bundle.yaml 307 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488248924902491249224932494249524962497249824992500250125022503250425052506250725082509251025112512251325142515251625172518251925202521252225232524252525262527252825292530253125322533253425352536253725382539254025412542254325442545254625472548254925502551255225532554255525562557255825592560256125622563256425652566256725682569257025712572257325742575257625772578257925802581258225832584258525862587258825892590259125922593259425952596259725982599260026012602260326042605260626072608260926102611261226132614261526162617261826192620262126222623262426252626262726282629263026312632263326342635263626372638263926402641264226432644264526462647264826492650265126522653265426552656265726582659266026612662266326642665266626672668266926702671267226732674267526762677267826792680268126822683268426852686268726882689269026912692269326942695269626972698269927002701270227032704270527062707270827092710271127122713271427152716271727182719272027212722272327242725272627272728272927302731273227332734273527362737273827392740274127422743274427452746274727482749275027512752275327542755275627572758275927602761276227632764276527662767276827692770277127722773277427752776277727782779278027812782278327842785278627872788278927902791279227932794279527962797279827992800280128022803280428052806280728082809281028112812281328142815281628172818281928202821282228232824282528262827282828292830283128322833283428352836283728382839284028412842284328442845284628472848284928502851285228532854285528562857285828592860286128622863286428652866286728682869287028712872287328742875287628772878287928802881288228832884288528862887288828892890289128922893289428952896289728982899290029012902290329042905290629072908290929102911291229132914291529162917291829192920292129222923292429252926292729282929293029312932293329342935293629372938293929402941294229432944294529462947294829492950295129522953295429552956295729582959296029612962296329642965296629672968296929702971297229732974297529762977297829792980298129822983298429852986298729882989299029912992299329942995299629972998299930003001300230033004300530063007300830093010301130123013301430153016301730183019302030213022302330243025302630273028302930303031303230333034303530363037303830393040304130423043304430453046304730483049305030513052305330543055305630573058305930603061306230633064306530663067306830693070307130723073307430753076307730783079308030813082308330843085308630873088308930903091309230933094309530963097309830993100310131023103310431053106310731083109311031113112311331143115311631173118311931203121312231233124312531263127312831293130313131323133313431353136313731383139314031413142314331443145314631473148314931503151315231533154315531563157315831593160316131623163316431653166316731683169317031713172317331743175317631773178317931803181318231833184318531863187318831893190319131923193319431953196319731983199320032013202320332043205320632073208320932103211321232133214321532163217321832193220322132223223322432253226322732283229323032313232323332343235323632373238323932403241324232433244324532463247324832493250325132523253325432553256325732583259326032613262326332643265326632673268326932703271327232733274327532763277327832793280328132823283328432853286328732883289329032913292329332943295329632973298329933003301330233033304330533063307330833093310331133123313331433153316331733183319332033213322332333243325332633273328332933303331333233333334333533363337333833393340334133423343334433453346334733483349335033513352335333543355335633573358335933603361336233633364336533663367336833693370337133723373337433753376337733783379338033813382338333843385338633873388338933903391339233933394339533963397339833993400340134023403340434053406340734083409341034113412341334143415341634173418341934203421342234233424342534263427342834293430343134323433343434353436343734383439344034413442344334443445344634473448344934503451345234533454345534563457345834593460346134623463346434653466346734683469347034713472347334743475347634773478347934803481348234833484348534863487348834893490349134923493349434953496349734983499350035013502350335043505350635073508350935103511351235133514351535163517351835193520352135223523352435253526352735283529353035313532353335343535353635373538353935403541354235433544354535463547354835493550355135523553355435553556355735583559356035613562356335643565356635673568356935703571357235733574357535763577357835793580358135823583358435853586358735883589359035913592359335943595359635973598359936003601360236033604360536063607360836093610361136123613361436153616361736183619362036213622362336243625362636273628362936303631363236333634363536363637363836393640364136423643364436453646364736483649365036513652365336543655365636573658365936603661366236633664366536663667366836693670367136723673367436753676367736783679368036813682368336843685368636873688368936903691369236933694369536963697369836993700370137023703370437053706370737083709371037113712371337143715371637173718371937203721372237233724372537263727372837293730373137323733373437353736373737383739374037413742374337443745374637473748374937503751375237533754375537563757375837593760376137623763376437653766376737683769377037713772377337743775377637773778377937803781378237833784378537863787378837893790379137923793379437953796379737983799380038013802380338043805380638073808380938103811381238133814381538163817381838193820382138223823382438253826382738283829383038313832383338343835383638373838383938403841384238433844384538463847384838493850385138523853385438553856385738583859386038613862386338643865386638673868386938703871387238733874387538763877387838793880388138823883388438853886388738883889389038913892389338943895389638973898389939003901390239033904390539063907390839093910391139123913391439153916391739183919392039213922392339243925392639273928392939303931393239333934393539363937393839393940394139423943394439453946394739483949395039513952395339543955395639573958395939603961396239633964396539663967396839693970397139723973397439753976397739783979398039813982398339843985398639873988398939903991399239933994399539963997399839994000400140024003400440054006400740084009401040114012401340144015401640174018401940204021402240234024402540264027402840294030403140324033403440354036403740384039404040414042404340444045404640474048404940504051405240534054405540564057405840594060406140624063406440654066406740684069407040714072407340744075407640774078407940804081408240834084408540864087408840894090409140924093409440954096409740984099410041014102410341044105410641074108410941104111411241134114411541164117411841194120412141224123412441254126412741284129413041314132413341344135413641374138413941404141414241434144414541464147414841494150415141524153415441554156415741584159416041614162416341644165416641674168416941704171417241734174417541764177417841794180418141824183418441854186418741884189419041914192419341944195419641974198419942004201420242034204420542064207420842094210421142124213421442154216421742184219422042214222422342244225422642274228422942304231423242334234423542364237423842394240424142424243424442454246424742484249425042514252425342544255425642574258425942604261426242634264426542664267426842694270427142724273427442754276427742784279428042814282428342844285428642874288428942904291429242934294429542964297429842994300430143024303430443054306430743084309431043114312431343144315431643174318431943204321432243234324432543264327432843294330433143324333433443354336433743384339434043414342434343444345434643474348434943504351435243534354435543564357435843594360436143624363436443654366436743684369437043714372437343744375437643774378437943804381438243834384438543864387438843894390439143924393439443954396439743984399440044014402440344044405440644074408440944104411441244134414441544164417441844194420442144224423442444254426442744284429443044314432443344344435443644374438443944404441444244434444444544464447444844494450445144524453445444554456445744584459446044614462446344644465446644674468446944704471447244734474447544764477447844794480448144824483448444854486448744884489449044914492449344944495449644974498449945004501450245034504450545064507450845094510451145124513451445154516451745184519452045214522452345244525452645274528452945304531453245334534453545364537453845394540454145424543454445454546454745484549455045514552455345544555455645574558455945604561456245634564456545664567456845694570457145724573457445754576457745784579458045814582458345844585458645874588458945904591459245934594459545964597459845994600460146024603460446054606460746084609461046114612461346144615461646174618461946204621462246234624462546264627462846294630463146324633463446354636463746384639464046414642464346444645464646474648464946504651465246534654465546564657465846594660466146624663466446654666466746684669467046714672467346744675467646774678467946804681468246834684468546864687468846894690469146924693469446954696469746984699470047014702470347044705470647074708470947104711471247134714471547164717471847194720472147224723472447254726472747284729473047314732473347344735473647374738473947404741474247434744474547464747474847494750475147524753475447554756475747584759476047614762476347644765476647674768476947704771477247734774477547764777477847794780478147824783478447854786478747884789479047914792479347944795479647974798479948004801480248034804480548064807480848094810481148124813481448154816481748184819482048214822482348244825482648274828482948304831483248334834483548364837483848394840484148424843484448454846484748484849485048514852485348544855485648574858485948604861486248634864486548664867486848694870487148724873487448754876487748784879488048814882488348844885488648874888488948904891489248934894489548964897489848994900490149024903490449054906490749084909491049114912491349144915491649174918491949204921492249234924492549264927492849294930493149324933493449354936493749384939494049414942494349444945494649474948494949504951495249534954495549564957495849594960496149624963496449654966496749684969497049714972497349744975497649774978497949804981498249834984498549864987498849894990499149924993499449954996499749984999500050015002500350045005500650075008500950105011501250135014501550165017501850195020502150225023502450255026502750285029503050315032503350345035503650375038503950405041504250435044504550465047504850495050505150525053505450555056505750585059506050615062506350645065506650675068506950705071507250735074507550765077507850795080508150825083508450855086508750885089509050915092509350945095509650975098509951005101510251035104510551065107510851095110511151125113511451155116511751185119512051215122512351245125512651275128512951305131513251335134513551365137513851395140514151425143514451455146514751485149515051515152515351545155515651575158515951605161516251635164516551665167516851695170
  1. apiVersion: apiextensions.k8s.io/v1
  2. kind: CustomResourceDefinition
  3. metadata:
  4. annotations:
  5. controller-gen.kubebuilder.io/version: v0.8.0
  6. creationTimestamp: null
  7. name: clusterexternalsecrets.external-secrets.io
  8. spec:
  9. group: external-secrets.io
  10. names:
  11. categories:
  12. - externalsecrets
  13. kind: ClusterExternalSecret
  14. listKind: ClusterExternalSecretList
  15. plural: clusterexternalsecrets
  16. shortNames:
  17. - ces
  18. singular: clusterexternalsecret
  19. scope: Cluster
  20. versions:
  21. - name: v1beta1
  22. schema:
  23. openAPIV3Schema:
  24. description: ClusterExternalSecret is the Schema for the clusterexternalsecrets API.
  25. properties:
  26. apiVersion:
  27. description: 'APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
  28. type: string
  29. kind:
  30. description: 'Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
  31. type: string
  32. metadata:
  33. type: object
  34. spec:
  35. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  36. properties:
  37. externalSecretName:
  38. description: The name of the external secrets to be created defaults to the name of the ClusterExternalSecret
  39. type: string
  40. externalSecretSpec:
  41. description: The spec for the ExternalSecrets to be created
  42. properties:
  43. data:
  44. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  45. items:
  46. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  47. properties:
  48. remoteRef:
  49. description: ExternalSecretDataRemoteRef defines Provider data location.
  50. properties:
  51. conversionStrategy:
  52. default: Default
  53. description: Used to define a conversion Strategy
  54. type: string
  55. key:
  56. description: Key is the key used in the Provider, mandatory
  57. type: string
  58. property:
  59. description: Used to select a specific property of the Provider value (if a map), if supported
  60. type: string
  61. version:
  62. description: Used to select a specific version of the Provider value, if supported
  63. type: string
  64. required:
  65. - key
  66. type: object
  67. secretKey:
  68. type: string
  69. required:
  70. - remoteRef
  71. - secretKey
  72. type: object
  73. type: array
  74. dataFrom:
  75. description: DataFrom is used to fetch all properties from a specific Provider data If multiple entries are specified, the Secret keys are merged in the specified order
  76. items:
  77. maxProperties: 1
  78. minProperties: 1
  79. properties:
  80. extract:
  81. description: Used to extract multiple key/value pairs from one secret
  82. properties:
  83. conversionStrategy:
  84. default: Default
  85. description: Used to define a conversion Strategy
  86. type: string
  87. key:
  88. description: Key is the key used in the Provider, mandatory
  89. type: string
  90. property:
  91. description: Used to select a specific property of the Provider value (if a map), if supported
  92. type: string
  93. version:
  94. description: Used to select a specific version of the Provider value, if supported
  95. type: string
  96. required:
  97. - key
  98. type: object
  99. find:
  100. description: Used to find secrets based on tags or regular expressions
  101. properties:
  102. conversionStrategy:
  103. default: Default
  104. description: Used to define a conversion Strategy
  105. type: string
  106. name:
  107. description: Finds secrets based on the name.
  108. properties:
  109. regexp:
  110. description: Finds secrets base
  111. type: string
  112. type: object
  113. path:
  114. description: A root path to start the find operations.
  115. type: string
  116. tags:
  117. additionalProperties:
  118. type: string
  119. description: Find secrets based on tags.
  120. type: object
  121. type: object
  122. type: object
  123. type: array
  124. refreshInterval:
  125. default: 1h
  126. description: RefreshInterval is the amount of time before the values are read again from the SecretStore provider Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h" May be set to zero to fetch and create it once. Defaults to 1h.
  127. type: string
  128. secretStoreRef:
  129. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  130. properties:
  131. kind:
  132. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore) Defaults to `SecretStore`
  133. type: string
  134. name:
  135. description: Name of the SecretStore resource
  136. type: string
  137. required:
  138. - name
  139. type: object
  140. target:
  141. description: ExternalSecretTarget defines the Kubernetes Secret to be created There can be only one target per ExternalSecret.
  142. properties:
  143. creationPolicy:
  144. default: Owner
  145. description: CreationPolicy defines rules on how to create the resulting Secret Defaults to 'Owner'
  146. enum:
  147. - Owner
  148. - Orphan
  149. - Merge
  150. - None
  151. type: string
  152. deletionPolicy:
  153. default: Retain
  154. description: DeletionPolicy defines rules on how to delete the resulting Secret Defaults to 'Retain'
  155. enum:
  156. - Delete
  157. - Merge
  158. - Retain
  159. type: string
  160. immutable:
  161. description: Immutable defines if the final secret will be immutable
  162. type: boolean
  163. name:
  164. description: Name defines the name of the Secret resource to be managed This field is immutable Defaults to the .metadata.name of the ExternalSecret resource
  165. type: string
  166. template:
  167. description: Template defines a blueprint for the created Secret resource.
  168. properties:
  169. data:
  170. additionalProperties:
  171. type: string
  172. type: object
  173. engineVersion:
  174. default: v2
  175. type: string
  176. metadata:
  177. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  178. properties:
  179. annotations:
  180. additionalProperties:
  181. type: string
  182. type: object
  183. labels:
  184. additionalProperties:
  185. type: string
  186. type: object
  187. type: object
  188. templateFrom:
  189. items:
  190. maxProperties: 1
  191. minProperties: 1
  192. properties:
  193. configMap:
  194. properties:
  195. items:
  196. items:
  197. properties:
  198. key:
  199. type: string
  200. required:
  201. - key
  202. type: object
  203. type: array
  204. name:
  205. type: string
  206. required:
  207. - items
  208. - name
  209. type: object
  210. secret:
  211. properties:
  212. items:
  213. items:
  214. properties:
  215. key:
  216. type: string
  217. required:
  218. - key
  219. type: object
  220. type: array
  221. name:
  222. type: string
  223. required:
  224. - items
  225. - name
  226. type: object
  227. type: object
  228. type: array
  229. type:
  230. type: string
  231. type: object
  232. type: object
  233. required:
  234. - secretStoreRef
  235. type: object
  236. namespaceSelector:
  237. description: The labels to select by to find the Namespaces to create the ExternalSecrets in.
  238. properties:
  239. matchExpressions:
  240. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  241. items:
  242. description: A label selector requirement is a selector that contains values, a key, and an operator that relates the key and values.
  243. properties:
  244. key:
  245. description: key is the label key that the selector applies to.
  246. type: string
  247. operator:
  248. description: operator represents a key's relationship to a set of values. Valid operators are In, NotIn, Exists and DoesNotExist.
  249. type: string
  250. values:
  251. description: values is an array of string values. If the operator is In or NotIn, the values array must be non-empty. If the operator is Exists or DoesNotExist, the values array must be empty. This array is replaced during a strategic merge patch.
  252. items:
  253. type: string
  254. type: array
  255. required:
  256. - key
  257. - operator
  258. type: object
  259. type: array
  260. matchLabels:
  261. additionalProperties:
  262. type: string
  263. description: matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.
  264. type: object
  265. type: object
  266. refreshTime:
  267. description: The time in which the controller should reconcile it's objects and recheck namespaces for labels.
  268. type: string
  269. required:
  270. - externalSecretSpec
  271. - namespaceSelector
  272. type: object
  273. status:
  274. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  275. properties:
  276. conditions:
  277. items:
  278. properties:
  279. message:
  280. type: string
  281. status:
  282. type: string
  283. type:
  284. type: string
  285. required:
  286. - status
  287. - type
  288. type: object
  289. type: array
  290. failedNamespaces:
  291. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  292. items:
  293. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  294. properties:
  295. namespace:
  296. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  297. type: string
  298. reason:
  299. description: Reason is why the ExternalSecret failed to apply to the namespace
  300. type: string
  301. required:
  302. - namespace
  303. type: object
  304. type: array
  305. provisionedNamespaces:
  306. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  307. items:
  308. type: string
  309. type: array
  310. type: object
  311. type: object
  312. served: true
  313. storage: true
  314. subresources:
  315. status: {}
  316. conversion:
  317. strategy: Webhook
  318. webhook:
  319. conversionReviewVersions:
  320. - v1
  321. clientConfig:
  322. service:
  323. name: kubernetes
  324. namespace: default
  325. path: /convert
  326. status:
  327. acceptedNames:
  328. kind: ""
  329. plural: ""
  330. conditions: []
  331. storedVersions: []
  332. ---
  333. apiVersion: apiextensions.k8s.io/v1
  334. kind: CustomResourceDefinition
  335. metadata:
  336. annotations:
  337. controller-gen.kubebuilder.io/version: v0.8.0
  338. creationTimestamp: null
  339. name: clustersecretstores.external-secrets.io
  340. spec:
  341. group: external-secrets.io
  342. names:
  343. categories:
  344. - externalsecrets
  345. kind: ClusterSecretStore
  346. listKind: ClusterSecretStoreList
  347. plural: clustersecretstores
  348. shortNames:
  349. - css
  350. singular: clustersecretstore
  351. scope: Cluster
  352. versions:
  353. - additionalPrinterColumns:
  354. - jsonPath: .metadata.creationTimestamp
  355. name: AGE
  356. type: date
  357. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  358. name: Status
  359. type: string
  360. deprecated: true
  361. name: v1alpha1
  362. schema:
  363. openAPIV3Schema:
  364. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  365. properties:
  366. apiVersion:
  367. description: 'APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
  368. type: string
  369. kind:
  370. description: 'Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
  371. type: string
  372. metadata:
  373. type: object
  374. spec:
  375. description: SecretStoreSpec defines the desired state of SecretStore.
  376. properties:
  377. controller:
  378. description: 'Used to select the correct KES controller (think: ingress.ingressClassName) The KES controller is instantiated with a specific controller name and filters ES based on this property'
  379. type: string
  380. provider:
  381. description: Used to configure the provider. Only one provider may be set
  382. maxProperties: 1
  383. minProperties: 1
  384. properties:
  385. akeyless:
  386. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  387. properties:
  388. akeylessGWApiURL:
  389. description: Akeyless GW API Url from which the secrets to be fetched from.
