bundle.yaml 1.9 MB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986498749884989499049914992499349944995499649974998499950005001500250035004500550065007500850095010501150125013501450155016501750185019502050215022502350245025502650275028502950305031503250335034503550365037503850395040504150425043504450455046504750485049505050515052505350545055505650575058505950605061506250635064506550665067506850695070507150725073507450755076507750785079508050815082508350845085508650875088508950905091509250935094509550965097509850995100510151025103510451055106510751085109511051115112511351145115511651175118511951205121512251235124512551265127512851295130513151325133513451355136513751385139514051415142514351445145514651475148514951505151515251535154515551565157515851595160516151625163516451655166516751685169517051715172517351745175517651775178517951805181518251835184518551865187518851895190519151925193519451955196519751985199520052015202520352045205520652075208520952105211521252135214521552165217521852195220522152225223522452255226522752285229523052315232523352345235523652375238523952405241524252435244524552465247524852495250525152525253525452555256525752585259526052615262526352645265526652675268526952705271527252735274527552765277527852795280528152825283528452855286528752885289529052915292529352945295529652975298529953005301530253035304530553065307530853095310531153125313531453155316531753185319532053215322532353245325532653275328532953305331533253335334533553365337533853395340534153425343534453455346534753485349535053515352535353545355535653575358535953605361536253635364536553665367536853695370537153725373537453755376537753785379538053815382538353845385538653875388538953905391539253935394539553965397539853995400540154025403540454055406540754085409541054115412541354145415541654175418541954205421542254235424542554265427542854295430543154325433543454355436543754385439544054415442544354445445544654475448544954505451545254535454545554565457545854595460546154625463546454655466546754685469547054715472547354745475547654775478547954805481548254835484548554865487548854895490549154925493549454955496549754985499550055015502550355045505550655075508550955105511551255135514551555165517551855195520552155225523552455255526552755285529553055315532553355345535553655375538553955405541554255435544554555465547554855495550555155525553555455555556555755585559556055615562556355645565556655675568556955705571557255735574557555765577557855795580558155825583558455855586558755885589559055915592559355945595559655975598559956005601560256035604560556065607560856095610561156125613561456155616561756185619562056215622562356245625562656275628562956305631563256335634563556365637563856395640564156425643564456455646564756485649565056515652565356545655565656575658565956605661566256635664566556665667566856695670567156725673567456755676567756785679568056815682568356845685568656875688568956905691569256935694569556965697569856995700570157025703570457055706570757085709571057115712571357145715571657175718571957205721572257235724572557265727572857295730573157325733573457355736573757385739574057415742574357445745574657475748574957505751575257535754575557565757575857595760576157625763576457655766576757685769577057715772577357745775577657775778577957805781578257835784578557865787578857895790579157925793579457955796579757985799580058015802580358045805580658075808580958105811581258135814581558165817581858195820582158225823582458255826582758285829583058315832583358345835583658375838583958405841584258435844584558465847584858495850585158525853585458555856585758585859586058615862586358645865586658675868586958705871587258735874587558765877587858795880588158825883588458855886588758885889589058915892589358945895589658975898589959005901590259035904590559065907590859095910591159125913591459155916591759185919592059215922592359245925592659275928592959305931593259335934593559365937593859395940594159425943594459455946594759485949595059515952595359545955595659575958595959605961596259635964596559665967596859695970597159725973597459755976597759785979598059815982598359845985598659875988598959905991599259935994599559965997599859996000600160026003600460056006600760086009601060116012601360146015601660176018601960206021602260236024602560266027602860296030603160326033603460356036603760386039604060416042604360446045604660476048604960506051605260536054605560566057605860596060606160626063606460656066606760686069607060716072607360746075607660776078607960806081608260836084608560866087608860896090609160926093609460956096609760986099610061016102610361046105610661076108610961106111611261136114611561166117611861196120612161226123612461256126612761286129613061316132613361346135613661376138613961406141614261436144614561466147614861496150615161526153615461556156615761586159616061616162616361646165616661676168616961706171617261736174617561766177617861796180618161826183618461856186618761886189619061916192619361946195619661976198619962006201620262036204620562066207620862096210621162126213621462156216621762186219622062216222622362246225622662276228622962306231623262336234623562366237623862396240624162426243624462456246624762486249625062516252625362546255625662576258625962606261626262636264626562666267626862696270627162726273627462756276627762786279628062816282628362846285628662876288628962906291629262936294629562966297629862996300630163026303630463056306630763086309631063116312631363146315631663176318631963206321632263236324632563266327632863296330633163326333633463356336633763386339634063416342634363446345634663476348634963506351635263536354635563566357635863596360636163626363636463656366636763686369637063716372637363746375637663776378637963806381638263836384638563866387638863896390639163926393639463956396639763986399640064016402640364046405640664076408640964106411641264136414641564166417641864196420642164226423642464256426642764286429643064316432643364346435643664376438643964406441644264436444644564466447644864496450645164526453645464556456645764586459646064616462646364646465646664676468646964706471647264736474647564766477647864796480648164826483648464856486648764886489649064916492649364946495649664976498649965006501650265036504650565066507650865096510651165126513651465156516651765186519652065216522652365246525652665276528652965306531653265336534653565366537653865396540654165426543654465456546654765486549655065516552655365546555655665576558655965606561656265636564656565666567656865696570657165726573657465756576657765786579658065816582658365846585658665876588658965906591659265936594659565966597659865996600660166026603660466056606660766086609661066116612661366146615661666176618661966206621662266236624662566266627662866296630663166326633663466356636663766386639664066416642664366446645664666476648664966506651665266536654665566566657665866596660666166626663666466656666666766686669667066716672667366746675667666776678667966806681668266836684668566866687668866896690669166926693669466956696669766986699670067016702670367046705670667076708670967106711671267136714671567166717671867196720672167226723672467256726672767286729673067316732673367346735673667376738673967406741674267436744674567466747674867496750675167526753675467556756675767586759676067616762676367646765676667676768676967706771677267736774677567766777677867796780678167826783678467856786678767886789679067916792679367946795679667976798679968006801680268036804680568066807680868096810681168126813681468156816681768186819682068216822682368246825682668276828682968306831683268336834683568366837683868396840684168426843684468456846684768486849685068516852685368546855685668576858685968606861686268636864686568666867686868696870687168726873687468756876687768786879688068816882688368846885688668876888688968906891689268936894689568966897689868996900690169026903690469056906690769086909691069116912691369146915691669176918691969206921692269236924692569266927692869296930693169326933693469356936693769386939694069416942694369446945694669476948694969506951695269536954695569566957695869596960696169626963696469656966696769686969697069716972697369746975697669776978697969806981698269836984698569866987698869896990699169926993699469956996699769986999700070017002700370047005700670077008700970107011701270137014701570167017701870197020702170227023702470257026702770287029703070317032703370347035703670377038703970407041704270437044704570467047704870497050705170527053705470557056705770587059706070617062706370647065706670677068706970707071707270737074707570767077707870797080708170827083708470857086708770887089709070917092709370947095709670977098709971007101710271037104710571067107710871097110711171127113711471157116711771187119712071217122712371247125712671277128712971307131713271337134713571367137713871397140714171427143714471457146714771487149715071517152715371547155715671577158715971607161716271637164716571667167716871697170717171727173717471757176717771787179718071817182718371847185718671877188718971907191719271937194719571967197719871997200720172027203720472057206720772087209721072117212721372147215721672177218721972207221722272237224722572267227722872297230723172327233723472357236723772387239724072417242724372447245724672477248724972507251725272537254725572567257725872597260726172627263726472657266726772687269727072717272727372747275727672777278727972807281728272837284728572867287728872897290729172927293729472957296729772987299730073017302730373047305730673077308730973107311731273137314731573167317731873197320732173227323732473257326732773287329733073317332733373347335733673377338733973407341734273437344734573467347734873497350735173527353735473557356735773587359736073617362736373647365736673677368736973707371737273737374737573767377737873797380738173827383738473857386738773887389739073917392739373947395739673977398739974007401740274037404740574067407740874097410741174127413741474157416741774187419742074217422742374247425742674277428742974307431743274337434743574367437743874397440744174427443744474457446744774487449745074517452745374547455745674577458745974607461746274637464746574667467746874697470747174727473747474757476747774787479748074817482748374847485748674877488748974907491749274937494749574967497749874997500750175027503750475057506750775087509751075117512751375147515751675177518751975207521752275237524752575267527752875297530753175327533753475357536753775387539754075417542754375447545754675477548754975507551755275537554755575567557755875597560756175627563756475657566756775687569757075717572757375747575757675777578757975807581758275837584758575867587758875897590759175927593759475957596759775987599760076017602760376047605760676077608760976107611761276137614761576167617761876197620762176227623762476257626762776287629763076317632763376347635763676377638763976407641764276437644764576467647764876497650765176527653765476557656765776587659766076617662766376647665766676677668766976707671767276737674767576767677767876797680768176827683768476857686768776887689769076917692769376947695769676977698769977007701770277037704770577067707770877097710771177127713771477157716771777187719772077217722772377247725772677277728772977307731773277337734773577367737773877397740774177427743774477457746774777487749775077517752775377547755775677577758775977607761776277637764776577667767776877697770777177727773777477757776777777787779778077817782778377847785778677877788778977907791779277937794779577967797779877997800780178027803780478057806780778087809781078117812781378147815781678177818781978207821782278237824782578267827782878297830783178327833783478357836783778387839784078417842784378447845784678477848784978507851785278537854785578567857785878597860786178627863786478657866786778687869787078717872787378747875787678777878787978807881788278837884788578867887788878897890789178927893789478957896789778987899790079017902790379047905790679077908790979107911791279137914791579167917791879197920792179227923792479257926792779287929793079317932793379347935793679377938793979407941794279437944794579467947794879497950795179527953795479557956795779587959796079617962796379647965796679677968796979707971797279737974797579767977797879797980798179827983798479857986798779887989799079917992799379947995799679977998799980008001800280038004800580068007800880098010801180128013801480158016801780188019802080218022802380248025802680278028802980308031803280338034803580368037803880398040804180428043804480458046804780488049805080518052805380548055805680578058805980608061806280638064806580668067806880698070807180728073807480758076807780788079808080818082808380848085808680878088808980908091809280938094809580968097809880998100810181028103810481058106810781088109811081118112811381148115811681178118811981208121812281238124812581268127812881298130813181328133813481358136813781388139814081418142814381448145814681478148814981508151815281538154815581568157815881598160816181628163816481658166816781688169817081718172817381748175817681778178817981808181818281838184818581868187818881898190819181928193819481958196819781988199820082018202820382048205820682078208820982108211821282138214821582168217821882198220822182228223822482258226822782288229823082318232823382348235823682378238823982408241824282438244824582468247824882498250825182528253825482558256825782588259826082618262826382648265826682678268826982708271827282738274827582768277827882798280828182828283828482858286828782888289829082918292829382948295829682978298829983008301830283038304830583068307830883098310831183128313831483158316831783188319832083218322832383248325832683278328832983308331833283338334833583368337833883398340834183428343834483458346834783488349835083518352835383548355835683578358835983608361836283638364836583668367836883698370837183728373837483758376837783788379838083818382838383848385838683878388838983908391839283938394839583968397839883998400840184028403840484058406840784088409841084118412841384148415841684178418841984208421842284238424842584268427842884298430843184328433843484358436843784388439844084418442844384448445844684478448844984508451845284538454845584568457845884598460846184628463846484658466846784688469847084718472847384748475847684778478847984808481848284838484848584868487848884898490849184928493849484958496849784988499850085018502850385048505850685078508850985108511851285138514851585168517851885198520852185228523852485258526852785288529853085318532853385348535853685378538853985408541854285438544854585468547854885498550855185528553855485558556855785588559856085618562856385648565856685678568856985708571857285738574857585768577857885798580858185828583858485858586858785888589859085918592859385948595859685978598859986008601860286038604860586068607860886098610861186128613861486158616861786188619862086218622862386248625862686278628862986308631863286338634863586368637863886398640864186428643864486458646864786488649865086518652865386548655865686578658865986608661866286638664866586668667866886698670867186728673867486758676867786788679868086818682868386848685868686878688868986908691869286938694869586968697869886998700870187028703870487058706870787088709871087118712871387148715871687178718871987208721872287238724872587268727872887298730873187328733873487358736873787388739874087418742874387448745874687478748874987508751875287538754875587568757875887598760876187628763876487658766876787688769877087718772877387748775877687778778877987808781878287838784878587868787878887898790879187928793879487958796879787988799880088018802880388048805880688078808880988108811881288138814881588168817881888198820882188228823882488258826882788288829883088318832883388348835883688378838883988408841884288438844884588468847884888498850885188528853885488558856885788588859886088618862886388648865886688678868886988708871887288738874887588768877887888798880888188828883888488858886888788888889889088918892889388948895889688978898889989008901890289038904890589068907890889098910891189128913891489158916891789188919892089218922892389248925892689278928892989308931893289338934893589368937893889398940894189428943894489458946894789488949895089518952895389548955895689578958895989608961896289638964896589668967896889698970897189728973897489758976897789788979898089818982898389848985898689878988898989908991899289938994899589968997899889999000900190029003900490059006900790089009901090119012901390149015901690179018901990209021902290239024902590269027902890299030903190329033903490359036903790389039904090419042904390449045904690479048904990509051905290539054905590569057905890599060906190629063906490659066906790689069907090719072907390749075907690779078907990809081908290839084908590869087908890899090909190929093909490959096909790989099910091019102910391049105910691079108910991109111911291139114911591169117911891199120912191229123912491259126912791289129913091319132913391349135913691379138913991409141914291439144914591469147914891499150915191529153915491559156915791589159916091619162916