount resource being referred to.
  28828. maxLength: 253
  28829. minLength: 1
  28830. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28831. type: string
  28832. namespace:
  28833. description: |-
  28834. Namespace of the resource being referred to.
  28835. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28836. maxLength: 63
  28837. minLength: 1
  28838. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28839. type: string
  28840. required:
  28841. - name
  28842. type: object
  28843. url:
  28844. description: URL configures the Quay instance URL. Defaults to quay.io.
  28845. type: string
  28846. required:
  28847. - robotAccount
  28848. - serviceAccountRef
  28849. type: object
  28850. sshKeySpec:
  28851. description: SSHKeySpec controls the behavior of the ssh key generator.
  28852. properties:
  28853. comment:
  28854. description: Comment specifies an optional comment for the SSH key
  28855. type: string
  28856. keySize:
  28857. description: |-
  28858. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  28859. For RSA keys: 2048, 3072, 4096
  28860. For ECDSA keys: 256, 384, 521
  28861. Ignored for ed25519 keys
  28862. maximum: 8192
  28863. minimum: 256
  28864. type: integer
  28865. keyType:
  28866. default: rsa
  28867. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  28868. enum:
  28869. - rsa
  28870. - ecdsa
  28871. - ed25519
  28872. type: string
  28873. type: object
  28874. stsSessionTokenSpec:
  28875. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  28876. properties:
  28877. auth:
  28878. description: Auth defines how to authenticate with AWS
  28879. properties:
  28880. jwt:
  28881. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  28882. properties:
  28883. serviceAccountRef:
  28884. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28885. properties:
  28886. audiences:
  28887. description: |-
  28888. Audience specifies the `aud` claim for the service account token
  28889. Some providers automatically extend the audience field based on well-known annotations for workload
  28890. identity (e.g. IRSA or GCP Workload Identity)
  28891. items:
  28892. type: string
  28893. type: array
  28894. name:
  28895. description: The name of the ServiceAccount resource being referred to.
  28896. maxLength: 253
  28897. minLength: 1
  28898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28899. type: string
  28900. namespace:
  28901. description: |-
  28902. Namespace of the resource being referred to.
  28903. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28904. maxLength: 63
  28905. minLength: 1
  28906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28907. type: string
  28908. required:
  28909. - name
  28910. type: object
  28911. type: object
  28912. secretRef:
  28913. description: |-
  28914. AWSAuthSecretRef holds secret references for AWS credentials
  28915. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  28916. properties:
  28917. accessKeyIDSecretRef:
  28918. description: The AccessKeyID is used for authentication
  28919. properties:
  28920. key:
  28921. description: |-
  28922. A key in the referenced Secret.
  28923. Some instances of this field may be defaulted, in others it may be required.
  28924. maxLength: 253
  28925. minLength: 1
  28926. pattern: ^[-._a-zA-Z0-9]+$
  28927. type: string
  28928. name:
  28929. description: The name of the Secret resource being referred to.
  28930. maxLength: 253
  28931. minLength: 1
  28932. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28933. type: string
  28934. namespace:
  28935. description: |-
  28936. The namespace of the Secret resource being referred to.
  28937. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28938. maxLength: 63
  28939. minLength: 1
  28940. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28941. type: string
  28942. type: object
  28943. secretAccessKeySecretRef:
  28944. description: The SecretAccessKey is used for authentication
  28945. properties:
  28946. key:
  28947. description: |-
  28948. A key in the referenced Secret.
  28949. Some instances of this field may be defaulted, in others it may be required.
  28950. maxLength: 253
  28951. minLength: 1
  28952. pattern: ^[-._a-zA-Z0-9]+$
  28953. type: string
  28954. name:
  28955. description: The name of the Secret resource being referred to.
  28956. maxLength: 253
  28957. minLength: 1
  28958. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28959. type: string
  28960. namespace:
  28961. description: |-
  28962. The namespace of the Secret resource being referred to.
  28963. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28964. maxLength: 63
  28965. minLength: 1
  28966. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28967. type: string
  28968. type: object
  28969. sessionTokenSecretRef:
  28970. description: |-
  28971. The SessionToken used for authentication
  28972. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28973. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28974. properties:
  28975. key:
  28976. description: |-
  28977. A key in the referenced Secret.
  28978. Some instances of this field may be defaulted, in others it may be required.
  28979. maxLength: 253
  28980. minLength: 1
  28981. pattern: ^[-._a-zA-Z0-9]+$
  28982. type: string
  28983. name:
  28984. description: The name of the Secret resource being referred to.
  28985. maxLength: 253
  28986. minLength: 1
  28987. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28988. type: string
  28989. namespace:
  28990. description: |-
  28991. The namespace of the Secret resource being referred to.
  28992. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28993. maxLength: 63
  28994. minLength: 1
  28995. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28996. type: string
  28997. type: object
  28998. type: object
  28999. type: object
  29000. region:
  29001. description: Region specifies the region to operate in.
  29002. type: string
  29003. requestParameters:
  29004. description: RequestParameters contains parameters that can be passed to the STS service.
  29005. properties:
  29006. serialNumber:
  29007. description: |-
  29008. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  29009. the GetSessionToken call.
  29010. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  29011. (such as arn:aws:iam::123456789012:mfa/user)
  29012. type: string
  29013. sessionDuration:
  29014. format: int32
  29015. type: integer
  29016. tokenCode:
  29017. description: TokenCode is the value provided by the MFA device, if MFA is required.
  29018. type: string
  29019. type: object
  29020. role:
  29021. description: |-
  29022. You can assume a role before making calls to the
  29023. desired AWS service.
  29024. type: string
  29025. required:
  29026. - region
  29027. type: object
  29028. uuidSpec:
  29029. description: UUIDSpec controls the behavior of the uuid generator.
  29030. type: object
  29031. vaultDynamicSecretSpec:
  29032. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  29033. properties:
  29034. allowEmptyResponse:
  29035. default: false
  29036. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  29037. type: boolean
  29038. controller:
  29039. description: |-
  29040. Used to select the correct ESO controller (think: ingress.ingressClassName)
  29041. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  29042. type: string
  29043. getParameters:
  29044. additionalProperties:
  29045. items:
  29046. type: string
  29047. type: array
  29048. description: |-
  29049. GetParameters are query-string parameters passed to Vault on GET calls.
  29050. Each key may map to multiple values, matching HTTP query-string semantics.
  29051. Ignored for non-GET methods; use Parameters for write bodies.
  29052. type: object
  29053. method:
  29054. description: Vault API method to use (GET/POST/other)
  29055. type: string
  29056. parameters:
  29057. description: Parameters to pass to Vault write (for non-GET methods)
  29058. x-kubernetes-preserve-unknown-fields: true
  29059. path:
  29060. description: Vault path to obtain the dynamic secret from
  29061. type: string
  29062. provider:
  29063. description: Vault provider common spec
  29064. properties:
  29065. auth:
  29066. description: Auth configures how secret-manager authenticates with the Vault server.
  29067. properties:
  29068. appRole:
  29069. description: |-
  29070. AppRole authenticates with Vault using the App Role auth mechanism,
  29071. with the role and secret stored in a Kubernetes Secret resource.
  29072. properties:
  29073. path:
  29074. default: approle
  29075. description: |-
  29076. Path where the App Role authentication backend is mounted
  29077. in Vault, e.g: "approle"
  29078. type: string
  29079. roleId:
  29080. description: |-
  29081. RoleID configured in the App Role authentication backend when setting
  29082. up the authentication backend in Vault.
  29083. type: string
  29084. roleRef:
  29085. description: |-
  29086. Reference to a key in a Secret that contains the App Role ID used
  29087. to authenticate with Vault.
  29088. The `key` field must be specified and denotes which entry within the Secret
  29089. resource is used as the app role id.
  29090. properties:
  29091. key:
  29092. description: |-
  29093. A key in the referenced Secret.
  29094. Some instances of this field may be defaulted, in others it may be required.
  29095. maxLength: 253
  29096. minLength: 1
  29097. pattern: ^[-._a-zA-Z0-9]+$
  29098. type: string
  29099. name:
  29100. description: The name of the Secret resource being referred to.
  29101. maxLength: 253
  29102. minLength: 1
  29103. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29104. type: string
  29105. namespace:
  29106. description: |-
  29107. The namespace of the Secret resource being referred to.
  29108. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29109. maxLength: 63
  29110. minLength: 1
  29111. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29112. type: string
  29113. type: object
  29114. secretRef:
  29115. description: |-
  29116. Reference to a key in a Secret that contains the App Role secret used
  29117. to authenticate with Vault.
  29118. The `key` field must be specified and denotes which entry within the Secret
  29119. resource is used as the app role secret.
  29120. properties:
  29121. key:
  29122. description: |-
  29123. A key in the referenced Secret.
  29124. Some instances of this field may be defaulted, in others it may be required.
  29125. maxLength: 253
  29126. minLength: 1
  29127. pattern: ^[-._a-zA-Z0-9]+$
  29128. type: string
  29129. name:
  29130. description: The name of the Secret resource being referred to.
  29131. maxLength: 253
  29132. minLength: 1
  29133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29134. type: string
  29135. namespace:
  29136. description: |-
  29137. The namespace of the Secret resource being referred to.
  29138. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29139. maxLength: 63
  29140. minLength: 1
  29141. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29142. type: string
  29143. type: object
  29144. required:
  29145. - path
  29146. - secretRef
  29147. type: object
  29148. cert:
  29149. description: |-
  29150. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  29151. Cert authentication method
  29152. properties:
  29153. clientCert:
  29154. description: |-
  29155. ClientCert is a certificate to authenticate using the Cert Vault
  29156. authentication method
  29157. properties:
  29158. key:
  29159. description: |-
  29160. A key in the referenced Secret.
  29161. Some instances of this field may be defaulted, in others it may be required.
  29162. maxLength: 253
  29163. minLength: 1
  29164. pattern: ^[-._a-zA-Z0-9]+$
  29165. type: string
  29166. name:
  29167. description: The name of the Secret resource being referred to.
  29168. maxLength: 253
  29169. minLength: 1
  29170. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29171. type: string
  29172. namespace:
  29173. description: |-
  29174. The namespace of the Secret resource being referred to.
  29175. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29176. maxLength: 63
  29177. minLength: 1
  29178. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29179. type: string
  29180. type: object
  29181. path:
  29182. default: cert
  29183. description: |-
  29184. Path where the Certificate authentication backend is mounted
  29185. in Vault, e.g: "cert"
  29186. type: string
  29187. secretRef:
  29188. description: |-
  29189. SecretRef to a key in a Secret resource containing client private key to
  29190. authenticate with Vault using the Cert authentication method
  29191. properties:
  29192. key:
  29193. description: |-
  29194. A key in the referenced Secret.
  29195. Some instances of this field may be defaulted, in others it may be required.
  29196. maxLength: 253
  29197. minLength: 1
  29198. pattern: ^[-._a-zA-Z0-9]+$
  29199. type: string
  29200. name:
  29201. description: The name of the Secret resource being referred to.
  29202. maxLength: 253
  29203. minLength: 1
  29204. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29205. type: string
  29206. namespace:
  29207. description: |-
  29208. The namespace of the Secret resource being referred to.
  29209. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29210. maxLength: 63
  29211. minLength: 1
  29212. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29213. type: string
  29214. type: object
  29215. vaultRole:
  29216. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  29217. type: string
  29218. type: object
  29219. gcp:
  29220. description: |-
  29221. Gcp authenticates with Vault using Google Cloud Platform authentication method
  29222. GCP authentication method
  29223. properties:
  29224. location:
  29225. description: Location optionally defines a location/region for the secret
  29226. type: string
  29227. path:
  29228. default: gcp
  29229. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  29230. type: string
  29231. projectID:
  29232. description: Project ID of the Google Cloud Platform project
  29233. type: string
  29234. role:
  29235. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  29236. type: string
  29237. secretRef:
  29238. description: Specify credentials in a Secret object
  29239. properties:
  29240. secretAccessKeySecretRef:
  29241. description: The SecretAccessKey is used for authentication
  29242. properties:
  29243. key:
  29244. description: |-
  29245. A key in the referenced Secret.
  29246. Some instances of this field may be defaulted, in others it may be required.
  29247. maxLength: 253
  29248. minLength: 1
  29249. pattern: ^[-._a-zA-Z0-9]+$
  29250. type: string
  29251. name:
  29252. description: The name of the Secret resource being referred to.
  29253. maxLength: 253
  29254. minLength: 1
  29255. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29256. type: string
  29257. namespace:
  29258. description: |-
  29259. The namespace of the Secret resource being referred to.
  29260. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29261. maxLength: 63
  29262. minLength: 1
  29263. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29264. type: string
  29265. type: object
  29266. type: object
  29267. serviceAccountRef:
  29268. description: ServiceAccountRef to a service account for impersonation
  29269. properties:
  29270. audiences:
  29271. description: |-
  29272. Audience specifies the `aud` claim for the service account token
  29273. Some providers automatically extend the audience field based on well-known annotations for workload
  29274. identity (e.g. IRSA or GCP Workload Identity)
  29275. items:
  29276. type: string
  29277. type: array
  29278. name:
  29279. description: The name of the ServiceAccount resource being referred to.
  29280. maxLength: 253
  29281. minLength: 1
  29282. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29283. type: string
  29284. namespace:
  29285. description: |-
  29286. Namespace of the resource being referred to.
  29287. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29288. maxLength: 63
  29289. minLength: 1
  29290. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29291. type: string
  29292. required:
  29293. - name
  29294. type: object
  29295. workloadIdentity:
  29296. description: Specify a service account with Workload Identity
  29297. properties:
  29298. clusterLocation:
  29299. description: |-
  29300. ClusterLocation is the location of the cluster
  29301. If not specified, it fetches information from the metadata server
  29302. type: string
  29303. clusterName:
  29304. description: |-
  29305. ClusterName is the name of the cluster
  29306. If not specified, it fetches information from the metadata server
  29307. type: string
  29308. clusterProjectID:
  29309. description: |-
  29310. ClusterProjectID is the project ID of the cluster
  29311. If not specified, it fetches information from the metadata server
  29312. type: string
  29313. serviceAccountRef:
  29314. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29315. properties:
  29316. audiences:
  29317. description: |-
  29318. Audience specifies the `aud` claim for the service account token
  29319. Some providers automatically extend the audience field based on well-known annotations for workload
  29320. identity (e.g. IRSA or GCP Workload Identity)
  29321. items:
  29322. type: string
  29323. type: array
  29324. name:
  29325. description: The name of the ServiceAccount resource being referred to.
  29326. maxLength: 253
  29327. minLength: 1
  29328. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29329. type: string
  29330. namespace:
  29331. description: |-
  29332. Namespace of the resource being referred to.
  29333. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29334. maxLength: 63
  29335. minLength: 1
  29336. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29337. type: string
  29338. required:
  29339. - name
  29340. type: object
  29341. required:
  29342. - serviceAccountRef
  29343. type: object
  29344. required:
  29345. - role
  29346. type: object
  29347. iam:
  29348. description: |-
  29349. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  29350. AWS IAM authentication method
  29351. properties:
  29352. externalID:
  29353. description: AWS External ID set on assumed IAM roles
  29354. type: string
  29355. jwt:
  29356. description: Specify a service account with IRSA enabled
  29357. properties:
  29358. serviceAccountRef:
  29359. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29360. properties:
  29361. audiences:
  29362. description: |-
  29363. Audience specifies the `aud` claim for the service account token
  29364. Some providers automatically extend the audience field based on well-known annotations for workload
  29365. identity (e.g. IRSA or GCP Workload Identity)
  29366. items:
  29367. type: string
  29368. type: array
  29369. name:
  29370. description: The name of the ServiceAccount resource being referred to.