  390. type: string
  391. authSecretRef:
  392. description: Auth configures how the operator authenticates with Akeyless.
  393. properties:
  394. secretRef:
  395. description: 'AkeylessAuthSecretRef AKEYLESS_ACCESS_TYPE_PARAM: AZURE_OBJ_ID OR GCP_AUDIENCE OR ACCESS_KEY OR KUB_CONFIG_NAME.'
  396. properties:
  397. accessID:
  398. description: The SecretAccessID is used for authentication
  399. properties:
  400. key:
  401. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  402. type: string
  403. name:
  404. description: The name of the Secret resource being referred to.
  405. type: string
  406. namespace:
  407. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  408. type: string
  409. type: object
  410. accessType:
  411. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  412. properties:
  413. key:
  414. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  415. type: string
  416. name:
  417. description: The name of the Secret resource being referred to.
  418. type: string
  419. namespace:
  420. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  421. type: string
  422. type: object
  423. accessTypeParam:
  424. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  425. properties:
  426. key:
  427. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  428. type: string
  429. name:
  430. description: The name of the Secret resource being referred to.
  431. type: string
  432. namespace:
  433. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  434. type: string
  435. type: object
  436. type: object
  437. required:
  438. - secretRef
  439. type: object
  440. required:
  441. - akeylessGWApiURL
  442. - authSecretRef
  443. type: object
  444. alibaba:
  445. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  446. properties:
  447. auth:
  448. description: AlibabaAuth contains a secretRef for credentials.
  449. properties:
  450. secretRef:
  451. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  452. properties:
  453. accessKeyIDSecretRef:
  454. description: The AccessKeyID is used for authentication
  455. properties:
  456. key:
  457. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  458. type: string
  459. name:
  460. description: The name of the Secret resource being referred to.
  461. type: string
  462. namespace:
  463. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  464. type: string
  465. type: object
  466. accessKeySecretSecretRef:
  467. description: The AccessKeySecret is used for authentication
  468. properties:
  469. key:
  470. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  471. type: string
  472. name:
  473. description: The name of the Secret resource being referred to.
  474. type: string
  475. namespace:
  476. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  477. type: string
  478. type: object
  479. required:
  480. - accessKeyIDSecretRef
  481. - accessKeySecretSecretRef
  482. type: object
  483. required:
  484. - secretRef
  485. type: object
  486. endpoint:
  487. type: string
  488. regionID:
  489. description: Alibaba Region to be used for the provider
  490. type: string
  491. required:
  492. - auth
  493. - regionID
  494. type: object
  495. aws:
  496. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  497. properties:
  498. auth:
  499. description: 'Auth defines the information necessary to authenticate against AWS if not set aws sdk will infer credentials from your environment see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials'
  500. properties:
  501. jwt:
  502. description: Authenticate against AWS using service account tokens.
  503. properties:
  504. serviceAccountRef:
  505. description: A reference to a ServiceAccount resource.
  506. properties:
  507. name:
  508. description: The name of the ServiceAccount resource being referred to.
  509. type: string
  510. namespace:
  511. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  512. type: string
  513. required:
  514. - name
  515. type: object
  516. type: object
  517. secretRef:
  518. description: AWSAuthSecretRef holds secret references for AWS credentials both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  519. properties:
  520. accessKeyIDSecretRef:
  521. description: The AccessKeyID is used for authentication
  522. properties:
  523. key:
  524. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  525. type: string
  526. name:
  527. description: The name of the Secret resource being referred to.
  528. type: string
  529. namespace:
  530. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  531. type: string
  532. type: object
  533. secretAccessKeySecretRef:
  534. description: The SecretAccessKey is used for authentication
  535. properties:
  536. key:
  537. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  538. type: string
  539. name:
  540. description: The name of the Secret resource being referred to.
  541. type: string
  542. namespace:
  543. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  544. type: string
  545. type: object
  546. type: object
  547. type: object
  548. region:
  549. description: AWS Region to be used for the provider
  550. type: string
  551. role:
  552. description: Role is a Role ARN which the SecretManager provider will assume
  553. type: string
  554. service:
  555. description: Service defines which service should be used to fetch the secrets
  556. enum:
  557. - SecretsManager
  558. - ParameterStore
  559. type: string
  560. required:
  561. - region
  562. - service
  563. type: object
  564. azurekv:
  565. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  566. properties:
  567. authSecretRef:
  568. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type.
  569. properties:
  570. clientId:
  571. description: The Azure clientId of the service principle used for authentication.
  572. properties:
  573. key:
  574. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  575. type: string
  576. name:
  577. description: The name of the Secret resource being referred to.
  578. type: string
  579. namespace:
  580. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  581. type: string
  582. type: object
  583. clientSecret:
  584. description: The Azure ClientSecret of the service principle used for authentication.
  585. properties:
  586. key:
  587. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  588. type: string
  589. name:
  590. description: The name of the Secret resource being referred to.
  591. type: string
  592. namespace:
  593. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  594. type: string
  595. type: object
  596. type: object
  597. authType:
  598. default: ServicePrincipal
  599. description: 'Auth type defines how to authenticate to the keyvault service. Valid values are: - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret) - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)'
  600. enum:
  601. - ServicePrincipal
  602. - ManagedIdentity
  603. - WorkloadIdentity
  604. type: string
  605. identityId:
  606. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  607. type: string
  608. serviceAccountRef:
  609. description: ServiceAccountRef specified the service account that should be used when authenticating with WorkloadIdentity.
  610. properties:
  611. name:
  612. description: The name of the ServiceAccount resource being referred to.
  613. type: string
  614. namespace:
  615. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  616. type: string
  617. required:
  618. - name
  619. type: object
  620. tenantId:
  621. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  622. type: string
  623. vaultUrl:
  624. description: Vault Url from which the secrets to be fetched from.
  625. type: string
  626. required:
  627. - vaultUrl
  628. type: object
  629. fake:
  630. description: Fake configures a store with static key/value pairs
  631. properties:
  632. data:
  633. items:
  634. properties:
  635. key:
  636. type: string
  637. value:
  638. type: string
  639. valueMap:
  640. additionalProperties:
  641. type: string
  642. type: object
  643. version:
  644. type: string
  645. required:
  646. - key
  647. type: object
  648. type: array
  649. required:
  650. - data
  651. type: object
  652. gcpsm:
  653. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  654. properties:
  655. auth:
  656. description: Auth defines the information necessary to authenticate against GCP
  657. properties:
  658. secretRef:
  659. properties:
  660. secretAccessKeySecretRef:
  661. description: The SecretAccessKey is used for authentication
  662. properties:
  663. key:
  664. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  665. type: string
  666. name:
  667. description: The name of the Secret resource being referred to.
  668. type: string
  669. namespace:
  670. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  671. type: string
  672. type: object
  673. type: object
  674. workloadIdentity:
  675. properties:
  676. clusterLocation:
  677. type: string
  678. clusterName:
  679. type: string
  680. clusterProjectID:
  681. type: string
  682. serviceAccountRef:
  683. description: A reference to a ServiceAccount resource.
  684. properties:
  685. name:
  686. description: The name of the ServiceAccount resource being referred to.
  687. type: string
  688. namespace:
  689. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  690. type: string
  691. required:
  692. - name
  693. type: object
  694. required:
  695. - clusterLocation
  696. - clusterName
  697. - serviceAccountRef
  698. type: object
  699. type: object
  700. projectID:
  701. description: ProjectID project where secret is located
  702. type: string
  703. type: object
  704. gitlab:
  705. description: Gitlab configures this store to sync secrets using Gitlab Variables provider
  706. properties:
  707. auth:
  708. description: Auth configures how secret-manager authenticates with a GitLab instance.
  709. properties:
  710. SecretRef:
  711. properties:
  712. accessToken:
  713. description: AccessToken is used for authentication.
  714. properties:
  715. key:
  716. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  717. type: string
  718. name:
  719. description: The name of the Secret resource being referred to.
  720. type: string
  721. namespace:
  722. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  723. type: string
  724. type: object
  725. type: object
  726. required:
  727. - SecretRef
  728. type: object
  729. projectID:
  730. description: ProjectID specifies a project where secrets are located.
  731. type: string
  732. url:
  733. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  734. type: string
  735. required:
  736. - auth
  737. type: object
  738. ibm:
  739. description: IBM configures this store to sync secrets using IBM Cloud provider
  740. properties:
  741. auth:
  742. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  743. properties:
  744. secretRef:
  745. properties:
  746. secretApiKeySecretRef:
  747. description: The SecretAccessKey is used for authentication
  748. properties:
  749. key:
  750. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  751. type: string
  752. name:
  753. description: The name of the Secret resource being referred to.
  754. type: string
  755. namespace:
  756. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  757. type: string
  758. type: object
  759. type: object
  760. required:
  761. - secretRef
  762. type: object
  763. serviceUrl:
  764. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  765. type: string
  766. required:
  767. - auth
  768. type: object
  769. kubernetes:
  770. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  771. properties:
  772. auth:
  773. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  774. maxProperties: 1
  775. minProperties: 1
  776. properties:
  777. cert:
  778. description: has both clientCert and clientKey as secretKeySelector
  779. properties:
  780. clientCert:
  781. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  782. properties:
  783. key:
  784. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  785. type: string
  786. name:
  787. description: The name of the Secret resource being referred to.
  788. type: string
  789. namespace:
  790. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  791. type: string
  792. type: object
  793. clientKey:
  794. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  795. properties:
  796. key:
  797. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  798. type: string
  799. name:
  800. description: The name of the Secret resource being referred to.
  801. type: string
  802. namespace:
  803. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  804. type: string
  805. type: object
  806. type: object
  807. serviceAccount:
  808. description: points to a service account that should be used for authentication
  809. properties:
  810. serviceAccount:
  811. description: A reference to a ServiceAccount resource.
  812. properties:
  813. name:
  814. description: The name of the ServiceAccount resource being referred to.
  815. type: string
  816. namespace:
  817. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  818. type: string
  819. required:
  820. - name
  821. type: object
  822. type: object
  823. token:
  824. description: use static token to authenticate with
  825. properties:
  826. bearerToken:
  827. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  828. properties:
  829. key:
  830. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  831. type: string
  832. name:
  833. description: The name of the Secret resource being referred to.
  834. type: string
  835. namespace:
  836. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  837. type: string
  838. type: object
  839. type: object
  840. type: object
  841. remoteNamespace:
  842. default: default
  843. description: Remote namespace to fetch the secrets from
  844. type: string
  845. server:
  846. description: configures the Kubernetes server Address.
  847. properties:
  848. caBundle:
  849. description: CABundle is a base64-encoded CA certificate
  850. format: byte
  851. type: string
  852. caProvider:
  853. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  854. properties:
  855. key:
  856. description: The key the value inside of the provider type to use, only used with "Secret" type
  857. type: string
  858. name:
  859. description: The name of the object located at the provider type.
  860. type: string
  861. namespace:
  862. description: The namespace the Provider type is in.
  863. type: string
  864. type:
  865. description: The type of provider to use such as "Secret", or "ConfigMap".
  866. enum:
  867. - Secret
  868. - ConfigMap
  869. type: string
  870. required:
  871. - name
  872. - type
  873. type: object
  874. url:
  875. default: kubernetes.default
  876. description: configures the Kubernetes server Address.
  877. type: string
  878. type: object
  879. required:
  880. - auth
  881. type: object
  882. oracle:
  883. description: Oracle configures this store to sync secrets using Oracle Vault provider
  884. properties:
  885. auth:
  886. description: Auth configures how secret-manager authenticates with the Oracle Vault. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  887. properties:
  888. secretRef:
  889. description: SecretRef to pass through sensitive information.
  890. properties:
  891. fingerprint:
  892. description: Fingerprint is the fingerprint of the API private key.
  893. properties:
  894. key:
  895. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  896. type: string
  897. name:
  898. description: The name of the Secret resource being referred to.
  899. type: string
  900. namespace:
  901. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  902. type: string
  903. type: object
  904. privatekey:
  905. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  906. properties:
  907. key:
  908. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  909. type: string
  910. name:
  911. description: The name of the Secret resource being referred to.
  912. type: string
  913. namespace:
  914. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  915. type: string
  916. type: object
  917. required:
  918. - fingerprint
  919. - privatekey
  920. type: object
  921. tenancy:
  922. description: Tenancy is the tenancy OCID where user is located.
  923. type: string
  924. user:
  925. description: User is an access OCID specific to the account.
  926. type: string
  927. required:
  928. - secretRef
  929. - tenancy
  930. - user
  931. type: object
  932. region:
  933. description: Region is the region where vault is located.
  934. type: string
  935. vault:
  936. description: Vault is the vault's OCID of the specific vault where secret is located.
  937. type: string
  938. required:
  939. - region
  940. - vault
  941. type: object
  942. vault:
  943. description: Vault configures this store to sync secrets using Hashi provider
  944. properties:
  945. auth:
  946. description: Auth configures how secret-manager authenticates with the Vault server.
  947. properties:
  948. appRole:
  949. description: AppRole authenticates with Vault using the App Role auth mechanism, with the role and secret stored in a Kubernetes Secret resource.
  950. properties:
  951. path:
  952. default: approle
  953. description: 'Path where the App Role authentication backend is mounted in Vault, e.g: "approle"'
  954. type: string
  955. roleId:
  956. description: RoleID configured in the App Role authentication backend when setting up the authentication backend in Vault.
  957. type: string
  958. secretRef:
  959. description: Reference to a key in a Secret that contains the App Role secret used to authenticate with Vault. The `key` field must be specified and denotes which entry within the Secret resource is used as the app role secret.
  960. properties:
  961. key:
  962. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  963. type: string
  964. name:
  965. description: The name of the Secret resource being referred to.
  966. type: string
  967. namespace:
  968. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  969. type: string
  970. type: object
  971. required:
  972. - path
  973. - roleId
  974. - secretRef
  975. type: object
  976. cert:
  977. description: Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate Cert authentication method
  978. properties:
  979. clientCert:
  980. description: ClientCert is a certificate to authenticate using the Cert Vault authentication method
  981. properties:
  982. key:
  983. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  984. type: string
  985. name:
  986. description: The name of the Secret resource being referred to.
  987. type: string
  988. namespace:
  989. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  990. type: string
  991. type: object
  992. secretRef:
  993. description: SecretRef to a key in a Secret resource containing client private key to authenticate with Vault using the Cert authentication method
  994. properties:
  995. key:
  996. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  997. type: string
  998. name:
  999. description: The name of the Secret resource being referred to.
  1000. type: string
  1001. namespace:
  1002. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1003. type: string
  1004. type: object
  1005. type: object
  1006. jwt:
  1007. description: Jwt authenticates with Vault by passing role and JWT token using the JWT/OIDC authentication method
  1008. properties:
  1009. kubernetesServiceAccountToken:
  1010. description: Optional ServiceAccountToken specifies the Kubernetes service account for which to request a token for with the `TokenRequest` API.
  1011. properties:
  1012. audiences:
  1013. description: Optional audiences field that will be used to request a temporary Kubernetes service account token for the service account referenced by `serviceAccountRef`. Defaults to a single audience `vault` it not specified.
  1014. items:
  1015. type: string
  1016. type: array
  1017. expirationSeconds:
  1018. description: Optional expiration time in seconds that will be used to request a temporary Kubernetes service account token for the service account referenced by `serviceAccountRef`. Defaults to 10 minutes.
  1019. format: int64
  1020. type: integer
  1021. serviceAccountRef:
  1022. description: Service account field containing the name of a kubernetes ServiceAccount.
  1023. properties:
  1024. name:
  1025. description: The name of the ServiceAccount resource being referred to.
  1026. type: string
  1027. namespace:
  1028. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1029. type: string
  1030. required:
  1031. - name
  1032. type: object
  1033. required:
  1034. - serviceAccountRef
  1035. type: object
  1036. path:
  1037. default: jwt
  1038. description: 'Path where the JWT authentication backend is mounted in Vault, e.g: "jwt"'
  1039. type: string
  1040. role:
  1041. description: Role is a JWT role to authenticate using the JWT/OIDC Vault authentication method
  1042. type: string
  1043. secretRef:
  1044. description: Optional SecretRef that refers to a key in a Secret resource containing JWT token to authenticate with Vault using the JWT/OIDC authentication method.
  1045. properties:
  1046. key:
  1047. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1048. type: string
  1049. name:
  1050. description: The name of the Secret resource being referred to.
  1051. type: string
  1052. namespace:
  1053. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1054. type: string
  1055. type: object
  1056. required:
  1057. - path
  1058. type: object
  1059. kubernetes:
  1060. description: Kubernetes authenticates with Vault by passing the ServiceAccount token stored in the named Secret resource to the Vault server.
  1061. properties:
  1062. mountPath:
  1063. default: kubernetes
  1064. description: 'Path where the Kubernetes authentication backend is mounted in Vault, e.g: "kubernetes"'
  1065. type: string
  1066. role:
  1067. description: A required field containing the Vault Role to assume. A Role binds a Kubernetes ServiceAccount with a set of Vault policies.
  1068. type: string
  1069. secretRef:
  1070. description: Optional secret field containing a Kubernetes ServiceAccount JWT used for authenticating with Vault. If a name is specified without a key, `token` is the default. If one is not specified, the one bound to the controller will be used.
  1071. properties:
  1072. key:
  1073. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1074. type: string
  1075. name:
  1076. description: The name of the Secret resource being referred to.
  1077. type: string
  1078. namespace:
  1079. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1080. type: string
  1081. type: object
  1082. serviceAccountRef:
  1083. description: Optional service account field containing the name of a kubernetes ServiceAccount. If the service account is specified, the service account secret token JWT will be used for authenticating with Vault. If the service account selector is not supplied, the secretRef will be used instead.
  1084. properties:
  1085. name:
  1086. description: The name of the ServiceAccount resource being referred to.
  1087. type: string
  1088. namespace:
  1089. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1090. type: string
  1091. required:
  1092. - name
  1093. type: object
  1094. required:
  1095. - mountPath
  1096. - role
  1097. type: object
  1098. ldap:
  1099. description: Ldap authenticates with Vault by passing username/password pair using the LDAP authentication method
  1100. properties:
  1101. path:
  1102. default: ldap
  1103. description: 'Path where the LDAP authentication backend is mounted in Vault, e.g: "ldap"'
  1104. type: string
  1105. secretRef:
  1106. description: SecretRef to a key in a Secret resource containing password for the LDAP user used to authenticate with Vault using the LDAP authentication method
  1107. properties:
  1108. key:
  1109. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1110. type: string
  1111. name:
  1112. description: The name of the Secret resource being referred to.