391649165916691679168916991709171917291739174917591769177917891799180918191829183918491859186918791889189919091919192919391949195919691979198919992009201920292039204920592069207920892099210921192129213921492159216921792189219922092219222922392249225922692279228922992309231923292339234923592369237923892399240924192429243924492459246924792489249925092519252925392549255925692579258925992609261926292639264926592669267926892699270927192729273927492759276927792789279928092819282928392849285928692879288928992909291929292939294929592969297929892999300930193029303930493059306930793089309931093119312931393149315931693179318931993209321932293239324932593269327932893299330933193329333933493359336933793389339934093419342934393449345934693479348934993509351935293539354935593569357935893599360936193629363936493659366936793689369937093719372937393749375937693779378937993809381938293839384938593869387938893899390939193929393939493959396939793989399940094019402940394049405940694079408940994109411941294139414941594169417941894199420942194229423942494259426942794289429943094319432943394349435943694379438943994409441944294439444944594469447944894499450945194529453945494559456945794589459946094619462946394649465946694679468946994709471947294739474947594769477947894799480948194829483948494859486948794889489949094919492949394949495949694979498949995009501950295039504950595069507950895099510951195129513951495159516951795189519952095219522952395249525952695279528952995309531953295339534953595369537953895399540954195429543954495459546954795489549955095519552955395549555955695579558955995609561956295639564956595669567956895699570957195729573957495759576957795789579958095819582958395849585958695879588958995909591959295939594959595969597959895999600960196029603960496059606960796089609961096119612961396149615961696179618961996209621962296239624962596269627962896299630963196329633963496359636963796389639964096419642964396449645964696479648964996509651965296539654965596569657965896599660966196629663966496659666966796689669967096719672967396749675967696779678967996809681968296839684968596869687968896899690969196929693969496959696969796989699970097019702970397049705970697079708970997109711971297139714971597169717971897199720972197229723972497259726972797289729973097319732973397349735973697379738973997409741974297439744974597469747974897499750975197529753975497559756975797589759976097619762976397649765976697679768976997709771977297739774977597769777977897799780978197829783978497859786978797889789979097919792979397949795979697979798979998009801980298039804980598069807980898099810981198129813981498159816981798189819982098219822982398249825982698279828982998309831983298339834983598369837983898399840984198429843984498459846984798489849985098519852985398549855985698579858985998609861986298639864986598669867986898699870987198729873987498759876987798789879988098819882988398849885988698879888988998909891989298939894989598969897989898999900990199029903990499059906990799089909991099119912991399149915991699179918991999209921992299239924992599269927992899299930993199329933993499359936993799389939994099419942994399449945994699479948994999509951995299539954995599569957995899599960996199629963996499659966996799689969997099719972997399749975997699779978997999809981998299839984998599869987998899899990999199929993999499959996999799989999100001000110002100031000410005100061000710008100091001010011100121001310014100151001610017100181001910020100211002210023100241002510026100271002810029100301003110032100331003410035100361003710038100391004010041100421004310044100451004610047100481004910050100511005210053100541005510056100571005810059100601006110062100631006410065100661006710068100691007010071100721007310074100751007610077100781007910080100811008210083100841008510086100871008810089100901009110092100931009410095100961009710098100991010010101101021010310104101051010610107101081010910110101111011210113101141011510116101171011810119101201012110122101231012410125101261012710128101291013010131101321013310134101351013610137101381013910140101411014210143101441014510146101471014810149101501015110152101531015410155101561015710158101591016010161101621016310164101651016610167101681016910170101711017210173101741017510176101771017810179101801018110182101831018410185101861018710188101891019010191101921019310194101951019610197101981019910200102011020210203102041020510206102071020810209102101021110212102131021410215102161021710218102191022010221102221022310224102251022610227102281022910230102311023210233102341023510236102371023810239102401024110242102431024410245102461024710248102491025010251102521025310254102551025610257102581025910260102611026210263102641026510266102671026810269102701027110272102731027410275102761027710278102791028010281102821028310284102851028610287102881028910290102911029210293102941029510296102971029810299103001030110302103031030410305103061030710308103091031010311103121031310314103151031610317103181031910320103211032210323103241032510326103271032810329103301033110332103331033410335103361033710338103391034010341103421034310344103451034610347103481034910350103511035210353103541035510356103571035810359103601036110362103631036410365103661036710368103691037010371103721037310374103751037610377103781037910380103811038210383103841038510386103871038810389103901039110392103931039410395103961039710398103991040010401104021040310404104051040610407104081040910410104111041210413104141041510416104171041810419104201042110422104231042410425104261042710428104291043010431104321043310434104351043610437104381043910440104411044210443104441044510446104471044810449104501045110452104531045410455104561045710458104591046010461104621046310464104651046610467104681046910470104711047210473104741047510476104771047810479104801048110482104831048410485104861048710488104891049010491104921049310494104951049610497104981049910500105011050210503105041050510506105071050810509105101051110512105131051410515105161051710518105191052010521105221052310524105251052610527105281052910530105311053210533105341053510536105371053810539105401054110542105431054410545105461054710548105491055010551105521055310554105551055610557105581055910560105611056210563105641056510566105671056810569105701057110572105731057410575105761057710578105791058010581105821058310584105851058610587105881058910590105911059210593105941059510596105971059810599106001060110602106031060410605106061060710608106091061010611106121061310614106151061610617106181061910620106211062210623106241062510626106271062810629106301063110632106331063410635106361063710638106391064010641106421064310644106451064610647106481064910650106511065210653106541065510656106571065810659106601066110662106631066410665106661066710668106691067010671106721067310674106751067610677106781067910680106811068210683106841068510686106871068810689106901069110692106931069410695106961069710698106991070010701107021070310704107051070610707107081070910710107111071210713107141071510716107171071810719107201072110722107231072410725107261072710728107291073010731107321073310734107351073610737107381073910740107411074210743107441074510746107471074810749107501075110752107531075410755107561075710758107591076010761107621076310764107651076610767107681076910770107711077210773107741077510776107771077810779107801078110782107831078410785107861078710788107891079010791107921079310794107951079610797107981079910800108011080210803108041080510806108071080810809108101081110812108131081410815108161081710818108191082010821108221082310824108251082610827108281082910830108311083210833108341083510836108371083810839108401084110842108431084410845108461084710848108491085010851108521085310854108551085610857108581085910860108611086210863108641086510866108671086810869108701087110872108731087410875108761087710878108791088010881108821088310884108851088610887108881088910890108911089210893108941089510896108971089810899109001090110902109031090410905109061090710908109091091010911109121091310914109151091610917109181091910920109211092210923109241092510926109271092810929109301093110932109331093410935109361093710938109391094010941109421094310944109451094610947109481094910950109511095210953109541095510956109571095810959109601096110962109631096410965109661096710968109691097010971109721097310974109751097610977109781097910980109811098210983109841098510986109871098810989109901099110992109931099410995109961099710998109991100011001110021100311004110051100611007110081100911010110111101211013110141101511016110171101811019110201102111022110231102411025110261102711028110291103011031110321103311034110351103611037110381103911040110411104211043110441104511046110471104811049110501105111052110531105411055110561105711058110591106011061110621106311064110651106611067110681106911070110711107211073110741107511076110771107811079110801108111082110831108411085110861108711088110891109011091110921109311094110951109611097110981109911100111011110211103111041110511106111071110811109111101111111112111131111411115111161111711118111191112011121111221112311124111251112611127111281112911130111311113211133111341113511136111371113811139111401114111142111431114411145111461114711148111491115011151111521115311154111551115611157111581115911160111611116211163111641116511166111671116811169111701117111172111731117411175111761117711178111791118011181111821118311184111851118611187111881118911190111911119211193111941119511196111971119811199112001120111202112031120411205112061120711208112091121011211112121121311214112151121611217112181121911220112211122211223112241122511226112271122811229112301123111232112331123411235112361123711238112391124011241112421124311244112451124611247112481124911250112511125211253112541125511256112571125811259112601126111262112631126411265112661126711268112691127011271112721127311274112751127611277112781127911280112811128211283112841128511286112871128811289112901129111292112931129411295112961129711298112991130011301113021130311304113051130611307113081130911310113111131211313113141131511316113171131811319113201132111322113231132411325113261132711328113291133011331113321133311334113351133611337113381133911340113411134211343113441134511346113471134811349113501135111352113531135411355113561135711358113591136011361113621136311364113651136611367113681136911370113711137211373113741137511376113771137811379113801138111382113831138411385113861138711388113891139011391113921139311394113951139611397113981139911400114011140211403114041140511406114071140811409114101141111412114131141411415114161141711418114191142011421114221142311424114251142611427114281142911430114311143211433114341143511436114371143811439114401144111442114431144411445114461144711448114491145011451114521145311454114551145611457114581145911460114611146211463114641146511466114671146811469114701147111472114731147411475114761147711478114791148011481114821148311484114851148611487114881148911490114911149211493114941149511496114971149811499115001150111502115031150411505115061150711508115091151011511115121151311514115151151611517115181151911520115211152211523115241152511526115271152811529115301153111532115331153411535115361153711538115391154011541115421154311544115451154611547115481154911550115511155211553115541155511556115571155811559115601156111562115631156411565115661156711568115691157011571115721157311574115751157611577115781157911580115811158211583115841158511586115871158811589115901159111592115931159411595115961159711598115991160011601116021160311604116051160611607116081160911610116111161211613116141161511616116171161811619116201162111622116231162411625116261162711628116291163011631116321163311634116351163611637116381163911640116411164211643116441164511646116471164811649116501165111652116531165411655116561165711658116591166011661116621166311664116651166611667116681166911670116711167211673116741167511676116771167811679116801168111682116831168411685116861168711688116891169011691116921169311694116951169611697116981169911700117011170211703117041170511706117071170811709117101171111712117131171411715117161171711718117191172011721117221172311724117251172611727117281172911730117311173211733117341173511736117371173811739117401174111742117431174411745117461174711748117491175011751117521175311754117551175611757117581175911760117611176211763117641176511766117671176811769117701177111772117731177411775117761177711778117791178011781117821178311784117851178611787117881178911790117911179211793117941179511796117971179811799118001180111802118031180411805118061180711808118091181011811118121181311814118151181611817118181181911820118211182211823118241182511826118271182811829118301183111832118331183411835118361183711838118391184011841118421184311844118451184611847118481184911850118511185211853118541185511856118571185811859118601186111862118631186411865118661186711868118691187011871118721187311874118751187611877118781187911880118811188211883118841188511886118871188811889118901189111892118931189411895118961189711898118991190011901119021190311904119051190611907119081190911910119111191211913119141191511916119171191811919119201192111922119231192411925119261192711928119291193011931119321193311934119351193611937119381193911940119411194211943119441194511946119471194811949119501195111952119531195411955119561195711958119591196011961119621196311964119651196611967119681196911970119711197211973119741197511976119771197811979119801198111982119831198411985119861198711988119891199011991119921199311994119951199611997119981199912000120011200212003120041200512006120071200812009120101201112012120131201412015120161201712018120191202012021120221202312024120251202612027120281202912030120311203212033120341203512036120371203812039120401204112042120431204412045120461204712048120491205012051120521205312054120551205612057120581205912060120611206212063120641206512066120671206812069120701207112072120731207412075120761207712078120791208012081120821208312084120851208612087120881208912090120911209212093120941209512096120971209812099121001210112102121031210412105121061210712108121091211012111121121211312114121151211612117121181211912120121211212212123121241212512126121271212812129121301213112132121331213412135121361213712138121391214012141121421214312144121451214612147121481214912150121511215212153121541215512156121571215812159121601216112162121631216412165121661216712168121691217012171121721217312174121751217612177121781217912180121811218212183121841218512186121871218812189121901219112192121931219412195121961219712198121991220012201122021220312204122051220612207122081220912210122111221212213122141221512216122171221812219122201222112222122231222412225122261222712228122291223012231122321223312234122351223612237122381223912240122411224212243122441224512246122471224812249122501225112252122531225412255122561225712258122591226012261122621226312264122651226612267122681226912270122711227212273122741227512276122771227812279122801228112282122831228412285122861228712288122891229012291122921229312294122951229612297122981229912300123011230212303123041230512306123071230812309123101231112312123131231412315123161231712318123191232012321123221232312324123251232612327123281232912330123311233212333123341233512336123371233812339123401234112342123431234412345123461234712348123491235012351123521235312354123551235612357123581235912360123611236212363123641236512366123671236812369123701237112372123731237412375123761237712378123791238012381123821238312384123851238612387123881238912390123911239212393123941239512396123971239812399124001240112402124031240412405124061240712408124091241012411124121241312414124151241612417124181241912420124211242212423124241242512426124271242812429124301243112432124331243412435124361243712438124391244012441124421244312444124451244612447124481244912450124511245212453124541245512456124571245812459124601246112462124631246412465124661246712468124691247012471124721247312474124751247612477124781247912480124811248212483124841248512486124871248812489124901249112492124931249412495124961249712498124991250012501125021250312504125051250612507125081250912510125111251212513125141251512516125171251812519125201252112522125231252412525125261252712528125291253012531125321253312534125351253612537125381253912540125411254212543125441254512546125471254812549125501255112552125531255412555125561255712558125591256012561125621256312564125651256612567125681256912570125711257212573125741257512576125771257812579125801258112582125831258412585125861258712588125891259012591125921259312594125951259612597125981259912600126011260212603126041260512606126071260812609126101261112612126131261412615126161261712618126191262012621126221262312624126251262612627126281262912630126311263212633126341263512636126371263812639126401264112642126431264412645126461264712648126491265012651126521265312654126551265612657126581265912660126611266212663126641266512666126671266812669126701267112672126731267412675126761267712678126791268012681126821268312684126851268612