  29371. maxLength: 253
  29372. minLength: 1
  29373. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29374. type: string
  29375. namespace:
  29376. description: |-
  29377. Namespace of the resource being referred to.
  29378. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29379. maxLength: 63
  29380. minLength: 1
  29381. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29382. type: string
  29383. required:
  29384. - name
  29385. type: object
  29386. type: object
  29387. path:
  29388. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  29389. type: string
  29390. region:
  29391. description: AWS region
  29392. type: string
  29393. role:
  29394. description: This is the AWS role to be assumed before talking to vault
  29395. type: string
  29396. secretRef:
  29397. description: Specify credentials in a Secret object
  29398. properties:
  29399. accessKeyIDSecretRef:
  29400. description: The AccessKeyID is used for authentication
  29401. properties:
  29402. key:
  29403. description: |-
  29404. A key in the referenced Secret.
  29405. Some instances of this field may be defaulted, in others it may be required.
  29406. maxLength: 253
  29407. minLength: 1
  29408. pattern: ^[-._a-zA-Z0-9]+$
  29409. type: string
  29410. name:
  29411. description: The name of the Secret resource being referred to.
  29412. maxLength: 253
  29413. minLength: 1
  29414. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29415. type: string
  29416. namespace:
  29417. description: |-
  29418. The namespace of the Secret resource being referred to.
  29419. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29420. maxLength: 63
  29421. minLength: 1
  29422. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29423. type: string
  29424. type: object
  29425. secretAccessKeySecretRef:
  29426. description: The SecretAccessKey is used for authentication
  29427. properties:
  29428. key:
  29429. description: |-
  29430. A key in the referenced Secret.
  29431. Some instances of this field may be defaulted, in others it may be required.
  29432. maxLength: 253
  29433. minLength: 1
  29434. pattern: ^[-._a-zA-Z0-9]+$
  29435. type: string
  29436. name:
  29437. description: The name of the Secret resource being referred to.
  29438. maxLength: 253
  29439. minLength: 1
  29440. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29441. type: string
  29442. namespace:
  29443. description: |-
  29444. The namespace of the Secret resource being referred to.
  29445. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29446. maxLength: 63
  29447. minLength: 1
  29448. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29449. type: string
  29450. type: object
  29451. sessionTokenSecretRef:
  29452. description: |-
  29453. The SessionToken used for authentication
  29454. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  29455. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  29456. properties:
  29457. key:
  29458. description: |-
  29459. A key in the referenced Secret.
  29460. Some instances of this field may be defaulted, in others it may be required.
  29461. maxLength: 253
  29462. minLength: 1
  29463. pattern: ^[-._a-zA-Z0-9]+$
  29464. type: string
  29465. name:
  29466. description: The name of the Secret resource being referred to.
  29467. maxLength: 253
  29468. minLength: 1
  29469. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29470. type: string
  29471. namespace:
  29472. description: |-
  29473. The namespace of the Secret resource being referred to.
  29474. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29475. maxLength: 63
  29476. minLength: 1
  29477. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29478. type: string
  29479. type: object
  29480. type: object
  29481. vaultAwsIamServerID:
  29482. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  29483. type: string
  29484. vaultRole:
  29485. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  29486. type: string
  29487. required:
  29488. - vaultRole
  29489. type: object
  29490. jwt:
  29491. description: |-
  29492. Jwt authenticates with Vault by passing role and JWT token using the
  29493. JWT/OIDC authentication method
  29494. properties:
  29495. kubernetesServiceAccountToken:
  29496. description: |-
  29497. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  29498. a token for with the `TokenRequest` API.
  29499. properties:
  29500. audiences:
  29501. description: |-
  29502. Optional audiences field that will be used to request a temporary Kubernetes service
  29503. account token for the service account referenced by `serviceAccountRef`.
  29504. Defaults to a single audience `vault` it not specified.
  29505. Deprecated: use serviceAccountRef.Audiences instead
  29506. items:
  29507. type: string
  29508. type: array
  29509. expirationSeconds:
  29510. description: |-
  29511. Optional expiration time in seconds that will be used to request a temporary
  29512. Kubernetes service account token for the service account referenced by
  29513. `serviceAccountRef`.
  29514. Deprecated: this will be removed in the future.
  29515. Defaults to 10 minutes.
  29516. format: int64
  29517. type: integer
  29518. serviceAccountRef:
  29519. description: Service account field containing the name of a kubernetes ServiceAccount.
  29520. properties:
  29521. audiences:
  29522. description: |-
  29523. Audience specifies the `aud` claim for the service account token
  29524. Some providers automatically extend the audience field based on well-known annotations for workload
  29525. identity (e.g. IRSA or GCP Workload Identity)
  29526. items:
  29527. type: string
  29528. type: array
  29529. name:
  29530. description: The name of the ServiceAccount resource being referred to.
  29531. maxLength: 253
  29532. minLength: 1
  29533. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29534. type: string
  29535. namespace:
  29536. description: |-
  29537. Namespace of the resource being referred to.
  29538. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29539. maxLength: 63
  29540. minLength: 1
  29541. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29542. type: string
  29543. required:
  29544. - name
  29545. type: object
  29546. required:
  29547. - serviceAccountRef
  29548. type: object
  29549. path:
  29550. default: jwt
  29551. description: |-
  29552. Path where the JWT authentication backend is mounted
  29553. in Vault, e.g: "jwt"
  29554. type: string
  29555. role:
  29556. description: |-
  29557. Role is a JWT role to authenticate using the JWT/OIDC Vault
  29558. authentication method
  29559. type: string
  29560. secretRef:
  29561. description: |-
  29562. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  29563. authenticate with Vault using the JWT/OIDC authentication method.
  29564. properties:
  29565. key:
  29566. description: |-
  29567. A key in the referenced Secret.
  29568. Some instances of this field may be defaulted, in others it may be required.
  29569. maxLength: 253
  29570. minLength: 1
  29571. pattern: ^[-._a-zA-Z0-9]+$
  29572. type: string
  29573. name:
  29574. description: The name of the Secret resource being referred to.
  29575. maxLength: 253
  29576. minLength: 1
  29577. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29578. type: string
  29579. namespace:
  29580. description: |-
  29581. The namespace of the Secret resource being referred to.
  29582. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29583. maxLength: 63
  29584. minLength: 1
  29585. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29586. type: string
  29587. type: object
  29588. required:
  29589. - path
  29590. type: object
  29591. kubernetes:
  29592. description: |-
  29593. Kubernetes authenticates with Vault by passing the ServiceAccount
  29594. token stored in the named Secret resource to the Vault server.
  29595. properties:
  29596. mountPath:
  29597. default: kubernetes
  29598. description: |-
  29599. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  29600. "kubernetes"
  29601. type: string
  29602. role:
  29603. description: |-
  29604. A required field containing the Vault Role to assume. A Role binds a
  29605. Kubernetes ServiceAccount with a set of Vault policies.
  29606. type: string
  29607. secretRef:
  29608. description: |-
  29609. Optional secret field containing a Kubernetes ServiceAccount JWT used
  29610. for authenticating with Vault. If a name is specified without a key,
  29611. `token` is the default. If one is not specified, the one bound to
  29612. the controller will be used.
  29613. properties:
  29614. key:
  29615. description: |-
  29616. A key in the referenced Secret.
  29617. Some instances of this field may be defaulted, in others it may be required.
  29618. maxLength: 253
  29619. minLength: 1
  29620. pattern: ^[-._a-zA-Z0-9]+$
  29621. type: string
  29622. name:
  29623. description: The name of the Secret resource being referred to.
  29624. maxLength: 253
  29625. minLength: 1
  29626. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29627. type: string
  29628. namespace:
  29629. description: |-
  29630. The namespace of the Secret resource being referred to.
  29631. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29632. maxLength: 63
  29633. minLength: 1
  29634. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29635. type: string
  29636. type: object
  29637. serviceAccountRef:
  29638. description: |-
  29639. Optional service account field containing the name of a kubernetes ServiceAccount.
  29640. If the service account is specified, the service account secret token JWT will be used
  29641. for authenticating with Vault. If the service account selector is not supplied,
  29642. the secretRef will be used instead.
  29643. properties:
  29644. audiences:
  29645. description: |-
  29646. Audience specifies the `aud` claim for the service account token
  29647. Some providers automatically extend the audience field based on well-known annotations for workload
  29648. identity (e.g. IRSA or GCP Workload Identity)
  29649. items:
  29650. type: string
  29651. type: array
  29652. name:
  29653. description: The name of the ServiceAccount resource being referred to.
  29654. maxLength: 253
  29655. minLength: 1
  29656. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29657. type: string
  29658. namespace:
  29659. description: |-
  29660. Namespace of the resource being referred to.
  29661. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29662. maxLength: 63
  29663. minLength: 1
  29664. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29665. type: string
  29666. required:
  29667. - name
  29668. type: object
  29669. required:
  29670. - mountPath
  29671. - role
  29672. type: object
  29673. ldap:
  29674. description: |-
  29675. Ldap authenticates with Vault by passing username/password pair using
  29676. the LDAP authentication method
  29677. properties:
  29678. path:
  29679. default: ldap
  29680. description: |-
  29681. Path where the LDAP authentication backend is mounted
  29682. in Vault, e.g: "ldap"
  29683. type: string
  29684. secretRef:
  29685. description: |-
  29686. SecretRef to a key in a Secret resource containing password for the LDAP
  29687. user used to authenticate with Vault using the LDAP authentication
  29688. method
  29689. properties:
  29690. key:
  29691. description: |-
  29692. A key in the referenced Secret.
  29693. Some instances of this field may be defaulted, in others it may be required.
  29694. maxLength: 253
  29695. minLength: 1
  29696. pattern: ^[-._a-zA-Z0-9]+$
  29697. type: string
  29698. name:
  29699. description: The name of the Secret resource being referred to.
  29700. maxLength: 253
  29701. minLength: 1
  29702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29703. type: string
  29704. namespace:
  29705. description: |-
  29706. The namespace of the Secret resource being referred to.
  29707. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29708. maxLength: 63
  29709. minLength: 1
  29710. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29711. type: string
  29712. type: object
  29713. username:
  29714. description: |-
  29715. Username is an LDAP username used to authenticate using the LDAP Vault
  29716. authentication method
  29717. type: string
  29718. required:
  29719. - path
  29720. - username
  29721. type: object
  29722. namespace:
  29723. description: |-
  29724. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  29725. Namespaces is a set of features within Vault Enterprise that allows
  29726. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  29727. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  29728. This will default to Vault.Namespace field if set, or empty otherwise
  29729. type: string
  29730. tokenSecretRef:
  29731. description: TokenSecretRef authenticates with Vault by presenting a token.
  29732. properties:
  29733. key:
  29734. description: |-
  29735. A key in the referenced Secret.
  29736. Some instances of this field may be defaulted, in others it may be required.
  29737. maxLength: 253
  29738. minLength: 1
  29739. pattern: ^[-._a-zA-Z0-9]+$
  29740. type: string
  29741. name:
  29742. description: The name of the Secret resource being referred to.
  29743. maxLength: 253
  29744. minLength: 1
  29745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29746. type: string
  29747. namespace:
  29748. description: |-
  29749. The namespace of the Secret resource being referred to.
  29750. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29751. maxLength: 63
  29752. minLength: 1
  29753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29754. type: string
  29755. type: object
  29756. userPass:
  29757. description: UserPass authenticates with Vault by passing username/password pair
  29758. properties:
  29759. path:
  29760. default: userpass
  29761. description: |-
  29762. Path where the UserPassword authentication backend is mounted
  29763. in Vault, e.g: "userpass"
  29764. type: string
  29765. secretRef:
  29766. description: |-
  29767. SecretRef to a key in a Secret resource containing password for the
  29768. user used to authenticate with Vault using the UserPass authentication
  29769. method
  29770. properties:
  29771. key:
  29772. description: |-
  29773. A key in the referenced Secret.
  29774. Some instances of this field may be defaulted, in others it may be required.
  29775. maxLength: 253
  29776. minLength: 1
  29777. pattern: ^[-._a-zA-Z0-9]+$
  29778. type: string
  29779. name:
  29780. description: The name of the Secret resource being referred to.
  29781. maxLength: 253
  29782. minLength: 1
  29783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29784. type: string
  29785. namespace:
  29786. description: |-
  29787. The namespace of the Secret resource being referred to.
  29788. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29789. maxLength: 63
  29790. minLength: 1
  29791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29792. type: string
  29793. type: object
  29794. username:
  29795. description: |-
  29796. Username is a username used to authenticate using the UserPass Vault
  29797. authentication method
  29798. type: string
  29799. required:
  29800. - path
  29801. - username
  29802. type: object
  29803. type: object
  29804. caBundle:
  29805. description: |-
  29806. PEM encoded CA bundle used to validate Vault server certificate. Only used
  29807. if the Server URL is using HTTPS protocol. This parameter is ignored for
  29808. plain HTTP protocol connection. If not set the system root certificates
  29809. are used to validate the TLS connection.
  29810. format: byte
  29811. type: string
  29812. caProvider:
  29813. description: The provider for the CA bundle to use to validate Vault server certificate.
  29814. properties:
  29815. key:
  29816. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  29817. maxLength: 253
  29818. minLength: 1
  29819. pattern: ^[-._a-zA-Z0-9]+$
  29820. type: string
  29821. name:
  29822. description: The name of the object located at the provider type.
  29823. maxLength: 253
  29824. minLength: 1
  29825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29826. type: string
  29827. namespace:
  29828. description: |-
  29829. The namespace the Provider type is in.
  29830. Can only be defined when used in a ClusterSecretStore.
  29831. maxLength: 63
  29832. minLength: 1
  29833. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29834. type: string
  29835. type:
  29836. description: The type of provider to use such as "Secret", or "ConfigMap".
  29837. enum:
  29838. - Secret
  29839. - ConfigMap
  29840. type: string
  29841. required:
  29842. - name
  29843. - type
  29844. type: object
  29845. checkAndSet:
  29846. description: |-
  29847. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  29848. Only applies to Vault KV v2 stores. When enabled, write operations must include
  29849. the current version of the secret to prevent unintentional overwrites.
  29850. properties:
  29851. required:
  29852. description: |-
  29853. Required when true, all write operations must include a check-and-set parameter.
  29854. This helps prevent unintentional overwrites of secrets.
  29855. type: boolean
  29856. type: object
  29857. forwardInconsistent:
  29858. description: |-
  29859. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  29860. leader instead of simply retrying within a loop. This can increase performance if
  29861. the option is enabled serverside.
  29862. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  29863. type: boolean
  29864. headers:
  29865. additionalProperties:
  29866. type: string
  29867. description: Headers to be added in Vault request
  29868. type: object
  29869. namespace:
  29870. description: |-
  29871. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  29872. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  29873. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  29874. type: string
  29875. path:
  29876. description: |-
  29877. Path is the mount path of the Vault KV backend endpoint, e.g:
  29878. "secret". The v2 KV secret engine version specific "/data" path suffix
  29879. for fetching secrets from Vault is optional and will be appended
  29880. if not present in specified path.
  29881. type: string
  29882. readYourWrites:
  29883. description: |-
  29884. ReadYourWrites ensures isolated read-after-write semantics by
  29885. providing discovered cluster replication states in each request.
  29886. More information about eventual consistency in Vault can be found here
  29887. https://www.vaultproject.io/docs/enterprise/consistency
  29888. type: boolean
  29889. server:
  29890. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  29891. type: string
  29892. tls:
  29893. description: |-
  29894. The configuration used for client side related TLS communication, when the Vault server
  29895. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  29896. This parameter is ignored for plain HTTP protocol connection.