  1113. type: string
  1114. namespace:
  1115. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1116. type: string
  1117. type: object
  1118. username:
  1119. description: Username is a LDAP user name used to authenticate using the LDAP Vault authentication method
  1120. type: string
  1121. required:
  1122. - path
  1123. - username
  1124. type: object
  1125. tokenSecretRef:
  1126. description: TokenSecretRef authenticates with Vault by presenting a token.
  1127. properties:
  1128. key:
  1129. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1130. type: string
  1131. name:
  1132. description: The name of the Secret resource being referred to.
  1133. type: string
  1134. namespace:
  1135. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1136. type: string
  1137. type: object
  1138. type: object
  1139. caBundle:
  1140. description: PEM encoded CA bundle used to validate Vault server certificate. Only used if the Server URL is using HTTPS protocol. This parameter is ignored for plain HTTP protocol connection. If not set the system root certificates are used to validate the TLS connection.
  1141. format: byte
  1142. type: string
  1143. caProvider:
  1144. description: The provider for the CA bundle to use to validate Vault server certificate.
  1145. properties:
  1146. key:
  1147. description: The key the value inside of the provider type to use, only used with "Secret" type
  1148. type: string
  1149. name:
  1150. description: The name of the object located at the provider type.
  1151. type: string
  1152. namespace:
  1153. description: The namespace the Provider type is in.
  1154. type: string
  1155. type:
  1156. description: The type of provider to use such as "Secret", or "ConfigMap".
  1157. enum:
  1158. - Secret
  1159. - ConfigMap
  1160. type: string
  1161. required:
  1162. - name
  1163. - type
  1164. type: object
  1165. forwardInconsistent:
  1166. description: ForwardInconsistent tells Vault to forward read-after-write requests to the Vault leader instead of simply retrying within a loop. This can increase performance if the option is enabled serverside. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  1167. type: boolean
  1168. namespace:
  1169. description: 'Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows Vault environments to support Secure Multi-tenancy. e.g: "ns1". More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces'
  1170. type: string
  1171. path:
  1172. description: 'Path is the mount path of the Vault KV backend endpoint, e.g: "secret". The v2 KV secret engine version specific "/data" path suffix for fetching secrets from Vault is optional and will be appended if not present in specified path.'
  1173. type: string
  1174. readYourWrites:
  1175. description: ReadYourWrites ensures isolated read-after-write semantics by providing discovered cluster replication states in each request. More information about eventual consistency in Vault can be found here https://www.vaultproject.io/docs/enterprise/consistency
  1176. type: boolean
  1177. server:
  1178. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  1179. type: string
  1180. version:
  1181. default: v2
  1182. description: Version is the Vault KV secret engine version. This can be either "v1" or "v2". Version defaults to "v2".
  1183. enum:
  1184. - v1
  1185. - v2
  1186. type: string
  1187. required:
  1188. - auth
  1189. - server
  1190. type: object
  1191. webhook:
  1192. description: Webhook configures this store to sync secrets using a generic templated webhook
  1193. properties:
  1194. body:
  1195. description: Body
  1196. type: string
  1197. caBundle:
  1198. description: PEM encoded CA bundle used to validate webhook server certificate. Only used if the Server URL is using HTTPS protocol. This parameter is ignored for plain HTTP protocol connection. If not set the system root certificates are used to validate the TLS connection.
  1199. format: byte
  1200. type: string
  1201. caProvider:
  1202. description: The provider for the CA bundle to use to validate webhook server certificate.
  1203. properties:
  1204. key:
  1205. description: The key the value inside of the provider type to use, only used with "Secret" type
  1206. type: string
  1207. name:
  1208. description: The name of the object located at the provider type.
  1209. type: string
  1210. namespace:
  1211. description: The namespace the Provider type is in.
  1212. type: string
  1213. type:
  1214. description: The type of provider to use such as "Secret", or "ConfigMap".
  1215. enum:
  1216. - Secret
  1217. - ConfigMap
  1218. type: string
  1219. required:
  1220. - name
  1221. - type
  1222. type: object
  1223. headers:
  1224. additionalProperties:
  1225. type: string
  1226. description: Headers
  1227. type: object
  1228. method:
  1229. description: Webhook Method
  1230. type: string
  1231. result:
  1232. description: Result formatting
  1233. properties:
  1234. jsonPath:
  1235. description: Json path of return value
  1236. type: string
  1237. type: object
  1238. secrets:
  1239. description: Secrets to fill in templates These secrets will be passed to the templating function as key value pairs under the given name
  1240. items:
  1241. properties:
  1242. name:
  1243. description: Name of this secret in templates
  1244. type: string
  1245. secretRef:
  1246. description: Secret ref to fill in credentials
  1247. properties:
  1248. key:
  1249. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1250. type: string
  1251. name:
  1252. description: The name of the Secret resource being referred to.
  1253. type: string
  1254. namespace:
  1255. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1256. type: string
  1257. type: object
  1258. required:
  1259. - name
  1260. - secretRef
  1261. type: object
  1262. type: array
  1263. timeout:
  1264. description: Timeout
  1265. type: string
  1266. url:
  1267. description: Webhook url to call
  1268. type: string
  1269. required:
  1270. - result
  1271. - url
  1272. type: object
  1273. yandexlockbox:
  1274. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  1275. properties:
  1276. apiEndpoint:
  1277. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  1278. type: string
  1279. auth:
  1280. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  1281. properties:
  1282. authorizedKeySecretRef:
  1283. description: The authorized key used for authentication
  1284. properties:
  1285. key:
  1286. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1287. type: string
  1288. name:
  1289. description: The name of the Secret resource being referred to.
  1290. type: string
  1291. namespace:
  1292. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1293. type: string
  1294. type: object
  1295. type: object
  1296. caProvider:
  1297. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  1298. properties:
  1299. certSecretRef:
  1300. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  1301. properties:
  1302. key:
  1303. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1304. type: string
  1305. name:
  1306. description: The name of the Secret resource being referred to.
  1307. type: string
  1308. namespace:
  1309. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1310. type: string
  1311. type: object
  1312. type: object
  1313. required:
  1314. - auth
  1315. type: object
  1316. type: object
  1317. retrySettings:
  1318. description: Used to configure http retries if failed
  1319. properties:
  1320. maxRetries:
  1321. format: int32
  1322. type: integer
  1323. retryInterval:
  1324. type: string
  1325. type: object
  1326. required:
  1327. - provider
  1328. type: object
  1329. status:
  1330. description: SecretStoreStatus defines the observed state of the SecretStore.
  1331. properties:
  1332. conditions:
  1333. items:
  1334. properties:
  1335. lastTransitionTime:
  1336. format: date-time
  1337. type: string
  1338. message:
  1339. type: string
  1340. reason:
  1341. type: string
  1342. status:
  1343. type: string
  1344. type:
  1345. type: string
  1346. required:
  1347. - status
  1348. - type
  1349. type: object
  1350. type: array
  1351. type: object
  1352. type: object
  1353. served: true
  1354. storage: false
  1355. subresources:
  1356. status: {}
  1357. - additionalPrinterColumns:
  1358. - jsonPath: .metadata.creationTimestamp
  1359. name: AGE
  1360. type: date
  1361. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  1362. name: Status
  1363. type: string
  1364. - jsonPath: .status.capabilities
  1365. name: Capabilities
  1366. type: string
  1367. name: v1beta1
  1368. schema:
  1369. openAPIV3Schema:
  1370. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  1371. properties:
  1372. apiVersion:
  1373. description: 'APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
  1374. type: string
  1375. kind:
  1376. description: 'Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
  1377. type: string
  1378. metadata:
  1379. type: object
  1380. spec:
  1381. description: SecretStoreSpec defines the desired state of SecretStore.
  1382. properties:
  1383. controller:
  1384. description: 'Used to select the correct KES controller (think: ingress.ingressClassName) The KES controller is instantiated with a specific controller name and filters ES based on this property'
  1385. type: string
  1386. provider:
  1387. description: Used to configure the provider. Only one provider may be set
  1388. maxProperties: 1
  1389. minProperties: 1
  1390. properties:
  1391. akeyless:
  1392. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  1393. properties:
  1394. akeylessGWApiURL:
  1395. description: Akeyless GW API Url from which the secrets to be fetched from.
  1396. type: string
  1397. authSecretRef:
  1398. description: Auth configures how the operator authenticates with Akeyless.
  1399. properties:
  1400. secretRef:
  1401. description: 'AkeylessAuthSecretRef AKEYLESS_ACCESS_TYPE_PARAM: AZURE_OBJ_ID OR GCP_AUDIENCE OR ACCESS_KEY OR KUB_CONFIG_NAME.'
  1402. properties:
  1403. accessID:
  1404. description: The SecretAccessID is used for authentication
  1405. properties:
  1406. key:
  1407. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1408. type: string
  1409. name:
  1410. description: The name of the Secret resource being referred to.
  1411. type: string
  1412. namespace:
  1413. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1414. type: string
  1415. type: object
  1416. accessType:
  1417. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  1418. properties:
  1419. key:
  1420. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1421. type: string
  1422. name:
  1423. description: The name of the Secret resource being referred to.
  1424. type: string
  1425. namespace:
  1426. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1427. type: string
  1428. type: object
  1429. accessTypeParam:
  1430. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  1431. properties:
  1432. key:
  1433. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1434. type: string
  1435. name:
  1436. description: The name of the Secret resource being referred to.
  1437. type: string
  1438. namespace:
  1439. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1440. type: string
  1441. type: object
  1442. type: object
  1443. required:
  1444. - secretRef
  1445. type: object
  1446. required:
  1447. - akeylessGWApiURL
  1448. - authSecretRef
  1449. type: object
  1450. alibaba:
  1451. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  1452. properties:
  1453. auth:
  1454. description: AlibabaAuth contains a secretRef for credentials.
  1455. properties:
  1456. secretRef:
  1457. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  1458. properties:
  1459. accessKeyIDSecretRef:
  1460. description: The AccessKeyID is used for authentication
  1461. properties:
  1462. key:
  1463. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1464. type: string
  1465. name:
  1466. description: The name of the Secret resource being referred to.
  1467. type: string
  1468. namespace:
  1469. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1470. type: string
  1471. type: object
  1472. accessKeySecretSecretRef:
  1473. description: The AccessKeySecret is used for authentication
  1474. properties:
  1475. key:
  1476. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1477. type: string
  1478. name:
  1479. description: The name of the Secret resource being referred to.
  1480. type: string
  1481. namespace:
  1482. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1483. type: string
  1484. type: object
  1485. required:
  1486. - accessKeyIDSecretRef
  1487. - accessKeySecretSecretRef
  1488. type: object
  1489. required:
  1490. - secretRef
  1491. type: object
  1492. endpoint:
  1493. type: string
  1494. regionID:
  1495. description: Alibaba Region to be used for the provider
  1496. type: string
  1497. required:
  1498. - auth
  1499. - regionID
  1500. type: object
  1501. aws:
  1502. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  1503. properties:
  1504. auth:
  1505. description: 'Auth defines the information necessary to authenticate against AWS if not set aws sdk will infer credentials from your environment see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials'
  1506. properties:
  1507. jwt:
  1508. description: Authenticate against AWS using service account tokens.
  1509. properties:
  1510. serviceAccountRef:
  1511. description: A reference to a ServiceAccount resource.
  1512. properties:
  1513. name:
  1514. description: The name of the ServiceAccount resource being referred to.
  1515. type: string
  1516. namespace:
  1517. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1518. type: string
  1519. required:
  1520. - name
  1521. type: object
  1522. type: object
  1523. secretRef:
  1524. description: AWSAuthSecretRef holds secret references for AWS credentials both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  1525. properties:
  1526. accessKeyIDSecretRef:
  1527. description: The AccessKeyID is used for authentication
  1528. properties:
  1529. key:
  1530. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1531. type: string
  1532. name:
  1533. description: The name of the Secret resource being referred to.
  1534. type: string
  1535. namespace:
  1536. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1537. type: string
  1538. type: object
  1539. secretAccessKeySecretRef:
  1540. description: The SecretAccessKey is used for authentication
  1541. properties:
  1542. key:
  1543. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1544. type: string
  1545. name:
  1546. description: The name of the Secret resource being referred to.
  1547. type: string
  1548. namespace:
  1549. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1550. type: string
  1551. type: object
  1552. type: object
  1553. type: object
  1554. region:
  1555. description: AWS Region to be used for the provider
  1556. type: string
  1557. role:
  1558. description: Role is a Role ARN which the SecretManager provider will assume
  1559. type: string
  1560. service:
  1561. description: Service defines which service should be used to fetch the secrets
  1562. enum:
  1563. - SecretsManager
  1564. - ParameterStore
  1565. type: string
  1566. required:
  1567. - region
  1568. - service
  1569. type: object
  1570. azurekv:
  1571. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  1572. properties:
  1573. authSecretRef:
  1574. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type.
  1575. properties:
  1576. clientId:
  1577. description: The Azure clientId of the service principle used for authentication.
  1578. properties:
  1579. key:
  1580. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1581. type: string
  1582. name:
  1583. description: The name of the Secret resource being referred to.
  1584. type: string
  1585. namespace:
  1586. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1587. type: string
  1588. type: object
  1589. clientSecret:
  1590. description: The Azure ClientSecret of the service principle used for authentication.
  1591. properties:
  1592. key:
  1593. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1594. type: string
  1595. name:
  1596. description: The name of the Secret resource being referred to.
  1597. type: string
  1598. namespace:
  1599. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1600. type: string
  1601. type: object
  1602. type: object
  1603. authType:
  1604. default: ServicePrincipal
  1605. description: 'Auth type defines how to authenticate to the keyvault service. Valid values are: - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret) - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)'
  1606. enum:
  1607. - ServicePrincipal
  1608. - ManagedIdentity
  1609. - WorkloadIdentity
  1610. type: string
  1611. identityId:
  1612. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  1613. type: string
  1614. serviceAccountRef:
  1615. description: ServiceAccountRef specified the service account that should be used when authenticating with WorkloadIdentity.
  1616. properties:
  1617. name:
  1618. description: The name of the ServiceAccount resource being referred to.
  1619. type: string
  1620. namespace:
  1621. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1622. type: string
  1623. required:
  1624. - name
  1625. type: object
  1626. tenantId:
  1627. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  1628. type: string
  1629. vaultUrl:
  1630. description: Vault Url from which the secrets to be fetched from.
  1631. type: string
  1632. required:
  1633. - vaultUrl
  1634. type: object
  1635. fake:
  1636. description: Fake configures a store with static key/value pairs
  1637. properties:
  1638. data:
  1639. items:
  1640. properties:
  1641. key:
  1642. type: string
  1643. value:
  1644. type: string
  1645. valueMap:
  1646. additionalProperties:
  1647. type: string
  1648. type: object
  1649. version:
  1650. type: string
  1651. required:
  1652. - key
  1653. type: object
  1654. type: array
  1655. required:
  1656. - data
  1657. type: object
  1658. gcpsm:
  1659. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  1660. properties:
  1661. auth:
  1662. description: Auth defines the information necessary to authenticate against GCP
  1663. properties:
  1664. secretRef:
  1665. properties:
  1666. secretAccessKeySecretRef:
  1667. description: The SecretAccessKey is used for authentication
  1668. properties:
  1669. key:
  1670. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1671. type: string
  1672. name:
  1673. description: The name of the Secret resource being referred to.
  1674. type: string
  1675. namespace:
  1676. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1677. type: string
  1678. type: object
  1679. type: object
  1680. workloadIdentity:
  1681. properties:
  1682. clusterLocation:
  1683. type: string
  1684. clusterName:
  1685. type: string
  1686. clusterProjectID:
  1687. type: string
  1688. serviceAccountRef:
  1689. description: A reference to a ServiceAccount resource.
  1690. properties:
  1691. name:
  1692. description: The name of the ServiceAccount resource being referred to.
  1693. type: string
  1694. namespace:
  1695. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1696. type: string
  1697. required:
  1698. - name
  1699. type: object
  1700. required:
  1701. - clusterLocation
  1702. - clusterName
  1703. - serviceAccountRef
  1704. type: object
  1705. type: object
  1706. projectID:
  1707. description: ProjectID project where secret is located
  1708. type: string
  1709. type: object
  1710. gitlab:
  1711. description: Gitlab configures this store to sync secrets using Gitlab Variables provider
  1712. properties:
  1713. auth:
  1714. description: Auth configures how secret-manager authenticates with a GitLab instance.
  1715. properties:
  1716. SecretRef:
  1717. properties:
  1718. accessToken:
  1719. description: AccessToken is used for authentication.
  1720. properties:
  1721. key:
  1722. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1723. type: string
  1724. name:
  1725. description: The name of the Secret resource being referred to.
  1726. type: string
  1727. namespace:
  1728. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1729. type: string
  1730. type: object
  1731. type: object
  1732. required:
  1733. - SecretRef
  1734. type: object
  1735. projectID:
  1736. description: ProjectID specifies a project where secrets are located.
  1737. type: string
  1738. url:
  1739. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  1740. type: string
  1741. required:
  1742. - auth
  1743. type: object
  1744. ibm:
  1745. description: IBM configures this store to sync secrets using IBM Cloud provider
  1746. properties:
  1747. auth:
  1748. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  1749. properties:
  1750. secretRef:
  1751. properties:
  1752. secretApiKeySecretRef:
  1753. description: The SecretAccessKey is used for authentication
  1754. properties:
  1755. key:
  1756. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1757. type: string
  1758. name:
  1759. description: The name of the Secret resource being referred to.
  1760. type: string
  1761. namespace:
  1762. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1763. type: string
  1764. type: object
  1765. type: object
  1766. required:
  1767. - secretRef
  1768. type: object
  1769. serviceUrl:
  1770. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  1771. type: string
  1772. required:
  1773. - auth
  1774. type: object
  1775. kubernetes:
  1776. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  1777. properties:
  1778. auth:
  1779. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  1780. maxProperties: 1
  1781. minProperties: 1
  1782. properties:
  1783. cert:
  1784. description: has both clientCert and clientKey as secretKeySelector
  1785. properties:
  1786. clientCert:
  1787. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  1788. properties:
  1789. key:
  1790. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1791. type: string
  1792. name:
  1793. description: The name of the Secret resource being referred to.
  1794. type: string
  1795. namespace:
  1796. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1797. type: string
  1798. type: object
  1799. clientKey:
  1800. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  1801. properties:
  1802. key:
  1803. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1804. type: string
  1805. name:
  1806. description: The name of the Secret resource being referred to.
  1807. type: string
  1808. namespace:
  1809. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1810. type: string
  1811. type: object
  1812. type: object
  1813. serviceAccount:
  1814. description: points to a service account that should be used for authentication
  1815. properties:
  1816. serviceAccount:
  1817. description: A reference to a ServiceAccount resource.