687126881268912690126911269212693126941269512696126971269812699127001270112702127031270412705127061270712708127091271012711127121271312714127151271612717127181271912720127211272212723127241272512726127271272812729127301273112732127331273412735127361273712738127391274012741127421274312744127451274612747127481274912750127511275212753127541275512756127571275812759127601276112762127631276412765127661276712768127691277012771127721277312774127751277612777127781277912780127811278212783127841278512786127871278812789127901279112792127931279412795127961279712798127991280012801128021280312804128051280612807128081280912810128111281212813128141281512816128171281812819128201282112822128231282412825128261282712828128291283012831128321283312834128351283612837128381283912840128411284212843128441284512846128471284812849128501285112852128531285412855128561285712858128591286012861128621286312864128651286612867128681286912870128711287212873128741287512876128771287812879128801288112882128831288412885128861288712888128891289012891128921289312894128951289612897128981289912900129011290212903129041290512906129071290812909129101291112912129131291412915129161291712918129191292012921129221292312924129251292612927129281292912930129311293212933129341293512936129371293812939129401294112942129431294412945129461294712948129491295012951129521295312954129551295612957129581295912960129611296212963129641296512966129671296812969129701297112972129731297412975129761297712978129791298012981129821298312984129851298612987129881298912990129911299212993129941299512996129971299812999130001300113002130031300413005130061300713008130091301013011130121301313014130151301613017130181301913020130211302213023130241302513026130271302813029130301303113032130331303413035130361303713038130391304013041130421304313044130451304613047130481304913050130511305213053130541305513056130571305813059130601306113062130631306413065130661306713068130691307013071130721307313074130751307613077130781307913080130811308213083130841308513086130871308813089130901309113092130931309413095130961309713098130991310013101131021310313104131051310613107131081310913110131111311213113131141311513116131171311813119131201312113122131231312413125131261312713128131291313013131131321313313134131351313613137131381313913140131411314213143131441314513146131471314813149131501315113152131531315413155131561315713158131591316013161131621316313164131651316613167131681316913170131711317213173131741317513176131771317813179131801318113182131831318413185131861318713188131891319013191131921319313194131951319613197131981319913200132011320213203132041320513206132071320813209132101321113212132131321413215132161321713218132191322013221132221322313224132251322613227132281322913230132311323213233132341323513236132371323813239132401324113242132431324413245132461324713248132491325013251132521325313254132551325613257132581325913260132611326213263132641326513266132671326813269132701327113272132731327413275132761327713278132791328013281132821328313284132851328613287132881328913290132911329213293132941329513296132971329813299133001330113302133031330413305133061330713308133091331013311133121331313314133151331613317133181331913320133211332213323133241332513326133271332813329133301333113332133331333413335133361333713338133391334013341133421334313344133451334613347133481334913350133511335213353133541335513356133571335813359133601336113362133631336413365133661336713368133691337013371133721337313374133751337613377133781337913380133811338213383133841338513386133871338813389133901339113392133931339413395133961339713398133991340013401134021340313404134051340613407134081340913410134111341213413134141341513416134171341813419134201342113422134231342413425134261342713428134291343013431134321343313434134351343613437134381343913440134411344213443134441344513446134471344813449134501345113452134531345413455134561345713458134591346013461134621346313464134651346613467134681346913470134711347213473134741347513476134771347813479134801348113482134831348413485134861348713488134891349013491134921349313494134951349613497134981349913500135011350213503135041350513506135071350813509135101351113512135131351413515135161351713518135191352013521135221352313524135251352613527135281352913530135311353213533135341353513536135371353813539135401354113542135431354413545135461354713548135491355013551135521355313554135551355613557135581355913560135611356213563135641356513566135671356813569135701357113572135731357413575135761357713578135791358013581135821358313584135851358613587135881358913590135911359213593135941359513596135971359813599136001360113602136031360413605136061360713608136091361013611136121361313614136151361613617136181361913620136211362213623136241362513626136271362813629136301363113632136331363413635136361363713638136391364013641136421364313644136451364613647136481364913650136511365213653136541365513656136571365813659136601366113662136631366413665136661366713668136691367013671136721367313674136751367613677136781367913680136811368213683136841368513686136871368813689136901369113692136931369413695136961369713698136991370013701137021370313704137051370613707137081370913710137111371213713137141371513716137171371813719137201372113722137231372413725137261372713728137291373013731137321373313734137351373613737137381373913740137411374213743137441374513746137471374813749137501375113752137531375413755137561375713758137591376013761137621376313764137651376613767137681376913770137711377213773137741377513776137771377813779137801378113782137831378413785137861378713788137891379013791137921379313794137951379613797137981379913800138011380213803138041380513806138071380813809138101381113812138131381413815138161381713818138191382013821138221382313824138251382613827138281382913830138311383213833138341383513836138371383813839138401384113842138431384413845138461384713848138491385013851138521385313854138551385613857138581385913860138611386213863138641386513866138671386813869138701387113872138731387413875138761387713878138791388013881138821388313884138851388613887138881388913890138911389213893138941389513896138971389813899139001390113902139031390413905139061390713908139091391013911139121391313914139151391613917139181391913920139211392213923139241392513926139271392813929139301393113932139331393413935139361393713938139391394013941139421394313944139451394613947139481394913950139511395213953139541395513956139571395813959139601396113962139631396413965139661396713968139691397013971139721397313974139751397613977139781397913980139811398213983139841398513986139871398813989139901399113992139931399413995139961399713998139991400014001140021400314004140051400614007140081400914010140111401214013140141401514016140171401814019140201402114022140231402414025140261402714028140291403014031140321403314034140351403614037140381403914040140411404214043140441404514046140471404814049140501405114052140531405414055140561405714058140591406014061140621406314064140651406614067140681406914070140711407214073140741407514076140771407814079140801408114082140831408414085140861408714088140891409014091140921409314094140951409614097140981409914100141011410214103141041410514106141071410814109141101411114112141131411414115141161411714118141191412014121141221412314124141251412614127141281412914130141311413214133141341413514136141371413814139141401414114142141431414414145141461414714148141491415014151141521415314154141551415614157141581415914160141611416214163141641416514166141671416814169141701417114172141731417414175141761417714178141791418014181141821418314184141851418614187141881418914190141911419214193141941419514196141971419814199142001420114202142031420414205142061420714208142091421014211142121421314214142151421614217142181421914220142211422214223142241422514226142271422814229142301423114232142331423414235142361423714238142391424014241142421424314244142451424614247142481424914250142511425214253142541425514256142571425814259142601426114262142631426414265142661426714268142691427014271142721427314274142751427614277142781427914280142811428214283142841428514286142871428814289142901429114292142931429414295142961429714298142991430014301143021430314304143051430614307143081430914310143111431214313143141431514316143171431814319143201432114322143231432414325143261432714328143291433014331143321433314334143351433614337143381433914340143411434214343143441434514346143471434814349143501435114352143531435414355143561435714358143591436014361143621436314364143651436614367143681436914370143711437214373143741437514376143771437814379143801438114382143831438414385143861438714388143891439014391143921439314394143951439614397143981439914400144011440214403144041440514406144071440814409144101441114412144131441414415144161441714418144191442014421144221442314424144251442614427144281442914430144311443214433144341443514436144371443814439144401444114442144431444414445144461444714448144491445014451144521445314454144551445614457144581445914460144611446214463144641446514466144671446814469144701447114472144731447414475144761447714478144791448014481144821448314484144851448614487144881448914490144911449214493144941449514496144971449814499145001450114502145031450414505145061450714508145091451014511145121451314514145151451614517145181451914520145211452214523145241452514526145271452814529145301453114532145331453414535145361453714538145391454014541145421454314544145451454614547145481454914550145511455214553145541455514556145571455814559145601456114562145631456414565145661456714568145691457014571145721457314574145751457614577145781457914580145811458214583145841458514586145871458814589145901459114592145931459414595145961459714598145991460014601146021460314604146051460614607146081460914610146111461214613146141461514616146171461814619146201462114622146231462414625146261462714628146291463014631146321463314634146351463614637146381463914640146411464214643146441464514646146471464814649146501465114652146531465414655146561465714658146591466014661146621466314664146651466614667146681466914670146711467214673146741467514676146771467814679146801468114682146831468414685146861468714688146891469014691146921469314694146951469614697146981469914700147011470214703147041470514706147071470814709147101471114712147131471414715147161471714718147191472014721147221472314724147251472614727147281472914730147311473214733147341473514736147371473814739147401474114742147431474414745147461474714748147491475014751147521475314754147551475614757147581475914760147611476214763147641476514766147671476814769147701477114772147731477414775147761477714778147791478014781147821478314784147851478614787147881478914790147911479214793147941479514796147971479814799148001480114802148031480414805148061480714808148091481014811148121481314814148151481614817148181481914820148211482214823148241482514826148271482814829148301483114832148331483414835148361483714838148391484014841148421484314844148451484614847148481484914850148511485214853148541485514856148571485814859148601486114862148631486414865148661486714868148691487014871148721487314874148751487614877148781487914880148811488214883148841488514886148871488814889148901489114892148931489414895148961489714898148991490014901149021490314904149051490614907149081490914910149111491214913149141491514916149171491814919149201492114922149231492414925149261492714928149291493014931149321493314934149351493614937149381493914940149411494214943149441494514946149471494814949149501495114952149531495414955149561495714958149591496014961149621496314964149651496614967149681496914970149711497214973149741497514976149771497814979149801498114982149831498414985149861498714988149891499014991149921499314994149951499614997149981499915000150011500215003150041500515006150071500815009150101501115012150131501415015150161501715018150191502015021150221502315024150251502615027150281502915030150311503215033150341503515036150371503815039150401504115042150431504415045150461504715048150491505015051150521505315054150551505615057150581505915060150611506215063150641506515066150671506815069150701507115072150731507415075150761507715078150791508015081150821508315084150851508615087150881508915090150911509215093150941509515096150971509815099151001510115102151031510415105151061510715108151091511015111151121511315114151151511615117151181511915120151211512215123151241512515126151271512815129151301513115132151331513415135151361513715138151391514015141151421514315144151451514615147151481514915150151511515215153151541515515156151571515815159151601516115162151631516415165151661516715168151691517015171151721517315174151751517615177151781517915180151811518215183151841518515186151871518815189151901519115192151931519415195151961519715198151991520015201152021520315204152051520615207152081520915210152111521215213152141521515216152171521815219152201522115222152231522415225152261522715228152291523015231152321523315234152351523615237152381523915240152411524215243152441524515246152471524815249152501525115252152531525415255152561525715258152591526015261152621526315264152651526615267152681526915270152711527215273152741527515276152771527815279152801528115282152831528415285152861528715288152891529015291152921529315294152951529615297152981529915300153011530215303153041530515306153071530815309153101531115312153131531415315153161531715318153191532015321153221532315324153251532615327153281532915330153311533215333153341533515336153371533815339153401534115342153431534415345153461534715348153491535015351153521535315354153551535615357153581535915360153611536215363153641536515366153671536815369153701537115372153731537415375153761537715378153791538015381153821538315384153851538615387153881538915390153911539215393153941539515396153971539815399154001540115402154031540415405154061540715408154091541015411154121541315414154151541615417154181541915420154211542215423154241542515426154271542815429154301543115432154331543415435154361543715438154391544015441154421544315444154451544615447154481544915450154511545215453154541545515456154571545815459154601546115462154631546415465154661546715468154691547015471154721547315474154751547615477154781547915480154811548215483154841548515486154871548815489154901549115492154931549415495154961549715498154991550015501155021550315504155051550615507155081550915510155111551215513155141551515516155171551815519155201552115522155231552415525155261552715528155291553015531155321553315534155351553615537155381553915540155411554215543155441554515546155471554815549155501555115552155531555415555155561555715558155591556015561155621556315564155651556615567155681556915570155711557215573155741557515576155771557815579155801558115582155831558415585155861558715588155891559015591155921559315594155951559615597155981559915600156011560215603156041560515606156071560815609156101561115612156131561415615156161561715618156191562015621156221562315624156251562615627156281562915630156311563215633156341563515636156371563815639156401564115642156431564415645156461564715648156491565015651156521565315654156551565615657156581565915660156611566215663156641566515666156671566815669156701567115672156731567415675156761567715678156791568015681156821568315684156851568615687156881568915690156911569215693156941569515696156971569815699157001570115702157031570415705157061570715708157091571015711157121571315714157151571615717157181571915720157211572215723157241572515726157271572815729157301573115732157331573415735157361573715738157391574015741157421574315744157451574615747157481574915750157511575215753157541575515756157571575815759157601576115762157631576415765157661576715768157691577015771157721577315774157751577615777157781577915780157811578215783157841578515786157871578815789157901579115792157931579415795157961579715798157991580015801158021580315804158051580615807158081580915810158111581215813158141581515816158171581815819158201582115822158231582415825158261582715828158291583015831158321583315834158351583615837158381583915840158411584215843158441584515846158471584815849158501585115852158531585415855158561585715858158591586015861158621586315864158651586615867158681586915870158711587215873158741587515876158771587815879158801588115882158831588415885158861588715888158891589015891158921589315894158951589615897158981589915900159011590215903159041590515906159071590815909159101591115912159131591415915159161591715918159191592015921159221592315924159251592615927159281592915930159311593215933159341593515936159371593815939159401594115942159431594415945159461594715948159491595015951159521595315954159551595615957159581595915960159611596215963159641596515966159671596815969159701597115972159731597415975159761597715978159791598015981159821598315984159851598615987159881598915990159911599215993159941599515996159971599815999160001600116002160031600416005160061600716008160091601016011160121601316014160151601616017160181601916020160211602216023160241602516026160271602816029160301603116032160331603416035160361603716038160391604016041160421