generators.external-secrets.io_clustergenerators.yaml 158 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488248924902491249224932494249524962497249824992500250125022503250425052506250725082509251025112512251325142515251625172518251925202521252225232524252525262527252825292530253125322533253425352536253725382539254025412542254325442545254625472548254925502551255225532554255525562557255825592560256125622563256425652566256725682569257025712572257325742575257625772578257925802581258225832584258525862587258825892590259125922593259425952596259725982599260026012602260326042605260626072608260926102611261226132614261526162617261826192620262126222623262426252626262726282629263026312632263326342635263626372638263926402641264226432644264526462647264826492650265126522653265426552656265726582659266026612662266326642665266626672668266926702671267226732674267526762677267826792680268126822683268426852686268726882689
  1. apiVersion: apiextensions.k8s.io/v1
  2. kind: CustomResourceDefinition
  3. metadata:
  4. annotations:
  5. controller-gen.kubebuilder.io/version: v0.19.0
  6. labels:
  7. external-secrets.io/component: controller
  8. name: clustergenerators.generators.external-secrets.io
  9. spec:
  10. group: generators.external-secrets.io
  11. names:
  12. categories:
  13. - external-secrets
  14. - external-secrets-generators
  15. kind: ClusterGenerator
  16. listKind: ClusterGeneratorList
  17. plural: clustergenerators
  18. singular: clustergenerator
  19. scope: Cluster
  20. versions:
  21. - name: v1alpha1
  22. schema:
  23. openAPIV3Schema:
  24. description: ClusterGenerator represents a cluster-wide generator which can
  25. be referenced as part of `generatorRef` fields.
  26. properties:
  27. apiVersion:
  28. description: |-
  29. APIVersion defines the versioned schema of this representation of an object.
  30. Servers should convert recognized schemas to the latest internal value, and
  31. may reject unrecognized values.
  32. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  33. type: string
  34. kind:
  35. description: |-
  36. Kind is a string value representing the REST resource this object represents.
  37. Servers may infer this from the endpoint the client submits requests to.
  38. Cannot be updated.
  39. In CamelCase.
  40. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  41. type: string
  42. metadata:
  43. type: object
  44. spec:
  45. description: ClusterGeneratorSpec defines the desired state of a ClusterGenerator.
  46. properties:
  47. generator:
  48. description: Generator the spec for this generator, must match the
  49. kind.
  50. maxProperties: 1
  51. minProperties: 1
  52. properties:
  53. acrAccessTokenSpec:
  54. description: |-
  55. ACRAccessTokenSpec defines how to generate the access token
  56. e.g. how to authenticate and which registry to use.
  57. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  58. properties:
  59. auth:
  60. description: ACRAuth defines the authentication methods for
  61. Azure Container Registry.
  62. properties:
  63. managedIdentity:
  64. description: ManagedIdentity uses Azure Managed Identity
  65. to authenticate with Azure.
  66. properties:
  67. identityId:
  68. description: If multiple Managed Identity is assigned
  69. to the pod, you can select the one to be used
  70. type: string
  71. type: object
  72. servicePrincipal:
  73. description: ServicePrincipal uses Azure Service Principal
  74. credentials to authenticate with Azure.
  75. properties:
  76. secretRef:
  77. description: |-
  78. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  79. It uses static credentials stored in a Kind=Secret.
  80. properties:
  81. clientId:
  82. description: The Azure clientId of the service
  83. principle used for authentication.
  84. properties:
  85. key:
  86. description: |-
  87. A key in the referenced Secret.
  88. Some instances of this field may be defaulted, in others it may be required.
  89. maxLength: 253
  90. minLength: 1
  91. pattern: ^[-._a-zA-Z0-9]+$
  92. type: string
  93. name:
  94. description: The name of the Secret resource
  95. being referred to.
  96. maxLength: 253
  97. minLength: 1
  98. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  99. type: string
  100. namespace:
  101. description: |-
  102. The namespace of the Secret resource being referred to.
  103. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  104. maxLength: 63
  105. minLength: 1
  106. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  107. type: string
  108. type: object
  109. clientSecret:
  110. description: The Azure ClientSecret of the service
  111. principle used for authentication.
  112. properties:
  113. key:
  114. description: |-
  115. A key in the referenced Secret.
  116. Some instances of this field may be defaulted, in others it may be required.
  117. maxLength: 253
  118. minLength: 1
  119. pattern: ^[-._a-zA-Z0-9]+$
  120. type: string
  121. name:
  122. description: The name of the Secret resource
  123. being referred to.
  124. maxLength: 253
  125. minLength: 1
  126. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  127. type: string
  128. namespace:
  129. description: |-
  130. The namespace of the Secret resource being referred to.
  131. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  132. maxLength: 63
  133. minLength: 1
  134. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  135. type: string
  136. type: object
  137. type: object
  138. required:
  139. - secretRef
  140. type: object
  141. workloadIdentity:
  142. description: WorkloadIdentity uses Azure Workload Identity
  143. to authenticate with Azure.
  144. properties:
  145. serviceAccountRef:
  146. description: |-
  147. ServiceAccountRef specified the service account
  148. that should be used when authenticating with WorkloadIdentity.
  149. properties:
  150. audiences:
  151. description: |-
  152. Audience specifies the `aud` claim for the service account token
  153. Some providers automatically extend the audience field based on well-known annotations for workload
  154. identity (e.g. IRSA or GCP Workload Identity)
  155. items:
  156. type: string
  157. type: array
  158. name:
  159. description: The name of the ServiceAccount resource
  160. being referred to.
  161. maxLength: 253
  162. minLength: 1
  163. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  164. type: string
  165. namespace:
  166. description: |-
  167. Namespace of the resource being referred to.
  168. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  169. maxLength: 63
  170. minLength: 1
  171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  172. type: string
  173. required:
  174. - name
  175. type: object
  176. type: object
  177. type: object
  178. environmentType:
  179. default: PublicCloud
  180. description: |-
  181. EnvironmentType specifies the Azure cloud environment endpoints to use for
  182. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  183. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  184. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  185. enum:
  186. - PublicCloud
  187. - USGovernmentCloud
  188. - ChinaCloud
  189. - GermanCloud
  190. - AzureStackCloud
  191. type: string
  192. registry:
  193. description: |-
  194. the domain name of the ACR registry
  195. e.g. foobarexample.azurecr.io
  196. type: string
  197. scope:
  198. description: |-
  199. Define the scope for the access token, e.g. pull/push access for a repository.
  200. if not provided it will return a refresh token that has full scope.
  201. Note: you need to pin it down to the repository level, there is no wildcard available.
  202. examples:
  203. repository:my-repository:pull,push
  204. repository:my-repository:pull
  205. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  206. type: string
  207. tenantId:
  208. description: TenantID configures the Azure Tenant to send
  209. requests to. Required for ServicePrincipal auth type.
  210. type: string
  211. required:
  212. - auth
  213. - registry
  214. type: object
  215. beyondtrustWorkloadCredentialsDynamicSecretSpec:
  216. description: |-
  217. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  218. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  219. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  220. properties:
  221. controller:
  222. description: |-
  223. Controller selects the controller that should handle this generator.
  224. Leave empty to use the default controller.
  225. type: string
  226. provider:
  227. description: |-
  228. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  229. server connection details, and the folder path to the dynamic secret definition.
  230. The folderPath should point to a dynamic secret definition that has been created in
  231. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  232. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  233. properties:
  234. auth:
  235. description: |-
  236. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  237. Currently supports API key authentication via Kubernetes secret reference.
  238. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  239. properties:
  240. apikey:
  241. description: |-
  242. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  243. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  244. properties:
  245. token:
  246. description: |-
  247. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  248. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  249. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  250. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  251. properties:
  252. key:
  253. description: |-
  254. A key in the referenced Secret.
  255. Some instances of this field may be defaulted, in others it may be required.
  256. maxLength: 253
  257. minLength: 1
  258. pattern: ^[-._a-zA-Z0-9]+$
  259. type: string
  260. name:
  261. description: The name of the Secret resource
  262. being referred to.
  263. maxLength: 253
  264. minLength: 1
  265. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  266. type: string
  267. namespace:
  268. description: |-
  269. The namespace of the Secret resource being referred to.
  270. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  271. maxLength: 63
  272. minLength: 1
  273. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  274. type: string
  275. type: object
  276. required:
  277. - token
  278. type: object
  279. required:
  280. - apikey
  281. type: object
  282. caBundle:
  283. description: |-
  284. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  285. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  286. If not set, the system's trusted root certificates are used.
  287. format: byte
  288. type: string
  289. caProvider:
  290. description: |-
  291. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  292. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  293. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  294. properties:
  295. key:
  296. description: The key where the CA certificate can
  297. be found in the Secret or ConfigMap.
  298. maxLength: 253
  299. minLength: 1
  300. pattern: ^[-._a-zA-Z0-9]+$
  301. type: string
  302. name:
  303. description: The name of the object located at the
  304. provider type.
  305. maxLength: 253
  306. minLength: 1
  307. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  308. type: string
  309. namespace:
  310. description: |-
  311. The namespace the Provider type is in.
  312. Can only be defined when used in a ClusterSecretStore.
  313. maxLength: 63
  314. minLength: 1
  315. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  316. type: string
  317. type:
  318. description: The type of provider to use such as "Secret",
  319. or "ConfigMap".