  1818. properties:
  1819. name:
  1820. description: The name of the ServiceAccount resource being referred to.
  1821. type: string
  1822. namespace:
  1823. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1824. type: string
  1825. required:
  1826. - name
  1827. type: object
  1828. type: object
  1829. token:
  1830. description: use static token to authenticate with
  1831. properties:
  1832. bearerToken:
  1833. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  1834. properties:
  1835. key:
  1836. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1837. type: string
  1838. name:
  1839. description: The name of the Secret resource being referred to.
  1840. type: string
  1841. namespace:
  1842. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1843. type: string
  1844. type: object
  1845. type: object
  1846. type: object
  1847. remoteNamespace:
  1848. default: default
  1849. description: Remote namespace to fetch the secrets from
  1850. type: string
  1851. server:
  1852. description: configures the Kubernetes server Address.
  1853. properties:
  1854. caBundle:
  1855. description: CABundle is a base64-encoded CA certificate
  1856. format: byte
  1857. type: string
  1858. caProvider:
  1859. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  1860. properties:
  1861. key:
  1862. description: The key the value inside of the provider type to use, only used with "Secret" type
  1863. type: string
  1864. name:
  1865. description: The name of the object located at the provider type.
  1866. type: string
  1867. namespace:
  1868. description: The namespace the Provider type is in.
  1869. type: string
  1870. type:
  1871. description: The type of provider to use such as "Secret", or "ConfigMap".
  1872. enum:
  1873. - Secret
  1874. - ConfigMap
  1875. type: string
  1876. required:
  1877. - name
  1878. - type
  1879. type: object
  1880. url:
  1881. default: kubernetes.default
  1882. description: configures the Kubernetes server Address.
  1883. type: string
  1884. type: object
  1885. required:
  1886. - auth
  1887. type: object
  1888. oracle:
  1889. description: Oracle configures this store to sync secrets using Oracle Vault provider
  1890. properties:
  1891. auth:
  1892. description: Auth configures how secret-manager authenticates with the Oracle Vault. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  1893. properties:
  1894. secretRef:
  1895. description: SecretRef to pass through sensitive information.
  1896. properties:
  1897. fingerprint:
  1898. description: Fingerprint is the fingerprint of the API private key.
  1899. properties:
  1900. key:
  1901. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1902. type: string
  1903. name:
  1904. description: The name of the Secret resource being referred to.
  1905. type: string
  1906. namespace:
  1907. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1908. type: string
  1909. type: object
  1910. privatekey:
  1911. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  1912. properties:
  1913. key:
  1914. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1915. type: string
  1916. name:
  1917. description: The name of the Secret resource being referred to.
  1918. type: string
  1919. namespace:
  1920. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1921. type: string
  1922. type: object
  1923. required:
  1924. - fingerprint
  1925. - privatekey
  1926. type: object
  1927. tenancy:
  1928. description: Tenancy is the tenancy OCID where user is located.
  1929. type: string
  1930. user:
  1931. description: User is an access OCID specific to the account.
  1932. type: string
  1933. required:
  1934. - secretRef
  1935. - tenancy
  1936. - user
  1937. type: object
  1938. region:
  1939. description: Region is the region where vault is located.
  1940. type: string
  1941. vault:
  1942. description: Vault is the vault's OCID of the specific vault where secret is located.
  1943. type: string
  1944. required:
  1945. - region
  1946. - vault
  1947. type: object
  1948. senhasegura:
  1949. description: Senhasegura configures this store to sync secrets using senhasegura provider
  1950. properties:
  1951. auth:
  1952. description: Auth defines parameters to authenticate in senhasegura
  1953. properties:
  1954. clientId:
  1955. type: string
  1956. clientSecretSecretRef:
  1957. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  1958. properties:
  1959. key:
  1960. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1961. type: string
  1962. name:
  1963. description: The name of the Secret resource being referred to.
  1964. type: string
  1965. namespace:
  1966. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1967. type: string
  1968. type: object
  1969. required:
  1970. - clientId
  1971. - clientSecretSecretRef
  1972. type: object
  1973. ignoreSslCertificate:
  1974. default: false
  1975. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  1976. type: boolean
  1977. module:
  1978. description: Module defines which senhasegura module should be used to get secrets
  1979. type: string
  1980. url:
  1981. description: URL of senhasegura
  1982. type: string
  1983. required:
  1984. - auth
  1985. - module
  1986. - url
  1987. type: object
  1988. vault:
  1989. description: Vault configures this store to sync secrets using Hashi provider
  1990. properties:
  1991. auth:
  1992. description: Auth configures how secret-manager authenticates with the Vault server.
  1993. properties:
  1994. appRole:
  1995. description: AppRole authenticates with Vault using the App Role auth mechanism, with the role and secret stored in a Kubernetes Secret resource.
  1996. properties:
  1997. path:
  1998. default: approle
  1999. description: 'Path where the App Role authentication backend is mounted in Vault, e.g: "approle"'
  2000. type: string
  2001. roleId:
  2002. description: RoleID configured in the App Role authentication backend when setting up the authentication backend in Vault.
  2003. type: string
  2004. secretRef:
  2005. description: Reference to a key in a Secret that contains the App Role secret used to authenticate with Vault. The `key` field must be specified and denotes which entry within the Secret resource is used as the app role secret.
  2006. properties:
  2007. key:
  2008. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  2009. type: string
  2010. name:
  2011. description: The name of the Secret resource being referred to.
  2012. type: string
  2013. namespace:
  2014. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2015. type: string
  2016. type: object
  2017. required:
  2018. - path
  2019. - roleId
  2020. - secretRef
  2021. type: object
  2022. cert:
  2023. description: Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate Cert authentication method
  2024. properties:
  2025. clientCert:
  2026. description: ClientCert is a certificate to authenticate using the Cert Vault authentication method
  2027. properties:
  2028. key:
  2029. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  2030. type: string
  2031. name:
  2032. description: The name of the Secret resource being referred to.
  2033. type: string
  2034. namespace:
  2035. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2036. type: string
  2037. type: object
  2038. secretRef:
  2039. description: SecretRef to a key in a Secret resource containing client private key to authenticate with Vault using the Cert authentication method
  2040. properties:
  2041. key:
  2042. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  2043. type: string
  2044. name:
  2045. description: The name of the Secret resource being referred to.
  2046. type: string
  2047. namespace:
  2048. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2049. type: string
  2050. type: object
  2051. type: object
  2052. jwt:
  2053. description: Jwt authenticates with Vault by passing role and JWT token using the JWT/OIDC authentication method
  2054. properties:
  2055. kubernetesServiceAccountToken:
  2056. description: Optional ServiceAccountToken specifies the Kubernetes service account for which to request a token for with the `TokenRequest` API.
  2057. properties:
  2058. audiences:
  2059. description: Optional audiences field that will be used to request a temporary Kubernetes service account token for the service account referenced by `serviceAccountRef`. Defaults to a single audience `vault` it not specified.
  2060. items:
  2061. type: string
  2062. type: array
  2063. expirationSeconds:
  2064. description: Optional expiration time in seconds that will be used to request a temporary Kubernetes service account token for the service account referenced by `serviceAccountRef`. Defaults to 10 minutes.
  2065. format: int64
  2066. type: integer
  2067. serviceAccountRef:
  2068. description: Service account field containing the name of a kubernetes ServiceAccount.
  2069. properties:
  2070. name:
  2071. description: The name of the ServiceAccount resource being referred to.
  2072. type: string
  2073. namespace:
  2074. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2075. type: string
  2076. required:
  2077. - name
  2078. type: object
  2079. required:
  2080. - serviceAccountRef
  2081. type: object
  2082. path:
  2083. default: jwt
  2084. description: 'Path where the JWT authentication backend is mounted in Vault, e.g: "jwt"'
  2085. type: string
  2086. role:
  2087. description: Role is a JWT role to authenticate using the JWT/OIDC Vault authentication method
  2088. type: string
  2089. secretRef:
  2090. description: Optional SecretRef that refers to a key in a Secret resource containing JWT token to authenticate with Vault using the JWT/OIDC authentication method.
  2091. properties:
  2092. key:
  2093. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  2094. type: string
  2095. name:
  2096. description: The name of the Secret resource being referred to.
  2097. type: string
  2098. namespace:
  2099. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2100. type: string
  2101. type: object
  2102. required:
  2103. - path
  2104. type: object
  2105. kubernetes:
  2106. description: Kubernetes authenticates with Vault by passing the ServiceAccount token stored in the named Secret resource to the Vault server.
  2107. properties:
  2108. mountPath:
  2109. default: kubernetes
  2110. description: 'Path where the Kubernetes authentication backend is mounted in Vault, e.g: "kubernetes"'
  2111. type: string
  2112. role:
  2113. description: A required field containing the Vault Role to assume. A Role binds a Kubernetes ServiceAccount with a set of Vault policies.
  2114. type: string
  2115. secretRef:
  2116. description: Optional secret field containing a Kubernetes ServiceAccount JWT used for authenticating with Vault. If a name is specified without a key, `token` is the default. If one is not specified, the one bound to the controller will be used.
  2117. properties:
  2118. key:
  2119. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  2120. type: string
  2121. name:
  2122. description: The name of the Secret resource being referred to.
  2123. type: string
  2124. namespace:
  2125. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2126. type: string
  2127. type: object
  2128. serviceAccountRef:
  2129. description: Optional service account field containing the name of a kubernetes ServiceAccount. If the service account is specified, the service account secret token JWT will be used for authenticating with Vault. If the service account selector is not supplied, the secretRef will be used instead.
  2130. properties:
  2131. name:
  2132. description: The name of the ServiceAccount resource being referred to.
  2133. type: string
  2134. namespace:
  2135. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2136. type: string
  2137. required:
  2138. - name
  2139. type: object
  2140. required:
  2141. - mountPath
  2142. - role
  2143. type: object
  2144. ldap:
  2145. description: Ldap authenticates with Vault by passing username/password pair using the LDAP authentication method
  2146. properties:
  2147. path:
  2148. default: ldap
  2149. description: 'Path where the LDAP authentication backend is mounted in Vault, e.g: "ldap"'
  2150. type: string
  2151. secretRef:
  2152. description: SecretRef to a key in a Secret resource containing password for the LDAP user used to authenticate with Vault using the LDAP authentication method
  2153. properties:
  2154. key:
  2155. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  2156. type: string
  2157. name:
  2158. description: The name of the Secret resource being referred to.
  2159. type: string
  2160. namespace:
  2161. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2162. type: string
  2163. type: object
  2164. username:
  2165. description: Username is a LDAP user name used to authenticate using the LDAP Vault authentication method
  2166. type: string
  2167. required:
  2168. - path
  2169. - username
  2170. type: object
  2171. tokenSecretRef:
  2172. description: TokenSecretRef authenticates with Vault by presenting a token.
  2173. properties:
  2174. key:
  2175. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  2176. type: string
  2177. name:
  2178. description: The name of the Secret resource being referred to.
  2179. type: string
  2180. namespace:
  2181. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2182. type: string
  2183. type: object
  2184. type: object
  2185. caBundle:
  2186. description: PEM encoded CA bundle used to validate Vault server certificate. Only used if the Server URL is using HTTPS protocol. This parameter is ignored for plain HTTP protocol connection. If not set the system root certificates are used to validate the TLS connection.
  2187. format: byte
  2188. type: string
  2189. caProvider:
  2190. description: The provider for the CA bundle to use to validate Vault server certificate.
  2191. properties:
  2192. key:
  2193. description: The key the value inside of the provider type to use, only used with "Secret" type
  2194. type: string
  2195. name:
  2196. description: The name of the object located at the provider type.
  2197. type: string
  2198. namespace:
  2199. description: The namespace the Provider type is in.
  2200. type: string
  2201. type:
  2202. description: The type of provider to use such as "Secret", or "ConfigMap".
  2203. enum:
  2204. - Secret
  2205. - ConfigMap
  2206. type: string
  2207. required:
  2208. - name
  2209. - type
  2210. type: object
  2211. forwardInconsistent:
  2212. description: ForwardInconsistent tells Vault to forward read-after-write requests to the Vault leader instead of simply retrying within a loop. This can increase performance if the option is enabled serverside. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  2213. type: boolean
  2214. namespace:
  2215. description: 'Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows Vault environments to support Secure Multi-tenancy. e.g: "ns1". More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces'
  2216. type: string
  2217. path:
  2218. description: 'Path is the mount path of the Vault KV backend endpoint, e.g: "secret". The v2 KV secret engine version specific "/data" path suffix for fetching secrets from Vault is optional and will be appended if not present in specified path.'
  2219. type: string
  2220. readYourWrites:
  2221. description: ReadYourWrites ensures isolated read-after-write semantics by providing discovered cluster replication states in each request. More information about eventual consistency in Vault can be found here https://www.vaultproject.io/docs/enterprise/consistency
  2222. type: boolean
  2223. server:
  2224. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  2225. type: string
  2226. version:
  2227. default: v2
  2228. description: Version is the Vault KV secret engine version. This can be either "v1" or "v2". Version defaults to "v2".
  2229. enum:
  2230. - v1
  2231. - v2
  2232. type: string
  2233. required:
  2234. - auth
  2235. - server
  2236. type: object
  2237. webhook:
  2238. description: Webhook configures this store to sync secrets using a generic templated webhook
  2239. properties:
  2240. body:
  2241. description: Body
  2242. type: string
  2243. caBundle:
  2244. description: PEM encoded CA bundle used to validate webhook server certificate. Only used if the Server URL is using HTTPS protocol. This parameter is ignored for plain HTTP protocol connection. If not set the system root certificates are used to validate the TLS connection.
  2245. format: byte
  2246. type: string
  2247. caProvider:
  2248. description: The provider for the CA bundle to use to validate webhook server certificate.
  2249. properties:
  2250. key:
  2251. description: The key the value inside of the provider type to use, only used with "Secret" type
  2252. type: string
  2253. name:
  2254. description: The name of the object located at the provider type.
  2255. type: string
  2256. namespace:
  2257. description: The namespace the Provider type is in.
  2258. type: string
  2259. type:
  2260. description: The type of provider to use such as "Secret", or "ConfigMap".
  2261. enum:
  2262. - Secret
  2263. - ConfigMap
  2264. type: string
  2265. required:
  2266. - name
  2267. - type
  2268. type: object
  2269. headers:
  2270. additionalProperties:
  2271. type: string
  2272. description: Headers
  2273. type: object
  2274. method:
  2275. description: Webhook Method
  2276. type: string
  2277. result:
  2278. description: Result formatting
  2279. properties:
  2280. jsonPath:
  2281. description: Json path of return value
  2282. type: string
  2283. type: object
  2284. secrets:
  2285. description: Secrets to fill in templates These secrets will be passed to the templating function as key value pairs under the given name
  2286. items:
  2287. properties:
  2288. name:
  2289. description: Name of this secret in templates
  2290. type: string
  2291. secretRef:
  2292. description: Secret ref to fill in credentials
  2293. properties:
  2294. key:
  2295. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  2296. type: string
  2297. name:
  2298. description: The name of the Secret resource being referred to.
  2299. type: string
  2300. namespace:
  2301. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2302. type: string
  2303. type: object
  2304. required:
  2305. - name
  2306. - secretRef
  2307. type: object
  2308. type: array
  2309. timeout:
  2310. description: Timeout
  2311. type: string
  2312. url:
  2313. description: Webhook url to call
  2314. type: string
  2315. required:
  2316. - result
  2317. - url
  2318. type: object
  2319. yandexlockbox:
  2320. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  2321. properties:
  2322. apiEndpoint:
  2323. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  2324. type: string
  2325. auth:
  2326. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  2327. properties:
  2328. authorizedKeySecretRef:
  2329. description: The authorized key used for authentication
  2330. properties:
  2331. key:
  2332. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  2333. type: string
  2334. name:
  2335. description: The name of the Secret resource being referred to.
  2336. type: string
  2337. namespace:
  2338. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2339. type: string
  2340. type: object
  2341. type: object
  2342. caProvider:
  2343. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  2344. properties:
  2345. certSecretRef:
  2346. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  2347. properties:
  2348. key:
  2349. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  2350. type: string
  2351. name:
  2352. description: The name of the Secret resource being referred to.
  2353. type: string
  2354. namespace:
  2355. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2356. type: string
  2357. type: object
  2358. type: object
  2359. required:
  2360. - auth
  2361. type: object
  2362. type: object
  2363. refreshInterval:
  2364. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  2365. type: integer
  2366. retrySettings:
  2367. description: Used to configure http retries if failed
  2368. properties:
  2369. maxRetries:
  2370. format: int32
  2371. type: integer
  2372. retryInterval:
  2373. type: string
  2374. type: object
  2375. required:
  2376. - provider
  2377. type: object
  2378. status:
  2379. description: SecretStoreStatus defines the observed state of the SecretStore.
  2380. properties:
  2381. capabilities:
  2382. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  2383. type: string
  2384. conditions:
  2385. items:
  2386. properties:
  2387. lastTransitionTime:
  2388. format: date-time
  2389. type: string
  2390. message:
  2391. type: string
  2392. reason:
  2393. type: string
  2394. status:
  2395. type: string
  2396. type:
  2397. type: string
  2398. required:
  2399. - status
  2400. - type
  2401. type: object
  2402. type: array
  2403. type: object
  2404. type: object
  2405. served: true
  2406. storage: true
  2407. subresources:
  2408. status: {}
  2409. conversion:
  2410. strategy: Webhook
  2411. webhook:
  2412. conversionReviewVersions:
  2413. - v1
  2414. clientConfig:
  2415. service:
  2416. name: kubernetes
  2417. namespace: default
  2418. path: /convert
  2419. status:
  2420. acceptedNames:
  2421. kind: ""
  2422. plural: ""
  2423. conditions: []
  2424. storedVersions: []
  2425. ---
  2426. apiVersion: apiextensions.k8s.io/v1
  2427. kind: CustomResourceDefinition
  2428. metadata:
  2429. annotations:
  2430. controller-gen.kubebuilder.io/version: v0.8.0
  2431. creationTimestamp: null
  2432. name: externalsecrets.external-secrets.io
  2433. spec:
  2434. group: external-secrets.io
  2435. names:
  2436. categories:
  2437. - externalsecrets
  2438. kind: ExternalSecret
  2439. listKind: ExternalSecretList
  2440. plural: externalsecrets
  2441. shortNames:
  2442. - es
  2443. singular: externalsecret
  2444. scope: Namespaced
  2445. versions:
  2446. - additionalPrinterColumns:
  2447. - jsonPath: .spec.secretStoreRef.name
  2448. name: Store
  2449. type: string
  2450. - jsonPath: .spec.refreshInterval
  2451. name: Refresh Interval
  2452. type: string
  2453. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  2454. name: Status
  2455. type: string
  2456. deprecated: true
  2457. name: v1alpha1
  2458. schema:
  2459. openAPIV3Schema:
  2460. description: ExternalSecret is the Schema for the external-secrets API.