604316044160451604616047160481604916050160511605216053160541605516056160571605816059160601606116062160631606416065160661606716068160691607016071160721607316074160751607616077160781607916080160811608216083160841608516086160871608816089160901609116092160931609416095160961609716098160991610016101161021610316104161051610616107161081610916110161111611216113161141611516116161171611816119161201612116122161231612416125161261612716128161291613016131161321613316134161351613616137161381613916140161411614216143161441614516146161471614816149161501615116152161531615416155161561615716158161591616016161161621616316164161651616616167161681616916170161711617216173161741617516176161771617816179161801618116182161831618416185161861618716188161891619016191161921619316194161951619616197161981619916200162011620216203162041620516206162071620816209162101621116212162131621416215162161621716218162191622016221162221622316224162251622616227162281622916230162311623216233162341623516236162371623816239162401624116242162431624416245162461624716248162491625016251162521625316254162551625616257162581625916260162611626216263162641626516266162671626816269162701627116272162731627416275162761627716278162791628016281162821628316284162851628616287162881628916290162911629216293162941629516296162971629816299163001630116302163031630416305163061630716308163091631016311163121631316314163151631616317163181631916320163211632216323163241632516326163271632816329163301633116332163331633416335163361633716338163391634016341163421634316344163451634616347163481634916350163511635216353163541635516356163571635816359163601636116362163631636416365163661636716368163691637016371163721637316374163751637616377163781637916380163811638216383163841638516386163871638816389163901639116392163931639416395163961639716398163991640016401164021640316404164051640616407164081640916410164111641216413164141641516416164171641816419164201642116422164231642416425164261642716428164291643016431164321643316434164351643616437164381643916440164411644216443164441644516446164471644816449164501645116452164531645416455164561645716458164591646016461164621646316464164651646616467164681646916470164711647216473164741647516476164771647816479164801648116482164831648416485164861648716488164891649016491164921649316494164951649616497164981649916500165011650216503165041650516506165071650816509165101651116512165131651416515165161651716518165191652016521165221652316524165251652616527165281652916530165311653216533165341653516536165371653816539165401654116542165431654416545165461654716548165491655016551165521655316554165551655616557165581655916560165611656216563165641656516566165671656816569165701657116572165731657416575165761657716578165791658016581165821658316584165851658616587165881658916590165911659216593165941659516596165971659816599166001660116602166031660416605166061660716608166091661016611166121661316614166151661616617166181661916620166211662216623166241662516626166271662816629166301663116632166331663416635166361663716638166391664016641166421664316644166451664616647166481664916650166511665216653166541665516656166571665816659166601666116662166631666416665166661666716668166691667016671166721667316674166751667616677166781667916680166811668216683166841668516686166871668816689166901669116692166931669416695166961669716698166991670016701167021670316704167051670616707167081670916710167111671216713167141671516716167171671816719167201672116722167231672416725167261672716728167291673016731167321673316734167351673616737167381673916740167411674216743167441674516746167471674816749167501675116752167531675416755167561675716758167591676016761167621676316764167651676616767167681676916770167711677216773167741677516776167771677816779167801678116782167831678416785167861678716788167891679016791167921679316794167951679616797167981679916800168011680216803168041680516806168071680816809168101681116812168131681416815168161681716818168191682016821168221682316824168251682616827168281682916830168311683216833168341683516836168371683816839168401684116842168431684416845168461684716848168491685016851168521685316854168551685616857168581685916860168611686216863168641686516866168671686816869168701687116872168731687416875168761687716878168791688016881168821688316884168851688616887168881688916890168911689216893168941689516896168971689816899169001690116902169031690416905169061690716908169091691016911169121691316914169151691616917169181691916920169211692216923169241692516926169271692816929169301693116932169331693416935169361693716938169391694016941169421694316944169451694616947169481694916950169511695216953169541695516956169571695816959169601696116962169631696416965169661696716968169691697016971169721697316974169751697616977169781697916980169811698216983169841698516986169871698816989169901699116992169931699416995169961699716998169991700017001170021700317004170051700617007170081700917010170111701217013170141701517016170171701817019170201702117022170231702417025170261702717028170291703017031170321703317034170351703617037170381703917040170411704217043170441704517046170471704817049170501705117052170531705417055170561705717058170591706017061170621706317064170651706617067170681706917070170711707217073170741707517076170771707817079170801708117082170831708417085170861708717088170891709017091170921709317094170951709617097170981709917100171011710217103171041710517106171071710817109171101711117112171131711417115171161711717118171191712017121171221712317124171251712617127171281712917130171311713217133171341713517136171371713817139171401714117142171431714417145171461714717148171491715017151171521715317154171551715617157171581715917160171611716217163171641716517166171671716817169171701717117172171731717417175171761717717178171791718017181171821718317184171851718617187171881718917190171911719217193171941719517196171971719817199172001720117202172031720417205172061720717208172091721017211172121721317214172151721617217172181721917220172211722217223172241722517226172271722817229172301723117232172331723417235172361723717238172391724017241172421724317244172451724617247172481724917250172511725217253172541725517256172571725817259172601726117262172631726417265172661726717268172691727017271172721727317274172751727617277172781727917280172811728217283172841728517286172871728817289172901729117292172931729417295172961729717298172991730017301173021730317304173051730617307173081730917310173111731217313173141731517316173171731817319173201732117322173231732417325173261732717328173291733017331173321733317334173351733617337173381733917340173411734217343173441734517346173471734817349173501735117352173531735417355173561735717358173591736017361173621736317364173651736617367173681736917370173711737217373173741737517376173771737817379173801738117382173831738417385173861738717388173891739017391173921739317394173951739617397173981739917400174011740217403174041740517406174071740817409174101741117412174131741417415174161741717418174191742017421174221742317424174251742617427174281742917430174311743217433174341743517436174371743817439174401744117442174431744417445174461744717448174491745017451174521745317454174551745617457174581745917460174611746217463174641746517466174671746817469174701747117472174731747417475174761747717478174791748017481174821748317484174851748617487174881748917490174911749217493174941749517496174971749817499175001750117502175031750417505175061750717508175091751017511175121751317514175151751617517175181751917520175211752217523175241752517526175271752817529175301753117532175331753417535175361753717538175391754017541175421754317544175451754617547175481754917550175511755217553175541755517556175571755817559175601756117562175631756417565175661756717568175691757017571175721757317574175751757617577175781757917580175811758217583175841758517586175871758817589175901759117592175931759417595175961759717598175991760017601176021760317604176051760617607176081760917610176111761217613176141761517616176171761817619176201762117622176231762417625176261762717628176291763017631176321763317634176351763617637176381763917640176411764217643176441764517646176471764817649176501765117652176531765417655176561765717658176591766017661176621766317664176651766617667176681766917670176711767217673176741767517676176771767817679176801768117682176831768417685176861768717688176891769017691176921769317694176951769617697176981769917700177011770217703177041770517706177071770817709177101771117712177131771417715177161771717718177191772017721177221772317724177251772617727177281772917730177311773217733177341773517736177371773817739177401774117742177431774417745177461774717748177491775017751177521775317754177551775617757177581775917760177611776217763177641776517766177671776817769177701777117772177731777417775177761777717778177791778017781177821778317784177851778617787177881778917790177911779217793177941779517796177971779817799178001780117802178031780417805178061780717808178091781017811178121781317814178151781617817178181781917820178211782217823178241782517826178271782817829178301783117832178331783417835178361783717838178391784017841178421784317844178451784617847178481784917850178511785217853178541785517856178571785817859178601786117862178631786417865178661786717868178691787017871178721787317874178751787617877178781787917880178811788217883178841788517886178871788817889178901789117892178931789417895178961789717898178991790017901179021790317904179051790617907179081790917910179111791217913179141791517916179171791817919179201792117922179231792417925179261792717928179291793017931179321793317934179351793617937179381793917940179411794217943179441794517946179471794817949179501795117952179531795417955179561795717958179591796017961179621796317964179651796617967179681796917970179711797217973179741797517976179771797817979179801798117982179831798417985179861798717988179891799017991179921799317994179951799617997179981799918000180011800218003180041800518006180071800818009180101801118012180131801418015180161801718018180191802018021180221802318024180251802618027180281802918030180311803218033180341803518036180371803818039180401804118042180431804418045180461804718048180491805018051180521805318054180551805618057180581805918060180611806218063180641806518066180671806818069180701807118072180731807418075180761807718078180791808018081180821808318084180851808618087180881808918090180911809218093180941809518096180971809818099181001810118102181031810418105181061810718108181091811018111181121811318114181151811618117181181811918120181211812218123181241812518126181271812818129181301813118132181331813418135181361813718138181391814018141181421814318144181451814618147181481814918150181511815218153181541815518156181571815818159181601816118162181631816418165181661816718168181691817018171181721817318174181751817618177181781817918180181811818218183181841818518186181871818818189181901819118192181931819418195181961819718198181991820018201182021820318204182051820618207182081820918210182111821218213182141821518216182171821818219182201822118222182231822418225182261822718228182291823018231182321823318234182351823618237182381823918240182411824218243182441824518246182471824818249182501825118252182531825418255182561825718258182591826018261182621826318264182651826618267182681826918270182711827218273182741827518276182771827818279182801828118282182831828418285182861828718288182891829018291182921829318294182951829618297182981829918300183011830218303183041830518306183071830818309183101831118312183131831418315183161831718318183191832018321183221832318324183251832618327183281832918330183311833218333183341833518336183371833818339183401834118342183431834418345183461834718348183491835018351183521835318354183551835618357183581835918360183611836218363183641836518366183671836818369183701837118372183731837418375183761837718378183791838018381183821838318384183851838618387183881838918390183911839218393183941839518396183971839818399184001840118402184031840418405184061840718408184091841018411184121841318414184151841618417184181841918420184211842218423184241842518426184271842818429184301843118432184331843418435184361843718438184391844018441184421844318444184451844618447184481844918450184511845218453184541845518456184571845818459184601846118462184631846418465184661846718468184691847018471184721847318474184751847618477184781847918480184811848218483184841848518486184871848818489184901849118492184931849418495184961849718498184991850018501185021850318504185051850618507185081850918510185111851218513185141851518516185171851818519185201852118522185231852418525185261852718528185291853018531185321853318534185351853618537185381853918540185411854218543185441854518546185471854818549185501855118552185531855418555185561855718558185591856018561185621856318564185651856618567185681856918570185711857218573185741857518576185771857818579185801858118582185831858418585185861858718588185891859018591185921859318594185951859618597185981859918600186011860218603186041860518606186071860818609186101861118612186131861418615186161861718618186191862018621186221862318624186251862618627186281862918630186311863218633186341863518636186371863818639186401864118642186431864418645186461864718648186491865018651186521865318654186551865618657186581865918660186611866218663186641866518666186671866818669186701867118672186731867418675186761867718678186791868018681186821868318684186851868618687186881868918690186911869218693186941869518696186971869818699187001870118702187031870418705187061870718708187091871018711187121871318714187151871618717187181871918720187211872218723187241872518726187271872818729187301873118732187331873418735187361873718738187391874018741187421874318744187451874618747187481874918750187511875218753187541875518756187571875818759187601876118762187631876418765187661876718768187691877018771187721877318774187751877618777187781877918780187811878218783187841878518786187871878818789187901879118792187931879418795187961879718798187991880018801188021880318804188051880618807188081880918810188111881218813188141881518816188171881818819188201882118822188231882418825188261882718828188291883018831188321883318834188351883618837188381883918840188411884218843188441884518846188471884818849188501885118852188531885418855188561885718858188591886018861188621886318864188651886618867188681886918870188711887218873188741887518876188771887818879188801888118882188831888418885188861888718888188891889018891188921889318894188951889618897188981889918900189011890218903189041890518906189071890818909189101891118912189131891418915189161891718918189191892018921189221892318924189251892618927189281892918930189311893218933189341893518936189371893818939189401894118942189431894418945189461894718948189491895018951189521895318954189551895618957189581895918960189611896218963189641896518966189671896818969189701897118972189731897418975189761897718978189791898018981189821898318984189851898618987189881898918990189911899218993189941899518996189971899818999190001900119002190031900419005190061900719008190091901019011190121901319014190151901619017190181901919020190211902219023190241902519026190271902819029190301903119032190331903419035190361903719038190391904019041190421904319044190451904619047190481904919050190511905219053190541905519056190571905819059190601906119062190631906419065190661906719068190691907019071190721907319074190751907619077190781907919080190811908219083190841908519086190871908819089190901909119092190931909419095190961909719098190991910019101191021910319104191051910619107191081910919110191111911219113191141911519116191171911819119191201912119122191231912419125191261912719128191291913019131191321913319134191351913619137191381913919140191411914219143191441914519146191471914819149191501915119152191531915419155191561915719158191591916019161191621916319164191651916619167191681916919170191711917219173191741917519176191771917819179191801918119182191831918419185191861918719188191891919019191191921919319194191951919619197191981919919200192011920219203192041920519206192071920819209192101921119212192131921419215192161921719218192191922019221192221922319224192251922619227192281922919230192311923219233192341923519236192371923819239192401924119242192431924419245192461924719248192491925019251192521925319254192551925619257192581925919260192611926219263192641926519266192671926819269192701927119272192731927419275192761927719278192791928019281192821928319284192851928619287192881928919290192911929219293192941929519296192971929819299193001930119302193031930419305193061930719308193091931019311193121931319314193151931619317193181931919320193211932219323193241932519326193271932819329193301933119332193331933419335193361933719338193391934019341193421934319344193451934619347193481934919350193511935219353193541935519356193571935819359193601936119362193631936419365193661936719368193691937019371193721937319374193751937619377193781937919380193811938219383193841938519386193871938819389193901939119392193931939419395193961939719398193