  29897. It's worth noting this configuration is different from the "TLS certificates auth method",
  29898. which is available under the `auth.cert` section.
  29899. properties:
  29900. certSecretRef:
  29901. description: |-
  29902. CertSecretRef is a certificate added to the transport layer
  29903. when communicating with the Vault server.
  29904. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  29905. properties:
  29906. key:
  29907. description: |-
  29908. A key in the referenced Secret.
  29909. Some instances of this field may be defaulted, in others it may be required.
  29910. maxLength: 253
  29911. minLength: 1
  29912. pattern: ^[-._a-zA-Z0-9]+$
  29913. type: string
  29914. name:
  29915. description: The name of the Secret resource being referred to.
  29916. maxLength: 253
  29917. minLength: 1
  29918. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29919. type: string
  29920. namespace:
  29921. description: |-
  29922. The namespace of the Secret resource being referred to.
  29923. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29924. maxLength: 63
  29925. minLength: 1
  29926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29927. type: string
  29928. type: object
  29929. keySecretRef:
  29930. description: |-
  29931. KeySecretRef to a key in a Secret resource containing client private key
  29932. added to the transport layer when communicating with the Vault server.
  29933. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  29934. properties:
  29935. key:
  29936. description: |-
  29937. A key in the referenced Secret.
  29938. Some instances of this field may be defaulted, in others it may be required.
  29939. maxLength: 253
  29940. minLength: 1
  29941. pattern: ^[-._a-zA-Z0-9]+$
  29942. type: string
  29943. name:
  29944. description: The name of the Secret resource being referred to.
  29945. maxLength: 253
  29946. minLength: 1
  29947. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29948. type: string
  29949. namespace:
  29950. description: |-
  29951. The namespace of the Secret resource being referred to.
  29952. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29953. maxLength: 63
  29954. minLength: 1
  29955. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29956. type: string
  29957. type: object
  29958. type: object
  29959. version:
  29960. default: v2
  29961. description: |-
  29962. Version is the Vault KV secret engine version. This can be either "v1" or
  29963. "v2". Version defaults to "v2".
  29964. enum:
  29965. - v1
  29966. - v2
  29967. type: string
  29968. required:
  29969. - server
  29970. type: object
  29971. resultType:
  29972. default: Data
  29973. description: |-
  29974. Result type defines which data is returned from the generator.
  29975. By default, it is the "data" section of the Vault API response.
  29976. When using e.g. /auth/token/create the "data" section is empty but
  29977. the "auth" section contains the generated token.
  29978. Please refer to the vault docs regarding the result data structure.
  29979. Additionally, accessing the raw response is possibly by using "Raw" result type.
  29980. enum:
  29981. - Data
  29982. - Auth
  29983. - Raw
  29984. type: string
  29985. retrySettings:
  29986. description: Used to configure http retries if failed
  29987. properties:
  29988. maxRetries:
  29989. format: int32
  29990. type: integer
  29991. retryInterval:
  29992. type: string
  29993. type: object
  29994. required:
  29995. - path
  29996. - provider
  29997. type: object
  29998. webhookSpec:
  29999. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  30000. properties:
  30001. auth:
  30002. description: Auth specifies a authorization protocol. Only one protocol may be set.
  30003. maxProperties: 1
  30004. minProperties: 1
  30005. properties:
  30006. ntlm:
  30007. description: NTLMProtocol configures the store to use NTLM for auth
  30008. properties:
  30009. passwordSecret:
  30010. description: |-
  30011. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30012. In some instances, `key` is a required field.
  30013. properties:
  30014. key:
  30015. description: |-
  30016. A key in the referenced Secret.
  30017. Some instances of this field may be defaulted, in others it may be required.
  30018. maxLength: 253
  30019. minLength: 1
  30020. pattern: ^[-._a-zA-Z0-9]+$
  30021. type: string
  30022. name:
  30023. description: The name of the Secret resource being referred to.
  30024. maxLength: 253
  30025. minLength: 1
  30026. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30027. type: string
  30028. namespace:
  30029. description: |-
  30030. The namespace of the Secret resource being referred to.
  30031. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30032. maxLength: 63
  30033. minLength: 1
  30034. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30035. type: string
  30036. type: object
  30037. usernameSecret:
  30038. description: |-
  30039. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30040. In some instances, `key` is a required field.
  30041. properties:
  30042. key:
  30043. description: |-
  30044. A key in the referenced Secret.
  30045. Some instances of this field may be defaulted, in others it may be required.
  30046. maxLength: 253
  30047. minLength: 1
  30048. pattern: ^[-._a-zA-Z0-9]+$
  30049. type: string
  30050. name:
  30051. description: The name of the Secret resource being referred to.
  30052. maxLength: 253
  30053. minLength: 1
  30054. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30055. type: string
  30056. namespace:
  30057. description: |-
  30058. The namespace of the Secret resource being referred to.
  30059. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30060. maxLength: 63
  30061. minLength: 1
  30062. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30063. type: string
  30064. type: object
  30065. required:
  30066. - passwordSecret
  30067. - usernameSecret
  30068. type: object
  30069. type: object
  30070. body:
  30071. description: Body
  30072. type: string
  30073. caBundle:
  30074. description: |-
  30075. PEM encoded CA bundle used to validate webhook server certificate. Only used
  30076. if the Server URL is using HTTPS protocol. This parameter is ignored for
  30077. plain HTTP protocol connection. If not set the system root certificates
  30078. are used to validate the TLS connection.
  30079. format: byte
  30080. type: string
  30081. caProvider:
  30082. description: The provider for the CA bundle to use to validate webhook server certificate.
  30083. properties:
  30084. key:
  30085. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  30086. maxLength: 253
  30087. minLength: 1
  30088. pattern: ^[-._a-zA-Z0-9]+$
  30089. type: string
  30090. name:
  30091. description: The name of the object located at the provider type.
  30092. maxLength: 253
  30093. minLength: 1
  30094. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30095. type: string
  30096. namespace:
  30097. description: The namespace the Provider type is in.
  30098. maxLength: 63
  30099. minLength: 1
  30100. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30101. type: string
  30102. type:
  30103. description: The type of provider to use such as "Secret", or "ConfigMap".
  30104. enum:
  30105. - Secret
  30106. - ConfigMap
  30107. type: string
  30108. required:
  30109. - name
  30110. - type
  30111. type: object
  30112. headers:
  30113. additionalProperties:
  30114. type: string
  30115. description: Headers
  30116. type: object
  30117. method:
  30118. description: Webhook Method
  30119. type: string
  30120. result:
  30121. description: Result formatting
  30122. properties:
  30123. jsonPath:
  30124. description: Json path of return value
  30125. type: string
  30126. type: object
  30127. secrets:
  30128. description: |-
  30129. Secrets to fill in templates
  30130. These secrets will be passed to the templating function as key value pairs under the given name
  30131. items:
  30132. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  30133. properties:
  30134. name:
  30135. description: Name of this secret in templates
  30136. type: string
  30137. secretRef:
  30138. description: Secret ref to fill in credentials
  30139. properties:
  30140. key:
  30141. description: The key where the token is found.
  30142. maxLength: 253
  30143. minLength: 1
  30144. pattern: ^[-._a-zA-Z0-9]+$
  30145. type: string
  30146. name:
  30147. description: The name of the Secret resource being referred to.
  30148. maxLength: 253
  30149. minLength: 1
  30150. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30151. type: string
  30152. type: object
  30153. required:
  30154. - name
  30155. - secretRef
  30156. type: object
  30157. type: array
  30158. timeout:
  30159. description: Timeout
  30160. type: string
  30161. url:
  30162. description: Webhook url to call
  30163. type: string
  30164. required:
  30165. - result
  30166. - url
  30167. type: object
  30168. type: object
  30169. kind:
  30170. description: Kind the kind of this generator.
  30171. enum:
  30172. - ACRAccessToken
  30173. - BeyondtrustWorkloadCredentialsDynamicSecret
  30174. - CloudsmithAccessToken
  30175. - ECRAuthorizationToken
  30176. - Fake
  30177. - GCRAccessToken
  30178. - GithubAccessToken
  30179. - GitlabDeployToken
  30180. - QuayAccessToken
  30181. - Password
  30182. - SSHKey
  30183. - STSSessionToken
  30184. - UUID
  30185. - VaultDynamicSecret
  30186. - Webhook
  30187. - Grafana
  30188. - MFA
  30189. type: string
  30190. required:
  30191. - generator
  30192. - kind
  30193. type: object
  30194. type: object
  30195. served: true
  30196. storage: true
  30197. subresources:
  30198. status: {}
  30199. ---
  30200. apiVersion: apiextensions.k8s.io/v1
  30201. kind: CustomResourceDefinition
  30202. metadata:
  30203. annotations:
  30204. controller-gen.kubebuilder.io/version: v0.19.0
  30205. labels:
  30206. external-secrets.io/component: controller
  30207. name: ecrauthorizationtokens.generators.external-secrets.io
  30208. spec:
  30209. group: generators.external-secrets.io
  30210. names:
  30211. categories:
  30212. - external-secrets
  30213. - external-secrets-generators
  30214. kind: ECRAuthorizationToken
  30215. listKind: ECRAuthorizationTokenList
  30216. plural: ecrauthorizationtokens
  30217. singular: ecrauthorizationtoken
  30218. scope: Namespaced
  30219. versions:
  30220. - name: v1alpha1
  30221. schema:
  30222. openAPIV3Schema:
  30223. description: |-
  30224. ECRAuthorizationToken uses the GetAuthorizationToken API to retrieve an authorization token.
  30225. The authorization token is valid for 12 hours.
  30226. The authorizationToken returned is a base64 encoded string that can be decoded
  30227. and used in a docker login command to authenticate to a registry.
  30228. For more information, see Registry authentication (https://docs.aws.amazon.com/AmazonECR/latest/userguide/Registries.html#registry_auth) in the Amazon Elastic Container Registry User Guide.
  30229. properties:
  30230. apiVersion:
  30231. description: |-
  30232. APIVersion defines the versioned schema of this representation of an object.
  30233. Servers should convert recognized schemas to the latest internal value, and
  30234. may reject unrecognized values.
  30235. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30236. type: string
  30237. kind:
  30238. description: |-
  30239. Kind is a string value representing the REST resource this object represents.
  30240. Servers may infer this from the endpoint the client submits requests to.
  30241. Cannot be updated.
  30242. In CamelCase.
  30243. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30244. type: string
  30245. metadata:
  30246. type: object
  30247. spec:
  30248. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  30249. properties:
  30250. auth:
  30251. description: Auth defines how to authenticate with AWS
  30252. properties:
  30253. jwt:
  30254. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  30255. properties:
  30256. serviceAccountRef:
  30257. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  30258. properties:
  30259. audiences:
  30260. description: |-
  30261. Audience specifies the `aud` claim for the service account token
  30262. Some providers automatically extend the audience field based on well-known annotations for workload
  30263. identity (e.g. IRSA or GCP Workload Identity)
  30264. items:
  30265. type: string
  30266. type: array
  30267. name:
  30268. description: The name of the ServiceAccount resource being referred to.
  30269. maxLength: 253
  30270. minLength: 1
  30271. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30272. type: string
  30273. namespace:
  30274. description: |-
  30275. Namespace of the resource being referred to.
  30276. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30277. maxLength: 63
  30278. minLength: 1
  30279. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30280. type: string
  30281. required:
  30282. - name
  30283. type: object
  30284. type: object
  30285. secretRef:
  30286. description: |-
  30287. AWSAuthSecretRef holds secret references for AWS credentials
  30288. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  30289. properties:
  30290. accessKeyIDSecretRef:
  30291. description: The AccessKeyID is used for authentication
  30292. properties:
  30293. key:
  30294. description: |-
  30295. A key in the referenced Secret.
  30296. Some instances of this field may be defaulted, in others it may be required.
  30297. maxLength: 253
  30298. minLength: 1
  30299. pattern: ^[-._a-zA-Z0-9]+$
  30300. type: string
  30301. name:
  30302. description: The name of the Secret resource being referred to.
  30303. maxLength: 253
  30304. minLength: 1
  30305. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30306. type: string
  30307. namespace:
  30308. description: |-
  30309. The namespace of the Secret resource being referred to.
  30310. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30311. maxLength: 63
  30312. minLength: 1
  30313. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30314. type: string
  30315. type: object
  30316. secretAccessKeySecretRef:
  30317. description: The SecretAccessKey is used for authentication
  30318. properties:
  30319. key:
  30320. description: |-
  30321. A key in the referenced Secret.
  30322. Some instances of this field may be defaulted, in others it may be required.
  30323. maxLength: 253
  30324. minLength: 1
  30325. pattern: ^[-._a-zA-Z0-9]+$
  30326. type: string
  30327. name:
  30328. description: The name of the Secret resource being referred to.
  30329. maxLength: 253
  30330. minLength: 1
  30331. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30332. type: string
  30333. namespace:
  30334. description: |-
  30335. The namespace of the Secret resource being referred to.
  30336. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30337. maxLength: 63
  30338. minLength: 1
  30339. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30340. type: string
  30341. type: object
  30342. sessionTokenSecretRef:
  30343. description: |-
  30344. The SessionToken used for authentication
  30345. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  30346. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  30347. properties:
  30348. key:
  30349. description: |-
  30350. A key in the referenced Secret.
  30351. Some instances of this field may be defaulted, in others it may be required.
  30352. maxLength: 253
  30353. minLength: 1
  30354. pattern: ^[-._a-zA-Z0-9]+$
  30355. type: string
  30356. name:
  30357. description: The name of the Secret resource being referred to.
  30358. maxLength: 253
  30359. minLength: 1
  30360. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30361. type: string
  30362. namespace:
  30363. description: |-
  30364. The namespace of the Secret resource being referred to.
  30365. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30366. maxLength: 63
  30367. minLength: 1
  30368. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30369. type: string
  30370. type: object
  30371. type: object
  30372. type: object
  30373. region:
  30374. description: Region specifies the region to operate in.
  30375. type: string
  30376. role:
  30377. description: |-
  30378. You can assume a role before making calls to the
  30379. desired AWS service.
  30380. type: string
  30381. scope:
  30382. description: |-
  30383. Scope specifies the ECR service scope.
  30384. Valid options are private and public.
  30385. type: string
  30386. required:
  30387. - region
  30388. type: object
  30389. type: object
  30390. served: true
  30391. storage: true
  30392. subresources:
  30393. status: {}
  30394. ---
  30395. apiVersion: apiextensions.k8s.io/v1
  30396. kind: CustomResourceDefinition
  30397. metadata:
  30398. annotations:
  30399. controller-gen.kubebuilder.io/version: v0.19.0
  30400. labels:
  30401. external-secrets.io/component: controller
  30402. name: fakes.generators.external-secrets.io
  30403. spec:
  30404. group: generators.external-secrets.io
  30405. names:
  30406. categories:
  30407. - external-secrets
  30408. - external-secrets-generators
  30409. kind: Fake
  30410. listKind: FakeList
  30411. plural: fakes
  30412. singular: fake
  30413. scope: Namespaced
  30414. versions:
  30415. - name: v1alpha1
  30416. schema:
  30417. openAPIV3Schema:
  30418. description: |-
  30419. Fake generator is used for testing. It lets you define
  30420. a static set of credentials that is always returned.
  30421. properties:
  30422. apiVersion:
  30423. description: |-
  30424. APIVersion defines the versioned schema of this representation of an object.
  30425. Servers should convert recognized schemas to the latest internal value, and
  30426. may reject unrecognized values.
  30427. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30428. type: string
  30429. kind:
  30430. description: |-
  30431. Kind is a string value representing the REST resource this object represents.
  30432. Servers may infer this from the endpoint the client submits requests to.
  30433. Cannot be updated.
  30434. In CamelCase.
  30435. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30436. type: string
  30437. metadata:
  30438. type: object
  30439. spec:
  30440. description: FakeSpec contains the static data.