  2461. properties:
  2462. apiVersion:
  2463. description: 'APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
  2464. type: string
  2465. kind:
  2466. description: 'Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
  2467. type: string
  2468. metadata:
  2469. type: object
  2470. spec:
  2471. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  2472. properties:
  2473. data:
  2474. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  2475. items:
  2476. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  2477. properties:
  2478. remoteRef:
  2479. description: ExternalSecretDataRemoteRef defines Provider data location.
  2480. properties:
  2481. conversionStrategy:
  2482. default: Default
  2483. description: Used to define a conversion Strategy
  2484. type: string
  2485. key:
  2486. description: Key is the key used in the Provider, mandatory
  2487. type: string
  2488. property:
  2489. description: Used to select a specific property of the Provider value (if a map), if supported
  2490. type: string
  2491. version:
  2492. description: Used to select a specific version of the Provider value, if supported
  2493. type: string
  2494. required:
  2495. - key
  2496. type: object
  2497. secretKey:
  2498. type: string
  2499. required:
  2500. - remoteRef
  2501. - secretKey
  2502. type: object
  2503. type: array
  2504. dataFrom:
  2505. description: DataFrom is used to fetch all properties from a specific Provider data If multiple entries are specified, the Secret keys are merged in the specified order
  2506. items:
  2507. description: ExternalSecretDataRemoteRef defines Provider data location.
  2508. properties:
  2509. conversionStrategy:
  2510. default: Default
  2511. description: Used to define a conversion Strategy
  2512. type: string
  2513. key:
  2514. description: Key is the key used in the Provider, mandatory
  2515. type: string
  2516. property:
  2517. description: Used to select a specific property of the Provider value (if a map), if supported
  2518. type: string
  2519. version:
  2520. description: Used to select a specific version of the Provider value, if supported
  2521. type: string
  2522. required:
  2523. - key
  2524. type: object
  2525. type: array
  2526. refreshInterval:
  2527. default: 1h
  2528. description: RefreshInterval is the amount of time before the values are read again from the SecretStore provider Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h" May be set to zero to fetch and create it once. Defaults to 1h.
  2529. type: string
  2530. secretStoreRef:
  2531. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  2532. properties:
  2533. kind:
  2534. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore) Defaults to `SecretStore`
  2535. type: string
  2536. name:
  2537. description: Name of the SecretStore resource
  2538. type: string
  2539. required:
  2540. - name
  2541. type: object
  2542. target:
  2543. description: ExternalSecretTarget defines the Kubernetes Secret to be created There can be only one target per ExternalSecret.
  2544. properties:
  2545. creationPolicy:
  2546. default: Owner
  2547. description: CreationPolicy defines rules on how to create the resulting Secret Defaults to 'Owner'
  2548. type: string
  2549. immutable:
  2550. description: Immutable defines if the final secret will be immutable
  2551. type: boolean
  2552. name:
  2553. description: Name defines the name of the Secret resource to be managed This field is immutable Defaults to the .metadata.name of the ExternalSecret resource
  2554. type: string
  2555. template:
  2556. description: Template defines a blueprint for the created Secret resource.
  2557. properties:
  2558. data:
  2559. additionalProperties:
  2560. type: string
  2561. type: object
  2562. engineVersion:
  2563. default: v1
  2564. description: EngineVersion specifies the template engine version that should be used to compile/execute the template specified in .data and .templateFrom[].
  2565. type: string
  2566. metadata:
  2567. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  2568. properties:
  2569. annotations:
  2570. additionalProperties:
  2571. type: string
  2572. type: object
  2573. labels:
  2574. additionalProperties:
  2575. type: string
  2576. type: object
  2577. type: object
  2578. templateFrom:
  2579. items:
  2580. maxProperties: 1
  2581. minProperties: 1
  2582. properties:
  2583. configMap:
  2584. properties:
  2585. items:
  2586. items:
  2587. properties:
  2588. key:
  2589. type: string
  2590. required:
  2591. - key
  2592. type: object
  2593. type: array
  2594. name:
  2595. type: string
  2596. required:
  2597. - items
  2598. - name
  2599. type: object
  2600. secret:
  2601. properties:
  2602. items:
  2603. items:
  2604. properties:
  2605. key:
  2606. type: string
  2607. required:
  2608. - key
  2609. type: object
  2610. type: array
  2611. name:
  2612. type: string
  2613. required:
  2614. - items
  2615. - name
  2616. type: object
  2617. type: object
  2618. type: array
  2619. type:
  2620. type: string
  2621. type: object
  2622. type: object
  2623. required:
  2624. - secretStoreRef
  2625. - target
  2626. type: object
  2627. status:
  2628. properties:
  2629. conditions:
  2630. items:
  2631. properties:
  2632. lastTransitionTime:
  2633. format: date-time
  2634. type: string
  2635. message:
  2636. type: string
  2637. reason:
  2638. type: string
  2639. status:
  2640. type: string
  2641. type:
  2642. type: string
  2643. required:
  2644. - status
  2645. - type
  2646. type: object
  2647. type: array
  2648. refreshTime:
  2649. description: refreshTime is the time and date the external secret was fetched and the target secret updated
  2650. format: date-time
  2651. nullable: true
  2652. type: string
  2653. syncedResourceVersion:
  2654. description: SyncedResourceVersion keeps track of the last synced version
  2655. type: string
  2656. type: object
  2657. type: object
  2658. served: true
  2659. storage: false
  2660. subresources:
  2661. status: {}
  2662. - additionalPrinterColumns:
  2663. - jsonPath: .spec.secretStoreRef.name
  2664. name: Store
  2665. type: string
  2666. - jsonPath: .spec.refreshInterval
  2667. name: Refresh Interval
  2668. type: string
  2669. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  2670. name: Status
  2671. type: string
  2672. name: v1beta1
  2673. schema:
  2674. openAPIV3Schema:
  2675. description: ExternalSecret is the Schema for the external-secrets API.
  2676. properties:
  2677. apiVersion:
  2678. description: 'APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
  2679. type: string
  2680. kind:
  2681. description: 'Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
  2682. type: string
  2683. metadata:
  2684. type: object
  2685. spec:
  2686. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  2687. properties:
  2688. data:
  2689. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  2690. items:
  2691. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  2692. properties:
  2693. remoteRef:
  2694. description: ExternalSecretDataRemoteRef defines Provider data location.
  2695. properties:
  2696. conversionStrategy:
  2697. default: Default
  2698. description: Used to define a conversion Strategy
  2699. type: string
  2700. key:
  2701. description: Key is the key used in the Provider, mandatory
  2702. type: string
  2703. property:
  2704. description: Used to select a specific property of the Provider value (if a map), if supported
  2705. type: string
  2706. version:
  2707. description: Used to select a specific version of the Provider value, if supported
  2708. type: string
  2709. required:
  2710. - key
  2711. type: object
  2712. secretKey:
  2713. type: string
  2714. required:
  2715. - remoteRef
  2716. - secretKey
  2717. type: object
  2718. type: array
  2719. dataFrom:
  2720. description: DataFrom is used to fetch all properties from a specific Provider data If multiple entries are specified, the Secret keys are merged in the specified order
  2721. items:
  2722. maxProperties: 1
  2723. minProperties: 1
  2724. properties:
  2725. extract:
  2726. description: Used to extract multiple key/value pairs from one secret
  2727. properties:
  2728. conversionStrategy:
  2729. default: Default
  2730. description: Used to define a conversion Strategy
  2731. type: string
  2732. key:
  2733. description: Key is the key used in the Provider, mandatory
  2734. type: string
  2735. property:
  2736. description: Used to select a specific property of the Provider value (if a map), if supported
  2737. type: string
  2738. version:
  2739. description: Used to select a specific version of the Provider value, if supported
  2740. type: string
  2741. required:
  2742. - key
  2743. type: object
  2744. find:
  2745. description: Used to find secrets based on tags or regular expressions
  2746. properties:
  2747. conversionStrategy:
  2748. default: Default
  2749. description: Used to define a conversion Strategy
  2750. type: string
  2751. name:
  2752. description: Finds secrets based on the name.
  2753. properties:
  2754. regexp:
  2755. description: Finds secrets base
  2756. type: string
  2757. type: object
  2758. path:
  2759. description: A root path to start the find operations.
  2760. type: string
  2761. tags:
  2762. additionalProperties:
  2763. type: string
  2764. description: Find secrets based on tags.
  2765. type: object
  2766. type: object
  2767. type: object
  2768. type: array
  2769. refreshInterval:
  2770. default: 1h
  2771. description: RefreshInterval is the amount of time before the values are read again from the SecretStore provider Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h" May be set to zero to fetch and create it once. Defaults to 1h.
  2772. type: string
  2773. secretStoreRef:
  2774. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  2775. properties:
  2776. kind:
  2777. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore) Defaults to `SecretStore`
  2778. type: string
  2779. name:
  2780. description: Name of the SecretStore resource
  2781. type: string
  2782. required:
  2783. - name
  2784. type: object
  2785. target:
  2786. description: ExternalSecretTarget defines the Kubernetes Secret to be created There can be only one target per ExternalSecret.
  2787. properties:
  2788. creationPolicy:
  2789. default: Owner
  2790. description: CreationPolicy defines rules on how to create the resulting Secret Defaults to 'Owner'
  2791. enum:
  2792. - Owner
  2793. - Orphan
  2794. - Merge
  2795. - None
  2796. type: string
  2797. deletionPolicy:
  2798. default: Retain
  2799. description: DeletionPolicy defines rules on how to delete the resulting Secret Defaults to 'Retain'
  2800. enum:
  2801. - Delete
  2802. - Merge
  2803. - Retain
  2804. type: string
  2805. immutable:
  2806. description: Immutable defines if the final secret will be immutable
  2807. type: boolean
  2808. name:
  2809. description: Name defines the name of the Secret resource to be managed This field is immutable Defaults to the .metadata.name of the ExternalSecret resource
  2810. type: string
  2811. template:
  2812. description: Template defines a blueprint for the created Secret resource.
  2813. properties:
  2814. data:
  2815. additionalProperties:
  2816. type: string
  2817. type: object
  2818. engineVersion:
  2819. default: v2
  2820. type: string
  2821. metadata:
  2822. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  2823. properties:
  2824. annotations:
  2825. additionalProperties:
  2826. type: string
  2827. type: object
  2828. labels:
  2829. additionalProperties:
  2830. type: string
  2831. type: object
  2832. type: object
  2833. templateFrom:
  2834. items:
  2835. maxProperties: 1
  2836. minProperties: 1
  2837. properties:
  2838. configMap:
  2839. properties:
  2840. items:
  2841. items:
  2842. properties:
  2843. key:
  2844. type: string
  2845. required:
  2846. - key
  2847. type: object
  2848. type: array
  2849. name:
  2850. type: string
  2851. required:
  2852. - items
  2853. - name
  2854. type: object
  2855. secret:
  2856. properties:
  2857. items:
  2858. items:
  2859. properties:
  2860. key:
  2861. type: string
  2862. required:
  2863. - key
  2864. type: object
  2865. type: array
  2866. name:
  2867. type: string
  2868. required:
  2869. - items
  2870. - name
  2871. type: object
  2872. type: object
  2873. type: array
  2874. type:
  2875. type: string
  2876. type: object
  2877. type: object
  2878. required:
  2879. - secretStoreRef
  2880. type: object
  2881. status:
  2882. properties:
  2883. conditions:
  2884. items:
  2885. properties:
  2886. lastTransitionTime:
  2887. format: date-time
  2888. type: string
  2889. message:
  2890. type: string
  2891. reason:
  2892. type: string
  2893. status:
  2894. type: string
  2895. type:
  2896. type: string
  2897. required:
  2898. - status
  2899. - type
  2900. type: object
  2901. type: array
  2902. refreshTime:
  2903. description: refreshTime is the time and date the external secret was fetched and the target secret updated
  2904. format: date-time
  2905. nullable: true
  2906. type: string
  2907. syncedResourceVersion:
  2908. description: SyncedResourceVersion keeps track of the last synced version
  2909. type: string
  2910. type: object
  2911. type: object
  2912. served: true
  2913. storage: true
  2914. subresources:
  2915. status: {}
  2916. conversion:
  2917. strategy: Webhook
  2918. webhook:
  2919. conversionReviewVersions:
  2920. - v1
  2921. clientConfig:
  2922. service:
  2923. name: kubernetes
  2924. namespace: default
  2925. path: /convert
  2926. status:
  2927. acceptedNames:
  2928. kind: ""
  2929. plural: ""
  2930. conditions: []
  2931. storedVersions: []
  2932. ---
  2933. apiVersion: apiextensions.k8s.io/v1
  2934. kind: CustomResourceDefinition
  2935. metadata:
  2936. annotations:
  2937. controller-gen.kubebuilder.io/version: v0.8.0
  2938. creationTimestamp: null
  2939. name: secretsinks.external-secrets.io
  2940. spec:
  2941. group: external-secrets.io
  2942. names:
  2943. categories:
  2944. - secretsinks
  2945. kind: SecretSink
  2946. listKind: SecretSinkList
  2947. plural: secretsinks
  2948. singular: secretsink
  2949. scope: Namespaced
  2950. versions:
  2951. - name: v1alpha1
  2952. schema:
  2953. openAPIV3Schema:
  2954. properties:
  2955. apiVersion:
  2956. description: 'APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
  2957. type: string
  2958. kind:
  2959. description: 'Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
  2960. type: string
  2961. metadata:
  2962. type: object
  2963. spec:
  2964. description: SecretSinkSpec configures the behavior of the SecretSink.
  2965. properties:
  2966. data:
  2967. items:
  2968. properties:
  2969. match:
  2970. items:
  2971. properties:
  2972. remoteRefs:
  2973. items:
  2974. properties:
  2975. remoteKey:
  2976. type: string
  2977. required:
  2978. - remoteKey
  2979. type: object
  2980. type: array
  2981. secretKey:
  2982. type: string
  2983. required:
  2984. - remoteRefs
  2985. - secretKey
  2986. type: object
  2987. type: array
  2988. required:
  2989. - match
  2990. type: object
  2991. type: array
  2992. secretStoreRefs:
  2993. items:
  2994. properties:
  2995. kind:
  2996. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore) Defaults to `SecretStore`
  2997. type: string
  2998. name:
  2999. description: Name of the SecretStore resource
  3000. type: string
  3001. status:
  3002. type: string
  3003. required:
  3004. - name
  3005. - status
  3006. type: object
  3007. type: array
  3008. selector:
  3009. properties:
  3010. secret:
  3011. properties:
  3012. name:
  3013. type: string
  3014. required:
  3015. - name
  3016. type: object
  3017. required:
  3018. - secret
  3019. type: object
  3020. required:
  3021. - secretStoreRefs
  3022. - selector
  3023. type: object
  3024. status:
  3025. description: SecretSinkStatus indicates the history of the status of SecretSink.
  3026. properties:
  3027. conditions:
  3028. items:
  3029. description: SecretSinkStatusCondition indicates the status of the SecretSink.
  3030. properties:
  3031. lastTransitionTime:
  3032. format: date-time
  3033. type: string
  3034. message:
  3035. type: string
  3036. reason:
  3037. type: string
  3038. status:
  3039. type: string
  3040. type:
  3041. description: SecretSinkConditionType indicates the condition of the SecretSink.
  3042. type: string
  3043. required:
  3044. - status
  3045. - type
  3046. type: object
  3047. type: array
  3048. refreshTime:
  3049. description: refreshTime is the time and date the external secret was fetched and the target secret updated
  3050. format: date-time
  3051. nullable: true
  3052. type: string
  3053. syncedResourceVersion:
  3054. description: SyncedResourceVersion keeps track of the last synced version.
  3055. type: string
  3056. type: object
  3057. type: object
  3058. served: true
  3059. storage: true
  3060. subresources:
  3061. status: {}
  3062. conversion:
  3063. strategy: Webhook
  3064. webhook:
  3065. conversionReviewVersions:
  3066. - v1
  3067. clientConfig:
  3068. service:
  3069. name: kubernetes
  3070. namespace: default
  3071. path: /convert
  3072. status:
  3073. acceptedNames:
  3074. kind: ""
  3075. plural: ""
  3076. conditions: []
  3077. storedVersions: []
  3078. ---
  3079. apiVersion: apiextensions.k8s.io/v1
  3080. kind: CustomResourceDefinition
  3081. metadata:
  3082. annotations:
  3083. controller-gen.kubebuilder.io/version: v0.8.0
  3084. creationTimestamp: null
  3085. name: secretstores.external-secrets.io
  3086. spec:
  3087. group: external-secrets.io
  3088. names:
  3089. categories:
  3090. - externalsecrets
  3091. kind: SecretStore
  3092. listKind: SecretStoreList
  3093. plural: secretstores
  3094. shortNames:
  3095. - ss
  3096. singular: secretstore
  3097. scope: Namespaced
  3098. versions:
  3099. - additionalPrinterColumns:
  3100. - jsonPath: .metadata.creationTimestamp
  3101. name: AGE
  3102. type: date
  3103. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  3104. name: Status
  3105. type: string
  3106. deprecated: true
  3107. name: v1alpha1
  3108. schema:
  3109. openAPIV3Schema:
  3110. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  3111. properties:
  3112. apiVersion:
  3113. description: 'APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
  3114. type: string
  3115. kind:
  3116. description: 'Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
  3117. type: string
  3118. metadata:
  3119. type: object
  3120. spec:
  3121. description: SecretStoreSpec defines the desired state of SecretStore.
  3122. properties:
  3123. controller:
  3124. description: 'Used to select the correct KES controller (think: ingress.ingressClassName) The KES controller is instantiated with a specific controller name and filters ES based on this property'
  3125. type: string
  3126. provider:
  3127. description: Used to configure the provider. Only one provider may be set
  3128. maxProperties: 1
  3129. minProperties: 1
  3130. properties:
  3131. akeyless:
  3132. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  3133. properties:
  3134. akeylessGWApiURL:
  3135. description: Akeyless GW API Url from which the secrets to be fetched from.
  3136. type: string
  3137. authSecretRef:
  3138. description: Auth configures how the operator authenticates with Akeyless.
  3139. properties:
  3140. secretRef:
  3141. description: 'AkeylessAuthSecretRef AKEYLESS_ACCESS_TYPE_PARAM: AZURE_OBJ_ID OR GCP_AUDIENCE OR ACCESS_KEY OR KUB_CONFIG_NAME.'