991940019401194021940319404194051940619407194081940919410194111941219413194141941519416194171941819419194201942119422194231942419425194261942719428194291943019431194321943319434194351943619437194381943919440194411944219443194441944519446194471944819449194501945119452194531945419455194561945719458194591946019461194621946319464194651946619467194681946919470194711947219473194741947519476194771947819479194801948119482194831948419485194861948719488194891949019491194921949319494194951949619497194981949919500195011950219503195041950519506195071950819509195101951119512195131951419515195161951719518195191952019521195221952319524195251952619527195281952919530195311953219533195341953519536195371953819539195401954119542195431954419545195461954719548195491955019551195521955319554195551955619557195581955919560195611956219563195641956519566195671956819569195701957119572195731957419575195761957719578195791958019581195821958319584195851958619587195881958919590195911959219593195941959519596195971959819599196001960119602196031960419605196061960719608196091961019611196121961319614196151961619617196181961919620196211962219623196241962519626196271962819629196301963119632196331963419635196361963719638196391964019641196421964319644196451964619647196481964919650196511965219653196541965519656196571965819659196601966119662196631966419665196661966719668196691967019671196721967319674196751967619677196781967919680196811968219683196841968519686196871968819689196901969119692196931969419695196961969719698196991970019701197021970319704197051970619707197081970919710197111971219713197141971519716197171971819719197201972119722197231972419725197261972719728197291973019731197321973319734197351973619737197381973919740197411974219743197441974519746197471974819749197501975119752197531975419755197561975719758197591976019761197621976319764197651976619767197681976919770197711977219773197741977519776197771977819779197801978119782197831978419785197861978719788197891979019791197921979319794197951979619797197981979919800198011980219803198041980519806198071980819809198101981119812198131981419815198161981719818198191982019821198221982319824198251982619827198281982919830198311983219833198341983519836198371983819839198401984119842198431984419845198461984719848198491985019851198521985319854198551985619857198581985919860198611986219863198641986519866198671986819869198701987119872198731987419875198761987719878198791988019881198821988319884198851988619887198881988919890198911989219893198941989519896198971989819899199001990119902199031990419905199061990719908199091991019911199121991319914199151991619917199181991919920199211992219923199241992519926199271992819929199301993119932199331993419935199361993719938199391994019941199421994319944199451994619947199481994919950199511995219953199541995519956199571995819959199601996119962199631996419965199661996719968199691997019971199721997319974199751997619977199781997919980199811998219983199841998519986199871998819989199901999119992199931999419995199961999719998199992000020001200022000320004200052000620007200082000920010200112001220013200142001520016200172001820019200202002120022200232002420025200262002720028200292003020031200322003320034200352003620037200382003920040200412004220043200442004520046200472004820049200502005120052200532005420055200562005720058200592006020061200622006320064200652006620067200682006920070200712007220073200742007520076200772007820079200802008120082200832008420085200862008720088200892009020091200922009320094200952009620097200982009920100201012010220103201042010520106201072010820109201102011120112201132011420115201162011720118201192012020121201222012320124201252012620127201282012920130201312013220133201342013520136201372013820139201402014120142201432014420145201462014720148201492015020151201522015320154201552015620157201582015920160201612016220163201642016520166201672016820169201702017120172201732017420175201762017720178201792018020181201822018320184201852018620187201882018920190201912019220193201942019520196201972019820199202002020120202202032020420205202062020720208202092021020211202122021320214202152021620217202182021920220202212022220223202242022520226202272022820229202302023120232202332023420235202362023720238202392024020241202422024320244202452024620247202482024920250202512025220253202542025520256202572025820259202602026120262202632026420265202662026720268202692027020271202722027320274202752027620277202782027920280202812028220283202842028520286202872028820289202902029120292202932029420295202962029720298202992030020301203022030320304203052030620307203082030920310203112031220313203142031520316203172031820319203202032120322203232032420325203262032720328203292033020331203322033320334203352033620337203382033920340203412034220343203442034520346203472034820349203502035120352203532035420355203562035720358203592036020361203622036320364203652036620367203682036920370203712037220373203742037520376203772037820379203802038120382203832038420385203862038720388203892039020391203922039320394203952039620397203982039920400204012040220403204042040520406204072040820409204102041120412204132041420415204162041720418204192042020421204222042320424204252042620427204282042920430204312043220433204342043520436204372043820439204402044120442204432044420445204462044720448204492045020451204522045320454204552045620457204582045920460204612046220463204642046520466204672046820469204702047120472204732047420475204762047720478204792048020481204822048320484204852048620487204882048920490204912049220493204942049520496204972049820499205002050120502205032050420505205062050720508205092051020511205122051320514205152051620517205182051920520205212052220523205242052520526205272052820529205302053120532205332053420535205362053720538205392054020541205422054320544205452054620547205482054920550205512055220553205542055520556205572055820559205602056120562205632056420565205662056720568205692057020571205722057320574205752057620577205782057920580205812058220583205842058520586205872058820589205902059120592205932059420595205962059720598205992060020601206022060320604206052060620607206082060920610206112061220613206142061520616206172061820619206202062120622206232062420625206262062720628206292063020631206322063320634206352063620637206382063920640206412064220643206442064520646206472064820649206502065120652206532065420655206562065720658206592066020661206622066320664206652066620667206682066920670206712067220673206742067520676206772067820679206802068120682206832068420685206862068720688206892069020691206922069320694206952069620697206982069920700207012070220703207042070520706207072070820709207102071120712207132071420715207162071720718207192072020721207222072320724207252072620727207282072920730207312073220733207342073520736207372073820739207402074120742207432074420745207462074720748207492075020751207522075320754207552075620757207582075920760207612076220763207642076520766207672076820769207702077120772207732077420775207762077720778207792078020781207822078320784207852078620787207882078920790207912079220793207942079520796207972079820799208002080120802208032080420805208062080720808208092081020811208122081320814208152081620817208182081920820208212082220823208242082520826208272082820829208302083120832208332083420835208362083720838208392084020841208422084320844208452084620847208482084920850208512085220853208542085520856208572085820859208602086120862208632086420865208662086720868208692087020871208722087320874208752087620877208782087920880208812088220883208842088520886208872088820889208902089120892208932089420895208962089720898208992090020901209022090320904209052090620907209082090920910209112091220913209142091520916209172091820919209202092120922209232092420925209262092720928209292093020931209322093320934209352093620937209382093920940209412094220943209442094520946209472094820949209502095120952209532095420955209562095720958209592096020961209622096320964209652096620967209682096920970209712097220973209742097520976209772097820979209802098120982209832098420985209862098720988209892099020991209922099320994209952099620997209982099921000210012100221003210042100521006210072100821009210102101121012210132101421015210162101721018210192102021021210222102321024210252102621027210282102921030210312103221033210342103521036210372103821039210402104121042210432104421045210462104721048210492105021051210522105321054210552105621057210582105921060210612106221063210642106521066210672106821069210702107121072210732107421075210762107721078210792108021081210822108321084210852108621087210882108921090210912109221093210942109521096210972109821099211002110121102211032110421105211062110721108211092111021111211122111321114211152111621117211182111921120211212112221123211242112521126211272112821129211302113121132211332113421135211362113721138211392114021141211422114321144211452114621147211482114921150211512115221153211542115521156211572115821159211602116121162211632116421165211662116721168211692117021171211722117321174211752117621177211782117921180211812118221183211842118521186211872118821189211902119121192211932119421195211962119721198211992120021201212022120321204212052120621207212082120921210212112121221213212142121521216212172121821219212202122121222212232122421225212262122721228212292123021231212322123321234212352123621237212382123921240212412124221243212442124521246212472124821249212502125121252212532125421255212562125721258212592126021261212622126321264212652126621267212682126921270212712127221273212742127521276212772127821279212802128121282212832128421285212862128721288212892129021291212922129321294212952129621297212982129921300213012130221303213042130521306213072130821309213102131121312213132131421315213162131721318213192132021321213222132321324213252132621327213282132921330213312133221333213342133521336213372133821339213402134121342213432134421345213462134721348213492135021351213522135321354213552135621357213582135921360213612136221363213642136521366213672136821369213702137121372213732137421375213762137721378213792138021381213822138321384213852138621387213882138921390213912139221393213942139521396213972139821399214002140121402214032140421405214062140721408214092141021411214122141321414214152141621417214182141921420214212142221423214242142521426214272142821429214302143121432214332143421435214362143721438214392144021441214422144321444214452144621447214482144921450214512145221453214542145521456214572145821459214602146121462214632146421465214662146721468214692147021471214722147321474214752147621477214782147921480214812148221483214842148521486214872148821489214902149121492214932149421495214962149721498214992150021501215022150321504215052150621507215082150921510215112151221513215142151521516215172151821519215202152121522215232152421525215262152721528215292153021531215322153321534215352153621537215382153921540215412154221543215442154521546215472154821549215502155121552215532155421555215562155721558215592156021561215622156321564215652156621567215682156921570215712157221573215742157521576215772157821579215802158121582215832158421585215862158721588215892159021591215922159321594215952159621597215982159921600216012160221603216042160521606216072160821609216102161121612216132161421615216162161721618216192162021621216222162321624216252162621627216282162921630216312163221633216342163521636216372163821639216402164121642216432164421645216462164721648216492165021651216522165321654216552165621657216582165921660216612166221663216642166521666216672166821669216702167121672216732167421675216762167721678216792168021681216822168321684216852168621687216882168921690216912169221693216942169521696216972169821699217002170121702217032170421705217062170721708217092171021711217122171321714217152171621717217182171921720217212172221723217242172521726217272172821729217302173121732217332173421735217362173721738217392174021741217422174321744217452174621747217482174921750217512175221753217542175521756217572175821759217602176121762217632176421765217662176721768217692177021771217722177321774217752177621777217782177921780217812178221783217842178521786217872178821789217902179121792217932179421795217962179721798217992180021801218022180321804218052180621807218082180921810218112181221813218142181521816218172181821819218202182121822218232182421825218262182721828218292183021831218322183321834218352183621837218382183921840218412184221843218442184521846218472184821849218502185121852218532185421855218562185721858218592186021861218622186321864218652186621867218682186921870218712187221873218742187521876218772187821879218802188121882218832188421885218862188721888218892189021891218922189321894218952189621897218982189921900219012190221903219042190521906219072190821909219102191121912219132191421915219162191721918219192192021921219222192321924219252192621927219282192921930219312193221933219342193521936219372193821939219402194121942219432194421945219462194721948219492195021951219522195321954219552195621957219582195921960219612196221963219642196521966219672196821969219702197121972219732197421975219762197721978219792198021981219822198321984219852198621987219882198921990219912199221993219942199521996219972199821999220002200122002220032200422005220062200722008220092201022011220122201322014220152201622017220182201922020220212202222023220242202522026220272202822029220302203122032220332203422035220362203722038220392204022041220422204322044220452204622047220482204922050220512205222053220542205522056220572205822059220602206122062220632206422065220662206722068220692207022071220722207322074220752207622077220782207922080220812208222083220842208522086220872208822089220902209122092220932209422095220962209722098220992210022101221022210322104221052210622107221082210922110221112211222113221142211522116221172211822119221202212122122221232212422125221262212722128221292213022131221322213322134221352213622137221382213922140221412214222143221442214522146221472214822149221502215122152221532215422155221562215722158221592216022161221622216322164221652216622167221682216922170221712217222173221742217522176221772217822179221802218122182221832218422185221862218722188221892219022191221922219322194221952219622197221982219922200222012220222203222042220522206222072220822209222102221122212222132221422215222162221722218222192222022221222222222322224222252222622227222282222922230222312223222233222342223522236222372223822239222402224122242222432224422245222462224722248222492225022251222522225322254222552225622257222582225922260222612226222263222642226522266222672226822269222702227122272222732227422275222762227722278222792228022281222822228322284222852228622287222882228922290222912229222293222942229522296222972229822299223002230122302223032230422305223062230722308223092231022311223122231322314223152231622317223182231922320223212232222323223242232522326223272232822329223302233122332223332233422335223362233722338223392234022341223422234322344223452234622347223482234922350223512235222353223542235522356223572235822359223602236122362223632236422365223662236722368223692237022371223722237322374223752237622377223782237922380223812238222383223842238522386223872238822389223902239122392223932239422395223962239722398223992240022401224022240322404224052240622407224082240922410224112241222413224142241522416224172241822419224202242122422224232242422425224262242722428224292243022431224322243322434224352243622437224382243922440224412244222443224442244522446224472244822449224502245122452224532245422455224562245722458224592246022461224622246322464224652246622467224682246922470224712247222473224742247522476224772247822479224802248122482224832248422485224862248722488224892249022491224922249322494224952249622497224982249922500225012250222503225042250522506225072250822509225102251122512225132251422515225162251722518225192252022521225222252322524225252252622527225282252922530225312253222533225342253522536225372253822539225402254122542225432254422545225462254722548225492255022551225522255322554225552255622557225582255922560225612256222563225642256522566225672256822569225702257122572225732257422575225762257722578225792258022581225822258322584225852258622587225882258922590225912259222593225942259522596225972259822599226002260122602226032260422605226062260722608226092261022611226122261322614226152261622617226182261922620226212262222623226242262522626226272262822629226302263122632226332263422635226362263722638226392264022641226422264322644226452264622647226482264922650226512265222653226542265522656226572265822659226602266122662226632266422665226662266722668226692267022671226722267322674226752267622677226782267922680226812268222683226842268522686226872268822689226902269122692226932269422695226962269722698226992270022701227022270322704227052270622707227082270922710227112271222713227142271522716227172271822719227202272122722227232272422725227262272722728227292273022731227322273322734227352273622737227382273922740227412274222743227442274522746227472274822749227502275122752227532275422