  320. enum:
  321. - Secret
  322. - ConfigMap
  323. type: string
  324. required:
  325. - name
  326. - type
  327. type: object
  328. folderPath:
  329. description: |-
  330. FolderPath specifies the default folder path for secret retrieval.
  331. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  332. Example: "production/database" or "dev/api-keys"
  333. Leave empty to retrieve secrets from the root folder.
  334. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  335. type: string
  336. server:
  337. description: |-
  338. Server configures the BeyondTrust Workload Credentials server connection details.
  339. Includes the API URL and Site ID for your BeyondTrust instance.
  340. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  341. properties:
  342. apiUrl:
  343. description: |-
  344. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  345. This should be the full URL to your BeyondTrust instance.
  346. Example: https://api.beyondtrust.io/siie
  347. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  348. type: string
  349. siteId:
  350. description: |-
  351. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  352. This identifier is unique to your BeyondTrust Workload Credentials instance.
  353. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  354. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  355. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  356. type: string
  357. required:
  358. - apiUrl
  359. - siteId
  360. type: object
  361. required:
  362. - auth
  363. - server
  364. type: object
  365. retrySettings:
  366. description: |-
  367. RetrySettings configures exponential backoff for failed API requests.
  368. If not specified, uses the default retry settings.
  369. properties:
  370. maxRetries:
  371. format: int32
  372. type: integer
  373. retryInterval:
  374. type: string
  375. type: object
  376. required:
  377. - provider
  378. type: object
  379. cloudsmithAccessTokenSpec:
  380. description: CloudsmithAccessTokenSpec defines the configuration
  381. for generating a Cloudsmith access token using OIDC authentication.
  382. properties:
  383. apiUrl:
  384. description: APIURL configures the Cloudsmith API URL. Defaults
  385. to https://api.cloudsmith.io.
  386. type: string
  387. orgSlug:
  388. description: OrgSlug is the organization slug in Cloudsmith
  389. type: string
  390. serviceAccountRef:
  391. description: Name of the service account you are federating
  392. with
  393. properties:
  394. audiences:
  395. description: |-
  396. Audience specifies the `aud` claim for the service account token
  397. Some providers automatically extend the audience field based on well-known annotations for workload
  398. identity (e.g. IRSA or GCP Workload Identity)
  399. items:
  400. type: string
  401. type: array
  402. name:
  403. description: The name of the ServiceAccount resource being
  404. referred to.
  405. maxLength: 253
  406. minLength: 1
  407. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  408. type: string
  409. namespace:
  410. description: |-
  411. Namespace of the resource being referred to.
  412. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  413. maxLength: 63
  414. minLength: 1
  415. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  416. type: string
  417. required:
  418. - name
  419. type: object
  420. serviceSlug:
  421. description: ServiceSlug is the service slug in Cloudsmith
  422. for OIDC authentication
  423. type: string
  424. required:
  425. - orgSlug
  426. - serviceAccountRef
  427. - serviceSlug
  428. type: object
  429. ecrAuthorizationTokenSpec:
  430. description: ECRAuthorizationTokenSpec defines the desired state
  431. to generate an AWS ECR authorization token.
  432. properties:
  433. auth:
  434. description: Auth defines how to authenticate with AWS
  435. properties:
  436. jwt:
  437. description: AWSJWTAuth provides configuration to authenticate
  438. against AWS using service account tokens.
  439. properties:
  440. serviceAccountRef:
  441. description: ServiceAccountSelector is a reference
  442. to a ServiceAccount resource.
  443. properties:
  444. audiences:
  445. description: |-
  446. Audience specifies the `aud` claim for the service account token
  447. Some providers automatically extend the audience field based on well-known annotations for workload
  448. identity (e.g. IRSA or GCP Workload Identity)
  449. items:
  450. type: string
  451. type: array
  452. name:
  453. description: The name of the ServiceAccount resource
  454. being referred to.
  455. maxLength: 253
  456. minLength: 1
  457. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  458. type: string
  459. namespace:
  460. description: |-
  461. Namespace of the resource being referred to.
  462. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  463. maxLength: 63
  464. minLength: 1
  465. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  466. type: string
  467. required:
  468. - name
  469. type: object
  470. type: object
  471. secretRef:
  472. description: |-
  473. AWSAuthSecretRef holds secret references for AWS credentials
  474. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  475. properties:
  476. accessKeyIDSecretRef:
  477. description: The AccessKeyID is used for authentication
  478. properties:
  479. key:
  480. description: |-
  481. A key in the referenced Secret.
  482. Some instances of this field may be defaulted, in others it may be required.
  483. maxLength: 253
  484. minLength: 1
  485. pattern: ^[-._a-zA-Z0-9]+$
  486. type: string
  487. name:
  488. description: The name of the Secret resource being
  489. referred to.
  490. maxLength: 253
  491. minLength: 1
  492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  493. type: string
  494. namespace:
  495. description: |-
  496. The namespace of the Secret resource being referred to.
  497. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  498. maxLength: 63
  499. minLength: 1
  500. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  501. type: string
  502. type: object
  503. secretAccessKeySecretRef:
  504. description: The SecretAccessKey is used for authentication
  505. properties:
  506. key:
  507. description: |-
  508. A key in the referenced Secret.
  509. Some instances of this field may be defaulted, in others it may be required.
  510. maxLength: 253
  511. minLength: 1
  512. pattern: ^[-._a-zA-Z0-9]+$
  513. type: string
  514. name:
  515. description: The name of the Secret resource being
  516. referred to.
  517. maxLength: 253
  518. minLength: 1
  519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  520. type: string
  521. namespace:
  522. description: |-
  523. The namespace of the Secret resource being referred to.
  524. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  525. maxLength: 63
  526. minLength: 1
  527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  528. type: string
  529. type: object
  530. sessionTokenSecretRef:
  531. description: |-
  532. The SessionToken used for authentication
  533. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  534. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  535. properties:
  536. key:
  537. description: |-
  538. A key in the referenced Secret.
  539. Some instances of this field may be defaulted, in others it may be required.
  540. maxLength: 253
  541. minLength: 1
  542. pattern: ^[-._a-zA-Z0-9]+$
  543. type: string
  544. name:
  545. description: The name of the Secret resource being
  546. referred to.
  547. maxLength: 253
  548. minLength: 1
  549. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  550. type: string
  551. namespace:
  552. description: |-
  553. The namespace of the Secret resource being referred to.
  554. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  555. maxLength: 63
  556. minLength: 1
  557. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  558. type: string
  559. type: object
  560. type: object
  561. type: object
  562. region:
  563. description: Region specifies the region to operate in.
  564. type: string
  565. role:
  566. description: |-
  567. You can assume a role before making calls to the
  568. desired AWS service.
  569. type: string
  570. scope:
  571. description: |-
  572. Scope specifies the ECR service scope.
  573. Valid options are private and public.
  574. type: string
  575. required:
  576. - region
  577. type: object
  578. fakeSpec:
  579. description: FakeSpec contains the static data.
  580. properties:
  581. controller:
  582. description: |-
  583. Used to select the correct ESO controller (think: ingress.ingressClassName)
  584. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  585. type: string
  586. data:
  587. additionalProperties:
  588. type: string
  589. description: |-
  590. Data defines the static data returned
  591. by this generator.
  592. type: object
  593. type: object
  594. gcrAccessTokenSpec:
  595. description: GCRAccessTokenSpec defines the desired state to generate
  596. a Google Container Registry access token.
  597. properties:
  598. auth:
  599. description: Auth defines the means for authenticating with
  600. GCP
  601. properties:
  602. secretRef:
  603. description: GCPSMAuthSecretRef defines the reference
  604. to a secret containing Google Cloud Platform credentials.
  605. properties:
  606. secretAccessKeySecretRef:
  607. description: The SecretAccessKey is used for authentication
  608. properties:
  609. key:
  610. description: |-
  611. A key in the referenced Secret.
  612. Some instances of this field may be defaulted, in others it may be required.
  613. maxLength: 253
  614. minLength: 1
  615. pattern: ^[-._a-zA-Z0-9]+$
  616. type: string
  617. name:
  618. description: The name of the Secret resource being
  619. referred to.
  620. maxLength: 253
  621. minLength: 1
  622. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  623. type: string
  624. namespace:
  625. description: |-
  626. The namespace of the Secret resource being referred to.
  627. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  628. maxLength: 63
  629. minLength: 1
  630. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  631. type: string
  632. type: object
  633. type: object
  634. workloadIdentity:
  635. description: GCPWorkloadIdentity defines the configuration
  636. for using GCP Workload Identity authentication.
  637. properties:
  638. clusterLocation:
  639. type: string
  640. clusterName:
  641. type: string
  642. clusterProjectID:
  643. type: string
  644. serviceAccountRef:
  645. description: ServiceAccountSelector is a reference
  646. to a ServiceAccount resource.
  647. properties:
  648. audiences:
  649. description: |-
  650. Audience specifies the `aud` claim for the service account token
  651. Some providers automatically extend the audience field based on well-known annotations for workload
  652. identity (e.g. IRSA or GCP Workload Identity)
  653. items:
  654. type: string
  655. type: array
  656. name:
  657. description: The name of the ServiceAccount resource
  658. being referred to.
  659. maxLength: 253
  660. minLength: 1
  661. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  662. type: string
  663. namespace:
  664. description: |-
  665. Namespace of the resource being referred to.
  666. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  667. maxLength: 63
  668. minLength: 1
  669. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  670. type: string
  671. required:
  672. - name
  673. type: object
  674. required:
  675. - clusterLocation
  676. - clusterName
  677. - serviceAccountRef
  678. type: object
  679. workloadIdentityFederation:
  680. description: GCPWorkloadIdentityFederation holds the configurations
  681. required for generating federated access tokens.
  682. properties:
  683. audience:
  684. description: |-
  685. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  686. If specified, Audience found in the external account credential config will be overridden with the configured value.