  3142. properties:
  3143. accessID:
  3144. description: The SecretAccessID is used for authentication
  3145. properties:
  3146. key:
  3147. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3148. type: string
  3149. name:
  3150. description: The name of the Secret resource being referred to.
  3151. type: string
  3152. namespace:
  3153. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3154. type: string
  3155. type: object
  3156. accessType:
  3157. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  3158. properties:
  3159. key:
  3160. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3161. type: string
  3162. name:
  3163. description: The name of the Secret resource being referred to.
  3164. type: string
  3165. namespace:
  3166. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3167. type: string
  3168. type: object
  3169. accessTypeParam:
  3170. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  3171. properties:
  3172. key:
  3173. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3174. type: string
  3175. name:
  3176. description: The name of the Secret resource being referred to.
  3177. type: string
  3178. namespace:
  3179. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3180. type: string
  3181. type: object
  3182. type: object
  3183. required:
  3184. - secretRef
  3185. type: object
  3186. required:
  3187. - akeylessGWApiURL
  3188. - authSecretRef
  3189. type: object
  3190. alibaba:
  3191. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  3192. properties:
  3193. auth:
  3194. description: AlibabaAuth contains a secretRef for credentials.
  3195. properties:
  3196. secretRef:
  3197. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  3198. properties:
  3199. accessKeyIDSecretRef:
  3200. description: The AccessKeyID is used for authentication
  3201. properties:
  3202. key:
  3203. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3204. type: string
  3205. name:
  3206. description: The name of the Secret resource being referred to.
  3207. type: string
  3208. namespace:
  3209. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3210. type: string
  3211. type: object
  3212. accessKeySecretSecretRef:
  3213. description: The AccessKeySecret is used for authentication
  3214. properties:
  3215. key:
  3216. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3217. type: string
  3218. name:
  3219. description: The name of the Secret resource being referred to.
  3220. type: string
  3221. namespace:
  3222. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3223. type: string
  3224. type: object
  3225. required:
  3226. - accessKeyIDSecretRef
  3227. - accessKeySecretSecretRef
  3228. type: object
  3229. required:
  3230. - secretRef
  3231. type: object
  3232. endpoint:
  3233. type: string
  3234. regionID:
  3235. description: Alibaba Region to be used for the provider
  3236. type: string
  3237. required:
  3238. - auth
  3239. - regionID
  3240. type: object
  3241. aws:
  3242. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  3243. properties:
  3244. auth:
  3245. description: 'Auth defines the information necessary to authenticate against AWS if not set aws sdk will infer credentials from your environment see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials'
  3246. properties:
  3247. jwt:
  3248. description: Authenticate against AWS using service account tokens.
  3249. properties:
  3250. serviceAccountRef:
  3251. description: A reference to a ServiceAccount resource.
  3252. properties:
  3253. name:
  3254. description: The name of the ServiceAccount resource being referred to.
  3255. type: string
  3256. namespace:
  3257. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3258. type: string
  3259. required:
  3260. - name
  3261. type: object
  3262. type: object
  3263. secretRef:
  3264. description: AWSAuthSecretRef holds secret references for AWS credentials both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  3265. properties:
  3266. accessKeyIDSecretRef:
  3267. description: The AccessKeyID is used for authentication
  3268. properties:
  3269. key:
  3270. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3271. type: string
  3272. name:
  3273. description: The name of the Secret resource being referred to.
  3274. type: string
  3275. namespace:
  3276. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3277. type: string
  3278. type: object
  3279. secretAccessKeySecretRef:
  3280. description: The SecretAccessKey is used for authentication
  3281. properties:
  3282. key:
  3283. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3284. type: string
  3285. name:
  3286. description: The name of the Secret resource being referred to.
  3287. type: string
  3288. namespace:
  3289. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3290. type: string
  3291. type: object
  3292. type: object
  3293. type: object
  3294. region:
  3295. description: AWS Region to be used for the provider
  3296. type: string
  3297. role:
  3298. description: Role is a Role ARN which the SecretManager provider will assume
  3299. type: string
  3300. service:
  3301. description: Service defines which service should be used to fetch the secrets
  3302. enum:
  3303. - SecretsManager
  3304. - ParameterStore
  3305. type: string
  3306. required:
  3307. - region
  3308. - service
  3309. type: object
  3310. azurekv:
  3311. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  3312. properties:
  3313. authSecretRef:
  3314. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type.
  3315. properties:
  3316. clientId:
  3317. description: The Azure clientId of the service principle used for authentication.
  3318. properties:
  3319. key:
  3320. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3321. type: string
  3322. name:
  3323. description: The name of the Secret resource being referred to.
  3324. type: string
  3325. namespace:
  3326. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3327. type: string
  3328. type: object
  3329. clientSecret:
  3330. description: The Azure ClientSecret of the service principle used for authentication.
  3331. properties:
  3332. key:
  3333. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3334. type: string
  3335. name:
  3336. description: The name of the Secret resource being referred to.
  3337. type: string
  3338. namespace:
  3339. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3340. type: string
  3341. type: object
  3342. type: object
  3343. authType:
  3344. default: ServicePrincipal
  3345. description: 'Auth type defines how to authenticate to the keyvault service. Valid values are: - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret) - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)'
  3346. enum:
  3347. - ServicePrincipal
  3348. - ManagedIdentity
  3349. - WorkloadIdentity
  3350. type: string
  3351. identityId:
  3352. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  3353. type: string
  3354. serviceAccountRef:
  3355. description: ServiceAccountRef specified the service account that should be used when authenticating with WorkloadIdentity.
  3356. properties:
  3357. name:
  3358. description: The name of the ServiceAccount resource being referred to.
  3359. type: string
  3360. namespace:
  3361. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3362. type: string
  3363. required:
  3364. - name
  3365. type: object
  3366. tenantId:
  3367. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  3368. type: string
  3369. vaultUrl:
  3370. description: Vault Url from which the secrets to be fetched from.
  3371. type: string
  3372. required:
  3373. - vaultUrl
  3374. type: object
  3375. fake:
  3376. description: Fake configures a store with static key/value pairs
  3377. properties:
  3378. data:
  3379. items:
  3380. properties:
  3381. key:
  3382. type: string
  3383. value:
  3384. type: string
  3385. valueMap:
  3386. additionalProperties:
  3387. type: string
  3388. type: object
  3389. version:
  3390. type: string
  3391. required:
  3392. - key
  3393. type: object
  3394. type: array
  3395. required:
  3396. - data
  3397. type: object
  3398. gcpsm:
  3399. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  3400. properties:
  3401. auth:
  3402. description: Auth defines the information necessary to authenticate against GCP
  3403. properties:
  3404. secretRef:
  3405. properties:
  3406. secretAccessKeySecretRef:
  3407. description: The SecretAccessKey is used for authentication
  3408. properties:
  3409. key:
  3410. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3411. type: string
  3412. name:
  3413. description: The name of the Secret resource being referred to.
  3414. type: string
  3415. namespace:
  3416. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3417. type: string
  3418. type: object
  3419. type: object
  3420. workloadIdentity:
  3421. properties:
  3422. clusterLocation:
  3423. type: string
  3424. clusterName:
  3425. type: string
  3426. clusterProjectID:
  3427. type: string
  3428. serviceAccountRef:
  3429. description: A reference to a ServiceAccount resource.
  3430. properties:
  3431. name:
  3432. description: The name of the ServiceAccount resource being referred to.
  3433. type: string
  3434. namespace:
  3435. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3436. type: string
  3437. required:
  3438. - name
  3439. type: object
  3440. required:
  3441. - clusterLocation
  3442. - clusterName
  3443. - serviceAccountRef
  3444. type: object
  3445. type: object
  3446. projectID:
  3447. description: ProjectID project where secret is located
  3448. type: string
  3449. type: object
  3450. gitlab:
  3451. description: Gitlab configures this store to sync secrets using Gitlab Variables provider
  3452. properties:
  3453. auth:
  3454. description: Auth configures how secret-manager authenticates with a GitLab instance.
  3455. properties:
  3456. SecretRef:
  3457. properties:
  3458. accessToken:
  3459. description: AccessToken is used for authentication.
  3460. properties:
  3461. key:
  3462. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3463. type: string
  3464. name:
  3465. description: The name of the Secret resource being referred to.
  3466. type: string
  3467. namespace:
  3468. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3469. type: string
  3470. type: object
  3471. type: object
  3472. required:
  3473. - SecretRef
  3474. type: object
  3475. projectID:
  3476. description: ProjectID specifies a project where secrets are located.
  3477. type: string
  3478. url:
  3479. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  3480. type: string
  3481. required:
  3482. - auth
  3483. type: object
  3484. ibm:
  3485. description: IBM configures this store to sync secrets using IBM Cloud provider
  3486. properties:
  3487. auth:
  3488. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  3489. properties:
  3490. secretRef:
  3491. properties:
  3492. secretApiKeySecretRef:
  3493. description: The SecretAccessKey is used for authentication
  3494. properties:
  3495. key:
  3496. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3497. type: string
  3498. name:
  3499. description: The name of the Secret resource being referred to.
  3500. type: string
  3501. namespace:
  3502. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3503. type: string
  3504. type: object
  3505. type: object
  3506. required:
  3507. - secretRef
  3508. type: object
  3509. serviceUrl:
  3510. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  3511. type: string
  3512. required:
  3513. - auth
  3514. type: object
  3515. kubernetes:
  3516. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  3517. properties:
  3518. auth:
  3519. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  3520. maxProperties: 1
  3521. minProperties: 1
  3522. properties:
  3523. cert:
  3524. description: has both clientCert and clientKey as secretKeySelector
  3525. properties:
  3526. clientCert:
  3527. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  3528. properties:
  3529. key:
  3530. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3531. type: string
  3532. name:
  3533. description: The name of the Secret resource being referred to.
  3534. type: string
  3535. namespace:
  3536. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3537. type: string
  3538. type: object
  3539. clientKey:
  3540. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  3541. properties:
  3542. key:
  3543. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3544. type: string
  3545. name:
  3546. description: The name of the Secret resource being referred to.
  3547. type: string
  3548. namespace:
  3549. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3550. type: string
  3551. type: object
  3552. type: object
  3553. serviceAccount:
  3554. description: points to a service account that should be used for authentication
  3555. properties:
  3556. serviceAccount:
  3557. description: A reference to a ServiceAccount resource.
  3558. properties:
  3559. name:
  3560. description: The name of the ServiceAccount resource being referred to.
  3561. type: string
  3562. namespace:
  3563. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3564. type: string
  3565. required:
  3566. - name
  3567. type: object
  3568. type: object
  3569. token:
  3570. description: use static token to authenticate with
  3571. properties:
  3572. bearerToken:
  3573. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  3574. properties:
  3575. key:
  3576. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3577. type: string
  3578. name:
  3579. description: The name of the Secret resource being referred to.
  3580. type: string
  3581. namespace:
  3582. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3583. type: string
  3584. type: object
  3585. type: object
  3586. type: object
  3587. remoteNamespace:
  3588. default: default
  3589. description: Remote namespace to fetch the secrets from
  3590. type: string
  3591. server:
  3592. description: configures the Kubernetes server Address.
  3593. properties:
  3594. caBundle:
  3595. description: CABundle is a base64-encoded CA certificate
  3596. format: byte
  3597. type: string
  3598. caProvider:
  3599. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  3600. properties:
  3601. key:
  3602. description: The key the value inside of the provider type to use, only used with "Secret" type
  3603. type: string
  3604. name:
  3605. description: The name of the object located at the provider type.
  3606. type: string
  3607. namespace:
  3608. description: The namespace the Provider type is in.
  3609. type: string
  3610. type:
  3611. description: The type of provider to use such as "Secret", or "ConfigMap".
  3612. enum:
  3613. - Secret
  3614. - ConfigMap
  3615. type: string
  3616. required:
  3617. - name
  3618. - type
  3619. type: object
  3620. url:
  3621. default: kubernetes.default
  3622. description: configures the Kubernetes server Address.
  3623. type: string
  3624. type: object
  3625. required:
  3626. - auth
  3627. type: object
  3628. oracle:
  3629. description: Oracle configures this store to sync secrets using Oracle Vault provider
  3630. properties:
  3631. auth:
  3632. description: Auth configures how secret-manager authenticates with the Oracle Vault. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  3633. properties:
  3634. secretRef:
  3635. description: SecretRef to pass through sensitive information.
  3636. properties:
  3637. fingerprint:
  3638. description: Fingerprint is the fingerprint of the API private key.
  3639. properties:
  3640. key:
  3641. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3642. type: string
  3643. name:
  3644. description: The name of the Secret resource being referred to.
  3645. type: string
  3646. namespace:
  3647. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3648. type: string
  3649. type: object
  3650. privatekey:
  3651. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  3652. properties:
  3653. key:
  3654. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3655. type: string
  3656. name:
  3657. description: The name of the Secret resource being referred to.
  3658. type: string
  3659. namespace:
  3660. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3661. type: string
  3662. type: object
  3663. required:
  3664. - fingerprint
  3665. - privatekey
  3666. type: object
  3667. tenancy:
  3668. description: Tenancy is the tenancy OCID where user is located.
  3669. type: string
  3670. user:
  3671. description: User is an access OCID specific to the account.
  3672. type: string
  3673. required:
  3674. - secretRef
  3675. - tenancy
  3676. - user
  3677. type: object
  3678. region:
  3679. description: Region is the region where vault is located.
  3680. type: string
  3681. vault:
  3682. description: Vault is the vault's OCID of the specific vault where secret is located.
  3683. type: string
  3684. required:
  3685. - region
  3686. - vault
  3687. type: object
  3688. vault:
  3689. description: Vault configures this store to sync secrets using Hashi provider
  3690. properties:
  3691. auth:
  3692. description: Auth configures how secret-manager authenticates with the Vault server.
  3693. properties:
  3694. appRole:
  3695. description: AppRole authenticates with Vault using the App Role auth mechanism, with the role and secret stored in a Kubernetes Secret resource.
  3696. properties:
  3697. path:
  3698. default: approle
  3699. description: 'Path where the App Role authentication backend is mounted in Vault, e.g: "approle"'
  3700. type: string
  3701. roleId:
  3702. description: RoleID configured in the App Role authentication backend when setting up the authentication backend in Vault.
  3703. type: string
  3704. secretRef:
  3705. description: Reference to a key in a Secret that contains the App Role secret used to authenticate with Vault. The `key` field must be specified and denotes which entry within the Secret resource is used as the app role secret.
  3706. properties:
  3707. key:
  3708. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3709. type: string
  3710. name:
  3711. description: The name of the Secret resource being referred to.
  3712. type: string
  3713. namespace:
  3714. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3715. type: string
  3716. type: object
  3717. required:
  3718. - path
  3719. - roleId
  3720. - secretRef
  3721. type: object
  3722. cert:
  3723. description: Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate Cert authentication method
  3724. properties:
  3725. clientCert:
  3726. description: ClientCert is a certificate to authenticate using the Cert Vault authentication method
  3727. properties:
  3728. key:
  3729. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3730. type: string
  3731. name:
  3732. description: The name of the Secret resource being referred to.
  3733. type: string
  3734. namespace:
  3735. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3736. type: string
  3737. type: object
  3738. secretRef:
  3739. description: SecretRef to a key in a Secret resource containing client private key to authenticate with Vault using the Cert authentication method
  3740. properties:
  3741. key:
  3742. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3743. type: string
  3744. name:
  3745. description: The name of the Secret resource being referred to.
  3746. type: string
  3747. namespace:
  3748. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3749. type: string
  3750. type: object
  3751. type: object
  3752. jwt:
  3753. description: Jwt authenticates with Vault by passing role and JWT token using the JWT/OIDC authentication method
  3754. properties:
  3755. kubernetesServiceAccountToken:
  3756. description: Optional ServiceAccountToken specifies the Kubernetes service account for which to request a token for with the `TokenRequest` API.
  3757. properties:
  3758. audiences:
  3759. description: Optional audiences field that will be used to request a temporary Kubernetes service account token for the service account referenced by `serviceAccountRef`. Defaults to a single audience `vault` it not specified.
  3760. items:
  3761. type: string
  3762. type: array
  3763. expirationSeconds:
  3764. description: Optional expiration time in seconds that will be used to request a temporary Kubernetes service account token for the service account referenced by `serviceAccountRef`. Defaults to 10 minutes.
  3765. format: int64
  3766. type: integer
  3767. serviceAccountRef:
  3768. description: Service account field containing the name of a kubernetes ServiceAccount.
  3769. properties:
  3770. name:
  3771. description: The name of the ServiceAccount resource being referred to.
  3772. type: string
  3773. namespace:
  3774. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3775. type: string
  3776. required:
  3777. - name
  3778. type: object
  3779. required:
  3780. - serviceAccountRef
  3781. type: object
  3782. path:
  3783. default: jwt
  3784. description: 'Path where the JWT authentication backend is mounted in Vault, e.g: "jwt"'
  3785. type: string
  3786. role:
  3787. description: Role is a JWT role to authenticate using the JWT/OIDC Vault authentication method
  3788. type: string
  3789. secretRef:
  3790. description: Optional SecretRef that refers to a key in a Secret resource containing JWT token to authenticate with Vault using the JWT/OIDC authentication method.
  3791. properties:
  3792. key:
  3793. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3794. type: string
  3795. name:
  3796. description: The name of the Secret resource being referred to.
  3797. type: string
  3798. namespace:
  3799. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3800. type: string
  3801. type: object
  3802. required:
  3803. - path
  3804. type: object
  3805. kubernetes:
  3806. description: Kubernetes authenticates with Vault by passing the ServiceAccount token stored in the named Secret resource to the Vault server.
  3807. properties:
  3808. mountPath:
  3809. default: kubernetes
  3810. description: 'Path where the Kubernetes authentication backend is mounted in Vault, e.g: "kubernetes"'
  3811. type: string
  3812. role:
  3813. description: A required field containing the Vault Role to assume. A Role binds a Kubernetes ServiceAccount with a set of Vault policies.
  3814. type: string
  3815. secretRef:
  3816. description: Optional secret field containing a Kubernetes ServiceAccount JWT used for authenticating with Vault. If a name is specified without a key, `token` is the default. If one is not specified, the one bound to the controller will be used.
  3817. properties:
  3818. key:
  3819. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3820. type: string
  3821. name:
  3822. description: The name of the Secret resource being referred to.
  3823. type: string
  3824. namespace:
  3825. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3826. type: string
  3827. type: object
  3828. serviceAccountRef:
  3829. description: Optional service account field containing the name of a kubernetes ServiceAccount. If the service account is specified, the service account secret token JWT will be used for authenticating with Vault. If the service account selector is not supplied, the secretRef will be used instead.