755227562275722758227592276022761227622276322764227652276622767227682276922770227712277222773227742277522776227772277822779227802278122782227832278422785227862278722788227892279022791227922279322794227952279622797227982279922800228012280222803228042280522806228072280822809228102281122812228132281422815228162281722818228192282022821228222282322824228252282622827228282282922830228312283222833228342283522836228372283822839228402284122842228432284422845228462284722848228492285022851228522285322854228552285622857228582285922860228612286222863228642286522866228672286822869228702287122872228732287422875228762287722878228792288022881228822288322884228852288622887228882288922890228912289222893228942289522896228972289822899229002290122902229032290422905229062290722908229092291022911229122291322914229152291622917229182291922920229212292222923229242292522926229272292822929229302293122932229332293422935229362293722938229392294022941229422294322944229452294622947229482294922950229512295222953229542295522956229572295822959229602296122962229632296422965229662296722968229692297022971229722297322974229752297622977229782297922980229812298222983229842298522986229872298822989229902299122992229932299422995229962299722998229992300023001230022300323004230052300623007230082300923010230112301223013230142301523016230172301823019230202302123022230232302423025230262302723028230292303023031230322303323034230352303623037230382303923040230412304223043230442304523046230472304823049230502305123052230532305423055230562305723058230592306023061230622306323064230652306623067230682306923070230712307223073230742307523076230772307823079230802308123082230832308423085230862308723088230892309023091230922309323094230952309623097230982309923100231012310223103231042310523106231072310823109231102311123112231132311423115231162311723118231192312023121231222312323124231252312623127231282312923130231312313223133231342313523136231372313823139231402314123142231432314423145231462314723148231492315023151231522315323154231552315623157231582315923160231612316223163231642316523166231672316823169231702317123172231732317423175231762317723178231792318023181231822318323184231852318623187231882318923190231912319223193231942319523196231972319823199232002320123202232032320423205232062320723208232092321023211232122321323214232152321623217232182321923220232212322223223232242322523226232272322823229232302323123232232332323423235232362323723238232392324023241232422324323244232452324623247232482324923250232512325223253232542325523256232572325823259232602326123262232632326423265232662326723268232692327023271232722327323274232752327623277232782327923280232812328223283232842328523286232872328823289232902329123292232932329423295232962329723298232992330023301233022330323304233052330623307233082330923310233112331223313233142331523316233172331823319233202332123322233232332423325233262332723328233292333023331233322333323334233352333623337233382333923340233412334223343233442334523346233472334823349233502335123352233532335423355233562335723358233592336023361233622336323364233652336623367233682336923370233712337223373233742337523376233772337823379233802338123382233832338423385233862338723388233892339023391233922339323394233952339623397233982339923400234012340223403234042340523406234072340823409234102341123412234132341423415234162341723418234192342023421234222342323424234252342623427234282342923430234312343223433234342343523436234372343823439234402344123442234432344423445234462344723448234492345023451234522345323454234552345623457234582345923460234612346223463234642346523466234672346823469234702347123472234732347423475234762347723478234792348023481234822348323484234852348623487234882348923490234912349223493234942349523496234972349823499235002350123502235032350423505235062350723508235092351023511235122351323514235152351623517235182351923520235212352223523235242352523526235272352823529235302353123532235332353423535235362353723538235392354023541235422354323544235452354623547235482354923550235512355223553235542355523556235572355823559235602356123562235632356423565235662356723568235692357023571235722357323574235752357623577235782357923580235812358223583235842358523586235872358823589235902359123592235932359423595235962359723598235992360023601236022360323604236052360623607236082360923610236112361223613236142361523616236172361823619236202362123622236232362423625236262362723628236292363023631236322363323634236352363623637236382363923640236412364223643236442364523646236472364823649236502365123652236532365423655236562365723658236592366023661236622366323664236652366623667236682366923670236712367223673236742367523676236772367823679236802368123682236832368423685236862368723688236892369023691236922369323694236952369623697236982369923700237012370223703237042370523706237072370823709237102371123712237132371423715237162371723718237192372023721237222372323724237252372623727237282372923730237312373223733237342373523736237372373823739237402374123742237432374423745237462374723748237492375023751237522375323754237552375623757237582375923760237612376223763237642376523766237672376823769237702377123772237732377423775237762377723778237792378023781237822378323784237852378623787237882378923790237912379223793237942379523796237972379823799238002380123802238032380423805238062380723808238092381023811238122381323814238152381623817238182381923820238212382223823238242382523826238272382823829238302383123832238332383423835238362383723838238392384023841238422384323844238452384623847238482384923850238512385223853238542385523856238572385823859238602386123862238632386423865238662386723868238692387023871238722387323874238752387623877238782387923880238812388223883238842388523886238872388823889238902389123892238932389423895238962389723898238992390023901239022390323904239052390623907239082390923910239112391223913239142391523916239172391823919239202392123922239232392423925239262392723928239292393023931239322393323934239352393623937239382393923940239412394223943239442394523946239472394823949239502395123952239532395423955239562395723958239592396023961239622396323964239652396623967239682396923970239712397223973239742397523976239772397823979239802398123982239832398423985239862398723988239892399023991239922399323994239952399623997239982399924000240012400224003240042400524006240072400824009240102401124012240132401424015240162401724018240192402024021240222402324024240252402624027240282402924030240312403224033240342403524036240372403824039240402404124042240432404424045240462404724048240492405024051240522405324054240552405624057240582405924060240612406224063240642406524066240672406824069240702407124072240732407424075240762407724078240792408024081240822408324084240852408624087240882408924090240912409224093240942409524096240972409824099241002410124102241032410424105241062410724108241092411024111241122411324114241152411624117241182411924120241212412224123241242412524126241272412824129241302413124132241332413424135241362413724138241392414024141241422414324144241452414624147241482414924150241512415224153241542415524156241572415824159241602416124162241632416424165241662416724168241692417024171241722417324174241752417624177241782417924180241812418224183241842418524186241872418824189241902419124192241932419424195241962419724198241992420024201242022420324204242052420624207242082420924210242112421224213242142421524216242172421824219242202422124222242232422424225242262422724228242292423024231242322423324234242352423624237242382423924240242412424224243242442424524246242472424824249242502425124252242532425424255242562425724258242592426024261242622426324264242652426624267242682426924270242712427224273242742427524276242772427824279242802428124282242832428424285242862428724288242892429024291242922429324294242952429624297242982429924300243012430224303243042430524306243072430824309243102431124312243132431424315243162431724318243192432024321243222432324324243252432624327243282432924330243312433224333243342433524336243372433824339243402434124342243432434424345243462434724348243492435024351243522435324354243552435624357243582435924360243612436224363243642436524366243672436824369243702437124372243732437424375243762437724378243792438024381243822438324384243852438624387243882438924390243912439224393243942439524396243972439824399244002440124402244032440424405244062440724408244092441024411244122441324414244152441624417244182441924420244212442224423244242442524426244272442824429244302443124432244332443424435244362443724438244392444024441244422444324444244452444624447244482444924450244512445224453244542445524456244572445824459244602446124462244632446424465244662446724468244692447024471244722447324474244752447624477244782447924480244812448224483244842448524486244872448824489244902449124492244932449424495244962449724498244992450024501245022450324504245052450624507245082450924510245112451224513245142451524516245172451824519245202452124522245232452424525245262452724528245292453024531245322453324534245352453624537245382453924540245412454224543245442454524546245472454824549245502455124552245532455424555245562455724558245592456024561245622456324564245652456624567245682456924570245712457224573245742457524576245772457824579245802458124582245832458424585245862458724588245892459024591245922459324594245952459624597245982459924600246012460224603246042460524606246072460824609246102461124612246132461424615246162461724618246192462024621246222462324624246252462624627246282462924630246312463224633246342463524636246372463824639246402464124642246432464424645246462464724648246492465024651246522465324654246552465624657246582465924660246612466224663246642466524666246672466824669246702467124672246732467424675246762467724678246792468024681246822468324684246852468624687246882468924690246912469224693246942469524696246972469824699247002470124702247032470424705247062470724708247092471024711247122471324714247152471624717247182471924720247212472224723247242472524726247272472824729247302473124732247332473424735247362473724738247392474024741247422474324744247452474624747247482474924750247512475224753247542475524756247572475824759247602476124762247632476424765247662476724768247692477024771247722477324774247752477624777247782477924780247812478224783247842478524786247872478824789247902479124792247932479424795247962479724798247992480024801248022480324804248052480624807248082480924810248112481224813248142481524816248172481824819248202482124822248232482424825248262482724828248292483024831248322483324834248352483624837248382483924840248412484224843248442484524846248472484824849248502485124852248532485424855248562485724858248592486024861248622486324864248652486624867248682486924870248712487224873248742487524876248772487824879248802488124882248832488424885248862488724888248892489024891248922489324894248952489624897248982489924900249012490224903249042490524906249072490824909249102491124912249132491424915249162491724918249192492024921249222492324924249252492624927249282492924930249312493224933249342493524936249372493824939249402494124942249432494424945249462494724948249492495024951249522495324954249552495624957249582495924960249612496224963249642496524966249672496824969249702497124972249732497424975249762497724978249792498024981249822498324984249852498624987249882498924990249912499224993249942499524996249972499824999250002500125002250032500425005250062500725008250092501025011250122501325014250152501625017250182501925020250212502225023250242502525026250272502825029250302503125032250332503425035250362503725038250392504025041250422504325044250452504625047250482504925050250512505225053250542505525056250572505825059250602506125062250632506425065250662506725068250692507025071250722507325074250752507625077250782507925080250812508225083250842508525086250872508825089250902509125092250932509425095250962509725098250992510025101251022510325104251052510625107251082510925110251112511225113251142511525116251172511825119251202512125122251232512425125251262512725128251292513025131251322513325134251352513625137251382513925140251412514225143251442514525146251472514825149251502515125152251532515425155251562515725158251592516025161251622516325164251652516625167251682516925170251712517225173251742517525176251772517825179251802518125182251832518425185251862518725188251892519025191251922519325194251952519625197251982519925200252012520225203252042520525206252072520825209252102521125212252132521425215252162521725218252192522025221252222522325224252252522625227252282522925230252312523225233252342523525236252372523825239252402524125242252432524425245252462524725248252492525025251252522525325254252552525625257252582525925260252612526225263252642526525266252672526825269252702527125272252732527425275252762527725278252792528025281252822528325284252852528625287252882528925290252912529225293252942529525296252972529825299253002530125302253032530425305253062530725308253092531025311253122531325314253152531625317253182531925320253212532225323253242532525326253272532825329253302533125332253332533425335253362533725338253392534025341253422534325344253452534625347253482534925350253512535225353253542535525356253572535825359253602536125362253632536425365253662536725368253692537025371253722537325374253752537625377253782537925380253812538225383253842538525386253872538825389253902539125392253932539425395253962539725398253992540025401254022540325404254052540625407254082540925410254112541225413254142541525416254172541825419254202542125422254232542425425254262542725428254292543025431254322543325434254352543625437254382543925440254412544225443254442544525446254472544825449254502545125452254532545425455254562545725458254592546025461254622546325464254652546625467254682546925470254712547225473254742547525476254772547825479254802548125482254832548425485254862548725488254892549025491254922549325494254952549625497254982549925500255012550225503255042550525506255072550825509255102551125512255132551425515255162551725518255192552025521255222552325524255252552625527255282552925530255312553225533255342553525536255372553825539255402554125542255432554425545255462554725548255492555025551255522555325554255552555625557255582555925560255612556225563255642556525566255672556825569255702557125572255732557425575255762557725578255792558025581255822558325584255852558625587255882558925590255912559225593255942559525596255972559825599256002560125602256032560425605256062560725608256092561025611256122561325614256152561625617256182561925620256212562225623256242562525626256272562825629256302563125632256332563425635256362563725638256392564025641256422564325644256452564625647256482564925650256512565225653256542565525656256572565825659256602566125662256632566425665256662566725668256692567025671256722567325674256752567625677256782567925680256812568225683256842568525686256872568825689256902569125692256932569425695256962569725698256992570025701257022570325704257052570625707257082570925710257112571225713257142571525716257172571825719257202572125722257232572425725257262572725728257292573025731257322573325734257352573625737257382573925740257412574225743257442574525746257472574825749257502575125752257532575425755257562575725758257592576025761257622576325764257652576625767257682576925770257712577225773257742577525776257772577825779257802578125782257832578425785257862578725788257892579025791257922579325794257952579625797257982579925800258012580225803258042580525806258072580825809258102581125812258132581425815258162581725818258192582025821258222582325824258252582625827258282582925830258312583225833258342583525836258372583825839258402584125842258432584425845258462584725848258492585025851258522585325854258552585625857258582585925860258612586225863258642586525866258672586825869258702587125872258732587425875258762587725878258792588025881258822588325884258852588625887258882588925890258912589225893258942589525896258972589825899259002590125902259032590425905259062590725908259092591025911259122591325914259152591625917259182591925920259212592225923259242592525926259272592825929259302593125932259332593425935259362593725938259392594025941259422594325944259452594625947259482594925950259512595225953259542595525956259572595825959259602596125962259632596425965259662596725968259692597025971259722597325974259752597625977259782597925980259812598225983259842598525986259872598825989259902599125992259932599425995259962599725998259992600026001260022600326004260052600626007260082600926010260112601226013260142601526016260172601826019260202602126022260232602426025260262602726028260292603026031260322603326034260352603626037260382603926040260412604226043260442604526046260472604826049260502605126052260532605426055260562605726058260592606026061260622606326064260652606626067260682606926070260712607226073260742607526076260772607826079260802608126082260832608426085260862608726088260892609026091260922609326094260952609626097260982609926100261012610226103261042610526106261072610826109261102