  687. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  688. type: string
  689. awsSecurityCredentials:
  690. description: |-
  691. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  692. when using the AWS metadata server is not an option.
  693. properties:
  694. awsCredentialsSecretRef:
  695. description: |-
  696. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  697. Secret should be created with below names for keys
  698. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  699. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  700. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  701. properties:
  702. name:
  703. description: name of the secret.
  704. maxLength: 253
  705. minLength: 1
  706. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  707. type: string
  708. namespace:
  709. description: namespace in which the secret
  710. exists. If empty, secret will looked up
  711. in local namespace.
  712. maxLength: 63
  713. minLength: 1
  714. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  715. type: string
  716. required:
  717. - name
  718. type: object
  719. region:
  720. description: region is for configuring the AWS
  721. region to be used.
  722. example: ap-south-1
  723. maxLength: 50
  724. minLength: 1
  725. pattern: ^[a-z0-9-]+$
  726. type: string
  727. required:
  728. - awsCredentialsSecretRef
  729. - region
  730. type: object
  731. credConfig:
  732. description: |-
  733. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  734. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  735. serviceAccountRef must be used by providing operators service account details.
  736. properties:
  737. key:
  738. description: key name holding the external account
  739. credential config.
  740. maxLength: 253
  741. minLength: 1
  742. pattern: ^[-._a-zA-Z0-9]+$
  743. type: string
  744. name:
  745. description: name of the configmap.
  746. maxLength: 253
  747. minLength: 1
  748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  749. type: string
  750. namespace:
  751. description: namespace in which the configmap
  752. exists. If empty, configmap will looked up in
  753. local namespace.
  754. maxLength: 63
  755. minLength: 1
  756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  757. type: string
  758. required:
  759. - key
  760. - name
  761. type: object
  762. externalTokenEndpoint:
  763. description: |-
  764. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  765. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  766. URL is having the expected value.
  767. type: string
  768. gcpServiceAccountEmail:
  769. description: |-
  770. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  771. after Workload Identity Federation. Use this to grant access through the service account's
  772. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  773. service_account_impersonation_url in the external account JSON from credConfig;
  774. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  775. on that ServiceAccount.
  776. example: my-gsa@my-project.iam.gserviceaccount.com
  777. minLength: 1
  778. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  779. type: string
  780. serviceAccountRef:
  781. description: |-
  782. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  783. when Kubernetes is configured as provider in workload identity pool.
  784. properties:
  785. audiences:
  786. description: |-
  787. Audience specifies the `aud` claim for the service account token
  788. Some providers automatically extend the audience field based on well-known annotations for workload
  789. identity (e.g. IRSA or GCP Workload Identity)
  790. items:
  791. type: string
  792. type: array
  793. name:
  794. description: The name of the ServiceAccount resource
  795. being referred to.
  796. maxLength: 253
  797. minLength: 1
  798. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  799. type: string
  800. namespace:
  801. description: |-
  802. Namespace of the resource being referred to.
  803. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  804. maxLength: 63
  805. minLength: 1
  806. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  807. type: string
  808. required:
  809. - name
  810. type: object
  811. type: object
  812. type: object
  813. projectID:
  814. description: ProjectID defines which project to use to authenticate
  815. with
  816. type: string
  817. required:
  818. - auth
  819. - projectID
  820. type: object
  821. githubAccessTokenSpec:
  822. description: GithubAccessTokenSpec defines the desired state to
  823. generate a GitHub access token.
  824. properties:
  825. appID:
  826. type: string
  827. auth:
  828. description: Auth configures how ESO authenticates with a
  829. Github instance.
  830. properties:
  831. privateKey:
  832. description: GithubSecretRef references a secret containing
  833. GitHub credentials.
  834. properties:
  835. secretRef:
  836. description: |-
  837. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  838. In some instances, `key` is a required field.
  839. properties:
  840. key:
  841. description: |-
  842. A key in the referenced Secret.
  843. Some instances of this field may be defaulted, in others it may be required.
  844. maxLength: 253
  845. minLength: 1
  846. pattern: ^[-._a-zA-Z0-9]+$
  847. type: string
  848. name:
  849. description: The name of the Secret resource being
  850. referred to.
  851. maxLength: 253
  852. minLength: 1
  853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  854. type: string
  855. namespace:
  856. description: |-
  857. The namespace of the Secret resource being referred to.
  858. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  859. maxLength: 63
  860. minLength: 1
  861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  862. type: string
  863. type: object
  864. required:
  865. - secretRef
  866. type: object
  867. required:
  868. - privateKey
  869. type: object
  870. installID:
  871. type: string
  872. permissions:
  873. additionalProperties:
  874. type: string
  875. description: Map of permissions the token will have. If omitted,
  876. defaults to all permissions the GitHub App has.
  877. type: object
  878. repositories:
  879. description: |-
  880. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  881. is installed to.
  882. items:
  883. type: string
  884. type: array
  885. url:
  886. description: URL configures the GitHub instance URL. Defaults
  887. to https://github.com/.
  888. type: string
  889. required:
  890. - appID
  891. - auth
  892. - installID
  893. type: object
  894. gitlabDeployTokenSpec:
  895. description: GitlabDeployTokenSpec defines the desired state to
  896. generate a GitLab deploy token.
  897. properties:
  898. auth:
  899. description: Auth configures how ESO authenticates with the
  900. GitLab API.
  901. properties:
  902. token:
  903. description: |-
  904. Token references a secret containing a GitLab access token (personal, group, or
  905. project) with the api scope and at least the Maintainer role on the target.
  906. properties:
  907. secretRef:
  908. description: |-
  909. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  910. In some instances, `key` is a required field.
  911. properties:
  912. key:
  913. description: |-
  914. A key in the referenced Secret.
  915. Some instances of this field may be defaulted, in others it may be required.
  916. maxLength: 253
  917. minLength: 1
  918. pattern: ^[-._a-zA-Z0-9]+$
  919. type: string
  920. name:
  921. description: The name of the Secret resource being
  922. referred to.
  923. maxLength: 253
  924. minLength: 1
  925. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  926. type: string
  927. namespace:
  928. description: |-
  929. The namespace of the Secret resource being referred to.
  930. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  931. maxLength: 63
  932. minLength: 1
  933. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  934. type: string
  935. type: object
  936. required:
  937. - secretRef
  938. type: object
  939. required:
  940. - token
  941. type: object
  942. expiresAt:
  943. description: |-
  944. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  945. not expire on the GitLab side and is revoked only when the generator state is
  946. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  947. format: date-time
  948. type: string
  949. groupID:
  950. description: |-
  951. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  952. create the deploy token in. The generator URL-escapes paths before calling the
  953. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  954. minLength: 1
  955. type: string
  956. name:
  957. description: Name of the deploy token.
  958. minLength: 1
  959. type: string
  960. projectID:
  961. description: |-
  962. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  963. project to create the deploy token in. The generator URL-escapes paths before
  964. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  965. minLength: 1
  966. type: string
  967. scopes:
  968. description: Scopes granted to the deploy token. At least
  969. one scope is required.
  970. items:
  971. description: GitlabDeployTokenScope is a scope that can
  972. be granted to a GitLab deploy token.
  973. enum:
  974. - read_repository
  975. - read_registry
  976. - write_registry
  977. - read_package_registry
  978. - write_package_registry
  979. - read_virtual_registry
  980. - write_virtual_registry
  981. type: string
  982. minItems: 1
  983. type: array
  984. url:
  985. description: URL configures the GitLab instance URL. Defaults
  986. to https://gitlab.com.
  987. type: string
  988. username:
  989. description: |-
  990. Username is an optional username for the deploy token. GitLab defaults it to
  991. gitlab+deploy-token-{n} when omitted.
  992. type: string
  993. required:
  994. - auth
  995. - name
  996. - scopes
  997. type: object
  998. x-kubernetes-validations:
  999. - message: exactly one of projectID or groupID must be set
  1000. rule: has(self.projectID) != has(self.groupID)
  1001. grafanaSpec:
  1002. description: GrafanaSpec controls the behavior of the grafana
  1003. generator.
  1004. properties:
  1005. auth:
  1006. description: |-
  1007. Auth is the authentication configuration to authenticate
  1008. against the Grafana instance.
  1009. properties:
  1010. basic:
  1011. description: |-
  1012. Basic auth credentials used to authenticate against the Grafana instance.
  1013. Note: you need a token which has elevated permissions to create service accounts.
  1014. See here for the documentation on basic roles offered by Grafana:
  1015. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  1016. properties:
  1017. password:
  1018. description: A basic auth password used to authenticate
  1019. against the Grafana instance.
  1020. properties:
  1021. key:
  1022. description: The key where the token is found.
  1023. maxLength: 253
  1024. minLength: 1
  1025. pattern: ^[-._a-zA-Z0-9]+$
  1026. type: string
  1027. name:
  1028. description: The name of the Secret resource being
  1029. referred to.
  1030. maxLength: 253
  1031. minLength: 1
  1032. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1033. type: string
  1034. type: object
  1035. username:
  1036. description: A basic auth username used to authenticate
  1037. against the Grafana instance.
  1038. type: string
  1039. required:
  1040. - password
  1041. - username
  1042. type: object
  1043. token:
  1044. description: |-
  1045. A service account token used to authenticate against the Grafana instance.
  1046. Note: you need a token which has elevated permissions to create service accounts.
  1047. See here for the documentation on basic roles offered by Grafana:
  1048. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  1049. properties:
  1050. key:
  1051. description: The key where the token is found.
  1052. maxLength: 253
  1053. minLength: 1
  1054. pattern: ^[-._a-zA-Z0-9]+$
  1055. type: string
  1056. name:
  1057. description: The name of the Secret resource being
  1058. referred to.