  3830. properties:
  3831. name:
  3832. description: The name of the ServiceAccount resource being referred to.
  3833. type: string
  3834. namespace:
  3835. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3836. type: string
  3837. required:
  3838. - name
  3839. type: object
  3840. required:
  3841. - mountPath
  3842. - role
  3843. type: object
  3844. ldap:
  3845. description: Ldap authenticates with Vault by passing username/password pair using the LDAP authentication method
  3846. properties:
  3847. path:
  3848. default: ldap
  3849. description: 'Path where the LDAP authentication backend is mounted in Vault, e.g: "ldap"'
  3850. type: string
  3851. secretRef:
  3852. description: SecretRef to a key in a Secret resource containing password for the LDAP user used to authenticate with Vault using the LDAP authentication method
  3853. properties:
  3854. key:
  3855. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3856. type: string
  3857. name:
  3858. description: The name of the Secret resource being referred to.
  3859. type: string
  3860. namespace:
  3861. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3862. type: string
  3863. type: object
  3864. username:
  3865. description: Username is a LDAP user name used to authenticate using the LDAP Vault authentication method
  3866. type: string
  3867. required:
  3868. - path
  3869. - username
  3870. type: object
  3871. tokenSecretRef:
  3872. description: TokenSecretRef authenticates with Vault by presenting a token.
  3873. properties:
  3874. key:
  3875. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3876. type: string
  3877. name:
  3878. description: The name of the Secret resource being referred to.
  3879. type: string
  3880. namespace:
  3881. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3882. type: string
  3883. type: object
  3884. type: object
  3885. caBundle:
  3886. description: PEM encoded CA bundle used to validate Vault server certificate. Only used if the Server URL is using HTTPS protocol. This parameter is ignored for plain HTTP protocol connection. If not set the system root certificates are used to validate the TLS connection.
  3887. format: byte
  3888. type: string
  3889. caProvider:
  3890. description: The provider for the CA bundle to use to validate Vault server certificate.
  3891. properties:
  3892. key:
  3893. description: The key the value inside of the provider type to use, only used with "Secret" type
  3894. type: string
  3895. name:
  3896. description: The name of the object located at the provider type.
  3897. type: string
  3898. namespace:
  3899. description: The namespace the Provider type is in.
  3900. type: string
  3901. type:
  3902. description: The type of provider to use such as "Secret", or "ConfigMap".
  3903. enum:
  3904. - Secret
  3905. - ConfigMap
  3906. type: string
  3907. required:
  3908. - name
  3909. - type
  3910. type: object
  3911. forwardInconsistent:
  3912. description: ForwardInconsistent tells Vault to forward read-after-write requests to the Vault leader instead of simply retrying within a loop. This can increase performance if the option is enabled serverside. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  3913. type: boolean
  3914. namespace:
  3915. description: 'Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows Vault environments to support Secure Multi-tenancy. e.g: "ns1". More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces'
  3916. type: string
  3917. path:
  3918. description: 'Path is the mount path of the Vault KV backend endpoint, e.g: "secret". The v2 KV secret engine version specific "/data" path suffix for fetching secrets from Vault is optional and will be appended if not present in specified path.'
  3919. type: string
  3920. readYourWrites:
  3921. description: ReadYourWrites ensures isolated read-after-write semantics by providing discovered cluster replication states in each request. More information about eventual consistency in Vault can be found here https://www.vaultproject.io/docs/enterprise/consistency
  3922. type: boolean
  3923. server:
  3924. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  3925. type: string
  3926. version:
  3927. default: v2
  3928. description: Version is the Vault KV secret engine version. This can be either "v1" or "v2". Version defaults to "v2".
  3929. enum:
  3930. - v1
  3931. - v2
  3932. type: string
  3933. required:
  3934. - auth
  3935. - server
  3936. type: object
  3937. webhook:
  3938. description: Webhook configures this store to sync secrets using a generic templated webhook
  3939. properties:
  3940. body:
  3941. description: Body
  3942. type: string
  3943. caBundle:
  3944. description: PEM encoded CA bundle used to validate webhook server certificate. Only used if the Server URL is using HTTPS protocol. This parameter is ignored for plain HTTP protocol connection. If not set the system root certificates are used to validate the TLS connection.
  3945. format: byte
  3946. type: string
  3947. caProvider:
  3948. description: The provider for the CA bundle to use to validate webhook server certificate.
  3949. properties:
  3950. key:
  3951. description: The key the value inside of the provider type to use, only used with "Secret" type
  3952. type: string
  3953. name:
  3954. description: The name of the object located at the provider type.
  3955. type: string
  3956. namespace:
  3957. description: The namespace the Provider type is in.
  3958. type: string
  3959. type:
  3960. description: The type of provider to use such as "Secret", or "ConfigMap".
  3961. enum:
  3962. - Secret
  3963. - ConfigMap
  3964. type: string
  3965. required:
  3966. - name
  3967. - type
  3968. type: object
  3969. headers:
  3970. additionalProperties:
  3971. type: string
  3972. description: Headers
  3973. type: object
  3974. method:
  3975. description: Webhook Method
  3976. type: string
  3977. result:
  3978. description: Result formatting
  3979. properties:
  3980. jsonPath:
  3981. description: Json path of return value
  3982. type: string
  3983. type: object
  3984. secrets:
  3985. description: Secrets to fill in templates These secrets will be passed to the templating function as key value pairs under the given name
  3986. items:
  3987. properties:
  3988. name:
  3989. description: Name of this secret in templates
  3990. type: string
  3991. secretRef:
  3992. description: Secret ref to fill in credentials
  3993. properties:
  3994. key:
  3995. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3996. type: string
  3997. name:
  3998. description: The name of the Secret resource being referred to.
  3999. type: string
  4000. namespace:
  4001. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4002. type: string
  4003. type: object
  4004. required:
  4005. - name
  4006. - secretRef
  4007. type: object
  4008. type: array
  4009. timeout:
  4010. description: Timeout
  4011. type: string
  4012. url:
  4013. description: Webhook url to call
  4014. type: string
  4015. required:
  4016. - result
  4017. - url
  4018. type: object
  4019. yandexlockbox:
  4020. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  4021. properties:
  4022. apiEndpoint:
  4023. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  4024. type: string
  4025. auth:
  4026. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  4027. properties:
  4028. authorizedKeySecretRef:
  4029. description: The authorized key used for authentication
  4030. properties:
  4031. key:
  4032. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4033. type: string
  4034. name:
  4035. description: The name of the Secret resource being referred to.
  4036. type: string
  4037. namespace:
  4038. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4039. type: string
  4040. type: object
  4041. type: object
  4042. caProvider:
  4043. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  4044. properties:
  4045. certSecretRef:
  4046. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  4047. properties:
  4048. key:
  4049. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4050. type: string
  4051. name:
  4052. description: The name of the Secret resource being referred to.
  4053. type: string
  4054. namespace:
  4055. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4056. type: string
  4057. type: object
  4058. type: object
  4059. required:
  4060. - auth
  4061. type: object
  4062. type: object
  4063. retrySettings:
  4064. description: Used to configure http retries if failed
  4065. properties:
  4066. maxRetries:
  4067. format: int32
  4068. type: integer
  4069. retryInterval:
  4070. type: string
  4071. type: object
  4072. required:
  4073. - provider
  4074. type: object
  4075. status:
  4076. description: SecretStoreStatus defines the observed state of the SecretStore.
  4077. properties:
  4078. conditions:
  4079. items:
  4080. properties:
  4081. lastTransitionTime:
  4082. format: date-time
  4083. type: string
  4084. message:
  4085. type: string
  4086. reason:
  4087. type: string
  4088. status:
  4089. type: string
  4090. type:
  4091. type: string
  4092. required:
  4093. - status
  4094. - type
  4095. type: object
  4096. type: array
  4097. type: object
  4098. type: object
  4099. served: true
  4100. storage: false
  4101. subresources:
  4102. status: {}
  4103. - additionalPrinterColumns:
  4104. - jsonPath: .metadata.creationTimestamp
  4105. name: AGE
  4106. type: date
  4107. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  4108. name: Status
  4109. type: string
  4110. - jsonPath: .status.capabilities
  4111. name: Capabilities
  4112. type: string
  4113. name: v1beta1
  4114. schema:
  4115. openAPIV3Schema:
  4116. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  4117. properties:
  4118. apiVersion:
  4119. description: 'APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
  4120. type: string
  4121. kind:
  4122. description: 'Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
  4123. type: string
  4124. metadata:
  4125. type: object
  4126. spec:
  4127. description: SecretStoreSpec defines the desired state of SecretStore.
  4128. properties:
  4129. controller:
  4130. description: 'Used to select the correct KES controller (think: ingress.ingressClassName) The KES controller is instantiated with a specific controller name and filters ES based on this property'
  4131. type: string
  4132. provider:
  4133. description: Used to configure the provider. Only one provider may be set
  4134. maxProperties: 1
  4135. minProperties: 1
  4136. properties:
  4137. akeyless:
  4138. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  4139. properties:
  4140. akeylessGWApiURL:
  4141. description: Akeyless GW API Url from which the secrets to be fetched from.
  4142. type: string
  4143. authSecretRef:
  4144. description: Auth configures how the operator authenticates with Akeyless.
  4145. properties:
  4146. secretRef:
  4147. description: 'AkeylessAuthSecretRef AKEYLESS_ACCESS_TYPE_PARAM: AZURE_OBJ_ID OR GCP_AUDIENCE OR ACCESS_KEY OR KUB_CONFIG_NAME.'
  4148. properties:
  4149. accessID:
  4150. description: The SecretAccessID is used for authentication
  4151. properties:
  4152. key:
  4153. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4154. type: string
  4155. name:
  4156. description: The name of the Secret resource being referred to.
  4157. type: string
  4158. namespace:
  4159. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4160. type: string
  4161. type: object
  4162. accessType:
  4163. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  4164. properties:
  4165. key:
  4166. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4167. type: string
  4168. name:
  4169. description: The name of the Secret resource being referred to.
  4170. type: string
  4171. namespace:
  4172. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4173. type: string
  4174. type: object
  4175. accessTypeParam:
  4176. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  4177. properties:
  4178. key:
  4179. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4180. type: string
  4181. name:
  4182. description: The name of the Secret resource being referred to.
  4183. type: string
  4184. namespace:
  4185. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4186. type: string
  4187. type: object
  4188. type: object
  4189. required:
  4190. - secretRef
  4191. type: object
  4192. required:
  4193. - akeylessGWApiURL
  4194. - authSecretRef
  4195. type: object
  4196. alibaba:
  4197. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  4198. properties:
  4199. auth:
  4200. description: AlibabaAuth contains a secretRef for credentials.
  4201. properties:
  4202. secretRef:
  4203. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  4204. properties:
  4205. accessKeyIDSecretRef:
  4206. description: The AccessKeyID is used for authentication
  4207. properties:
  4208. key:
  4209. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4210. type: string
  4211. name:
  4212. description: The name of the Secret resource being referred to.
  4213. type: string
  4214. namespace:
  4215. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4216. type: string
  4217. type: object
  4218. accessKeySecretSecretRef:
  4219. description: The AccessKeySecret is used for authentication
  4220. properties:
  4221. key:
  4222. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4223. type: string
  4224. name:
  4225. description: The name of the Secret resource being referred to.
  4226. type: string
  4227. namespace:
  4228. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4229. type: string
  4230. type: object
  4231. required:
  4232. - accessKeyIDSecretRef
  4233. - accessKeySecretSecretRef
  4234. type: object
  4235. required:
  4236. - secretRef
  4237. type: object
  4238. endpoint:
  4239. type: string
  4240. regionID:
  4241. description: Alibaba Region to be used for the provider
  4242. type: string
  4243. required:
  4244. - auth
  4245. - regionID
  4246. type: object
  4247. aws:
  4248. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  4249. properties:
  4250. auth:
  4251. description: 'Auth defines the information necessary to authenticate against AWS if not set aws sdk will infer credentials from your environment see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials'
  4252. properties:
  4253. jwt:
  4254. description: Authenticate against AWS using service account tokens.
  4255. properties:
  4256. serviceAccountRef:
  4257. description: A reference to a ServiceAccount resource.
  4258. properties:
  4259. name:
  4260. description: The name of the ServiceAccount resource being referred to.
  4261. type: string
  4262. namespace:
  4263. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4264. type: string
  4265. required:
  4266. - name
  4267. type: object
  4268. type: object
  4269. secretRef:
  4270. description: AWSAuthSecretRef holds secret references for AWS credentials both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  4271. properties:
  4272. accessKeyIDSecretRef:
  4273. description: The AccessKeyID is used for authentication
  4274. properties:
  4275. key:
  4276. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4277. type: string
  4278. name:
  4279. description: The name of the Secret resource being referred to.
  4280. type: string
  4281. namespace:
  4282. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4283. type: string
  4284. type: object
  4285. secretAccessKeySecretRef:
  4286. description: The SecretAccessKey is used for authentication
  4287. properties:
  4288. key:
  4289. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4290. type: string
  4291. name:
  4292. description: The name of the Secret resource being referred to.
  4293. type: string
  4294. namespace:
  4295. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4296. type: string
  4297. type: object
  4298. type: object
  4299. type: object
  4300. region:
  4301. description: AWS Region to be used for the provider
  4302. type: string
  4303. role:
  4304. description: Role is a Role ARN which the SecretManager provider will assume
  4305. type: string
  4306. service:
  4307. description: Service defines which service should be used to fetch the secrets
  4308. enum:
  4309. - SecretsManager
  4310. - ParameterStore
  4311. type: string
  4312. required:
  4313. - region
  4314. - service
  4315. type: object
  4316. azurekv:
  4317. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  4318. properties:
  4319. authSecretRef:
  4320. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type.
  4321. properties:
  4322. clientId:
  4323. description: The Azure clientId of the service principle used for authentication.
  4324. properties:
  4325. key:
  4326. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4327. type: string
  4328. name:
  4329. description: The name of the Secret resource being referred to.
  4330. type: string
  4331. namespace:
  4332. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4333. type: string
  4334. type: object
  4335. clientSecret:
  4336. description: The Azure ClientSecret of the service principle used for authentication.
  4337. properties:
  4338. key:
  4339. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4340. type: string
  4341. name:
  4342. description: The name of the Secret resource being referred to.
  4343. type: string
  4344. namespace:
  4345. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4346. type: string
  4347. type: object
  4348. type: object
  4349. authType:
  4350. default: ServicePrincipal
  4351. description: 'Auth type defines how to authenticate to the keyvault service. Valid values are: - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret) - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)'
  4352. enum:
  4353. - ServicePrincipal
  4354. - ManagedIdentity
  4355. - WorkloadIdentity
  4356. type: string
  4357. identityId:
  4358. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  4359. type: string
  4360. serviceAccountRef:
  4361. description: ServiceAccountRef specified the service account that should be used when authenticating with WorkloadIdentity.
  4362. properties:
  4363. name:
  4364. description: The name of the ServiceAccount resource being referred to.
  4365. type: string
  4366. namespace:
  4367. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4368. type: string
  4369. required:
  4370. - name
  4371. type: object
  4372. tenantId:
  4373. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  4374. type: string
  4375. vaultUrl:
  4376. description: Vault Url from which the secrets to be fetched from.
  4377. type: string
  4378. required:
  4379. - vaultUrl
  4380. type: object
  4381. fake:
  4382. description: Fake configures a store with static key/value pairs
  4383. properties:
  4384. data:
  4385. items:
  4386. properties:
  4387. key:
  4388. type: string
  4389. value:
  4390. type: string
  4391. valueMap:
  4392. additionalProperties:
  4393. type: string
  4394. type: object
  4395. version:
  4396. type: string
  4397. required:
  4398. - key
  4399. type: object
  4400. type: array
  4401. required:
  4402. - data
  4403. type: object
  4404. gcpsm:
  4405. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  4406. properties:
  4407. auth:
  4408. description: Auth defines the information necessary to authenticate against GCP
  4409. properties:
  4410. secretRef:
  4411. properties:
  4412. secretAccessKeySecretRef:
  4413. description: The SecretAccessKey is used for authentication
  4414. properties:
  4415. key:
  4416. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4417. type: string
  4418. name:
  4419. description: The name of the Secret resource being referred to.
  4420. type: string
  4421. namespace:
  4422. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4423. type: string
  4424. type: object
  4425. type: object
  4426. workloadIdentity:
  4427. properties:
  4428. clusterLocation:
  4429. type: string
  4430. clusterName:
  4431. type: string
  4432. clusterProjectID:
  4433. type: string
  4434. serviceAccountRef:
  4435. description: A reference to a ServiceAccount resource.
  4436. properties:
  4437. name:
  4438. description: The name of the ServiceAccount resource being referred to.
  4439. type: string
  4440. namespace:
  4441. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4442. type: string
  4443. required:
  4444. - name
  4445. type: object
  4446. required:
  4447. - clusterLocation
  4448. - clusterName
  4449. - serviceAccountRef
  4450. type: object
  4451. type: object
  4452. projectID:
  4453. description: ProjectID project where secret is located
  4454. type: string
  4455. type: object
  4456. gitlab:
  4457. description: Gitlab configures this store to sync secrets using Gitlab Variables provider
  4458. properties:
  4459. auth:
  4460. description: Auth configures how secret-manager authenticates with a GitLab instance.
  4461. properties:
  4462. SecretRef:
  4463. properties:
  4464. accessToken:
  4465. description: AccessToken is used for authentication.
  4466. properties:
  4467. key:
  4468. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4469. type: string
  4470. name:
  4471. description: The name of the Secret resource being referred to.
  4472. type: string
  4473. namespace:
  4474. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4475. type: string
  4476. type: object
  4477. type: object
  4478. required:
  4479. - SecretRef
  4480. type: object
  4481. projectID:
  4482. description: ProjectID specifies a project where secrets are located.
  4483. type: string
  4484. url:
  4485. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  4486. type: string
  4487. required:
  4488. - auth
  4489. type: object
  4490. ibm:
  4491. description: IBM configures this store to sync secrets using IBM Cloud provider
  4492. properties:
  4493. auth:
  4494. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  4495. properties:
  4496. secretRef:
  4497. properties:
  4498. secretApiKeySecretRef:
  4499. description: The SecretAccessKey is used for authentication
  4500. properties:
  4501. key:
  4502. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4503. type: string
  4504. name:
  4505. description: The name of the Secret resource being referred to.