  30441. properties:
  30442. controller:
  30443. description: |-
  30444. Used to select the correct ESO controller (think: ingress.ingressClassName)
  30445. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  30446. type: string
  30447. data:
  30448. additionalProperties:
  30449. type: string
  30450. description: |-
  30451. Data defines the static data returned
  30452. by this generator.
  30453. type: object
  30454. type: object
  30455. type: object
  30456. served: true
  30457. storage: true
  30458. subresources:
  30459. status: {}
  30460. ---
  30461. apiVersion: apiextensions.k8s.io/v1
  30462. kind: CustomResourceDefinition
  30463. metadata:
  30464. annotations:
  30465. controller-gen.kubebuilder.io/version: v0.19.0
  30466. labels:
  30467. external-secrets.io/component: controller
  30468. name: gcraccesstokens.generators.external-secrets.io
  30469. spec:
  30470. group: generators.external-secrets.io
  30471. names:
  30472. categories:
  30473. - external-secrets
  30474. - external-secrets-generators
  30475. kind: GCRAccessToken
  30476. listKind: GCRAccessTokenList
  30477. plural: gcraccesstokens
  30478. singular: gcraccesstoken
  30479. scope: Namespaced
  30480. versions:
  30481. - name: v1alpha1
  30482. schema:
  30483. openAPIV3Schema:
  30484. description: |-
  30485. GCRAccessToken generates an GCP access token
  30486. that can be used to authenticate with GCR.
  30487. properties:
  30488. apiVersion:
  30489. description: |-
  30490. APIVersion defines the versioned schema of this representation of an object.
  30491. Servers should convert recognized schemas to the latest internal value, and
  30492. may reject unrecognized values.
  30493. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30494. type: string
  30495. kind:
  30496. description: |-
  30497. Kind is a string value representing the REST resource this object represents.
  30498. Servers may infer this from the endpoint the client submits requests to.
  30499. Cannot be updated.
  30500. In CamelCase.
  30501. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30502. type: string
  30503. metadata:
  30504. type: object
  30505. spec:
  30506. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  30507. properties:
  30508. auth:
  30509. description: Auth defines the means for authenticating with GCP
  30510. properties:
  30511. secretRef:
  30512. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  30513. properties:
  30514. secretAccessKeySecretRef:
  30515. description: The SecretAccessKey is used for authentication
  30516. properties:
  30517. key:
  30518. description: |-
  30519. A key in the referenced Secret.
  30520. Some instances of this field may be defaulted, in others it may be required.
  30521. maxLength: 253
  30522. minLength: 1
  30523. pattern: ^[-._a-zA-Z0-9]+$
  30524. type: string
  30525. name:
  30526. description: The name of the Secret resource being referred to.
  30527. maxLength: 253
  30528. minLength: 1
  30529. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30530. type: string
  30531. namespace:
  30532. description: |-
  30533. The namespace of the Secret resource being referred to.
  30534. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30535. maxLength: 63
  30536. minLength: 1
  30537. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30538. type: string
  30539. type: object
  30540. type: object
  30541. workloadIdentity:
  30542. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  30543. properties:
  30544. clusterLocation:
  30545. type: string
  30546. clusterName:
  30547. type: string
  30548. clusterProjectID:
  30549. type: string
  30550. serviceAccountRef:
  30551. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  30552. properties:
  30553. audiences:
  30554. description: |-
  30555. Audience specifies the `aud` claim for the service account token
  30556. Some providers automatically extend the audience field based on well-known annotations for workload
  30557. identity (e.g. IRSA or GCP Workload Identity)
  30558. items:
  30559. type: string
  30560. type: array
  30561. name:
  30562. description: The name of the ServiceAccount resource being referred to.
  30563. maxLength: 253
  30564. minLength: 1
  30565. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30566. type: string
  30567. namespace:
  30568. description: |-
  30569. Namespace of the resource being referred to.
  30570. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30571. maxLength: 63
  30572. minLength: 1
  30573. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30574. type: string
  30575. required:
  30576. - name
  30577. type: object
  30578. required:
  30579. - clusterLocation
  30580. - clusterName
  30581. - serviceAccountRef
  30582. type: object
  30583. workloadIdentityFederation:
  30584. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  30585. properties:
  30586. audience:
  30587. description: |-
  30588. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  30589. If specified, Audience found in the external account credential config will be overridden with the configured value.
  30590. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  30591. type: string
  30592. awsSecurityCredentials:
  30593. description: |-
  30594. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  30595. when using the AWS metadata server is not an option.
  30596. properties:
  30597. awsCredentialsSecretRef:
  30598. description: |-
  30599. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  30600. Secret should be created with below names for keys
  30601. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  30602. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  30603. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  30604. properties:
  30605. name:
  30606. description: name of the secret.
  30607. maxLength: 253
  30608. minLength: 1
  30609. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30610. type: string
  30611. namespace:
  30612. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  30613. maxLength: 63
  30614. minLength: 1
  30615. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30616. type: string
  30617. required:
  30618. - name
  30619. type: object
  30620. region:
  30621. description: region is for configuring the AWS region to be used.
  30622. example: ap-south-1
  30623. maxLength: 50
  30624. minLength: 1
  30625. pattern: ^[a-z0-9-]+$
  30626. type: string
  30627. required:
  30628. - awsCredentialsSecretRef
  30629. - region
  30630. type: object
  30631. credConfig:
  30632. description: |-
  30633. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  30634. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  30635. serviceAccountRef must be used by providing operators service account details.
  30636. properties:
  30637. key:
  30638. description: key name holding the external account credential config.
  30639. maxLength: 253
  30640. minLength: 1
  30641. pattern: ^[-._a-zA-Z0-9]+$
  30642. type: string
  30643. name:
  30644. description: name of the configmap.
  30645. maxLength: 253
  30646. minLength: 1
  30647. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30648. type: string
  30649. namespace:
  30650. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  30651. maxLength: 63
  30652. minLength: 1
  30653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30654. type: string
  30655. required:
  30656. - key
  30657. - name
  30658. type: object
  30659. externalTokenEndpoint:
  30660. description: |-
  30661. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  30662. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  30663. URL is having the expected value.
  30664. type: string
  30665. gcpServiceAccountEmail:
  30666. description: |-
  30667. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  30668. after Workload Identity Federation. Use this to grant access through the service account's
  30669. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  30670. service_account_impersonation_url in the external account JSON from credConfig;
  30671. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  30672. on that ServiceAccount.
  30673. example: my-gsa@my-project.iam.gserviceaccount.com
  30674. minLength: 1
  30675. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  30676. type: string
  30677. serviceAccountRef:
  30678. description: |-
  30679. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  30680. when Kubernetes is configured as provider in workload identity pool.
  30681. properties:
  30682. audiences:
  30683. description: |-
  30684. Audience specifies the `aud` claim for the service account token
  30685. Some providers automatically extend the audience field based on well-known annotations for workload
  30686. identity (e.g. IRSA or GCP Workload Identity)
  30687. items:
  30688. type: string
  30689. type: array
  30690. name:
  30691. description: The name of the ServiceAccount resource being referred to.
  30692. maxLength: 253
  30693. minLength: 1
  30694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30695. type: string
  30696. namespace:
  30697. description: |-
  30698. Namespace of the resource being referred to.
  30699. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30700. maxLength: 63
  30701. minLength: 1
  30702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30703. type: string
  30704. required:
  30705. - name
  30706. type: object
  30707. type: object
  30708. type: object
  30709. projectID:
  30710. description: ProjectID defines which project to use to authenticate with
  30711. type: string
  30712. required:
  30713. - auth
  30714. - projectID
  30715. type: object
  30716. type: object
  30717. served: true
  30718. storage: true
  30719. subresources:
  30720. status: {}
  30721. ---
  30722. apiVersion: apiextensions.k8s.io/v1
  30723. kind: CustomResourceDefinition
  30724. metadata:
  30725. annotations:
  30726. controller-gen.kubebuilder.io/version: v0.19.0
  30727. labels:
  30728. external-secrets.io/component: controller
  30729. name: generatorstates.generators.external-secrets.io
  30730. spec:
  30731. group: generators.external-secrets.io
  30732. names:
  30733. categories:
  30734. - external-secrets
  30735. - external-secrets-generators
  30736. kind: GeneratorState
  30737. listKind: GeneratorStateList
  30738. plural: generatorstates
  30739. shortNames:
  30740. - gs
  30741. singular: generatorstate
  30742. scope: Namespaced
  30743. versions:
  30744. - additionalPrinterColumns:
  30745. - jsonPath: .spec.garbageCollectionDeadline
  30746. name: GC Deadline
  30747. type: string
  30748. - jsonPath: .metadata.creationTimestamp
  30749. name: Age
  30750. type: date
  30751. name: v1alpha1
  30752. schema:
  30753. openAPIV3Schema:
  30754. description: GeneratorState represents the state created and managed by a generator resource.
  30755. properties:
  30756. apiVersion:
  30757. description: |-
  30758. APIVersion defines the versioned schema of this representation of an object.
  30759. Servers should convert recognized schemas to the latest internal value, and
  30760. may reject unrecognized values.
  30761. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30762. type: string
  30763. kind:
  30764. description: |-
  30765. Kind is a string value representing the REST resource this object represents.
  30766. Servers may infer this from the endpoint the client submits requests to.
  30767. Cannot be updated.
  30768. In CamelCase.
  30769. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30770. type: string
  30771. metadata:
  30772. type: object
  30773. spec:
  30774. description: GeneratorStateSpec defines the desired state of a generator state resource.
  30775. properties:
  30776. garbageCollectionDeadline:
  30777. description: |-
  30778. GarbageCollectionDeadline is the time after which the generator state
  30779. will be deleted.
  30780. It is set by the controller which creates the generator state and
  30781. can be set configured by the user.
  30782. If the garbage collection deadline is not set the generator state will not be deleted.
  30783. format: date-time
  30784. type: string
  30785. resource:
  30786. description: |-
  30787. Resource is the generator manifest that produced the state.
  30788. It is a snapshot of the generator manifest at the time the state was produced.
  30789. This manifest will be used to delete the resource. Any configuration that is referenced
  30790. in the manifest should be available at the time of garbage collection. If that is not the case deletion will
  30791. be blocked by a finalizer.
  30792. x-kubernetes-preserve-unknown-fields: true
  30793. state:
  30794. description: State is the state that was produced by the generator implementation.
  30795. x-kubernetes-preserve-unknown-fields: true
  30796. required:
  30797. - resource
  30798. - state
  30799. type: object
  30800. status:
  30801. description: GeneratorStateStatus defines the observed state of a generator state resource.
  30802. properties:
  30803. conditions:
  30804. items:
  30805. description: GeneratorStateStatusCondition represents the observed condition of a generator state.
  30806. properties:
  30807. lastTransitionTime:
  30808. format: date-time
  30809. type: string
  30810. message:
  30811. type: string
  30812. reason:
  30813. type: string
  30814. status:
  30815. type: string
  30816. type:
  30817. description: GeneratorStateConditionType represents the type of condition for a generator state.
  30818. type: string
  30819. required:
  30820. - status
  30821. - type
  30822. type: object
  30823. type: array
  30824. type: object
  30825. type: object
  30826. served: true
  30827. storage: true
  30828. subresources: {}
  30829. ---
  30830. apiVersion: apiextensions.k8s.io/v1
  30831. kind: CustomResourceDefinition
  30832. metadata:
  30833. annotations:
  30834. controller-gen.kubebuilder.io/version: v0.19.0
  30835. labels:
  30836. external-secrets.io/component: controller
  30837. name: githubaccesstokens.generators.external-secrets.io
  30838. spec:
  30839. group: generators.external-secrets.io
  30840. names:
  30841. categories:
  30842. - external-secrets
  30843. - external-secrets-generators
  30844. kind: GithubAccessToken
  30845. listKind: GithubAccessTokenList
  30846. plural: githubaccesstokens
  30847. singular: githubaccesstoken
  30848. scope: Namespaced
  30849. versions:
  30850. - name: v1alpha1
  30851. schema:
  30852. openAPIV3Schema:
  30853. description: GithubAccessToken generates ghs_ accessToken
  30854. properties:
  30855. apiVersion:
  30856. description: |-
  30857. APIVersion defines the versioned schema of this representation of an object.
  30858. Servers should convert recognized schemas to the latest internal value, and
  30859. may reject unrecognized values.
  30860. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30861. type: string
  30862. kind:
  30863. description: |-
  30864. Kind is a string value representing the REST resource this object represents.
  30865. Servers may infer this from the endpoint the client submits requests to.
  30866. Cannot be updated.
  30867. In CamelCase.
  30868. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30869. type: string
  30870. metadata:
  30871. type: object
  30872. spec:
  30873. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  30874. properties:
  30875. appID:
  30876. type: string
  30877. auth:
  30878. description: Auth configures how ESO authenticates with a Github instance.
  30879. properties:
  30880. privateKey:
  30881. description: GithubSecretRef references a secret containing GitHub credentials.
  30882. properties:
  30883. secretRef:
  30884. description: |-
  30885. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30886. In some instances, `key` is a required field.
  30887. properties:
  30888. key:
  30889. description: |-
  30890. A key in the referenced Secret.
  30891. Some instances of this field may be defaulted, in others it may be required.
  30892. maxLength: 253
  30893. minLength: 1
  30894. pattern: ^[-._a-zA-Z0-9]+$
  30895. type: string
  30896. name:
  30897. description: The name of the Secret resource being referred to.
  30898. maxLength: 253
  30899. minLength: 1
  30900. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30901. type: string
  30902. namespace:
  30903. description: |-
  30904. The namespace of the Secret resource being referred to.
  30905. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30906. maxLength: 63
  30907. minLength: 1
  30908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30909. type: string
  30910. type: object
  30911. required:
  30912. - secretRef
  30913. type: object
  30914. required:
  30915. - privateKey
  30916. type: object
  30917. installID:
  30918. type: string
  30919. permissions:
  30920. additionalProperties:
  30921. type: string
  30922. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  30923. type: object
  30924. repositories:
  30925. description: |-
  30926. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  30927. is installed to.
  30928. items:
  30929. type: string
  30930. type: array
  30931. url:
  30932. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  30933. type: string
  30934. required:
  30935. - appID
  30936. - auth
  30937. - installID
  30938. type: object
  30939. type: object
  30940. served: true
  30941. storage: true
  30942. subresources:
  30943. status: {}
  30944. ---
  30945. apiVersion: apiextensions.k8s.io/v1
  30946. kind: CustomResourceDefinition
  30947. metadata:
  30948. annotations:
  30949. controller-gen.kubebuilder.io/version: v0.19.0
  30950. labels:
  30951. external-secrets.io/component: controller
  30952. name: gitlabdeploytokens.generators.external-secrets.io
  30953. spec:
  30954. group: generators.external-secrets.io
  30955. names:
  30956. categories:
  30957. - external-secrets
  30958. - external-secrets-generators
  30959. kind: GitlabDeployToken
  30960. listKind: GitlabDeployTokenList
  30961. plural: gitlabdeploytokens
  30962. singular: gitlabdeploytoken
  30963. scope: Namespaced
  30964. versions:
  30965. - name: v1alpha1
  30966. schema:
  30967. openAPIV3Schema:
  30968. description: GitlabDeployToken generates a GitLab deploy token.
  30969. properties:
  30970. apiVersion:
  30971. description: |-
  30972. APIVersion defines the versioned schema of this representation of an object.
  30973. Servers should convert recognized schemas to the latest internal value, and
  30974. may reject unrecognized values.