  1059. maxLength: 253
  1060. minLength: 1
  1061. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1062. type: string
  1063. type: object
  1064. type: object
  1065. serviceAccount:
  1066. description: |-
  1067. ServiceAccount is the configuration for the service account that
  1068. is supposed to be generated by the generator.
  1069. properties:
  1070. name:
  1071. description: Name is the name of the service account that
  1072. will be created by ESO.
  1073. type: string
  1074. role:
  1075. description: |-
  1076. Role is the role of the service account.
  1077. See here for the documentation on basic roles offered by Grafana:
  1078. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  1079. type: string
  1080. secondsToLive:
  1081. description: |-
  1082. SecondsToLive is the number of seconds before the generated service account token will expire.
  1083. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  1084. format: int64
  1085. minimum: 1
  1086. type: integer
  1087. required:
  1088. - name
  1089. - role
  1090. type: object
  1091. url:
  1092. description: URL is the URL of the Grafana instance.
  1093. type: string
  1094. required:
  1095. - auth
  1096. - serviceAccount
  1097. - url
  1098. type: object
  1099. mfaSpec:
  1100. description: MFASpec controls the behavior of the mfa generator.
  1101. properties:
  1102. algorithm:
  1103. description: Algorithm to use for encoding. Defaults to SHA1
  1104. as per the RFC.
  1105. type: string
  1106. length:
  1107. description: Length defines the token length. Defaults to
  1108. 6 characters.
  1109. type: integer
  1110. secret:
  1111. description: Secret is a secret selector to a secret containing
  1112. the seed secret to generate the TOTP value from.
  1113. properties:
  1114. key:
  1115. description: |-
  1116. A key in the referenced Secret.
  1117. Some instances of this field may be defaulted, in others it may be required.
  1118. maxLength: 253
  1119. minLength: 1
  1120. pattern: ^[-._a-zA-Z0-9]+$
  1121. type: string
  1122. name:
  1123. description: The name of the Secret resource being referred
  1124. to.
  1125. maxLength: 253
  1126. minLength: 1
  1127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1128. type: string
  1129. namespace:
  1130. description: |-
  1131. The namespace of the Secret resource being referred to.
  1132. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1133. maxLength: 63
  1134. minLength: 1
  1135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1136. type: string
  1137. type: object
  1138. timePeriod:
  1139. description: TimePeriod defines how long the token can be
  1140. active. Defaults to 30 seconds.
  1141. type: integer
  1142. when:
  1143. description: When defines a time parameter that can be used
  1144. to pin the origin time of the generated token.
  1145. format: date-time
  1146. type: string
  1147. required:
  1148. - secret
  1149. type: object
  1150. passwordSpec:
  1151. description: PasswordSpec controls the behavior of the password
  1152. generator.
  1153. properties:
  1154. allowRepeat:
  1155. default: false
  1156. description: set AllowRepeat to true to allow repeating characters.
  1157. type: boolean
  1158. digits:
  1159. description: |-
  1160. Digits specifies the number of digits in the generated
  1161. password. If omitted it defaults to 25% of the length of the password
  1162. type: integer
  1163. encoding:
  1164. default: raw
  1165. description: |-
  1166. Encoding specifies the encoding of the generated password.
  1167. Valid values are:
  1168. - "raw" (default): no encoding
  1169. - "base64": standard base64 encoding
  1170. - "base64url": base64url encoding
  1171. - "base32": base32 encoding
  1172. - "hex": hexadecimal encoding
  1173. enum:
  1174. - base64
  1175. - base64url
  1176. - base32
  1177. - hex
  1178. - raw
  1179. type: string
  1180. length:
  1181. default: 24
  1182. description: |-
  1183. Length of the password to be generated.
  1184. Defaults to 24
  1185. type: integer
  1186. noUpper:
  1187. default: false
  1188. description: Set NoUpper to disable uppercase characters
  1189. type: boolean
  1190. secretKeys:
  1191. description: |-
  1192. SecretKeys defines the keys that will be populated with generated passwords.
  1193. Defaults to "password" when not set.
  1194. items:
  1195. type: string
  1196. minItems: 1
  1197. type: array
  1198. symbolCharacters:
  1199. description: |-
  1200. SymbolCharacters specifies the special characters that should be used
  1201. in the generated password.
  1202. type: string
  1203. symbols:
  1204. description: |-
  1205. Symbols specifies the number of symbol characters in the generated
  1206. password. If omitted it defaults to 25% of the length of the password
  1207. type: integer
  1208. required:
  1209. - allowRepeat
  1210. - length
  1211. - noUpper
  1212. type: object
  1213. quayAccessTokenSpec:
  1214. description: QuayAccessTokenSpec defines the desired state to
  1215. generate a Quay access token.
  1216. properties:
  1217. robotAccount:
  1218. description: Name of the robot account you are federating
  1219. with
  1220. type: string
  1221. serviceAccountRef:
  1222. description: Name of the service account you are federating
  1223. with
  1224. properties:
  1225. audiences:
  1226. description: |-
  1227. Audience specifies the `aud` claim for the service account token
  1228. Some providers automatically extend the audience field based on well-known annotations for workload
  1229. identity (e.g. IRSA or GCP Workload Identity)
  1230. items:
  1231. type: string
  1232. type: array
  1233. name:
  1234. description: The name of the ServiceAccount resource being
  1235. referred to.
  1236. maxLength: 253
  1237. minLength: 1
  1238. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1239. type: string
  1240. namespace:
  1241. description: |-
  1242. Namespace of the resource being referred to.
  1243. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1244. maxLength: 63
  1245. minLength: 1
  1246. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1247. type: string
  1248. required:
  1249. - name
  1250. type: object
  1251. url:
  1252. description: URL configures the Quay instance URL. Defaults
  1253. to quay.io.
  1254. type: string
  1255. required:
  1256. - robotAccount
  1257. - serviceAccountRef
  1258. type: object
  1259. sshKeySpec:
  1260. description: SSHKeySpec controls the behavior of the ssh key generator.
  1261. properties:
  1262. comment:
  1263. description: Comment specifies an optional comment for the
  1264. SSH key
  1265. type: string
  1266. keySize:
  1267. description: |-
  1268. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  1269. For RSA keys: 2048, 3072, 4096
  1270. For ECDSA keys: 256, 384, 521
  1271. Ignored for ed25519 keys
  1272. maximum: 8192
  1273. minimum: 256
  1274. type: integer
  1275. keyType:
  1276. default: rsa
  1277. description: KeyType specifies the SSH key type (rsa, ecdsa,
  1278. ed25519)
  1279. enum:
  1280. - rsa
  1281. - ecdsa
  1282. - ed25519
  1283. type: string
  1284. type: object
  1285. stsSessionTokenSpec:
  1286. description: STSSessionTokenSpec defines the desired state to
  1287. generate an AWS STS session token.
  1288. properties:
  1289. auth:
  1290. description: Auth defines how to authenticate with AWS
  1291. properties:
  1292. jwt:
  1293. description: AWSJWTAuth provides configuration to authenticate
  1294. against AWS using service account tokens.
  1295. properties:
  1296. serviceAccountRef:
  1297. description: ServiceAccountSelector is a reference
  1298. to a ServiceAccount resource.
  1299. properties:
  1300. audiences:
  1301. description: |-
  1302. Audience specifies the `aud` claim for the service account token
  1303. Some providers automatically extend the audience field based on well-known annotations for workload
  1304. identity (e.g. IRSA or GCP Workload Identity)
  1305. items:
  1306. type: string
  1307. type: array
  1308. name:
  1309. description: The name of the ServiceAccount resource
  1310. being referred to.
  1311. maxLength: 253
  1312. minLength: 1
  1313. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1314. type: string
  1315. namespace:
  1316. description: |-
  1317. Namespace of the resource being referred to.
  1318. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1319. maxLength: 63
  1320. minLength: 1
  1321. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1322. type: string
  1323. required:
  1324. - name
  1325. type: object
  1326. type: object
  1327. secretRef:
  1328. description: |-
  1329. AWSAuthSecretRef holds secret references for AWS credentials
  1330. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  1331. properties:
  1332. accessKeyIDSecretRef:
  1333. description: The AccessKeyID is used for authentication
  1334. properties:
  1335. key:
  1336. description: |-
  1337. A key in the referenced Secret.
  1338. Some instances of this field may be defaulted, in others it may be required.
  1339. maxLength: 253
  1340. minLength: 1
  1341. pattern: ^[-._a-zA-Z0-9]+$
  1342. type: string
  1343. name:
  1344. description: The name of the Secret resource being
  1345. referred to.
  1346. maxLength: 253
  1347. minLength: 1
  1348. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1349. type: string
  1350. namespace:
  1351. description: |-
  1352. The namespace of the Secret resource being referred to.
  1353. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1354. maxLength: 63
  1355. minLength: 1
  1356. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1357. type: string
  1358. type: object
  1359. secretAccessKeySecretRef:
  1360. description: The SecretAccessKey is used for authentication
  1361. properties:
  1362. key:
  1363. description: |-
  1364. A key in the referenced Secret.
  1365. Some instances of this field may be defaulted, in others it may be required.
  1366. maxLength: 253
  1367. minLength: 1
  1368. pattern: ^[-._a-zA-Z0-9]+$
  1369. type: string
  1370. name:
  1371. description: The name of the Secret resource being
  1372. referred to.