611126112261132611426115261162611726118261192612026121261222612326124261252612626127261282612926130261312613226133261342613526136261372613826139261402614126142261432614426145261462614726148261492615026151261522615326154261552615626157261582615926160261612616226163261642616526166261672616826169261702617126172261732617426175261762617726178261792618026181261822618326184261852618626187261882618926190261912619226193261942619526196261972619826199262002620126202262032620426205262062620726208262092621026211262122621326214262152621626217262182621926220262212622226223262242622526226262272622826229262302623126232262332623426235262362623726238262392624026241262422624326244262452624626247262482624926250262512625226253262542625526256262572625826259262602626126262262632626426265262662626726268262692627026271262722627326274262752627626277262782627926280262812628226283262842628526286262872628826289262902629126292262932629426295262962629726298262992630026301263022630326304263052630626307263082630926310263112631226313263142631526316263172631826319263202632126322263232632426325263262632726328263292633026331263322633326334263352633626337263382633926340263412634226343263442634526346263472634826349263502635126352263532635426355263562635726358263592636026361263622636326364263652636626367263682636926370263712637226373263742637526376263772637826379263802638126382263832638426385263862638726388263892639026391263922639326394263952639626397263982639926400264012640226403264042640526406264072640826409264102641126412264132641426415264162641726418264192642026421264222642326424264252642626427264282642926430264312643226433264342643526436264372643826439264402644126442264432644426445264462644726448264492645026451264522645326454264552645626457264582645926460264612646226463264642646526466264672646826469264702647126472264732647426475264762647726478264792648026481264822648326484264852648626487264882648926490264912649226493264942649526496264972649826499265002650126502265032650426505265062650726508265092651026511265122651326514265152651626517265182651926520265212652226523265242652526526265272652826529265302653126532265332653426535265362653726538265392654026541265422654326544265452654626547265482654926550265512655226553265542655526556265572655826559265602656126562265632656426565265662656726568265692657026571265722657326574265752657626577265782657926580265812658226583265842658526586265872658826589265902659126592265932659426595265962659726598265992660026601266022660326604266052660626607266082660926610266112661226613266142661526616266172661826619266202662126622266232662426625266262662726628266292663026631266322663326634266352663626637266382663926640266412664226643266442664526646266472664826649266502665126652266532665426655266562665726658266592666026661266622666326664266652666626667266682666926670266712667226673266742667526676266772667826679266802668126682266832668426685266862668726688266892669026691266922669326694266952669626697266982669926700267012670226703267042670526706267072670826709267102671126712267132671426715267162671726718267192672026721267222672326724267252672626727267282672926730267312673226733267342673526736267372673826739267402674126742267432674426745267462674726748267492675026751267522675326754267552675626757267582675926760267612676226763267642676526766267672676826769267702677126772267732677426775267762677726778267792678026781267822678326784267852678626787267882678926790267912679226793267942679526796267972679826799268002680126802268032680426805268062680726808268092681026811268122681326814268152681626817268182681926820268212682226823268242682526826268272682826829268302683126832268332683426835268362683726838268392684026841268422684326844268452684626847268482684926850268512685226853268542685526856268572685826859268602686126862268632686426865268662686726868268692687026871268722687326874268752687626877268782687926880268812688226883268842688526886268872688826889268902689126892268932689426895268962689726898268992690026901269022690326904269052690626907269082690926910269112691226913269142691526916269172691826919269202692126922269232692426925269262692726928269292693026931269322693326934269352693626937269382693926940269412694226943269442694526946269472694826949269502695126952269532695426955269562695726958269592696026961269622696326964269652696626967269682696926970269712697226973269742697526976269772697826979269802698126982269832698426985269862698726988269892699026991269922699326994269952699626997269982699927000270012700227003270042700527006270072700827009270102701127012270132701427015270162701727018270192702027021270222702327024270252702627027270282702927030270312703227033270342703527036270372703827039270402704127042270432704427045270462704727048270492705027051270522705327054270552705627057270582705927060270612706227063270642706527066270672706827069270702707127072270732707427075270762707727078270792708027081270822708327084270852708627087270882708927090270912709227093270942709527096270972709827099271002710127102271032710427105271062710727108271092711027111271122711327114271152711627117271182711927120271212712227123271242712527126271272712827129271302713127132271332713427135271362713727138271392714027141271422714327144271452714627147271482714927150271512715227153271542715527156271572715827159271602716127162271632716427165271662716727168271692717027171271722717327174271752717627177271782717927180271812718227183271842718527186271872718827189271902719127192271932719427195271962719727198271992720027201272022720327204272052720627207272082720927210272112721227213272142721527216272172721827219272202722127222272232722427225272262722727228272292723027231272322723327234272352723627237272382723927240272412724227243272442724527246272472724827249272502725127252272532725427255272562725727258272592726027261272622726327264272652726627267272682726927270272712727227273272742727527276272772727827279272802728127282272832728427285272862728727288272892729027291272922729327294272952729627297272982729927300273012730227303273042730527306273072730827309273102731127312273132731427315273162731727318273192732027321273222732327324273252732627327273282732927330273312733227333273342733527336273372733827339273402734127342273432734427345273462734727348273492735027351273522735327354273552735627357273582735927360273612736227363273642736527366273672736827369273702737127372273732737427375273762737727378273792738027381273822738327384273852738627387273882738927390273912739227393273942739527396273972739827399274002740127402274032740427405274062740727408274092741027411274122741327414274152741627417274182741927420274212742227423274242742527426274272742827429274302743127432274332743427435274362743727438274392744027441274422744327444274452744627447274482744927450274512745227453274542745527456274572745827459274602746127462274632746427465274662746727468274692747027471274722747327474274752747627477274782747927480274812748227483274842748527486274872748827489274902749127492274932749427495274962749727498274992750027501275022750327504275052750627507275082750927510275112751227513275142751527516275172751827519275202752127522275232752427525275262752727528275292753027531275322753327534275352753627537275382753927540275412754227543275442754527546275472754827549275502755127552275532755427555275562755727558275592756027561275622756327564275652756627567275682756927570275712757227573275742757527576275772757827579275802758127582275832758427585275862758727588275892759027591275922759327594275952759627597275982759927600276012760227603276042760527606276072760827609276102761127612276132761427615276162761727618276192762027621276222762327624276252762627627276282762927630276312763227633276342763527636276372763827639276402764127642276432764427645276462764727648276492765027651276522765327654276552765627657276582765927660276612766227663276642766527666276672766827669276702767127672276732767427675276762767727678276792768027681276822768327684276852768627687276882768927690276912769227693276942769527696276972769827699277002770127702277032770427705277062770727708277092771027711277122771327714277152771627717277182771927720277212772227723277242772527726277272772827729277302773127732277332773427735277362773727738277392774027741277422774327744277452774627747277482774927750277512775227753277542775527756277572775827759277602776127762277632776427765277662776727768277692777027771277722777327774277752777627777277782777927780277812778227783277842778527786277872778827789277902779127792277932779427795277962779727798277992780027801278022780327804278052780627807278082780927810278112781227813278142781527816278172781827819278202782127822278232782427825278262782727828278292783027831278322783327834278352783627837278382783927840278412784227843278442784527846278472784827849278502785127852278532785427855278562785727858278592786027861278622786327864278652786627867278682786927870278712787227873278742787527876278772787827879278802788127882278832788427885278862788727888278892789027891278922789327894278952789627897278982789927900279012790227903279042790527906279072790827909279102791127912279132791427915279162791727918279192792027921279222792327924279252792627927279282792927930279312793227933279342793527936279372793827939279402794127942279432794427945279462794727948279492795027951279522795327954279552795627957279582795927960279612796227963279642796527966279672796827969279702797127972279732797427975279762797727978279792798027981279822798327984279852798627987279882798927990279912799227993279942799527996279972799827999280002800128002280032800428005280062800728008280092801028011280122801328014280152801628017280182801928020280212802228023280242802528026280272802828029280302803128032280332803428035280362803728038280392804028041280422804328044280452804628047280482804928050280512805228053280542805528056280572805828059280602806128062280632806428065280662806728068280692807028071280722807328074280752807628077280782807928080280812808228083280842808528086280872808828089280902809128092280932809428095280962809728098280992810028101281022810328104281052810628107281082810928110281112811228113281142811528116281172811828119281202812128122281232812428125281262812728128281292813028131281322813328134281352813628137281382813928140281412814228143281442814528146281472814828149281502815128152281532815428155281562815728158281592816028161281622816328164281652816628167281682816928170281712817228173281742817528176281772817828179281802818128182281832818428185281862818728188281892819028191281922819328194281952819628197281982819928200282012820228203282042820528206282072820828209282102821128212282132821428215282162821728218282192822028221282222822328224282252822628227282282822928230282312823228233282342823528236282372823828239282402824128242282432824428245282462824728248282492825028251282522825328254282552825628257282582825928260282612826228263282642826528266282672826828269282702827128272282732827428275282762827728278282792828028281282822828328284282852828628287282882828928290282912829228293282942829528296282972829828299283002830128302283032830428305283062830728308283092831028311283122831328314283152831628317283182831928320283212832228323283242832528326283272832828329283302833128332283332833428335283362833728338283392834028341283422834328344283452834628347283482834928350283512835228353283542835528356283572835828359283602836128362283632836428365283662836728368283692837028371283722837328374283752837628377283782837928380283812838228383283842838528386283872838828389283902839128392283932839428395283962839728398283992840028401284022840328404284052840628407284082840928410284112841228413284142841528416284172841828419284202842128422284232842428425284262842728428284292843028431284322843328434284352843628437284382843928440284412844228443284442844528446284472844828449284502845128452284532845428455284562845728458284592846028461284622846328464284652846628467284682846928470284712847228473284742847528476284772847828479284802848128482284832848428485284862848728488284892849028491284922849328494284952849628497284982849928500285012850228503285042850528506285072850828509285102851128512285132851428515285162851728518285192852028521285222852328524285252852628527285282852928530285312853228533285342853528536285372853828539285402854128542285432854428545285462854728548285492855028551285522855328554285552855628557285582855928560285612856228563285642856528566285672856828569285702857128572285732857428575285762857728578285792858028581285822858328584285852858628587285882858928590285912859228593285942859528596285972859828599286002860128602286032860428605286062860728608286092861028611286122861328614286152861628617286182861928620286212862228623286242862528626286272862828629286302863128632286332863428635286362863728638286392864028641286422864328644286452864628647286482864928650286512865228653286542865528656286572865828659286602866128662286632866428665286662866728668286692867028671286722867328674286752867628677286782867928680286812868228683286842868528686286872868828689286902869128692286932869428695286962869728698286992870028701287022870328704287052870628707287082870928710287112871228713287142871528716287172871828719287202872128722287232872428725287262872728728287292873028731287322873328734287352873628737287382873928740287412874228743287442874528746287472874828749287502875128752287532875428755287562875728758287592876028761287622876328764287652876628767287682876928770287712877228773287742877528776287772877828779287802878128782287832878428785287862878728788287892879028791287922879328794287952879628797287982879928800288012880228803288042880528806288072880828809288102881128812288132881428815288162881728818288192882028821288222882328824288252882628827288282882928830288312883228833288342883528836288372883828839288402884128842288432884428845288462884728848288492885028851288522885328854288552885628857288582885928860288612886228863288642886528866288672886828869288702887128872288732887428875288762887728878288792888028881288822888328884288852888628887288882888928890288912889228893288942889528896288972889828899289002890128902289032890428905289062890728908289092891028911289122891328914289152891628917289182891928920289212892228923289242892528926289272892828929289302893128932289332893428935289362893728938289392894028941289422894328944289452894628947289482894928950289512895228953289542895528956289572895828959289602896128962289632896428965289662896728968289692897028971289722897328974289752897628977289782897928980289812898228983289842898528986289872898828989289902899128992289932899428995289962899728998289992900029001290022900329004290052900629007290082900929010290112901229013290142901529016290172901829019290202902129022290232902429025290262902729028290292903029031290322903329034290352903629037290382903929040290412904229043290442904529046290472904829049290502905129052290532905429055290562905729058290592906029061290622906329064290652906629067290682906929070290712907229073290742907529076290772907829079290802908129082290832908429085290862908729088290892909029091290922909329094290952909629097290982909929100291012910229103291042910529106291072910829109291102911129112291132911429115291162911729118291192912029121291222912329124291252912629127291282912929130291312913229133291342913529136291372913829139291402914129142291432914429145291462914729148291492915029151291522915329154291552915629157291582915929160291612916229163291642916529166291672916829169291702917129172291732917429175291762917729178291792918029181291822918329184291852918629187291882918929190291912919229193291942919529196291972919829199292002920129202292032920429205292062920729208292092921029211292122921329214292152921629217292182921929220292212922229223292242922529226292272922829229292302923129232292332923429235292362923729238292392924029241292422924329244292452924629247292482924929250292512925229253292542925529256292572925829259292602926129262292632926429265292662926729268292692927029271292722927329274292752927629277292782927929280292812928229283292842928529286292872928829289292902929129292292932929429295292962929729298292992930029301293022930329304293052930629307293082930929310293112931229313293142931529316293172931829319293202932129322293232932429325293262932729328293292933029331293322933329334293352933629337293382933929340293412934229343293442934529346293472934829349293502935129352293532935429355293562935729358293592936029361293622936329364293652936629367293682936929370293712937229373293742937529376293772937829379293802938129382293832938429385293862938729388293892939029391293922939329394293952939629397293982939929400294012940229403294042940529406294072940829409294102941129412294132941429415294162941729418294192942029421294222942329424294252942629427294282942929430294312943229433294342943529436294372943829439294402944129442294432944429445294462944729448294492945029451294522945329454294552945629457294582945929460294612946229463294642946529466294