  30975. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30976. type: string
  30977. kind:
  30978. description: |-
  30979. Kind is a string value representing the REST resource this object represents.
  30980. Servers may infer this from the endpoint the client submits requests to.
  30981. Cannot be updated.
  30982. In CamelCase.
  30983. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30984. type: string
  30985. metadata:
  30986. type: object
  30987. spec:
  30988. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  30989. properties:
  30990. auth:
  30991. description: Auth configures how ESO authenticates with the GitLab API.
  30992. properties:
  30993. token:
  30994. description: |-
  30995. Token references a secret containing a GitLab access token (personal, group, or
  30996. project) with the api scope and at least the Maintainer role on the target.
  30997. properties:
  30998. secretRef:
  30999. description: |-
  31000. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  31001. In some instances, `key` is a required field.
  31002. properties:
  31003. key:
  31004. description: |-
  31005. A key in the referenced Secret.
  31006. Some instances of this field may be defaulted, in others it may be required.
  31007. maxLength: 253
  31008. minLength: 1
  31009. pattern: ^[-._a-zA-Z0-9]+$
  31010. type: string
  31011. name:
  31012. description: The name of the Secret resource being referred to.
  31013. maxLength: 253
  31014. minLength: 1
  31015. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31016. type: string
  31017. namespace:
  31018. description: |-
  31019. The namespace of the Secret resource being referred to.
  31020. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31021. maxLength: 63
  31022. minLength: 1
  31023. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31024. type: string
  31025. type: object
  31026. required:
  31027. - secretRef
  31028. type: object
  31029. required:
  31030. - token
  31031. type: object
  31032. expiresAt:
  31033. description: |-
  31034. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  31035. not expire on the GitLab side and is revoked only when the generator state is
  31036. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  31037. format: date-time
  31038. type: string
  31039. groupID:
  31040. description: |-
  31041. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  31042. create the deploy token in. The generator URL-escapes paths before calling the
  31043. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  31044. minLength: 1
  31045. type: string
  31046. name:
  31047. description: Name of the deploy token.
  31048. minLength: 1
  31049. type: string
  31050. projectID:
  31051. description: |-
  31052. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  31053. project to create the deploy token in. The generator URL-escapes paths before
  31054. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  31055. minLength: 1
  31056. type: string
  31057. scopes:
  31058. description: Scopes granted to the deploy token. At least one scope is required.
  31059. items:
  31060. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  31061. enum:
  31062. - read_repository
  31063. - read_registry
  31064. - write_registry
  31065. - read_package_registry
  31066. - write_package_registry
  31067. - read_virtual_registry
  31068. - write_virtual_registry
  31069. type: string
  31070. minItems: 1
  31071. type: array
  31072. url:
  31073. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  31074. type: string
  31075. username:
  31076. description: |-
  31077. Username is an optional username for the deploy token. GitLab defaults it to
  31078. gitlab+deploy-token-{n} when omitted.
  31079. type: string
  31080. required:
  31081. - auth
  31082. - name
  31083. - scopes
  31084. type: object
  31085. x-kubernetes-validations:
  31086. - message: exactly one of projectID or groupID must be set
  31087. rule: has(self.projectID) != has(self.groupID)
  31088. type: object
  31089. served: true
  31090. storage: true
  31091. subresources:
  31092. status: {}
  31093. ---
  31094. apiVersion: apiextensions.k8s.io/v1
  31095. kind: CustomResourceDefinition
  31096. metadata:
  31097. annotations:
  31098. controller-gen.kubebuilder.io/version: v0.19.0
  31099. labels:
  31100. external-secrets.io/component: controller
  31101. name: grafanas.generators.external-secrets.io
  31102. spec:
  31103. group: generators.external-secrets.io
  31104. names:
  31105. categories:
  31106. - external-secrets
  31107. - external-secrets-generators
  31108. kind: Grafana
  31109. listKind: GrafanaList
  31110. plural: grafanas
  31111. singular: grafana
  31112. scope: Namespaced
  31113. versions:
  31114. - name: v1alpha1
  31115. schema:
  31116. openAPIV3Schema:
  31117. description: Grafana represents a generator for Grafana service account tokens.
  31118. properties:
  31119. apiVersion:
  31120. description: |-
  31121. APIVersion defines the versioned schema of this representation of an object.
  31122. Servers should convert recognized schemas to the latest internal value, and
  31123. may reject unrecognized values.
  31124. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31125. type: string
  31126. kind:
  31127. description: |-
  31128. Kind is a string value representing the REST resource this object represents.
  31129. Servers may infer this from the endpoint the client submits requests to.
  31130. Cannot be updated.
  31131. In CamelCase.
  31132. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31133. type: string
  31134. metadata:
  31135. type: object
  31136. spec:
  31137. description: GrafanaSpec controls the behavior of the grafana generator.
  31138. properties:
  31139. auth:
  31140. description: |-
  31141. Auth is the authentication configuration to authenticate
  31142. against the Grafana instance.
  31143. properties:
  31144. basic:
  31145. description: |-
  31146. Basic auth credentials used to authenticate against the Grafana instance.
  31147. Note: you need a token which has elevated permissions to create service accounts.
  31148. See here for the documentation on basic roles offered by Grafana:
  31149. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  31150. properties:
  31151. password:
  31152. description: A basic auth password used to authenticate against the Grafana instance.
  31153. properties:
  31154. key:
  31155. description: The key where the token is found.
  31156. maxLength: 253
  31157. minLength: 1
  31158. pattern: ^[-._a-zA-Z0-9]+$
  31159. type: string
  31160. name:
  31161. description: The name of the Secret resource being referred to.
  31162. maxLength: 253
  31163. minLength: 1
  31164. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31165. type: string
  31166. type: object
  31167. username:
  31168. description: A basic auth username used to authenticate against the Grafana instance.
  31169. type: string
  31170. required:
  31171. - password
  31172. - username
  31173. type: object
  31174. token:
  31175. description: |-
  31176. A service account token used to authenticate against the Grafana instance.
  31177. Note: you need a token which has elevated permissions to create service accounts.
  31178. See here for the documentation on basic roles offered by Grafana:
  31179. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  31180. properties:
  31181. key:
  31182. description: The key where the token is found.
  31183. maxLength: 253
  31184. minLength: 1
  31185. pattern: ^[-._a-zA-Z0-9]+$
  31186. type: string
  31187. name:
  31188. description: The name of the Secret resource being referred to.
  31189. maxLength: 253
  31190. minLength: 1
  31191. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31192. type: string
  31193. type: object
  31194. type: object
  31195. serviceAccount:
  31196. description: |-
  31197. ServiceAccount is the configuration for the service account that
  31198. is supposed to be generated by the generator.
  31199. properties:
  31200. name:
  31201. description: Name is the name of the service account that will be created by ESO.
  31202. type: string
  31203. role:
  31204. description: |-
  31205. Role is the role of the service account.
  31206. See here for the documentation on basic roles offered by Grafana:
  31207. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  31208. type: string
  31209. secondsToLive:
  31210. description: |-
  31211. SecondsToLive is the number of seconds before the generated service account token will expire.
  31212. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  31213. format: int64
  31214. minimum: 1
  31215. type: integer
  31216. required:
  31217. - name
  31218. - role
  31219. type: object
  31220. url:
  31221. description: URL is the URL of the Grafana instance.
  31222. type: string
  31223. required:
  31224. - auth
  31225. - serviceAccount
  31226. - url
  31227. type: object
  31228. type: object
  31229. served: true
  31230. storage: true
  31231. subresources:
  31232. status: {}
  31233. ---
  31234. apiVersion: apiextensions.k8s.io/v1
  31235. kind: CustomResourceDefinition
  31236. metadata:
  31237. annotations:
  31238. controller-gen.kubebuilder.io/version: v0.19.0
  31239. labels:
  31240. external-secrets.io/component: controller
  31241. name: mfas.generators.external-secrets.io
  31242. spec:
  31243. group: generators.external-secrets.io
  31244. names:
  31245. categories:
  31246. - external-secrets
  31247. - external-secrets-generators
  31248. kind: MFA
  31249. listKind: MFAList
  31250. plural: mfas
  31251. singular: mfa
  31252. scope: Namespaced
  31253. versions:
  31254. - name: v1alpha1
  31255. schema:
  31256. openAPIV3Schema:
  31257. description: MFA generates a new TOTP token that is compliant with RFC 6238.
  31258. properties:
  31259. apiVersion:
  31260. description: |-
  31261. APIVersion defines the versioned schema of this representation of an object.
  31262. Servers should convert recognized schemas to the latest internal value, and
  31263. may reject unrecognized values.
  31264. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31265. type: string
  31266. kind:
  31267. description: |-
  31268. Kind is a string value representing the REST resource this object represents.
  31269. Servers may infer this from the endpoint the client submits requests to.
  31270. Cannot be updated.
  31271. In CamelCase.
  31272. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31273. type: string
  31274. metadata:
  31275. type: object
  31276. spec:
  31277. description: MFASpec controls the behavior of the mfa generator.
  31278. properties:
  31279. algorithm:
  31280. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  31281. type: string
  31282. length:
  31283. description: Length defines the token length. Defaults to 6 characters.
  31284. type: integer
  31285. secret:
  31286. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  31287. properties:
  31288. key:
  31289. description: |-
  31290. A key in the referenced Secret.
  31291. Some instances of this field may be defaulted, in others it may be required.
  31292. maxLength: 253
  31293. minLength: 1
  31294. pattern: ^[-._a-zA-Z0-9]+$
  31295. type: string
  31296. name:
  31297. description: The name of the Secret resource being referred to.
  31298. maxLength: 253
  31299. minLength: 1
  31300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31301. type: string
  31302. namespace:
  31303. description: |-
  31304. The namespace of the Secret resource being referred to.
  31305. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31306. maxLength: 63
  31307. minLength: 1
  31308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31309. type: string
  31310. type: object
  31311. timePeriod:
  31312. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  31313. type: integer
  31314. when:
  31315. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  31316. format: date-time
  31317. type: string
  31318. required:
  31319. - secret
  31320. type: object
  31321. type: object
  31322. served: true
  31323. storage: true
  31324. subresources:
  31325. status: {}
  31326. ---
  31327. apiVersion: apiextensions.k8s.io/v1
  31328. kind: CustomResourceDefinition
  31329. metadata:
  31330. annotations:
  31331. controller-gen.kubebuilder.io/version: v0.19.0
  31332. labels:
  31333. external-secrets.io/component: controller
  31334. name: passwords.generators.external-secrets.io
  31335. spec:
  31336. group: generators.external-secrets.io
  31337. names:
  31338. categories:
  31339. - external-secrets
  31340. - external-secrets-generators
  31341. kind: Password
  31342. listKind: PasswordList
  31343. plural: passwords
  31344. singular: password
  31345. scope: Namespaced
  31346. versions:
  31347. - name: v1alpha1
  31348. schema:
  31349. openAPIV3Schema:
  31350. description: |-
  31351. Password generates a random password based on the
  31352. configuration parameters in spec.
  31353. You can specify the length, characterset and other attributes.
  31354. properties:
  31355. apiVersion:
  31356. description: |-
  31357. APIVersion defines the versioned schema of this representation of an object.
  31358. Servers should convert recognized schemas to the latest internal value, and
  31359. may reject unrecognized values.
  31360. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31361. type: string
  31362. kind:
  31363. description: |-
  31364. Kind is a string value representing the REST resource this object represents.
  31365. Servers may infer this from the endpoint the client submits requests to.
  31366. Cannot be updated.
  31367. In CamelCase.
  31368. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31369. type: string
  31370. metadata:
  31371. type: object
  31372. spec:
  31373. description: PasswordSpec controls the behavior of the password generator.
  31374. properties:
  31375. allowRepeat:
  31376. default: false
  31377. description: set AllowRepeat to true to allow repeating characters.
  31378. type: boolean
  31379. digits:
  31380. description: |-
  31381. Digits specifies the number of digits in the generated
  31382. password. If omitted it defaults to 25% of the length of the password
  31383. type: integer
  31384. encoding:
  31385. default: raw
  31386. description: |-
  31387. Encoding specifies the encoding of the generated password.
  31388. Valid values are:
  31389. - "raw" (default): no encoding
  31390. - "base64": standard base64 encoding
  31391. - "base64url": base64url encoding
  31392. - "base32": base32 encoding
  31393. - "hex": hexadecimal encoding
  31394. enum:
  31395. - base64
  31396. - base64url
  31397. - base32
  31398. - hex
  31399. - raw
  31400. type: string
  31401. length:
  31402. default: 24
  31403. description: |-
  31404. Length of the password to be generated.
  31405. Defaults to 24
  31406. type: integer
  31407. noUpper:
  31408. default: false
  31409. description: Set NoUpper to disable uppercase characters
  31410. type: boolean
  31411. secretKeys:
  31412. description: |-
  31413. SecretKeys defines the keys that will be populated with generated passwords.
  31414. Defaults to "password" when not set.
  31415. items:
  31416. type: string
  31417. minItems: 1
  31418. type: array
  31419. symbolCharacters:
  31420. description: |-
  31421. SymbolCharacters specifies the special characters that should be used
  31422. in the generated password.
  31423. type: string
  31424. symbols:
  31425. description: |-
  31426. Symbols specifies the number of symbol characters in the generated
  31427. password. If omitted it defaults to 25% of the length of the password
  31428. type: integer
  31429. required:
  31430. - allowRepeat
  31431. - length
  31432. - noUpper
  31433. type: object
  31434. type: object
  31435. served: true
  31436. storage: true
  31437. subresources:
  31438. status: {}
  31439. ---
  31440. apiVersion: apiextensions.k8s.io/v1
  31441. kind: CustomResourceDefinition
  31442. metadata:
  31443. annotations:
  31444. controller-gen.kubebuilder.io/version: v0.19.0
  31445. labels:
  31446. external-secrets.io/component: controller
  31447. name: quayaccesstokens.generators.external-secrets.io
  31448. spec:
  31449. group: generators.external-secrets.io
  31450. names:
  31451. categories:
  31452. - external-secrets
  31453. - external-secrets-generators
  31454. kind: QuayAccessToken
  31455. listKind: QuayAccessTokenList
  31456. plural: quayaccesstokens
  31457. singular: quayaccesstoken
  31458. scope: Namespaced
  31459. versions:
  31460. - name: v1alpha1
  31461. schema:
  31462. openAPIV3Schema:
  31463. description: QuayAccessToken generates Quay oauth token for pulling/pushing images
  31464. properties:
  31465. apiVersion:
  31466. description: |-
  31467. APIVersion defines the versioned schema of this representation of an object.
  31468. Servers should convert recognized schemas to the latest internal value, and
  31469. may reject unrecognized values.
  31470. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31471. type: string
  31472. kind:
  31473. description: |-
  31474. Kind is a string value representing the REST resource this object represents.
  31475. Servers may infer this from the endpoint the client submits requests to.
  31476. Cannot be updated.
  31477. In CamelCase.
  31478. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31479. type: string
  31480. metadata:
  31481. type: object
  31482. spec:
  31483. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  31484. properties:
  31485. robotAccount:
  31486. description: Name of the robot account you are federating with
  31487. type: string
  31488. serviceAccountRef:
  31489. description: Name of the service account you are federating with
  31490. properties:
  31491. audiences:
  31492. description: |-
  31493. Audience specifies the `aud` claim for the service account token
  31494. Some providers automatically extend the audience field based on well-known annotations for workload
  31495. identity (e.g. IRSA or GCP Workload Identity)
  31496. items:
  31497. type: string
  31498. type: array
  31499. name:
  31500. description: The name of the ServiceAccount resource being referred to.