  1373. maxLength: 253
  1374. minLength: 1
  1375. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1376. type: string
  1377. namespace:
  1378. description: |-
  1379. The namespace of the Secret resource being referred to.
  1380. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1381. maxLength: 63
  1382. minLength: 1
  1383. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1384. type: string
  1385. type: object
  1386. sessionTokenSecretRef:
  1387. description: |-
  1388. The SessionToken used for authentication
  1389. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  1390. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  1391. properties:
  1392. key:
  1393. description: |-
  1394. A key in the referenced Secret.
  1395. Some instances of this field may be defaulted, in others it may be required.
  1396. maxLength: 253
  1397. minLength: 1
  1398. pattern: ^[-._a-zA-Z0-9]+$
  1399. type: string
  1400. name:
  1401. description: The name of the Secret resource being
  1402. referred to.
  1403. maxLength: 253
  1404. minLength: 1
  1405. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1406. type: string
  1407. namespace:
  1408. description: |-
  1409. The namespace of the Secret resource being referred to.
  1410. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1411. maxLength: 63
  1412. minLength: 1
  1413. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1414. type: string
  1415. type: object
  1416. type: object
  1417. type: object
  1418. region:
  1419. description: Region specifies the region to operate in.
  1420. type: string
  1421. requestParameters:
  1422. description: RequestParameters contains parameters that can
  1423. be passed to the STS service.
  1424. properties:
  1425. serialNumber:
  1426. description: |-
  1427. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  1428. the GetSessionToken call.
  1429. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  1430. (such as arn:aws:iam::123456789012:mfa/user)
  1431. type: string
  1432. sessionDuration:
  1433. format: int32
  1434. type: integer
  1435. tokenCode:
  1436. description: TokenCode is the value provided by the MFA
  1437. device, if MFA is required.
  1438. type: string
  1439. type: object
  1440. role:
  1441. description: |-
  1442. You can assume a role before making calls to the
  1443. desired AWS service.
  1444. type: string
  1445. required:
  1446. - region
  1447. type: object
  1448. uuidSpec:
  1449. description: UUIDSpec controls the behavior of the uuid generator.
  1450. type: object
  1451. vaultDynamicSecretSpec:
  1452. description: VaultDynamicSecretSpec defines the desired spec of
  1453. VaultDynamicSecret.
  1454. properties:
  1455. allowEmptyResponse:
  1456. default: false
  1457. description: Do not fail if no secrets are found. Useful for
  1458. requests where no data is expected.
  1459. type: boolean
  1460. controller:
  1461. description: |-
  1462. Used to select the correct ESO controller (think: ingress.ingressClassName)
  1463. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  1464. type: string
  1465. getParameters:
  1466. additionalProperties:
  1467. items:
  1468. type: string
  1469. type: array
  1470. description: |-
  1471. GetParameters are query-string parameters passed to Vault on GET calls.
  1472. Each key may map to multiple values, matching HTTP query-string semantics.
  1473. Ignored for non-GET methods; use Parameters for write bodies.
  1474. type: object
  1475. method:
  1476. description: Vault API method to use (GET/POST/other)
  1477. type: string
  1478. parameters:
  1479. description: Parameters to pass to Vault write (for non-GET
  1480. methods)
  1481. x-kubernetes-preserve-unknown-fields: true
  1482. path:
  1483. description: Vault path to obtain the dynamic secret from
  1484. type: string
  1485. provider:
  1486. description: Vault provider common spec
  1487. properties:
  1488. auth:
  1489. description: Auth configures how secret-manager authenticates
  1490. with the Vault server.
  1491. properties:
  1492. appRole:
  1493. description: |-
  1494. AppRole authenticates with Vault using the App Role auth mechanism,
  1495. with the role and secret stored in a Kubernetes Secret resource.
  1496. properties:
  1497. path:
  1498. default: approle
  1499. description: |-
  1500. Path where the App Role authentication backend is mounted
  1501. in Vault, e.g: "approle"
  1502. type: string
  1503. roleId:
  1504. description: |-
  1505. RoleID configured in the App Role authentication backend when setting
  1506. up the authentication backend in Vault.
  1507. type: string
  1508. roleRef:
  1509. description: |-
  1510. Reference to a key in a Secret that contains the App Role ID used
  1511. to authenticate with Vault.
  1512. The `key` field must be specified and denotes which entry within the Secret
  1513. resource is used as the app role id.
  1514. properties:
  1515. key:
  1516. description: |-
  1517. A key in the referenced Secret.
  1518. Some instances of this field may be defaulted, in others it may be required.
  1519. maxLength: 253
  1520. minLength: 1
  1521. pattern: ^[-._a-zA-Z0-9]+$
  1522. type: string
  1523. name:
  1524. description: The name of the Secret resource
  1525. being referred to.
  1526. maxLength: 253
  1527. minLength: 1
  1528. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1529. type: string
  1530. namespace:
  1531. description: |-
  1532. The namespace of the Secret resource being referred to.
  1533. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1534. maxLength: 63
  1535. minLength: 1
  1536. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1537. type: string
  1538. type: object
  1539. secretRef:
  1540. description: |-
  1541. Reference to a key in a Secret that contains the App Role secret used
  1542. to authenticate with Vault.
  1543. The `key` field must be specified and denotes which entry within the Secret
  1544. resource is used as the app role secret.
  1545. properties:
  1546. key:
  1547. description: |-
  1548. A key in the referenced Secret.
  1549. Some instances of this field may be defaulted, in others it may be required.
  1550. maxLength: 253
  1551. minLength: 1
  1552. pattern: ^[-._a-zA-Z0-9]+$
  1553. type: string
  1554. name:
  1555. description: The name of the Secret resource
  1556. being referred to.
  1557. maxLength: 253
  1558. minLength: 1
  1559. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1560. type: string
  1561. namespace:
  1562. description: |-
  1563. The namespace of the Secret resource being referred to.
  1564. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1565. maxLength: 63
  1566. minLength: 1
  1567. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1568. type: string
  1569. type: object
  1570. required:
  1571. - path
  1572. - secretRef
  1573. type: object
  1574. cert:
  1575. description: |-
  1576. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  1577. Cert authentication method
  1578. properties:
  1579. clientCert:
  1580. description: |-
  1581. ClientCert is a certificate to authenticate using the Cert Vault
  1582. authentication method
  1583. properties:
  1584. key:
  1585. description: |-
  1586. A key in the referenced Secret.
  1587. Some instances of this field may be defaulted, in others it may be required.
  1588. maxLength: 253
  1589. minLength: 1
  1590. pattern: ^[-._a-zA-Z0-9]+$
  1591. type: string
  1592. name:
  1593. description: The name of the Secret resource
  1594. being referred to.
  1595. maxLength: 253
  1596. minLength: 1
  1597. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1598. type: string
  1599. namespace:
  1600. description: |-
  1601. The namespace of the Secret resource being referred to.
  1602. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1603. maxLength: 63
  1604. minLength: 1
  1605. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1606. type: string
  1607. type: object
  1608. path:
  1609. default: cert
  1610. description: |-
  1611. Path where the Certificate authentication backend is mounted
  1612. in Vault, e.g: "cert"
  1613. type: string
  1614. secretRef:
  1615. description: |-
  1616. SecretRef to a key in a Secret resource containing client private key to
  1617. authenticate with Vault using the Cert authentication method
  1618. properties:
  1619. key:
  1620. description: |-
  1621. A key in the referenced Secret.
  1622. Some instances of this field may be defaulted, in others it may be required.
  1623. maxLength: 253
  1624. minLength: 1
  1625. pattern: ^[-._a-zA-Z0-9]+$
  1626. type: string
  1627. name:
  1628. description: The name of the Secret resource
  1629. being referred to.
  1630. maxLength: 253
  1631. minLength: 1
  1632. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1633. type: string
  1634. namespace:
  1635. description: |-
  1636. The namespace of the Secret resource being referred to.
  1637. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1638. maxLength: 63
  1639. minLength: 1
  1640. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1641. type: string
  1642. type: object
  1643. vaultRole:
  1644. description: VaultRole specifies the Vault role
  1645. to use for TLS certificate authentication.
  1646. type: string
  1647. type: object
  1648. gcp:
  1649. description: |-
  1650. Gcp authenticates with Vault using Google Cloud Platform authentication method
  1651. GCP authentication method
  1652. properties:
  1653. location:
  1654. description: Location optionally defines a location/region
  1655. for the secret
  1656. type: string
  1657. path:
  1658. default: gcp
  1659. description: 'Path where the GCP auth method is
  1660. enabled in Vault, e.g: "gcp"'
  1661. type: string
  1662. projectID:
  1663. description: Project ID of the Google Cloud Platform
  1664. project
  1665. type: string
  1666. role:
  1667. description: Vault Role. In Vault, a role describes
  1668. an identity with a set of permissions, groups,
  1669. or policies you want to attach to a user of
  1670. the secrets engine.
  1671. type: string
  1672. secretRef:
  1673. description: Specify credentials in a Secret object
  1674. properties:
  1675. secretAccessKeySecretRef:
  1676. description: The SecretAccessKey is used for
  1677. authentication
  1678. properties:
  1679. key:
  1680. description: |-
  1681. A key in the referenced Secret.
  1682. Some instances of this field may be defaulted, in others it may be required.
  1683. maxLength: 253
  1684. minLength: 1
  1685. pattern: ^[-._a-zA-Z0-9]+$
  1686. type: string
  1687. name:
  1688. description: The name of the Secret resource
  1689. being referred to.