  4506. type: string
  4507. namespace:
  4508. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4509. type: string
  4510. type: object
  4511. type: object
  4512. required:
  4513. - secretRef
  4514. type: object
  4515. serviceUrl:
  4516. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  4517. type: string
  4518. required:
  4519. - auth
  4520. type: object
  4521. kubernetes:
  4522. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  4523. properties:
  4524. auth:
  4525. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  4526. maxProperties: 1
  4527. minProperties: 1
  4528. properties:
  4529. cert:
  4530. description: has both clientCert and clientKey as secretKeySelector
  4531. properties:
  4532. clientCert:
  4533. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  4534. properties:
  4535. key:
  4536. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4537. type: string
  4538. name:
  4539. description: The name of the Secret resource being referred to.
  4540. type: string
  4541. namespace:
  4542. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4543. type: string
  4544. type: object
  4545. clientKey:
  4546. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  4547. properties:
  4548. key:
  4549. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4550. type: string
  4551. name:
  4552. description: The name of the Secret resource being referred to.
  4553. type: string
  4554. namespace:
  4555. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4556. type: string
  4557. type: object
  4558. type: object
  4559. serviceAccount:
  4560. description: points to a service account that should be used for authentication
  4561. properties:
  4562. serviceAccount:
  4563. description: A reference to a ServiceAccount resource.
  4564. properties:
  4565. name:
  4566. description: The name of the ServiceAccount resource being referred to.
  4567. type: string
  4568. namespace:
  4569. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4570. type: string
  4571. required:
  4572. - name
  4573. type: object
  4574. type: object
  4575. token:
  4576. description: use static token to authenticate with
  4577. properties:
  4578. bearerToken:
  4579. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  4580. properties:
  4581. key:
  4582. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4583. type: string
  4584. name:
  4585. description: The name of the Secret resource being referred to.
  4586. type: string
  4587. namespace:
  4588. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4589. type: string
  4590. type: object
  4591. type: object
  4592. type: object
  4593. remoteNamespace:
  4594. default: default
  4595. description: Remote namespace to fetch the secrets from
  4596. type: string
  4597. server:
  4598. description: configures the Kubernetes server Address.
  4599. properties:
  4600. caBundle:
  4601. description: CABundle is a base64-encoded CA certificate
  4602. format: byte
  4603. type: string
  4604. caProvider:
  4605. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  4606. properties:
  4607. key:
  4608. description: The key the value inside of the provider type to use, only used with "Secret" type
  4609. type: string
  4610. name:
  4611. description: The name of the object located at the provider type.
  4612. type: string
  4613. namespace:
  4614. description: The namespace the Provider type is in.
  4615. type: string
  4616. type:
  4617. description: The type of provider to use such as "Secret", or "ConfigMap".
  4618. enum:
  4619. - Secret
  4620. - ConfigMap
  4621. type: string
  4622. required:
  4623. - name
  4624. - type
  4625. type: object
  4626. url:
  4627. default: kubernetes.default
  4628. description: configures the Kubernetes server Address.
  4629. type: string
  4630. type: object
  4631. required:
  4632. - auth
  4633. type: object
  4634. oracle:
  4635. description: Oracle configures this store to sync secrets using Oracle Vault provider
  4636. properties:
  4637. auth:
  4638. description: Auth configures how secret-manager authenticates with the Oracle Vault. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  4639. properties:
  4640. secretRef:
  4641. description: SecretRef to pass through sensitive information.
  4642. properties:
  4643. fingerprint:
  4644. description: Fingerprint is the fingerprint of the API private key.
  4645. properties:
  4646. key:
  4647. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4648. type: string
  4649. name:
  4650. description: The name of the Secret resource being referred to.
  4651. type: string
  4652. namespace:
  4653. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4654. type: string
  4655. type: object
  4656. privatekey:
  4657. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  4658. properties:
  4659. key:
  4660. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4661. type: string
  4662. name:
  4663. description: The name of the Secret resource being referred to.
  4664. type: string
  4665. namespace:
  4666. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4667. type: string
  4668. type: object
  4669. required:
  4670. - fingerprint
  4671. - privatekey
  4672. type: object
  4673. tenancy:
  4674. description: Tenancy is the tenancy OCID where user is located.
  4675. type: string
  4676. user:
  4677. description: User is an access OCID specific to the account.
  4678. type: string
  4679. required:
  4680. - secretRef
  4681. - tenancy
  4682. - user
  4683. type: object
  4684. region:
  4685. description: Region is the region where vault is located.
  4686. type: string
  4687. vault:
  4688. description: Vault is the vault's OCID of the specific vault where secret is located.
  4689. type: string
  4690. required:
  4691. - region
  4692. - vault
  4693. type: object
  4694. senhasegura:
  4695. description: Senhasegura configures this store to sync secrets using senhasegura provider
  4696. properties:
  4697. auth:
  4698. description: Auth defines parameters to authenticate in senhasegura
  4699. properties:
  4700. clientId:
  4701. type: string
  4702. clientSecretSecretRef:
  4703. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  4704. properties:
  4705. key:
  4706. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4707. type: string
  4708. name:
  4709. description: The name of the Secret resource being referred to.
  4710. type: string
  4711. namespace:
  4712. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4713. type: string
  4714. type: object
  4715. required:
  4716. - clientId
  4717. - clientSecretSecretRef
  4718. type: object
  4719. ignoreSslCertificate:
  4720. default: false
  4721. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  4722. type: boolean
  4723. module:
  4724. description: Module defines which senhasegura module should be used to get secrets
  4725. type: string
  4726. url:
  4727. description: URL of senhasegura
  4728. type: string
  4729. required:
  4730. - auth
  4731. - module
  4732. - url
  4733. type: object
  4734. vault:
  4735. description: Vault configures this store to sync secrets using Hashi provider
  4736. properties:
  4737. auth:
  4738. description: Auth configures how secret-manager authenticates with the Vault server.
  4739. properties:
  4740. appRole:
  4741. description: AppRole authenticates with Vault using the App Role auth mechanism, with the role and secret stored in a Kubernetes Secret resource.
  4742. properties:
  4743. path:
  4744. default: approle
  4745. description: 'Path where the App Role authentication backend is mounted in Vault, e.g: "approle"'
  4746. type: string
  4747. roleId:
  4748. description: RoleID configured in the App Role authentication backend when setting up the authentication backend in Vault.
  4749. type: string
  4750. secretRef:
  4751. description: Reference to a key in a Secret that contains the App Role secret used to authenticate with Vault. The `key` field must be specified and denotes which entry within the Secret resource is used as the app role secret.
  4752. properties:
  4753. key:
  4754. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4755. type: string
  4756. name:
  4757. description: The name of the Secret resource being referred to.
  4758. type: string
  4759. namespace:
  4760. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4761. type: string
  4762. type: object
  4763. required:
  4764. - path
  4765. - roleId
  4766. - secretRef
  4767. type: object
  4768. cert:
  4769. description: Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate Cert authentication method
  4770. properties:
  4771. clientCert:
  4772. description: ClientCert is a certificate to authenticate using the Cert Vault authentication method
  4773. properties:
  4774. key:
  4775. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4776. type: string
  4777. name:
  4778. description: The name of the Secret resource being referred to.
  4779. type: string
  4780. namespace:
  4781. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4782. type: string
  4783. type: object
  4784. secretRef:
  4785. description: SecretRef to a key in a Secret resource containing client private key to authenticate with Vault using the Cert authentication method
  4786. properties:
  4787. key:
  4788. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4789. type: string
  4790. name:
  4791. description: The name of the Secret resource being referred to.
  4792. type: string
  4793. namespace:
  4794. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4795. type: string
  4796. type: object
  4797. type: object
  4798. jwt:
  4799. description: Jwt authenticates with Vault by passing role and JWT token using the JWT/OIDC authentication method
  4800. properties:
  4801. kubernetesServiceAccountToken:
  4802. description: Optional ServiceAccountToken specifies the Kubernetes service account for which to request a token for with the `TokenRequest` API.
  4803. properties:
  4804. audiences:
  4805. description: Optional audiences field that will be used to request a temporary Kubernetes service account token for the service account referenced by `serviceAccountRef`. Defaults to a single audience `vault` it not specified.
  4806. items:
  4807. type: string
  4808. type: array
  4809. expirationSeconds:
  4810. description: Optional expiration time in seconds that will be used to request a temporary Kubernetes service account token for the service account referenced by `serviceAccountRef`. Defaults to 10 minutes.
  4811. format: int64
  4812. type: integer
  4813. serviceAccountRef:
  4814. description: Service account field containing the name of a kubernetes ServiceAccount.
  4815. properties:
  4816. name:
  4817. description: The name of the ServiceAccount resource being referred to.
  4818. type: string
  4819. namespace:
  4820. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4821. type: string
  4822. required:
  4823. - name
  4824. type: object
  4825. required:
  4826. - serviceAccountRef
  4827. type: object
  4828. path:
  4829. default: jwt
  4830. description: 'Path where the JWT authentication backend is mounted in Vault, e.g: "jwt"'
  4831. type: string
  4832. role:
  4833. description: Role is a JWT role to authenticate using the JWT/OIDC Vault authentication method
  4834. type: string
  4835. secretRef:
  4836. description: Optional SecretRef that refers to a key in a Secret resource containing JWT token to authenticate with Vault using the JWT/OIDC authentication method.
  4837. properties:
  4838. key:
  4839. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4840. type: string
  4841. name:
  4842. description: The name of the Secret resource being referred to.
  4843. type: string
  4844. namespace:
  4845. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4846. type: string
  4847. type: object
  4848. required:
  4849. - path
  4850. type: object
  4851. kubernetes:
  4852. description: Kubernetes authenticates with Vault by passing the ServiceAccount token stored in the named Secret resource to the Vault server.
  4853. properties:
  4854. mountPath:
  4855. default: kubernetes
  4856. description: 'Path where the Kubernetes authentication backend is mounted in Vault, e.g: "kubernetes"'
  4857. type: string
  4858. role:
  4859. description: A required field containing the Vault Role to assume. A Role binds a Kubernetes ServiceAccount with a set of Vault policies.
  4860. type: string
  4861. secretRef:
  4862. description: Optional secret field containing a Kubernetes ServiceAccount JWT used for authenticating with Vault. If a name is specified without a key, `token` is the default. If one is not specified, the one bound to the controller will be used.
  4863. properties:
  4864. key:
  4865. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4866. type: string
  4867. name:
  4868. description: The name of the Secret resource being referred to.
  4869. type: string
  4870. namespace:
  4871. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4872. type: string
  4873. type: object
  4874. serviceAccountRef:
  4875. description: Optional service account field containing the name of a kubernetes ServiceAccount. If the service account is specified, the service account secret token JWT will be used for authenticating with Vault. If the service account selector is not supplied, the secretRef will be used instead.
  4876. properties:
  4877. name:
  4878. description: The name of the ServiceAccount resource being referred to.
  4879. type: string
  4880. namespace:
  4881. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4882. type: string
  4883. required:
  4884. - name
  4885. type: object
  4886. required:
  4887. - mountPath
  4888. - role
  4889. type: object
  4890. ldap:
  4891. description: Ldap authenticates with Vault by passing username/password pair using the LDAP authentication method
  4892. properties:
  4893. path:
  4894. default: ldap
  4895. description: 'Path where the LDAP authentication backend is mounted in Vault, e.g: "ldap"'
  4896. type: string
  4897. secretRef:
  4898. description: SecretRef to a key in a Secret resource containing password for the LDAP user used to authenticate with Vault using the LDAP authentication method
  4899. properties:
  4900. key:
  4901. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4902. type: string
  4903. name:
  4904. description: The name of the Secret resource being referred to.
  4905. type: string
  4906. namespace:
  4907. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4908. type: string
  4909. type: object
  4910. username:
  4911. description: Username is a LDAP user name used to authenticate using the LDAP Vault authentication method
  4912. type: string
  4913. required:
  4914. - path
  4915. - username
  4916. type: object
  4917. tokenSecretRef:
  4918. description: TokenSecretRef authenticates with Vault by presenting a token.
  4919. properties:
  4920. key:
  4921. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4922. type: string
  4923. name:
  4924. description: The name of the Secret resource being referred to.
  4925. type: string
  4926. namespace:
  4927. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4928. type: string
  4929. type: object
  4930. type: object
  4931. caBundle:
  4932. description: PEM encoded CA bundle used to validate Vault server certificate. Only used if the Server URL is using HTTPS protocol. This parameter is ignored for plain HTTP protocol connection. If not set the system root certificates are used to validate the TLS connection.
  4933. format: byte
  4934. type: string
  4935. caProvider:
  4936. description: The provider for the CA bundle to use to validate Vault server certificate.
  4937. properties:
  4938. key:
  4939. description: The key the value inside of the provider type to use, only used with "Secret" type
  4940. type: string
  4941. name:
  4942. description: The name of the object located at the provider type.
  4943. type: string
  4944. namespace:
  4945. description: The namespace the Provider type is in.
  4946. type: string
  4947. type:
  4948. description: The type of provider to use such as "Secret", or "ConfigMap".
  4949. enum:
  4950. - Secret
  4951. - ConfigMap
  4952. type: string
  4953. required:
  4954. - name
  4955. - type
  4956. type: object
  4957. forwardInconsistent:
  4958. description: ForwardInconsistent tells Vault to forward read-after-write requests to the Vault leader instead of simply retrying within a loop. This can increase performance if the option is enabled serverside. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  4959. type: boolean
  4960. namespace:
  4961. description: 'Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows Vault environments to support Secure Multi-tenancy. e.g: "ns1". More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces'
  4962. type: string
  4963. path:
  4964. description: 'Path is the mount path of the Vault KV backend endpoint, e.g: "secret". The v2 KV secret engine version specific "/data" path suffix for fetching secrets from Vault is optional and will be appended if not present in specified path.'
  4965. type: string
  4966. readYourWrites:
  4967. description: ReadYourWrites ensures isolated read-after-write semantics by providing discovered cluster replication states in each request. More information about eventual consistency in Vault can be found here https://www.vaultproject.io/docs/enterprise/consistency
  4968. type: boolean
  4969. server:
  4970. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  4971. type: string
  4972. version:
  4973. default: v2
  4974. description: Version is the Vault KV secret engine version. This can be either "v1" or "v2". Version defaults to "v2".
  4975. enum:
  4976. - v1
  4977. - v2
  4978. type: string
  4979. required:
  4980. - auth
  4981. - server
  4982. type: object
  4983. webhook:
  4984. description: Webhook configures this store to sync secrets using a generic templated webhook
  4985. properties:
  4986. body:
  4987. description: Body
  4988. type: string
  4989. caBundle:
  4990. description: PEM encoded CA bundle used to validate webhook server certificate. Only used if the Server URL is using HTTPS protocol. This parameter is ignored for plain HTTP protocol connection. If not set the system root certificates are used to validate the TLS connection.
  4991. format: byte
  4992. type: string
  4993. caProvider:
  4994. description: The provider for the CA bundle to use to validate webhook server certificate.
  4995. properties:
  4996. key:
  4997. description: The key the value inside of the provider type to use, only used with "Secret" type
  4998. type: string
  4999. name:
  5000. description: The name of the object located at the provider type.
  5001. type: string
  5002. namespace:
  5003. description: The namespace the Provider type is in.
  5004. type: string
  5005. type:
  5006. description: The type of provider to use such as "Secret", or "ConfigMap".
  5007. enum:
  5008. - Secret
  5009. - ConfigMap
  5010. type: string
  5011. required:
  5012. - name
  5013. - type
  5014. type: object
  5015. headers:
  5016. additionalProperties:
  5017. type: string
  5018. description: Headers
  5019. type: object
  5020. method:
  5021. description: Webhook Method
  5022. type: string
  5023. result:
  5024. description: Result formatting
  5025. properties:
  5026. jsonPath:
  5027. description: Json path of return value
  5028. type: string
  5029. type: object
  5030. secrets:
  5031. description: Secrets to fill in templates These secrets will be passed to the templating function as key value pairs under the given name
  5032. items:
  5033. properties:
  5034. name:
  5035. description: Name of this secret in templates
  5036. type: string
  5037. secretRef:
  5038. description: Secret ref to fill in credentials
  5039. properties:
  5040. key:
  5041. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  5042. type: string
  5043. name:
  5044. description: The name of the Secret resource being referred to.
  5045. type: string
  5046. namespace:
  5047. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  5048. type: string
  5049. type: object
  5050. required:
  5051. - name
  5052. - secretRef
  5053. type: object
  5054. type: array
  5055. timeout:
  5056. description: Timeout
  5057. type: string
  5058. url:
  5059. description: Webhook url to call
  5060. type: string
  5061. required:
  5062. - result
  5063. - url
  5064. type: object
  5065. yandexlockbox:
  5066. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  5067. properties:
  5068. apiEndpoint:
  5069. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  5070. type: string
  5071. auth:
  5072. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  5073. properties:
  5074. authorizedKeySecretRef:
  5075. description: The authorized key used for authentication
  5076. properties:
  5077. key:
  5078. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  5079. type: string
  5080. name:
  5081. description: The name of the Secret resource being referred to.
  5082. type: string
  5083. namespace:
  5084. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  5085. type: string
  5086. type: object
  5087. type: object
  5088. caProvider:
  5089. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  5090. properties:
  5091. certSecretRef:
  5092. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  5093. properties:
  5094. key:
  5095. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  5096. type: string
  5097. name:
  5098. description: The name of the Secret resource being referred to.
  5099. type: string
  5100. namespace:
  5101. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  5102. type: string
  5103. type: object
  5104. type: object
  5105. required:
  5106. - auth
  5107. type: object
  5108. type: object
  5109. refreshInterval:
  5110. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  5111. type: integer
  5112. retrySettings:
  5113. description: Used to configure http retries if failed
  5114. properties:
  5115. maxRetries:
  5116. format: int32
  5117. type: integer
  5118. retryInterval:
  5119. type: string
  5120. type: object
  5121. required:
  5122. - provider
  5123. type: object
  5124. status:
  5125. description: SecretStoreStatus defines the observed state of the SecretStore.
  5126. properties:
  5127. capabilities:
  5128. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  5129. type: string
  5130. conditions:
  5131. items:
  5132. properties:
  5133. lastTransitionTime:
  5134. format: date-time
  5135. type: string
  5136. message:
  5137. type: string
  5138. reason:
  5139. type: string
  5140. status:
  5141. type: string
  5142. type:
  5143. type: string
  5144. required:
  5145. - status
  5146. - type
  5147. type: object
  5148. type: array
  5149. type: object
  5150. type: object
  5151. served: true
  5152. storage: true
  5153. subresources:
  5154. status: {}
  5155. conversion:
  5156. strategy: Webhook
  5157. webhook:
  5158. conversionReviewVersions:
  5159. - v1
  5160. clientConfig:
  5161. service:
  5162. name: kubernetes
  5163. namespace: default
  5164. path: /convert
  5165. status:
  5166. acceptedNames:
  5167. kind: ""
  5168. plural: ""
  5169. conditions: []
  5170. storedVersions: []