  31501. maxLength: 253
  31502. minLength: 1
  31503. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31504. type: string
  31505. namespace:
  31506. description: |-
  31507. Namespace of the resource being referred to.
  31508. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31509. maxLength: 63
  31510. minLength: 1
  31511. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31512. type: string
  31513. required:
  31514. - name
  31515. type: object
  31516. url:
  31517. description: URL configures the Quay instance URL. Defaults to quay.io.
  31518. type: string
  31519. required:
  31520. - robotAccount
  31521. - serviceAccountRef
  31522. type: object
  31523. type: object
  31524. served: true
  31525. storage: true
  31526. subresources:
  31527. status: {}
  31528. ---
  31529. apiVersion: apiextensions.k8s.io/v1
  31530. kind: CustomResourceDefinition
  31531. metadata:
  31532. annotations:
  31533. controller-gen.kubebuilder.io/version: v0.19.0
  31534. labels:
  31535. external-secrets.io/component: controller
  31536. name: sshkeys.generators.external-secrets.io
  31537. spec:
  31538. group: generators.external-secrets.io
  31539. names:
  31540. categories:
  31541. - external-secrets
  31542. - external-secrets-generators
  31543. kind: SSHKey
  31544. listKind: SSHKeyList
  31545. plural: sshkeys
  31546. singular: sshkey
  31547. scope: Namespaced
  31548. versions:
  31549. - name: v1alpha1
  31550. schema:
  31551. openAPIV3Schema:
  31552. description: SSHKey generates SSH key pairs.
  31553. properties:
  31554. apiVersion:
  31555. description: |-
  31556. APIVersion defines the versioned schema of this representation of an object.
  31557. Servers should convert recognized schemas to the latest internal value, and
  31558. may reject unrecognized values.
  31559. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31560. type: string
  31561. kind:
  31562. description: |-
  31563. Kind is a string value representing the REST resource this object represents.
  31564. Servers may infer this from the endpoint the client submits requests to.
  31565. Cannot be updated.
  31566. In CamelCase.
  31567. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31568. type: string
  31569. metadata:
  31570. type: object
  31571. spec:
  31572. description: SSHKeySpec controls the behavior of the ssh key generator.
  31573. properties:
  31574. comment:
  31575. description: Comment specifies an optional comment for the SSH key
  31576. type: string
  31577. keySize:
  31578. description: |-
  31579. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  31580. For RSA keys: 2048, 3072, 4096
  31581. For ECDSA keys: 256, 384, 521
  31582. Ignored for ed25519 keys
  31583. maximum: 8192
  31584. minimum: 256
  31585. type: integer
  31586. keyType:
  31587. default: rsa
  31588. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  31589. enum:
  31590. - rsa
  31591. - ecdsa
  31592. - ed25519
  31593. type: string
  31594. type: object
  31595. type: object
  31596. served: true
  31597. storage: true
  31598. subresources:
  31599. status: {}
  31600. ---
  31601. apiVersion: apiextensions.k8s.io/v1
  31602. kind: CustomResourceDefinition
  31603. metadata:
  31604. annotations:
  31605. controller-gen.kubebuilder.io/version: v0.19.0
  31606. labels:
  31607. external-secrets.io/component: controller
  31608. name: stssessiontokens.generators.external-secrets.io
  31609. spec:
  31610. group: generators.external-secrets.io
  31611. names:
  31612. categories:
  31613. - external-secrets
  31614. - external-secrets-generators
  31615. kind: STSSessionToken
  31616. listKind: STSSessionTokenList
  31617. plural: stssessiontokens
  31618. singular: stssessiontoken
  31619. scope: Namespaced
  31620. versions:
  31621. - name: v1alpha1
  31622. schema:
  31623. openAPIV3Schema:
  31624. description: |-
  31625. STSSessionToken uses the GetSessionToken API to retrieve an authorization token.
  31626. The authorization token is valid for 12 hours.
  31627. The authorizationToken returned is a base64 encoded string that can be decoded.
  31628. For more information, see GetSessionToken (https://docs.aws.amazon.com/STS/latest/APIReference/API_GetSessionToken.html).
  31629. properties:
  31630. apiVersion:
  31631. description: |-
  31632. APIVersion defines the versioned schema of this representation of an object.
  31633. Servers should convert recognized schemas to the latest internal value, and
  31634. may reject unrecognized values.
  31635. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31636. type: string
  31637. kind:
  31638. description: |-
  31639. Kind is a string value representing the REST resource this object represents.
  31640. Servers may infer this from the endpoint the client submits requests to.
  31641. Cannot be updated.
  31642. In CamelCase.
  31643. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31644. type: string
  31645. metadata:
  31646. type: object
  31647. spec:
  31648. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  31649. properties:
  31650. auth:
  31651. description: Auth defines how to authenticate with AWS
  31652. properties:
  31653. jwt:
  31654. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  31655. properties:
  31656. serviceAccountRef:
  31657. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31658. properties:
  31659. audiences:
  31660. description: |-
  31661. Audience specifies the `aud` claim for the service account token
  31662. Some providers automatically extend the audience field based on well-known annotations for workload
  31663. identity (e.g. IRSA or GCP Workload Identity)
  31664. items:
  31665. type: string
  31666. type: array
  31667. name:
  31668. description: The name of the ServiceAccount resource being referred to.
  31669. maxLength: 253
  31670. minLength: 1
  31671. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31672. type: string
  31673. namespace:
  31674. description: |-
  31675. Namespace of the resource being referred to.
  31676. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31677. maxLength: 63
  31678. minLength: 1
  31679. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31680. type: string
  31681. required:
  31682. - name
  31683. type: object
  31684. type: object
  31685. secretRef:
  31686. description: |-
  31687. AWSAuthSecretRef holds secret references for AWS credentials
  31688. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  31689. properties:
  31690. accessKeyIDSecretRef:
  31691. description: The AccessKeyID is used for authentication
  31692. properties:
  31693. key:
  31694. description: |-
  31695. A key in the referenced Secret.
  31696. Some instances of this field may be defaulted, in others it may be required.
  31697. maxLength: 253
  31698. minLength: 1
  31699. pattern: ^[-._a-zA-Z0-9]+$
  31700. type: string
  31701. name:
  31702. description: The name of the Secret resource being referred to.
  31703. maxLength: 253
  31704. minLength: 1
  31705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31706. type: string
  31707. namespace:
  31708. description: |-
  31709. The namespace of the Secret resource being referred to.
  31710. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31711. maxLength: 63
  31712. minLength: 1
  31713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31714. type: string
  31715. type: object
  31716. secretAccessKeySecretRef:
  31717. description: The SecretAccessKey is used for authentication
  31718. properties:
  31719. key:
  31720. description: |-
  31721. A key in the referenced Secret.
  31722. Some instances of this field may be defaulted, in others it may be required.
  31723. maxLength: 253
  31724. minLength: 1
  31725. pattern: ^[-._a-zA-Z0-9]+$
  31726. type: string
  31727. name:
  31728. description: The name of the Secret resource being referred to.
  31729. maxLength: 253
  31730. minLength: 1
  31731. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31732. type: string
  31733. namespace:
  31734. description: |-
  31735. The namespace of the Secret resource being referred to.
  31736. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31737. maxLength: 63
  31738. minLength: 1
  31739. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31740. type: string
  31741. type: object
  31742. sessionTokenSecretRef:
  31743. description: |-
  31744. The SessionToken used for authentication
  31745. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  31746. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  31747. properties:
  31748. key:
  31749. description: |-
  31750. A key in the referenced Secret.
  31751. Some instances of this field may be defaulted, in others it may be required.
  31752. maxLength: 253
  31753. minLength: 1
  31754. pattern: ^[-._a-zA-Z0-9]+$
  31755. type: string
  31756. name:
  31757. description: The name of the Secret resource being referred to.
  31758. maxLength: 253
  31759. minLength: 1
  31760. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31761. type: string
  31762. namespace:
  31763. description: |-
  31764. The namespace of the Secret resource being referred to.
  31765. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31766. maxLength: 63
  31767. minLength: 1
  31768. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31769. type: string
  31770. type: object
  31771. type: object
  31772. type: object
  31773. region:
  31774. description: Region specifies the region to operate in.
  31775. type: string
  31776. requestParameters:
  31777. description: RequestParameters contains parameters that can be passed to the STS service.
  31778. properties:
  31779. serialNumber:
  31780. description: |-
  31781. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  31782. the GetSessionToken call.
  31783. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  31784. (such as arn:aws:iam::123456789012:mfa/user)
  31785. type: string
  31786. sessionDuration:
  31787. format: int32
  31788. type: integer
  31789. tokenCode:
  31790. description: TokenCode is the value provided by the MFA device, if MFA is required.
  31791. type: string
  31792. type: object
  31793. role:
  31794. description: |-
  31795. You can assume a role before making calls to the
  31796. desired AWS service.
  31797. type: string
  31798. required:
  31799. - region
  31800. type: object
  31801. type: object
  31802. served: true
  31803. storage: true
  31804. subresources:
  31805. status: {}
  31806. ---
  31807. apiVersion: apiextensions.k8s.io/v1
  31808. kind: CustomResourceDefinition
  31809. metadata:
  31810. annotations:
  31811. controller-gen.kubebuilder.io/version: v0.19.0
  31812. labels:
  31813. external-secrets.io/component: controller
  31814. name: uuids.generators.external-secrets.io
  31815. spec:
  31816. group: generators.external-secrets.io
  31817. names:
  31818. categories:
  31819. - external-secrets
  31820. - external-secrets-generators
  31821. kind: UUID
  31822. listKind: UUIDList
  31823. plural: uuids
  31824. singular: uuid
  31825. scope: Namespaced
  31826. versions:
  31827. - name: v1alpha1
  31828. schema:
  31829. openAPIV3Schema:
  31830. description: UUID generates a version 1 UUID (e56657e3-764f-11ef-a397-65231a88c216).
  31831. properties:
  31832. apiVersion:
  31833. description: |-
  31834. APIVersion defines the versioned schema of this representation of an object.
  31835. Servers should convert recognized schemas to the latest internal value, and
  31836. may reject unrecognized values.
  31837. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31838. type: string
  31839. kind:
  31840. description: |-
  31841. Kind is a string value representing the REST resource this object represents.
  31842. Servers may infer this from the endpoint the client submits requests to.
  31843. Cannot be updated.
  31844. In CamelCase.
  31845. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31846. type: string
  31847. metadata:
  31848. type: object
  31849. spec:
  31850. description: UUIDSpec controls the behavior of the uuid generator.
  31851. type: object
  31852. type: object
  31853. served: true
  31854. storage: true
  31855. subresources:
  31856. status: {}
  31857. ---
  31858. apiVersion: apiextensions.k8s.io/v1
  31859. kind: CustomResourceDefinition
  31860. metadata:
  31861. annotations:
  31862. controller-gen.kubebuilder.io/version: v0.19.0
  31863. labels:
  31864. external-secrets.io/component: controller
  31865. name: vaultdynamicsecrets.generators.external-secrets.io
  31866. spec:
  31867. group: generators.external-secrets.io
  31868. names:
  31869. categories:
  31870. - external-secrets
  31871. - external-secrets-generators
  31872. kind: VaultDynamicSecret
  31873. listKind: VaultDynamicSecretList
  31874. plural: vaultdynamicsecrets
  31875. singular: vaultdynamicsecret
  31876. scope: Namespaced
  31877. versions:
  31878. - name: v1alpha1
  31879. schema:
  31880. openAPIV3Schema:
  31881. description: VaultDynamicSecret represents a generator that can create dynamic secrets from HashiCorp Vault.
  31882. properties:
  31883. apiVersion:
  31884. description: |-
  31885. APIVersion defines the versioned schema of this representation of an object.
  31886. Servers should convert recognized schemas to the latest internal value, and
  31887. may reject unrecognized values.
  31888. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31889. type: string
  31890. kind:
  31891. description: |-
  31892. Kind is a string value representing the REST resource this object represents.
  31893. Servers may infer this from the endpoint the client submits requests to.
  31894. Cannot be updated.
  31895. In CamelCase.
  31896. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31897. type: string
  31898. metadata:
  31899. type: object
  31900. spec:
  31901. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  31902. properties:
  31903. allowEmptyResponse:
  31904. default: false
  31905. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  31906. type: boolean
  31907. controller:
  31908. description: |-
  31909. Used to select the correct ESO controller (think: ingress.ingressClassName)
  31910. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  31911. type: string
  31912. getParameters:
  31913. additionalProperties:
  31914. items:
  31915. type: string
  31916. type: array
  31917. description: |-
  31918. GetParameters are query-string parameters passed to Vault on GET calls.
  31919. Each key may map to multiple values, matching HTTP query-string semantics.
  31920. Ignored for non-GET methods; use Parameters for write bodies.
  31921. type: object
  31922. method:
  31923. description: Vault API method to use (GET/POST/other)
  31924. type: string
  31925. parameters:
  31926. description: Parameters to pass to Vault write (for non-GET methods)
  31927. x-kubernetes-preserve-unknown-fields: true
  31928. path:
  31929. description: Vault path to obtain the dynamic secret from
  31930. type: string
  31931. provider:
  31932. description: Vault provider common spec
  31933. properties:
  31934. auth:
  31935. description: Auth configures how secret-manager authenticates with the Vault server.
  31936. properties:
  31937. appRole:
  31938. description: |-
  31939. AppRole authenticates with Vault using the App Role auth mechanism,
  31940. with the role and secret stored in a Kubernetes Secret resource.
  31941. properties:
  31942. path:
  31943. default: approle
  31944. description: |-
  31945. Path where the App Role authentication backend is mounted
  31946. in Vault, e.g: "approle"
  31947. type: string
  31948. roleId:
  31949. description: |-
  31950. RoleID configured in the App Role authentication backend when setting
  31951. up the authentication backend in Vault.
  31952. type: string
  31953. roleRef:
  31954. description: |-
  31955. Reference to a key in a Secret that contains the App Role ID used
  31956. to authenticate with Vault.
  31957. The `key` field must be specified and denotes which entry within the Secret
  31958. resource is used as the app role id.
  31959. properties:
  31960. key:
  31961. description: |-
  31962. A key in the referenced Secret.
  31963. Some instances of this field may be defaulted, in others it may be required.
  31964. maxLength: 253
  31965. minLength: 1
  31966. pattern: ^[-._a-zA-Z0-9]+$
  31967. type: string
  31968. name:
  31969. description: The name of the Secret resource being referred to.
  31970. maxLength: 253
  31971. minLength: 1
  31972. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31973. type: string
  31974. namespace:
  31975. description: |-
  31976. The namespace of the Secret resource being referred to.
  31977. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31978. maxLength: 63
  31979. minLength: 1
  31980. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31981. type: string
  31982. type: object
  31983. secretRef:
  31984. description: |-
  31985. Reference to a key in a Secret that contains the App Role secret used
  31986. to authenticate with Vault.
  31987. The `key` field must be specified and denotes which entry within the Secret
  31988. resource is used as the app role secret.
  31989. properties:
  31990. key:
  31991. description: |-
  31992. A key in the referenced Secret.
  31993. Some instances of this field may be defaulted, in others it may be required.
  31994. maxLength: 253
  31995. minLength: 1
  31996. pattern: ^[-._a-zA-Z0-9]+$
  31997. type: string
  31998. name:
  31999. description: The name of the Secret resource being referred to.