  1690. maxLength: 253
  1691. minLength: 1
  1692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1693. type: string
  1694. namespace:
  1695. description: |-
  1696. The namespace of the Secret resource being referred to.
  1697. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1698. maxLength: 63
  1699. minLength: 1
  1700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1701. type: string
  1702. type: object
  1703. type: object
  1704. serviceAccountRef:
  1705. description: ServiceAccountRef to a service account
  1706. for impersonation
  1707. properties:
  1708. audiences:
  1709. description: |-
  1710. Audience specifies the `aud` claim for the service account token
  1711. Some providers automatically extend the audience field based on well-known annotations for workload
  1712. identity (e.g. IRSA or GCP Workload Identity)
  1713. items:
  1714. type: string
  1715. type: array
  1716. name:
  1717. description: The name of the ServiceAccount
  1718. resource being referred to.
  1719. maxLength: 253
  1720. minLength: 1
  1721. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1722. type: string
  1723. namespace:
  1724. description: |-
  1725. Namespace of the resource being referred to.
  1726. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1727. maxLength: 63
  1728. minLength: 1
  1729. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1730. type: string
  1731. required:
  1732. - name
  1733. type: object
  1734. workloadIdentity:
  1735. description: Specify a service account with Workload
  1736. Identity
  1737. properties:
  1738. clusterLocation:
  1739. description: |-
  1740. ClusterLocation is the location of the cluster
  1741. If not specified, it fetches information from the metadata server
  1742. type: string
  1743. clusterName:
  1744. description: |-
  1745. ClusterName is the name of the cluster
  1746. If not specified, it fetches information from the metadata server
  1747. type: string
  1748. clusterProjectID:
  1749. description: |-
  1750. ClusterProjectID is the project ID of the cluster
  1751. If not specified, it fetches information from the metadata server
  1752. type: string
  1753. serviceAccountRef:
  1754. description: ServiceAccountSelector is a reference
  1755. to a ServiceAccount resource.
  1756. properties:
  1757. audiences:
  1758. description: |-
  1759. Audience specifies the `aud` claim for the service account token
  1760. Some providers automatically extend the audience field based on well-known annotations for workload
  1761. identity (e.g. IRSA or GCP Workload Identity)
  1762. items:
  1763. type: string
  1764. type: array
  1765. name:
  1766. description: The name of the ServiceAccount
  1767. resource being referred to.
  1768. maxLength: 253
  1769. minLength: 1
  1770. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1771. type: string
  1772. namespace:
  1773. description: |-
  1774. Namespace of the resource being referred to.
  1775. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1776. maxLength: 63
  1777. minLength: 1
  1778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1779. type: string
  1780. required:
  1781. - name
  1782. type: object
  1783. required:
  1784. - serviceAccountRef
  1785. type: object
  1786. required:
  1787. - role
  1788. type: object
  1789. iam:
  1790. description: |-
  1791. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  1792. AWS IAM authentication method
  1793. properties:
  1794. externalID:
  1795. description: AWS External ID set on assumed IAM
  1796. roles
  1797. type: string
  1798. jwt:
  1799. description: Specify a service account with IRSA
  1800. enabled
  1801. properties:
  1802. serviceAccountRef:
  1803. description: ServiceAccountSelector is a reference
  1804. to a ServiceAccount resource.
  1805. properties:
  1806. audiences:
  1807. description: |-
  1808. Audience specifies the `aud` claim for the service account token
  1809. Some providers automatically extend the audience field based on well-known annotations for workload
  1810. identity (e.g. IRSA or GCP Workload Identity)
  1811. items:
  1812. type: string
  1813. type: array
  1814. name:
  1815. description: The name of the ServiceAccount
  1816. resource being referred to.
  1817. maxLength: 253
  1818. minLength: 1
  1819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1820. type: string
  1821. namespace:
  1822. description: |-
  1823. Namespace of the resource being referred to.
  1824. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1825. maxLength: 63
  1826. minLength: 1
  1827. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1828. type: string
  1829. required:
  1830. - name
  1831. type: object
  1832. type: object
  1833. path:
  1834. description: 'Path where the AWS auth method is
  1835. enabled in Vault, e.g: "aws"'
  1836. type: string
  1837. region:
  1838. description: AWS region
  1839. type: string
  1840. role:
  1841. description: This is the AWS role to be assumed
  1842. before talking to vault
  1843. type: string
  1844. secretRef:
  1845. description: Specify credentials in a Secret object
  1846. properties:
  1847. accessKeyIDSecretRef:
  1848. description: The AccessKeyID is used for authentication
  1849. properties:
  1850. key:
  1851. description: |-
  1852. A key in the referenced Secret.
  1853. Some instances of this field may be defaulted, in others it may be required.
  1854. maxLength: 253
  1855. minLength: 1
  1856. pattern: ^[-._a-zA-Z0-9]+$
  1857. type: string
  1858. name:
  1859. description: The name of the Secret resource
  1860. being referred to.
  1861. maxLength: 253
  1862. minLength: 1
  1863. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1864. type: string
  1865. namespace:
  1866. description: |-
  1867. The namespace of the Secret resource being referred to.
  1868. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1869. maxLength: 63
  1870. minLength: 1
  1871. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1872. type: string
  1873. type: object
  1874. secretAccessKeySecretRef:
  1875. description: The SecretAccessKey is used for
  1876. authentication
  1877. properties:
  1878. key:
  1879. description: |-
  1880. A key in the referenced Secret.
  1881. Some instances of this field may be defaulted, in others it may be required.
  1882. maxLength: 253
  1883. minLength: 1
  1884. pattern: ^[-._a-zA-Z0-9]+$
  1885. type: string
  1886. name:
  1887. description: The name of the Secret resource
  1888. being referred to.
  1889. maxLength: 253
  1890. minLength: 1
  1891. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1892. type: string
  1893. namespace:
  1894. description: |-
  1895. The namespace of the Secret resource being referred to.
  1896. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1897. maxLength: 63
  1898. minLength: 1
  1899. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1900. type: string
  1901. type: object
  1902. sessionTokenSecretRef:
  1903. description: |-
  1904. The SessionToken used for authentication
  1905. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  1906. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  1907. properties:
  1908. key:
  1909. description: |-
  1910. A key in the referenced Secret.
  1911. Some instances of this field may be defaulted, in others it may be required.
  1912. maxLength: 253
  1913. minLength: 1
  1914. pattern: ^[-._a-zA-Z0-9]+$
  1915. type: string
  1916. name:
  1917. description: The name of the Secret resource
  1918. being referred to.
  1919. maxLength: 253
  1920. minLength: 1
  1921. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1922. type: string
  1923. namespace:
  1924. description: |-
  1925. The namespace of the Secret resource being referred to.
  1926. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1927. maxLength: 63
  1928. minLength: 1
  1929. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1930. type: string
  1931. type: object
  1932. type: object
  1933. vaultAwsIamServerID:
  1934. description: 'X-Vault-AWS-IAM-Server-ID is an
  1935. additional header used by Vault IAM auth method
  1936. to mitigate against different types of replay
  1937. attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  1938. type: string
  1939. vaultRole:
  1940. description: Vault Role. In vault, a role describes
  1941. an identity with a set of permissions, groups,
  1942. or policies you want to attach a user of the
  1943. secrets engine
  1944. type: string
  1945. required:
  1946. - vaultRole
  1947. type: object
  1948. jwt:
  1949. description: |-
  1950. Jwt authenticates with Vault by passing role and JWT token using the
  1951. JWT/OIDC authentication method
  1952. properties:
  1953. kubernetesServiceAccountToken:
  1954. description: |-
  1955. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  1956. a token for with the `TokenRequest` API.
  1957. properties:
  1958. audiences:
  1959. description: |-
  1960. Optional audiences field that will be used to request a temporary Kubernetes service
  1961. account token for the service account referenced by `serviceAccountRef`.
  1962. Defaults to a single audience `vault` it not specified.
  1963. Deprecated: use serviceAccountRef.Audiences instead
  1964. items:
  1965. type: string
  1966. type: array
  1967. expirationSeconds:
  1968. description: |-
  1969. Optional expiration time in seconds that will be used to request a temporary
  1970. Kubernetes service account token for the service account referenced by
  1971. `serviceAccountRef`.
  1972. Deprecated: this will be removed in the future.
  1973. Defaults to 10 minutes.
  1974. format: int64
  1975. type: integer
  1976. serviceAccountRef:
  1977. description: Service account field containing
  1978. the name of a kubernetes ServiceAccount.
  1979. properties:
  1980. audiences:
  1981. description: |-
  1982. Audience specifies the `aud` claim for the service account token
  1983. Some providers automatically extend the audience field based on well-known annotations for workload
  1984. identity (e.g. IRSA or GCP Workload Identity)
  1985. items:
  1986. type: string
  1987. type: array
  1988. name:
  1989. description: The name of the ServiceAccount
  1990. resource being referred to.
  1991. maxLength: 253
  1992. minLength: 1
  1993. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1994. type: string
  1995. namespace:
  1996. description: |-
  1997. Namespace of the resource being referred to.
  1998. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1999. maxLength: 63
  2000. minLength: 1
  2001. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2002. type: string
  2003. required:
  2004. - name
  2005. type: object
  2006. required:
  2007. - serviceAccountRef
  2008. type: object
  2009. path:
  2010. default: jwt
  2011. description: |-
  2012. Path where the JWT authentication backend is mounted
  2013. in Vault, e.g: "jwt"
  2014. type: string
  2015. role:
  2016. description: |-
  2017. Role is a JWT role to authenticate using the JWT/OIDC Vault
  2018. authentication method
  2019. type: string
  2020. secretRef:
  2021. description: |-
  2022. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  2023. authenticate with Vault using the JWT/OIDC authentication method.
  2024. properties:
  2025. key:
  2026. description: |-
  2027. A key in the referenced Secret.
  2028. Some instances of this field may be defaulted, in others it may be required.
  2029. maxLength: 253
  2030. minLength: 1
  2031. pattern: ^[-._a-zA-Z0-9]+$
  2032. type: string
  2033. name:
  2034. description: The name of the Secret resource
  2035. being referred to.