  32000. maxLength: 253
  32001. minLength: 1
  32002. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32003. type: string
  32004. namespace:
  32005. description: |-
  32006. The namespace of the Secret resource being referred to.
  32007. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32008. maxLength: 63
  32009. minLength: 1
  32010. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32011. type: string
  32012. type: object
  32013. required:
  32014. - path
  32015. - secretRef
  32016. type: object
  32017. cert:
  32018. description: |-
  32019. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  32020. Cert authentication method
  32021. properties:
  32022. clientCert:
  32023. description: |-
  32024. ClientCert is a certificate to authenticate using the Cert Vault
  32025. authentication method
  32026. properties:
  32027. key:
  32028. description: |-
  32029. A key in the referenced Secret.
  32030. Some instances of this field may be defaulted, in others it may be required.
  32031. maxLength: 253
  32032. minLength: 1
  32033. pattern: ^[-._a-zA-Z0-9]+$
  32034. type: string
  32035. name:
  32036. description: The name of the Secret resource being referred to.
  32037. maxLength: 253
  32038. minLength: 1
  32039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32040. type: string
  32041. namespace:
  32042. description: |-
  32043. The namespace of the Secret resource being referred to.
  32044. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32045. maxLength: 63
  32046. minLength: 1
  32047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32048. type: string
  32049. type: object
  32050. path:
  32051. default: cert
  32052. description: |-
  32053. Path where the Certificate authentication backend is mounted
  32054. in Vault, e.g: "cert"
  32055. type: string
  32056. secretRef:
  32057. description: |-
  32058. SecretRef to a key in a Secret resource containing client private key to
  32059. authenticate with Vault using the Cert authentication method
  32060. properties:
  32061. key:
  32062. description: |-
  32063. A key in the referenced Secret.
  32064. Some instances of this field may be defaulted, in others it may be required.
  32065. maxLength: 253
  32066. minLength: 1
  32067. pattern: ^[-._a-zA-Z0-9]+$
  32068. type: string
  32069. name:
  32070. description: The name of the Secret resource being referred to.
  32071. maxLength: 253
  32072. minLength: 1
  32073. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32074. type: string
  32075. namespace:
  32076. description: |-
  32077. The namespace of the Secret resource being referred to.
  32078. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32079. maxLength: 63
  32080. minLength: 1
  32081. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32082. type: string
  32083. type: object
  32084. vaultRole:
  32085. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  32086. type: string
  32087. type: object
  32088. gcp:
  32089. description: |-
  32090. Gcp authenticates with Vault using Google Cloud Platform authentication method
  32091. GCP authentication method
  32092. properties:
  32093. location:
  32094. description: Location optionally defines a location/region for the secret
  32095. type: string
  32096. path:
  32097. default: gcp
  32098. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  32099. type: string
  32100. projectID:
  32101. description: Project ID of the Google Cloud Platform project
  32102. type: string
  32103. role:
  32104. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  32105. type: string
  32106. secretRef:
  32107. description: Specify credentials in a Secret object
  32108. properties:
  32109. secretAccessKeySecretRef:
  32110. description: The SecretAccessKey is used for authentication
  32111. properties:
  32112. key:
  32113. description: |-
  32114. A key in the referenced Secret.
  32115. Some instances of this field may be defaulted, in others it may be required.
  32116. maxLength: 253
  32117. minLength: 1
  32118. pattern: ^[-._a-zA-Z0-9]+$
  32119. type: string
  32120. name:
  32121. description: The name of the Secret resource being referred to.
  32122. maxLength: 253
  32123. minLength: 1
  32124. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32125. type: string
  32126. namespace:
  32127. description: |-
  32128. The namespace of the Secret resource being referred to.
  32129. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32130. maxLength: 63
  32131. minLength: 1
  32132. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32133. type: string
  32134. type: object
  32135. type: object
  32136. serviceAccountRef:
  32137. description: ServiceAccountRef to a service account for impersonation
  32138. properties:
  32139. audiences:
  32140. description: |-
  32141. Audience specifies the `aud` claim for the service account token
  32142. Some providers automatically extend the audience field based on well-known annotations for workload
  32143. identity (e.g. IRSA or GCP Workload Identity)
  32144. items:
  32145. type: string
  32146. type: array
  32147. name:
  32148. description: The name of the ServiceAccount resource being referred to.
  32149. maxLength: 253
  32150. minLength: 1
  32151. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32152. type: string
  32153. namespace:
  32154. description: |-
  32155. Namespace of the resource being referred to.
  32156. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32157. maxLength: 63
  32158. minLength: 1
  32159. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32160. type: string
  32161. required:
  32162. - name
  32163. type: object
  32164. workloadIdentity:
  32165. description: Specify a service account with Workload Identity
  32166. properties:
  32167. clusterLocation:
  32168. description: |-
  32169. ClusterLocation is the location of the cluster
  32170. If not specified, it fetches information from the metadata server
  32171. type: string
  32172. clusterName:
  32173. description: |-
  32174. ClusterName is the name of the cluster
  32175. If not specified, it fetches information from the metadata server
  32176. type: string
  32177. clusterProjectID:
  32178. description: |-
  32179. ClusterProjectID is the project ID of the cluster
  32180. If not specified, it fetches information from the metadata server
  32181. type: string
  32182. serviceAccountRef:
  32183. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  32184. properties:
  32185. audiences:
  32186. description: |-
  32187. Audience specifies the `aud` claim for the service account token
  32188. Some providers automatically extend the audience field based on well-known annotations for workload
  32189. identity (e.g. IRSA or GCP Workload Identity)
  32190. items:
  32191. type: string
  32192. type: array
  32193. name:
  32194. description: The name of the ServiceAccount resource being referred to.
  32195. maxLength: 253
  32196. minLength: 1
  32197. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32198. type: string
  32199. namespace:
  32200. description: |-
  32201. Namespace of the resource being referred to.
  32202. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32203. maxLength: 63
  32204. minLength: 1
  32205. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32206. type: string
  32207. required:
  32208. - name
  32209. type: object
  32210. required:
  32211. - serviceAccountRef
  32212. type: object
  32213. required:
  32214. - role
  32215. type: object
  32216. iam:
  32217. description: |-
  32218. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  32219. AWS IAM authentication method
  32220. properties:
  32221. externalID:
  32222. description: AWS External ID set on assumed IAM roles
  32223. type: string
  32224. jwt:
  32225. description: Specify a service account with IRSA enabled
  32226. properties:
  32227. serviceAccountRef:
  32228. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  32229. properties:
  32230. audiences:
  32231. description: |-
  32232. Audience specifies the `aud` claim for the service account token
  32233. Some providers automatically extend the audience field based on well-known annotations for workload
  32234. identity (e.g. IRSA or GCP Workload Identity)
  32235. items:
  32236. type: string
  32237. type: array
  32238. name:
  32239. description: The name of the ServiceAccount resource being referred to.
  32240. maxLength: 253
  32241. minLength: 1
  32242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32243. type: string
  32244. namespace:
  32245. description: |-
  32246. Namespace of the resource being referred to.
  32247. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32248. maxLength: 63
  32249. minLength: 1
  32250. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32251. type: string
  32252. required:
  32253. - name
  32254. type: object
  32255. type: object
  32256. path:
  32257. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  32258. type: string
  32259. region:
  32260. description: AWS region
  32261. type: string
  32262. role:
  32263. description: This is the AWS role to be assumed before talking to vault
  32264. type: string
  32265. secretRef:
  32266. description: Specify credentials in a Secret object
  32267. properties:
  32268. accessKeyIDSecretRef:
  32269. description: The AccessKeyID is used for authentication
  32270. properties:
  32271. key:
  32272. description: |-
  32273. A key in the referenced Secret.
  32274. Some instances of this field may be defaulted, in others it may be required.
  32275. maxLength: 253
  32276. minLength: 1
  32277. pattern: ^[-._a-zA-Z0-9]+$
  32278. type: string
  32279. name:
  32280. description: The name of the Secret resource being referred to.
  32281. maxLength: 253
  32282. minLength: 1
  32283. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32284. type: string
  32285. namespace:
  32286. description: |-
  32287. The namespace of the Secret resource being referred to.
  32288. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32289. maxLength: 63
  32290. minLength: 1
  32291. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32292. type: string
  32293. type: object
  32294. secretAccessKeySecretRef:
  32295. description: The SecretAccessKey is used for authentication
  32296. properties:
  32297. key:
  32298. description: |-
  32299. A key in the referenced Secret.
  32300. Some instances of this field may be defaulted, in others it may be required.
  32301. maxLength: 253
  32302. minLength: 1
  32303. pattern: ^[-._a-zA-Z0-9]+$
  32304. type: string
  32305. name:
  32306. description: The name of the Secret resource being referred to.
  32307. maxLength: 253
  32308. minLength: 1
  32309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32310. type: string
  32311. namespace:
  32312. description: |-
  32313. The namespace of the Secret resource being referred to.
  32314. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32315. maxLength: 63
  32316. minLength: 1
  32317. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32318. type: string
  32319. type: object
  32320. sessionTokenSecretRef:
  32321. description: |-
  32322. The SessionToken used for authentication
  32323. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  32324. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  32325. properties:
  32326. key:
  32327. description: |-
  32328. A key in the referenced Secret.
  32329. Some instances of this field may be defaulted, in others it may be required.
  32330. maxLength: 253
  32331. minLength: 1
  32332. pattern: ^[-._a-zA-Z0-9]+$
  32333. type: string
  32334. name:
  32335. description: The name of the Secret resource being referred to.
  32336. maxLength: 253
  32337. minLength: 1
  32338. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32339. type: string
  32340. namespace:
  32341. description: |-
  32342. The namespace of the Secret resource being referred to.
  32343. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32344. maxLength: 63
  32345. minLength: 1
  32346. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32347. type: string
  32348. type: object
  32349. type: object
  32350. vaultAwsIamServerID:
  32351. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  32352. type: string
  32353. vaultRole:
  32354. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  32355. type: string
  32356. required:
  32357. - vaultRole
  32358. type: object
  32359. jwt:
  32360. description: |-
  32361. Jwt authenticates with Vault by passing role and JWT token using the
  32362. JWT/OIDC authentication method
  32363. properties:
  32364. kubernetesServiceAccountToken:
  32365. description: |-
  32366. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  32367. a token for with the `TokenRequest` API.
  32368. properties:
  32369. audiences:
  32370. description: |-
  32371. Optional audiences field that will be used to request a temporary Kubernetes service
  32372. account token for the service account referenced by `serviceAccountRef`.
  32373. Defaults to a single audience `vault` it not specified.
  32374. Deprecated: use serviceAccountRef.Audiences instead
  32375. items:
  32376. type: string
  32377. type: array
  32378. expirationSeconds:
  32379. description: |-
  32380. Optional expiration time in seconds that will be used to request a temporary
  32381. Kubernetes service account token for the service account referenced by
  32382. `serviceAccountRef`.
  32383. Deprecated: this will be removed in the future.
  32384. Defaults to 10 minutes.
  32385. format: int64
  32386. type: integer
  32387. serviceAccountRef:
  32388. description: Service account field containing the name of a kubernetes ServiceAccount.
  32389. properties:
  32390. audiences:
  32391. description: |-
  32392. Audience specifies the `aud` claim for the service account token
  32393. Some providers automatically extend the audience field based on well-known annotations for workload
  32394. identity (e.g. IRSA or GCP Workload Identity)
  32395. items:
  32396. type: string
  32397. type: array
  32398. name:
  32399. description: The name of the ServiceAccount resource being referred to.
  32400. maxLength: 253
  32401. minLength: 1
  32402. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32403. type: string
  32404. namespace:
  32405. description: |-
  32406. Namespace of the resource being referred to.
  32407. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32408. maxLength: 63
  32409. minLength: 1
  32410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32411. type: string
  32412. required:
  32413. - name
  32414. type: object
  32415. required:
  32416. - serviceAccountRef
  32417. type: object
  32418. path:
  32419. default: jwt
  32420. description: |-
  32421. Path where the JWT authentication backend is mounted
  32422. in Vault, e.g: "jwt"
  32423. type: string
  32424. role:
  32425. description: |-
  32426. Role is a JWT role to authenticate using the JWT/OIDC Vault
  32427. authentication method
  32428. type: string
  32429. secretRef:
  32430. description: |-
  32431. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  32432. authenticate with Vault using the JWT/OIDC authentication method.
  32433. properties:
  32434. key:
  32435. description: |-
  32436. A key in the referenced Secret.
  32437. Some instances of this field may be defaulted, in others it may be required.
  32438. maxLength: 253
  32439. minLength: 1
  32440. pattern: ^[-._a-zA-Z0-9]+$
  32441. type: string
  32442. name:
  32443. description: The name of the Secret resource being referred to.
  32444. maxLength: 253
  32445. minLength: 1
  32446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32447. type: string
  32448. namespace:
  32449. description: |-
  32450. The namespace of the Secret resource being referred to.
  32451. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32452. maxLength: 63
  32453. minLength: 1
  32454. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32455. type: string
  32456. type: object
  32457. required:
  32458. - path
  32459. type: object
  32460. kubernetes:
  32461. description: |-
  32462. Kubernetes authenticates with Vault by passing the ServiceAccount
  32463. token stored in the named Secret resource to the Vault server.
  32464. properties:
  32465. mountPath:
  32466. default: kubernetes
  32467. description: |-
  32468. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  32469. "kubernetes"
  32470. type: string
  32471. role:
  32472. description: |-
  32473. A required field containing the Vault Role to assume. A Role binds a
  32474. Kubernetes ServiceAccount with a set of Vault policies.
  32475. type: string
  32476. secretRef:
  32477. description: |-
  32478. Optional secret field containing a Kubernetes ServiceAccount JWT used
  32479. for authenticating with Vault. If a name is specified without a key,
  32480. `token` is the default. If one is not specified, the one bound to
  32481. the controller will be used.
  32482. properties:
  32483. key:
  32484. description: |-
  32485. A key in the referenced Secret.
  32486. Some instances of this field may be defaulted, in others it may be required.
  32487. maxLength: 253
  32488. minLength: 1
  32489. pattern: ^[-._a-zA-Z0-9]+$
  32490. type: string
  32491. name:
  32492. description: The name of the Secret resource being referred to.
  32493. maxLength: 253
  32494. minLength: 1
  32495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32496. type: string
  32497. namespace:
  32498. description: |-
  32499. The namespace of the Secret resource being referred to.
  32500. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32501. maxLength: 63
  32502. minLength: 1
  32503. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32504. type: string
  32505. type: object
  32506. serviceAccountRef:
  32507. description: |-
  32508. Optional service account field containing the name of a kubernetes ServiceAccount.
  32509. If the service account is specified, the service account secret token JWT will be used
  32510. for authenticating with Vault. If the service account selector is not supplied,
  32511. the secretRef will be used instead.
  32512. properties:
  32513. audiences:
  32514. description: |-
  32515. Audience specifies the `aud` claim for the service account token
  32516. Some providers automatically extend the audience field based on well-known annotations for workload
  32517. identity (e.g. IRSA or GCP Workload Identity)
  32518. items:
  32519. type: string
  32520. type: array
  32521. name:
  32522. description: The name of the ServiceAccount resource being referred to.
  32523. maxLength: 253
  32524. minLength: 1
  32525. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32526. type: string
  32527. namespace:
  32528. description: |-
  32529. Namespace of the resource being referred to.
  32530. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32531. maxLength: 63
  32532. minLength: 1
  32533. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32534. type: string
  32535. required:
  32536. - name
  32537. type: object
  32538. required:
  32539. - mountPath
  32540. - role
  32541. type: object
  32542. ldap:
  32543. description: |-
  32544. Ldap authenticates with Vault by passing username/password pair using
  32545. the LDAP authentication method
  32546. properties:
  32547. path:
  32548. default: ldap
  32549. description: |-
  32550. Path where the LDAP authentication backend is mounted
  32551. in Vault, e.g: "ldap"
  32552. type: string
  32553. secretRef:
  32554. description: |-
  32555. SecretRef to a key in a Secret resource containing password for the LDAP
  32556. user used to authenticate with Vault using the LDAP authentication
  32557. method
  32558. properties:
  32559. key:
  32560. description: |-
  32561. A key in the referenced Secret.
  32562. Some instances of this field may be defaulted, in others it may be required.
  32563. maxLength: 253
  32564. minLength: 1
  32565. pattern: ^[-._a-zA-Z0-9]+$
  32566. type: string
  32567. name:
  32568. description: The name of the Secret resource being referred to.