  2036. maxLength: 253
  2037. minLength: 1
  2038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2039. type: string
  2040. namespace:
  2041. description: |-
  2042. The namespace of the Secret resource being referred to.
  2043. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2044. maxLength: 63
  2045. minLength: 1
  2046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2047. type: string
  2048. type: object
  2049. required:
  2050. - path
  2051. type: object
  2052. kubernetes:
  2053. description: |-
  2054. Kubernetes authenticates with Vault by passing the ServiceAccount
  2055. token stored in the named Secret resource to the Vault server.
  2056. properties:
  2057. mountPath:
  2058. default: kubernetes
  2059. description: |-
  2060. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  2061. "kubernetes"
  2062. type: string
  2063. role:
  2064. description: |-
  2065. A required field containing the Vault Role to assume. A Role binds a
  2066. Kubernetes ServiceAccount with a set of Vault policies.
  2067. type: string
  2068. secretRef:
  2069. description: |-
  2070. Optional secret field containing a Kubernetes ServiceAccount JWT used
  2071. for authenticating with Vault. If a name is specified without a key,
  2072. `token` is the default. If one is not specified, the one bound to
  2073. the controller will be used.
  2074. properties:
  2075. key:
  2076. description: |-
  2077. A key in the referenced Secret.
  2078. Some instances of this field may be defaulted, in others it may be required.
  2079. maxLength: 253
  2080. minLength: 1
  2081. pattern: ^[-._a-zA-Z0-9]+$
  2082. type: string
  2083. name:
  2084. description: The name of the Secret resource
  2085. being referred to.
  2086. maxLength: 253
  2087. minLength: 1
  2088. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2089. type: string
  2090. namespace:
  2091. description: |-
  2092. The namespace of the Secret resource being referred to.
  2093. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2094. maxLength: 63
  2095. minLength: 1
  2096. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2097. type: string
  2098. type: object
  2099. serviceAccountRef:
  2100. description: |-
  2101. Optional service account field containing the name of a kubernetes ServiceAccount.
  2102. If the service account is specified, the service account secret token JWT will be used
  2103. for authenticating with Vault. If the service account selector is not supplied,
  2104. the secretRef will be used instead.
  2105. properties:
  2106. audiences:
  2107. description: |-
  2108. Audience specifies the `aud` claim for the service account token
  2109. Some providers automatically extend the audience field based on well-known annotations for workload
  2110. identity (e.g. IRSA or GCP Workload Identity)
  2111. items:
  2112. type: string
  2113. type: array
  2114. name:
  2115. description: The name of the ServiceAccount
  2116. resource being referred to.
  2117. maxLength: 253
  2118. minLength: 1
  2119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2120. type: string
  2121. namespace:
  2122. description: |-
  2123. Namespace of the resource being referred to.
  2124. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2125. maxLength: 63
  2126. minLength: 1
  2127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2128. type: string
  2129. required:
  2130. - name
  2131. type: object
  2132. required:
  2133. - mountPath
  2134. - role
  2135. type: object
  2136. ldap:
  2137. description: |-
  2138. Ldap authenticates with Vault by passing username/password pair using
  2139. the LDAP authentication method
  2140. properties:
  2141. path:
  2142. default: ldap
  2143. description: |-
  2144. Path where the LDAP authentication backend is mounted
  2145. in Vault, e.g: "ldap"
  2146. type: string
  2147. secretRef:
  2148. description: |-
  2149. SecretRef to a key in a Secret resource containing password for the LDAP
  2150. user used to authenticate with Vault using the LDAP authentication
  2151. method
  2152. properties:
  2153. key:
  2154. description: |-
  2155. A key in the referenced Secret.
  2156. Some instances of this field may be defaulted, in others it may be required.
  2157. maxLength: 253
  2158. minLength: 1
  2159. pattern: ^[-._a-zA-Z0-9]+$
  2160. type: string
  2161. name:
  2162. description: The name of the Secret resource
  2163. being referred to.
  2164. maxLength: 253
  2165. minLength: 1
  2166. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2167. type: string
  2168. namespace:
  2169. description: |-
  2170. The namespace of the Secret resource being referred to.
  2171. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2172. maxLength: 63
  2173. minLength: 1
  2174. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2175. type: string
  2176. type: object
  2177. username:
  2178. description: |-
  2179. Username is an LDAP username used to authenticate using the LDAP Vault
  2180. authentication method
  2181. type: string
  2182. required:
  2183. - path
  2184. - username
  2185. type: object
  2186. namespace:
  2187. description: |-
  2188. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  2189. Namespaces is a set of features within Vault Enterprise that allows
  2190. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  2191. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  2192. This will default to Vault.Namespace field if set, or empty otherwise
  2193. type: string
  2194. tokenSecretRef:
  2195. description: TokenSecretRef authenticates with Vault
  2196. by presenting a token.
  2197. properties:
  2198. key:
  2199. description: |-
  2200. A key in the referenced Secret.
  2201. Some instances of this field may be defaulted, in others it may be required.
  2202. maxLength: 253
  2203. minLength: 1
  2204. pattern: ^[-._a-zA-Z0-9]+$
  2205. type: string
  2206. name:
  2207. description: The name of the Secret resource being
  2208. referred to.
  2209. maxLength: 253
  2210. minLength: 1
  2211. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2212. type: string
  2213. namespace:
  2214. description: |-
  2215. The namespace of the Secret resource being referred to.
  2216. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2217. maxLength: 63
  2218. minLength: 1
  2219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2220. type: string
  2221. type: object
  2222. userPass:
  2223. description: UserPass authenticates with Vault by
  2224. passing username/password pair
  2225. properties:
  2226. path:
  2227. default: userpass
  2228. description: |-
  2229. Path where the UserPassword authentication backend is mounted
  2230. in Vault, e.g: "userpass"
  2231. type: string
  2232. secretRef:
  2233. description: |-
  2234. SecretRef to a key in a Secret resource containing password for the
  2235. user used to authenticate with Vault using the UserPass authentication
  2236. method
  2237. properties:
  2238. key:
  2239. description: |-
  2240. A key in the referenced Secret.
  2241. Some instances of this field may be defaulted, in others it may be required.
  2242. maxLength: 253
  2243. minLength: 1
  2244. pattern: ^[-._a-zA-Z0-9]+$
  2245. type: string
  2246. name:
  2247. description: The name of the Secret resource
  2248. being referred to.
  2249. maxLength: 253
  2250. minLength: 1
  2251. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2252. type: string
  2253. namespace:
  2254. description: |-
  2255. The namespace of the Secret resource being referred to.
  2256. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2257. maxLength: 63
  2258. minLength: 1
  2259. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2260. type: string
  2261. type: object
  2262. username:
  2263. description: |-
  2264. Username is a username used to authenticate using the UserPass Vault
  2265. authentication method
  2266. type: string
  2267. required:
  2268. - path
  2269. - username
  2270. type: object
  2271. type: object
  2272. caBundle:
  2273. description: |-
  2274. PEM encoded CA bundle used to validate Vault server certificate. Only used
  2275. if the Server URL is using HTTPS protocol. This parameter is ignored for
  2276. plain HTTP protocol connection. If not set the system root certificates
  2277. are used to validate the TLS connection.
  2278. format: byte
  2279. type: string
  2280. caProvider:
  2281. description: The provider for the CA bundle to use to
  2282. validate Vault server certificate.
  2283. properties:
  2284. key:
  2285. description: The key where the CA certificate can
  2286. be found in the Secret or ConfigMap.
  2287. maxLength: 253
  2288. minLength: 1
  2289. pattern: ^[-._a-zA-Z0-9]+$
  2290. type: string
  2291. name:
  2292. description: The name of the object located at the
  2293. provider type.
  2294. maxLength: 253
  2295. minLength: 1
  2296. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2297. type: string
  2298. namespace:
  2299. description: |-
  2300. The namespace the Provider type is in.
  2301. Can only be defined when used in a ClusterSecretStore.
  2302. maxLength: 63
  2303. minLength: 1
  2304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2305. type: string
  2306. type:
  2307. description: The type of provider to use such as "Secret",
  2308. or "ConfigMap".
  2309. enum:
  2310. - Secret
  2311. - ConfigMap
  2312. type: string
  2313. required:
  2314. - name
  2315. - type
  2316. type: object
  2317. checkAndSet:
  2318. description: |-
  2319. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  2320. Only applies to Vault KV v2 stores. When enabled, write operations must include
  2321. the current version of the secret to prevent unintentional overwrites.
  2322. properties:
  2323. required:
  2324. description: |-
  2325. Required when true, all write operations must include a check-and-set parameter.
  2326. This helps prevent unintentional overwrites of secrets.
  2327. type: boolean
  2328. type: object
  2329. forwardInconsistent:
  2330. description: |-
  2331. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  2332. leader instead of simply retrying within a loop. This can increase performance if
  2333. the option is enabled serverside.
  2334. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  2335. type: boolean
  2336. headers:
  2337. additionalProperties:
  2338. type: string
  2339. description: Headers to be added in Vault request
  2340. type: object
  2341. namespace:
  2342. description: |-
  2343. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  2344. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  2345. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  2346. type: string
  2347. path:
  2348. description: |-
  2349. Path is the mount path of the Vault KV backend endpoint, e.g:
  2350. "secret". The v2 KV secret engine version specific "/data" path suffix
  2351. for fetching secrets from Vault is optional and will be appended
  2352. if not present in specified path.
  2353. type: string
  2354. readYourWrites:
  2355. description: |-
  2356. ReadYourWrites ensures isolated read-after-write semantics by
  2357. providing discovered cluster replication states in each request.
  2358. More information about eventual consistency in Vault can be found here
  2359. https://www.vaultproject.io/docs/enterprise/consistency
  2360. type: boolean
  2361. server:
  2362. description: 'Server is the connection address for the
  2363. Vault server, e.g: "https://vault.example.com:8200".'
  2364. type: string
  2365. tls:
  2366. description: |-
  2367. The configuration used for client side related TLS communication, when the Vault server
  2368. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  2369. This parameter is ignored for plain HTTP protocol connection.
  2370. It's worth noting this configuration is different from the "TLS certificates auth method",
  2371. which is available under the `auth.cert` section.
  2372. properties:
  2373. certSecretRef:
  2374. description: |-
  2375. CertSecretRef is a certificate added to the transport layer
  2376. when communicating with the Vault server.
  2377. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  2378. properties:
  2379. key:
  2380. description: |-
  2381. A key in the referenced Secret.
  2382. Some instances of this field may be defaulted, in others it may be required.
  2383. maxLength: 253
  2384. minLength: 1
  2385. pattern: ^[-._a-zA-Z0-9]+$
  2386. type: string
  2387. name:
  2388. description: The name of the Secret resource being
  2389. referred to.
  2390. maxLength: 253
  2391. minLength: 1
  2392. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2393. type: string
  2394. namespace:
  2395. description: |-
  2396. The namespace of the Secret resource being referred to.
  2397. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2398. maxLength: 63
  2399. minLength: 1
  2400. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2401. type: string
  2402. type: object
  2403. keySecretRef:
  2404. description: |-
  2405. KeySecretRef to a key in a Secret resource containing client private key
  2406. added to the transport layer when communicating with the Vault server.
  2407. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  2408. properties:
  2409. key:
  2410. description: |-
  2411. A key in the referenced Secret.
  2412. Some instances of this field may be defaulted, in others it may be required.
  2413. maxLength: 253
  2414. minLength: 1
  2415. pattern: ^[-._a-zA-Z0-9]+$
  2416. type: string
  2417. name:
  2418. description: The name of the Secret resource being
  2419. referred to.
  2420. maxLength: 253
  2421. minLength: 1
  2422. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2423. type: string
  2424. namespace:
  2425. description: |-
  2426. The namespace of the Secret resource being referred to.
  2427. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2428. maxLength: 63
  2429. minLength: 1
  2430. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2431. type: string
  2432. type: object
  2433. type: object
  2434. version:
  2435. default: v2
  2436. description: |-
  2437. Version is the Vault KV secret engine version. This can be either "v1" or
  2438. "v2". Version defaults to "v2".
  2439. enum:
  2440. - v1
  2441. - v2
  2442. type: string
  2443. required:
  2444. - server
  2445. type: object
  2446. resultType:
  2447. default: Data
  2448. description: |-
  2449. Result type defines which data is returned from the generator.
  2450. By default, it is the "data" section of the Vault API response.
  2451. When using e.g. /auth/token/create the "data" section is empty but
  2452. the "auth" section contains the generated token.
  2453. Please refer to the vault docs regarding the result data structure.
  2454. Additionally, accessing the raw response is possibly by using "Raw" result type.
  2455. enum:
  2456. - Data
  2457. - Auth
  2458. - Raw
  2459. type: string
  2460. retrySettings:
  2461. description: Used to configure http retries if failed
  2462. properties:
  2463. maxRetries:
  2464. format: int32
  2465. type: integer
  2466. retryInterval:
  2467. type: string
  2468. type: object
  2469. required:
  2470. - path
  2471. - provider
  2472. type: object
  2473. webhookSpec:
  2474. description: WebhookSpec controls the behavior of the external
  2475. generator. Any body parameters should be passed to the server
  2476. through the parameters field.
  2477. properties:
  2478. auth:
  2479. description: Auth specifies a authorization protocol. Only
  2480. one protocol may be set.
  2481. maxProperties: 1
  2482. minProperties: 1
  2483. properties:
  2484. ntlm:
  2485. description: NTLMProtocol configures the store to use
  2486. NTLM for auth
  2487. properties:
  2488. passwordSecret:
  2489. description: |-
  2490. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2491. In some instances, `key` is a required field.
  2492. properties:
  2493. key:
  2494. description: |-
  2495. A key in the referenced Secret.
  2496. Some instances of this field may be defaulted, in others it may be required.
  2497. maxLength: 253
  2498. minLength: 1
  2499. pattern: ^[-._a-zA-Z0-9]+$
  2500. type: string
  2501. name:
  2502. description: The name of the Secret resource being
  2503. referred to.
  2504. maxLength: 253
  2505. minLength: 1
  2506. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2507. type: string
  2508. namespace:
  2509. description: |-
  2510. The namespace of the Secret resource being referred to.
  2511. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2512. maxLength: 63
  2513. minLength: 1
  2514. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2515. type: string
  2516. type: object
  2517. usernameSecret:
  2518. description: |-
  2519. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2520. In some instances, `key` is a required field.
  2521. properties:
  2522. key:
  2523. description: |-
  2524. A key in the referenced Secret.
  2525. Some instances of this field may be defaulted, in others it may be required.
  2526. maxLength: 253
  2527. minLength: 1
  2528. pattern: ^[-._a-zA-Z0-9]+$
  2529. type: string
  2530. name:
  2531. description: The name of the Secret resource being
  2532. referred to.
  2533. maxLength: 253
  2534. minLength: 1
  2535. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2536. type: string
  2537. namespace:
  2538. description: |-
  2539. The namespace of the Secret resource being referred to.
  2540. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2541. maxLength: 63
  2542. minLength: 1
  2543. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2544. type: string
  2545. type: object
  2546. required:
  2547. - passwordSecret
  2548. - usernameSecret
  2549. type: object
  2550. type: object
  2551. body:
  2552. description: Body
  2553. type: string
  2554. caBundle:
  2555. description: |-
  2556. PEM encoded CA bundle used to validate webhook server certificate. Only used
  2557. if the Server URL is using HTTPS protocol. This parameter is ignored for
  2558. plain HTTP protocol connection. If not set the system root certificates
  2559. are used to validate the TLS connection.
  2560. format: byte
  2561. type: string
  2562. caProvider:
  2563. description: The provider for the CA bundle to use to validate
  2564. webhook server certificate.
  2565. properties:
  2566. key:
  2567. description: The key where the CA certificate can be found
  2568. in the Secret or ConfigMap.
  2569. maxLength: 253
  2570. minLength: 1
  2571. pattern: ^[-._a-zA-Z0-9]+$
  2572. type: string
  2573. name:
  2574. description: The name of the object located at the provider
  2575. type.
  2576. maxLength: 253
  2577. minLength: 1
  2578. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2579. type: string
  2580. namespace:
  2581. description: The namespace the Provider type is in.
  2582. maxLength: 63
  2583. minLength: 1
  2584. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2585. type: string
  2586. type:
  2587. description: The type of provider to use such as "Secret",
  2588. or "ConfigMap".
  2589. enum:
  2590. - Secret
  2591. - ConfigMap
  2592. type: string
  2593. required:
  2594. - name
  2595. - type
  2596. type: object
  2597. headers:
  2598. additionalProperties:
  2599. type: string
  2600. description: Headers
  2601. type: object
  2602. method:
  2603. description: Webhook Method
  2604. type: string
  2605. result:
  2606. description: Result formatting
  2607. properties:
  2608. jsonPath:
  2609. description: Json path of return value
  2610. type: string
  2611. type: object
  2612. secrets:
  2613. description: |-
  2614. Secrets to fill in templates
  2615. These secrets will be passed to the templating function as key value pairs under the given name
  2616. items:
  2617. description: WebhookSecret defines a secret reference that
  2618. will be used in webhook templates.
  2619. properties:
  2620. name:
  2621. description: Name of this secret in templates
  2622. type: string
  2623. secretRef:
  2624. description: Secret ref to fill in credentials
  2625. properties:
  2626. key:
  2627. description: The key where the token is found.
  2628. maxLength: 253
  2629. minLength: 1
  2630. pattern: ^[-._a-zA-Z0-9]+$
  2631. type: string
  2632. name:
  2633. description: The name of the Secret resource being
  2634. referred to.
  2635. maxLength: 253
  2636. minLength: 1
  2637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2638. type: string
  2639. type: object
  2640. required:
  2641. - name
  2642. - secretRef
  2643. type: object
  2644. type: array
  2645. timeout:
  2646. description: Timeout
  2647. type: string
  2648. url:
  2649. description: Webhook url to call
  2650. type: string
  2651. required:
  2652. - result
  2653. - url
  2654. type: object
  2655. type: object
  2656. kind:
  2657. description: Kind the kind of this generator.
  2658. enum:
  2659. - ACRAccessToken
  2660. - BeyondtrustWorkloadCredentialsDynamicSecret
  2661. - CloudsmithAccessToken
  2662. - ECRAuthorizationToken
  2663. - Fake
  2664. - GCRAccessToken
  2665. - GithubAccessToken
  2666. - GitlabDeployToken
  2667. - QuayAccessToken
  2668. - Password
  2669. - SSHKey
  2670. - STSSessionToken
  2671. - UUID
  2672. - VaultDynamicSecret
  2673. - Webhook
  2674. - Grafana
  2675. - MFA
  2676. type: string
  2677. required:
  2678. - generator
  2679. - kind
  2680. type: object
  2681. type: object
  2682. served: true
  2683. storage: true
  2684. subresources:
  2685. status: {}