  32569. maxLength: 253
  32570. minLength: 1
  32571. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32572. type: string
  32573. namespace:
  32574. description: |-
  32575. The namespace of the Secret resource being referred to.
  32576. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32577. maxLength: 63
  32578. minLength: 1
  32579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32580. type: string
  32581. type: object
  32582. username:
  32583. description: |-
  32584. Username is an LDAP username used to authenticate using the LDAP Vault
  32585. authentication method
  32586. type: string
  32587. required:
  32588. - path
  32589. - username
  32590. type: object
  32591. namespace:
  32592. description: |-
  32593. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  32594. Namespaces is a set of features within Vault Enterprise that allows
  32595. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  32596. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  32597. This will default to Vault.Namespace field if set, or empty otherwise
  32598. type: string
  32599. tokenSecretRef:
  32600. description: TokenSecretRef authenticates with Vault by presenting a token.
  32601. properties:
  32602. key:
  32603. description: |-
  32604. A key in the referenced Secret.
  32605. Some instances of this field may be defaulted, in others it may be required.
  32606. maxLength: 253
  32607. minLength: 1
  32608. pattern: ^[-._a-zA-Z0-9]+$
  32609. type: string
  32610. name:
  32611. description: The name of the Secret resource being referred to.
  32612. maxLength: 253
  32613. minLength: 1
  32614. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32615. type: string
  32616. namespace:
  32617. description: |-
  32618. The namespace of the Secret resource being referred to.
  32619. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32620. maxLength: 63
  32621. minLength: 1
  32622. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32623. type: string
  32624. type: object
  32625. userPass:
  32626. description: UserPass authenticates with Vault by passing username/password pair
  32627. properties:
  32628. path:
  32629. default: userpass
  32630. description: |-
  32631. Path where the UserPassword authentication backend is mounted
  32632. in Vault, e.g: "userpass"
  32633. type: string
  32634. secretRef:
  32635. description: |-
  32636. SecretRef to a key in a Secret resource containing password for the
  32637. user used to authenticate with Vault using the UserPass authentication
  32638. method
  32639. properties:
  32640. key:
  32641. description: |-
  32642. A key in the referenced Secret.
  32643. Some instances of this field may be defaulted, in others it may be required.
  32644. maxLength: 253
  32645. minLength: 1
  32646. pattern: ^[-._a-zA-Z0-9]+$
  32647. type: string
  32648. name:
  32649. description: The name of the Secret resource being referred to.
  32650. maxLength: 253
  32651. minLength: 1
  32652. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32653. type: string
  32654. namespace:
  32655. description: |-
  32656. The namespace of the Secret resource being referred to.
  32657. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32658. maxLength: 63
  32659. minLength: 1
  32660. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32661. type: string
  32662. type: object
  32663. username:
  32664. description: |-
  32665. Username is a username used to authenticate using the UserPass Vault
  32666. authentication method
  32667. type: string
  32668. required:
  32669. - path
  32670. - username
  32671. type: object
  32672. type: object
  32673. caBundle:
  32674. description: |-
  32675. PEM encoded CA bundle used to validate Vault server certificate. Only used
  32676. if the Server URL is using HTTPS protocol. This parameter is ignored for
  32677. plain HTTP protocol connection. If not set the system root certificates
  32678. are used to validate the TLS connection.
  32679. format: byte
  32680. type: string
  32681. caProvider:
  32682. description: The provider for the CA bundle to use to validate Vault server certificate.
  32683. properties:
  32684. key:
  32685. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  32686. maxLength: 253
  32687. minLength: 1
  32688. pattern: ^[-._a-zA-Z0-9]+$
  32689. type: string
  32690. name:
  32691. description: The name of the object located at the provider type.
  32692. maxLength: 253
  32693. minLength: 1
  32694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32695. type: string
  32696. namespace:
  32697. description: |-
  32698. The namespace the Provider type is in.
  32699. Can only be defined when used in a ClusterSecretStore.
  32700. maxLength: 63
  32701. minLength: 1
  32702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32703. type: string
  32704. type:
  32705. description: The type of provider to use such as "Secret", or "ConfigMap".
  32706. enum:
  32707. - Secret
  32708. - ConfigMap
  32709. type: string
  32710. required:
  32711. - name
  32712. - type
  32713. type: object
  32714. checkAndSet:
  32715. description: |-
  32716. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  32717. Only applies to Vault KV v2 stores. When enabled, write operations must include
  32718. the current version of the secret to prevent unintentional overwrites.
  32719. properties:
  32720. required:
  32721. description: |-
  32722. Required when true, all write operations must include a check-and-set parameter.
  32723. This helps prevent unintentional overwrites of secrets.
  32724. type: boolean
  32725. type: object
  32726. forwardInconsistent:
  32727. description: |-
  32728. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  32729. leader instead of simply retrying within a loop. This can increase performance if
  32730. the option is enabled serverside.
  32731. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  32732. type: boolean
  32733. headers:
  32734. additionalProperties:
  32735. type: string
  32736. description: Headers to be added in Vault request
  32737. type: object
  32738. namespace:
  32739. description: |-
  32740. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  32741. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  32742. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  32743. type: string
  32744. path:
  32745. description: |-
  32746. Path is the mount path of the Vault KV backend endpoint, e.g:
  32747. "secret". The v2 KV secret engine version specific "/data" path suffix
  32748. for fetching secrets from Vault is optional and will be appended
  32749. if not present in specified path.
  32750. type: string
  32751. readYourWrites:
  32752. description: |-
  32753. ReadYourWrites ensures isolated read-after-write semantics by
  32754. providing discovered cluster replication states in each request.
  32755. More information about eventual consistency in Vault can be found here
  32756. https://www.vaultproject.io/docs/enterprise/consistency
  32757. type: boolean
  32758. server:
  32759. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  32760. type: string
  32761. tls:
  32762. description: |-
  32763. The configuration used for client side related TLS communication, when the Vault server
  32764. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  32765. This parameter is ignored for plain HTTP protocol connection.
  32766. It's worth noting this configuration is different from the "TLS certificates auth method",
  32767. which is available under the `auth.cert` section.
  32768. properties:
  32769. certSecretRef:
  32770. description: |-
  32771. CertSecretRef is a certificate added to the transport layer
  32772. when communicating with the Vault server.
  32773. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  32774. properties:
  32775. key:
  32776. description: |-
  32777. A key in the referenced Secret.
  32778. Some instances of this field may be defaulted, in others it may be required.
  32779. maxLength: 253
  32780. minLength: 1
  32781. pattern: ^[-._a-zA-Z0-9]+$
  32782. type: string
  32783. name:
  32784. description: The name of the Secret resource being referred to.
  32785. maxLength: 253
  32786. minLength: 1
  32787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32788. type: string
  32789. namespace:
  32790. description: |-
  32791. The namespace of the Secret resource being referred to.
  32792. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32793. maxLength: 63
  32794. minLength: 1
  32795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32796. type: string
  32797. type: object
  32798. keySecretRef:
  32799. description: |-
  32800. KeySecretRef to a key in a Secret resource containing client private key
  32801. added to the transport layer when communicating with the Vault server.
  32802. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  32803. properties:
  32804. key:
  32805. description: |-
  32806. A key in the referenced Secret.
  32807. Some instances of this field may be defaulted, in others it may be required.
  32808. maxLength: 253
  32809. minLength: 1
  32810. pattern: ^[-._a-zA-Z0-9]+$
  32811. type: string
  32812. name:
  32813. description: The name of the Secret resource being referred to.
  32814. maxLength: 253
  32815. minLength: 1
  32816. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32817. type: string
  32818. namespace:
  32819. description: |-
  32820. The namespace of the Secret resource being referred to.
  32821. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32822. maxLength: 63
  32823. minLength: 1
  32824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32825. type: string
  32826. type: object
  32827. type: object
  32828. version:
  32829. default: v2
  32830. description: |-
  32831. Version is the Vault KV secret engine version. This can be either "v1" or
  32832. "v2". Version defaults to "v2".
  32833. enum:
  32834. - v1
  32835. - v2
  32836. type: string
  32837. required:
  32838. - server
  32839. type: object
  32840. resultType:
  32841. default: Data
  32842. description: |-
  32843. Result type defines which data is returned from the generator.
  32844. By default, it is the "data" section of the Vault API response.
  32845. When using e.g. /auth/token/create the "data" section is empty but
  32846. the "auth" section contains the generated token.
  32847. Please refer to the vault docs regarding the result data structure.
  32848. Additionally, accessing the raw response is possibly by using "Raw" result type.
  32849. enum:
  32850. - Data
  32851. - Auth
  32852. - Raw
  32853. type: string
  32854. retrySettings:
  32855. description: Used to configure http retries if failed
  32856. properties:
  32857. maxRetries:
  32858. format: int32
  32859. type: integer
  32860. retryInterval:
  32861. type: string
  32862. type: object
  32863. required:
  32864. - path
  32865. - provider
  32866. type: object
  32867. type: object
  32868. served: true
  32869. storage: true
  32870. subresources:
  32871. status: {}
  32872. ---
  32873. apiVersion: apiextensions.k8s.io/v1
  32874. kind: CustomResourceDefinition
  32875. metadata:
  32876. annotations:
  32877. controller-gen.kubebuilder.io/version: v0.19.0
  32878. labels:
  32879. external-secrets.io/component: controller
  32880. name: webhooks.generators.external-secrets.io
  32881. spec:
  32882. group: generators.external-secrets.io
  32883. names:
  32884. categories:
  32885. - external-secrets
  32886. - external-secrets-generators
  32887. kind: Webhook
  32888. listKind: WebhookList
  32889. plural: webhooks
  32890. singular: webhook
  32891. scope: Namespaced
  32892. versions:
  32893. - name: v1alpha1
  32894. schema:
  32895. openAPIV3Schema:
  32896. description: |-
  32897. Webhook connects to a third party API server to handle the secrets generation
  32898. configuration parameters in spec.
  32899. You can specify the server, the token, and additional body parameters.
  32900. See documentation for the full API specification for requests and responses.
  32901. properties:
  32902. apiVersion:
  32903. description: |-
  32904. APIVersion defines the versioned schema of this representation of an object.
  32905. Servers should convert recognized schemas to the latest internal value, and
  32906. may reject unrecognized values.
  32907. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  32908. type: string
  32909. kind:
  32910. description: |-
  32911. Kind is a string value representing the REST resource this object represents.
  32912. Servers may infer this from the endpoint the client submits requests to.
  32913. Cannot be updated.
  32914. In CamelCase.
  32915. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  32916. type: string
  32917. metadata:
  32918. type: object
  32919. spec:
  32920. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  32921. properties:
  32922. auth:
  32923. description: Auth specifies a authorization protocol. Only one protocol may be set.
  32924. maxProperties: 1
  32925. minProperties: 1
  32926. properties:
  32927. ntlm:
  32928. description: NTLMProtocol configures the store to use NTLM for auth
  32929. properties:
  32930. passwordSecret:
  32931. description: |-
  32932. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  32933. In some instances, `key` is a required field.
  32934. properties:
  32935. key:
  32936. description: |-
  32937. A key in the referenced Secret.
  32938. Some instances of this field may be defaulted, in others it may be required.
  32939. maxLength: 253
  32940. minLength: 1
  32941. pattern: ^[-._a-zA-Z0-9]+$
  32942. type: string
  32943. name:
  32944. description: The name of the Secret resource being referred to.
  32945. maxLength: 253
  32946. minLength: 1
  32947. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32948. type: string
  32949. namespace:
  32950. description: |-
  32951. The namespace of the Secret resource being referred to.
  32952. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32953. maxLength: 63
  32954. minLength: 1
  32955. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32956. type: string
  32957. type: object
  32958. usernameSecret:
  32959. description: |-
  32960. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  32961. In some instances, `key` is a required field.
  32962. properties:
  32963. key:
  32964. description: |-
  32965. A key in the referenced Secret.
  32966. Some instances of this field may be defaulted, in others it may be required.
  32967. maxLength: 253
  32968. minLength: 1
  32969. pattern: ^[-._a-zA-Z0-9]+$
  32970. type: string
  32971. name:
  32972. description: The name of the Secret resource being referred to.
  32973. maxLength: 253
  32974. minLength: 1
  32975. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32976. type: string
  32977. namespace:
  32978. description: |-
  32979. The namespace of the Secret resource being referred to.
  32980. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32981. maxLength: 63
  32982. minLength: 1
  32983. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32984. type: string
  32985. type: object
  32986. required:
  32987. - passwordSecret
  32988. - usernameSecret
  32989. type: object
  32990. type: object
  32991. body:
  32992. description: Body
  32993. type: string
  32994. caBundle:
  32995. description: |-
  32996. PEM encoded CA bundle used to validate webhook server certificate. Only used
  32997. if the Server URL is using HTTPS protocol. This parameter is ignored for
  32998. plain HTTP protocol connection. If not set the system root certificates
  32999. are used to validate the TLS connection.
  33000. format: byte
  33001. type: string
  33002. caProvider:
  33003. description: The provider for the CA bundle to use to validate webhook server certificate.
  33004. properties:
  33005. key:
  33006. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  33007. maxLength: 253
  33008. minLength: 1
  33009. pattern: ^[-._a-zA-Z0-9]+$
  33010. type: string
  33011. name:
  33012. description: The name of the object located at the provider type.
  33013. maxLength: 253
  33014. minLength: 1
  33015. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  33016. type: string
  33017. namespace:
  33018. description: The namespace the Provider type is in.
  33019. maxLength: 63
  33020. minLength: 1
  33021. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  33022. type: string
  33023. type:
  33024. description: The type of provider to use such as "Secret", or "ConfigMap".
  33025. enum:
  33026. - Secret
  33027. - ConfigMap
  33028. type: string
  33029. required:
  33030. - name
  33031. - type
  33032. type: object
  33033. headers:
  33034. additionalProperties:
  33035. type: string
  33036. description: Headers
  33037. type: object
  33038. method:
  33039. description: Webhook Method
  33040. type: string
  33041. result:
  33042. description: Result formatting
  33043. properties:
  33044. jsonPath:
  33045. description: Json path of return value
  33046. type: string
  33047. type: object
  33048. secrets:
  33049. description: |-
  33050. Secrets to fill in templates
  33051. These secrets will be passed to the templating function as key value pairs under the given name
  33052. items:
  33053. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  33054. properties:
  33055. name:
  33056. description: Name of this secret in templates
  33057. type: string
  33058. secretRef:
  33059. description: Secret ref to fill in credentials
  33060. properties:
  33061. key:
  33062. description: The key where the token is found.
  33063. maxLength: 253
  33064. minLength: 1
  33065. pattern: ^[-._a-zA-Z0-9]+$
  33066. type: string
  33067. name:
  33068. description: The name of the Secret resource being referred to.
  33069. maxLength: 253
  33070. minLength: 1
  33071. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  33072. type: string
  33073. type: object
  33074. required:
  33075. - name
  33076. - secretRef
  33077. type: object
  33078. type: array
  33079. timeout:
  33080. description: Timeout
  33081. type: string
  33082. url:
  33083. description: Webhook url to call
  33084. type: string
  33085. required:
  33086. - result
  33087. - url
  33088. type: object
  33089. type: object
  33090. served: true
  33091. storage: true
  33092. subresources:
  33093. status: {}