672946829469294702947129472294732947429475294762947729478294792948029481294822948329484294852948629487294882948929490294912949229493294942949529496294972949829499295002950129502295032950429505295062950729508295092951029511295122951329514295152951629517295182951929520295212952229523295242952529526295272952829529295302953129532295332953429535295362953729538295392954029541295422954329544295452954629547295482954929550295512955229553295542955529556295572955829559295602956129562295632956429565295662956729568295692957029571295722957329574295752957629577295782957929580295812958229583295842958529586295872958829589295902959129592295932959429595295962959729598295992960029601296022960329604296052960629607296082960929610296112961229613296142961529616296172961829619296202962129622296232962429625296262962729628296292963029631296322963329634296352963629637296382963929640296412964229643296442964529646296472964829649296502965129652296532965429655296562965729658296592966029661296622966329664296652966629667296682966929670296712967229673296742967529676296772967829679296802968129682296832968429685296862968729688296892969029691296922969329694296952969629697296982969929700297012970229703297042970529706297072970829709297102971129712297132971429715297162971729718297192972029721297222972329724297252972629727297282972929730297312973229733297342973529736297372973829739297402974129742297432974429745297462974729748297492975029751297522975329754297552975629757297582975929760297612976229763297642976529766297672976829769297702977129772297732977429775297762977729778297792978029781297822978329784297852978629787297882978929790297912979229793297942979529796297972979829799298002980129802298032980429805298062980729808298092981029811298122981329814298152981629817298182981929820298212982229823298242982529826298272982829829298302983129832298332983429835298362983729838298392984029841298422984329844298452984629847298482984929850298512985229853298542985529856298572985829859298602986129862298632986429865298662986729868298692987029871298722987329874298752987629877298782987929880298812988229883298842988529886298872988829889298902989129892298932989429895298962989729898298992990029901299022990329904299052990629907299082990929910299112991229913299142991529916299172991829919299202992129922299232992429925299262992729928299292993029931299322993329934299352993629937299382993929940299412994229943299442994529946299472994829949299502995129952299532995429955299562995729958299592996029961299622996329964299652996629967299682996929970299712997229973299742997529976299772997829979299802998129982299832998429985299862998729988299892999029991299922999329994299952999629997299982999930000300013000230003300043000530006300073000830009300103001130012300133001430015300163001730018300193002030021300223002330024300253002630027300283002930030300313003230033300343003530036300373003830039300403004130042300433004430045300463004730048300493005030051300523005330054300553005630057300583005930060300613006230063300643006530066300673006830069300703007130072300733007430075300763007730078300793008030081300823008330084300853008630087300883008930090300913009230093300943009530096300973009830099301003010130102301033010430105301063010730108301093011030111301123011330114301153011630117301183011930120301213012230123301243012530126301273012830129301303013130132301333013430135301363013730138301393014030141301423014330144301453014630147301483014930150301513015230153301543015530156301573015830159301603016130162301633016430165301663016730168301693017030171301723017330174301753017630177301783017930180301813018230183301843018530186301873018830189301903019130192301933019430195301963019730198301993020030201302023020330204302053020630207302083020930210302113021230213302143021530216302173021830219302203022130222302233022430225302263022730228302293023030231302323023330234302353023630237302383023930240302413024230243302443024530246302473024830249302503025130252302533025430255302563025730258302593026030261302623026330264302653026630267302683026930270302713027230273302743027530276302773027830279302803028130282302833028430285302863028730288302893029030291302923029330294302953029630297302983029930300303013030230303303043030530306303073030830309303103031130312303133031430315303163031730318303193032030321303223032330324303253032630327303283032930330303313033230333303343033530336303373033830339303403034130342303433034430345303463034730348303493035030351303523035330354303553035630357303583035930360303613036230363303643036530366303673036830369303703037130372303733037430375303763037730378303793038030381303823038330384303853038630387303883038930390303913039230393303943039530396303973039830399304003040130402304033040430405304063040730408304093041030411304123041330414304153041630417304183041930420304213042230423304243042530426304273042830429304303043130432304333043430435304363043730438304393044030441304423044330444304453044630447304483044930450304513045230453304543045530456304573045830459304603046130462304633046430465304663046730468304693047030471304723047330474304753047630477304783047930480304813048230483304843048530486304873048830489304903049130492304933049430495304963049730498304993050030501305023050330504305053050630507305083050930510305113051230513305143051530516305173051830519305203052130522305233052430525305263052730528305293053030531305323053330534305353053630537305383053930540305413054230543305443054530546305473054830549305503055130552305533055430555305563055730558305593056030561305623056330564305653056630567305683056930570305713057230573305743057530576305773057830579305803058130582305833058430585305863058730588305893059030591305923059330594305953059630597305983059930600306013060230603306043060530606306073060830609306103061130612306133061430615306163061730618306193062030621306223062330624306253062630627306283062930630306313063230633306343063530636306373063830639306403064130642306433064430645306463064730648306493065030651306523065330654306553065630657306583065930660306613066230663306643066530666306673066830669306703067130672306733067430675306763067730678306793068030681306823068330684306853068630687306883068930690306913069230693306943069530696306973069830699307003070130702307033070430705307063070730708307093071030711307123071330714307153071630717307183071930720307213072230723307243072530726307273072830729307303073130732307333073430735307363073730738307393074030741307423074330744307453074630747307483074930750307513075230753307543075530756307573075830759307603076130762307633076430765307663076730768307693077030771307723077330774307753077630777307783077930780307813078230783307843078530786307873078830789307903079130792307933079430795307963079730798307993080030801308023080330804308053080630807308083080930810308113081230813308143081530816308173081830819308203082130822308233082430825308263082730828308293083030831308323083330834308353083630837308383083930840308413084230843308443084530846308473084830849308503085130852308533085430855308563085730858308593086030861308623086330864308653086630867308683086930870308713087230873308743087530876308773087830879308803088130882308833088430885308863088730888308893089030891308923089330894308953089630897308983089930900309013090230903309043090530906309073090830909309103091130912309133091430915309163091730918309193092030921309223092330924309253092630927309283092930930309313093230933309343093530936309373093830939309403094130942309433094430945309463094730948309493095030951309523095330954309553095630957309583095930960309613096230963309643096530966309673096830969309703097130972309733097430975309763097730978309793098030981309823098330984309853098630987309883098930990309913099230993309943099530996309973099830999310003100131002310033100431005310063100731008310093101031011310123101331014310153101631017310183101931020310213102231023310243102531026310273102831029310303103131032310333103431035310363103731038310393104031041310423104331044310453104631047310483104931050310513105231053310543105531056310573105831059310603106131062310633106431065310663106731068310693107031071310723107331074310753107631077310783107931080310813108231083310843108531086310873108831089310903109131092310933109431095310963109731098310993110031101311023110331104311053110631107311083110931110311113111231113311143111531116311173111831119311203112131122311233112431125311263112731128311293113031131311323113331134311353113631137311383113931140311413114231143311443114531146311473114831149311503115131152311533115431155311563115731158311593116031161311623116331164311653116631167311683116931170311713117231173311743117531176311773117831179311803118131182311833118431185311863118731188311893119031191311923119331194311953119631197311983119931200312013120231203312043120531206312073120831209312103121131212312133121431215312163121731218312193122031221312223122331224312253122631227312283122931230312313123231233312343123531236312373123831239312403124131242312433124431245312463124731248312493125031251312523125331254312553125631257312583125931260312613126231263312643126531266312673126831269312703127131272312733127431275312763127731278312793128031281312823128331284312853128631287312883128931290312913129231293312943129531296312973129831299313003130131302313033130431305313063130731308313093131031311313123131331314313153131631317313183131931320313213132231323313243132531326313273132831329313303133131332313333133431335313363133731338313393134031341313423134331344313453134631347313483134931350313513135231353313543135531356313573135831359313603136131362313633136431365313663136731368313693137031371313723137331374313753137631377313783137931380313813138231383313843138531386313873138831389313903139131392313933139431395313963139731398313993140031401314023140331404314053140631407314083140931410314113141231413314143141531416314173141831419314203142131422314233142431425314263142731428314293143031431314323143331434314353143631437314383143931440314413144231443314443144531446314473144831449314503145131452314533145431455314563145731458314593146031461314623146331464314653146631467314683146931470314713147231473314743147531476314773147831479314803148131482314833148431485314863148731488314893149031491314923149331494314953149631497314983149931500315013150231503315043150531506315073150831509315103151131512315133151431515315163151731518315193152031521315223152331524315253152631527315283152931530315313153231533315343153531536315373153831539315403154131542315433154431545315463154731548315493155031551315523155331554315553155631557315583155931560315613156231563315643156531566315673156831569315703157131572315733157431575315763157731578315793158031581315823158331584315853158631587315883158931590315913159231593315943159531596315973159831599316003160131602316033160431605316063160731608316093161031611316123161331614316153161631617316183161931620316213162231623316243162531626316273162831629316303163131632316333163431635316363163731638316393164031641316423164331644316453164631647316483164931650316513165231653316543165531656316573165831659316603166131662316633166431665316663166731668316693167031671316723167331674316753167631677316783167931680316813168231683316843168531686316873168831689316903169131692316933169431695316963169731698316993170031701317023170331704317053170631707317083170931710317113171231713317143171531716317173171831719317203172131722317233172431725317263172731728317293173031731317323173331734317353173631737317383173931740317413174231743317443174531746317473174831749317503175131752317533175431755317563175731758317593176031761317623176331764317653176631767317683176931770317713177231773317743177531776317773177831779317803178131782317833178431785317863178731788317893179031791317923179331794317953179631797317983179931800318013180231803318043180531806318073180831809318103181131812318133181431815318163181731818318193182031821318223182331824318253182631827318283182931830318313183231833318343183531836318373183831839318403184131842318433184431845318463184731848318493185031851318523185331854318553185631857318583185931860318613186231863318643186531866318673186831869318703187131872318733187431875318763187731878318793188031881318823188331884318853188631887318883188931890318913189231893318943189531896318973189831899319003190131902319033190431905319063190731908319093191031911319123191331914319153191631917319183191931920319213192231923319243192531926319273192831929319303193131932319333193431935319363193731938319393194031941319423194331944319453194631947319483194931950319513195231953319543195531956319573195831959319603196131962319633196431965319663196731968319693197031971319723197331974319753197631977319783197931980319813198231983319843198531986319873198831989319903199131992319933199431995319963199731998319993200032001320023200332004320053200632007320083200932010320113201232013320143201532016320173201832019320203202132022320233202432025320263202732028320293203032031320323203332034320353203632037320383203932040320413204232043320443204532046320473204832049320503205132052320533205432055320563205732058320593206032061320623206332064320653206632067320683206932070320713207232073320743207532076320773207832079320803208132082320833208432085320863208732088320893209032091320923209332094320953209632097320983209932100321013210232103321043210532106321073210832109321103211132112321133211432115321163211732118321193212032121321223212332124321253212632127321283212932130321313213232133321343213532136321373213832139321403214132142321433214432145321463214732148321493215032151321523215332154321553215632157321583215932160321613216232163321643216532166321673216832169321703217132172321733217432175321763217732178321793218032181321823218332184321853218632187321883218932190321913219232193321943219532196321973219832199322003220132202322033220432205322063220732208322093221032211322123221332214322153221632217322183221932220322213222232223322243222532226322273222832229322303223132232322333223432235322363223732238322393224032241322423224332244322453224632247322483224932250322513225232253322543225532256322573225832259322603226132262322633226432265322663226732268322693227032271322723227332274322753227632277322783227932280322813228232283322843228532286322873228832289322903229132292322933229432295322963229732298322993230032301323023230332304323053230632307323083230932310323113231232313323143231532316323173231832319323203232132322323233232432325323263232732328323293233032331323323233332334323353233632337323383233932340323413234232343323443234532346323473234832349323503235132352323533235432355323563235732358323593236032361323623236332364323653236632367323683236932370323713237232373323743237532376323773237832379323803238132382323833238432385323863238732388323893239032391323923239332394323953239632397323983239932400324013240232403324043240532406324073240832409324103241132412324133241432415324163241732418324193242032421324223242332424324253242632427324283242932430324313243232433324343243532436324373243832439324403244132442324433244432445324463244732448324493245032451324523245332454324553245632457324583245932460324613246232463324643246532466324673246832469324703247132472324733247432475324763247732478324793248032481324823248332484324853248632487324883248932490324913249232493324943249532496324973249832499325003250132502325033250432505325063250732508325093251032511325123251332514325153251632517325183251932520325213252232523325243252532526325273252832529325303253132532325333253432535325363253732538325393254032541325423254332544325453254632547325483254932550325513255232553325543255532556325573255832559325603256132562325633256432565325663256732568325693257032571325723257332574325753257632577325783257932580325813258232583325843258532586325873258832589325903259132592325933259432595325963259732598325993260032601326023260332604326053260632607326083260932610326113261232613326143261532616326173261832619326203262132622326233262432625326263262732628326293263032631326323263332634326353263632637
  1. apiVersion: apiextensions.k8s.io/v1
  2. kind: CustomResourceDefinition
  3. metadata:
  4. annotations:
  5. controller-gen.kubebuilder.io/version: v0.19.0
  6. labels:
  7. external-secrets.io/component: controller
  8. name: clusterexternalsecrets.external-secrets.io
  9. spec:
  10. group: external-secrets.io
  11. names:
  12. categories:
  13. - external-secrets
  14. kind: ClusterExternalSecret
  15. listKind: ClusterExternalSecretList
  16. plural: clusterexternalsecrets
  17. shortNames:
  18. - ces
  19. singular: clusterexternalsecret
  20. scope: Cluster
  21. versions:
  22. - additionalPrinterColumns:
  23. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  24. name: Store
  25. type: string
  26. - jsonPath: .spec.refreshTime
  27. name: Refresh Interval
  28. type: string
  29. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  30. name: Ready
  31. type: string
  32. name: v1
  33. schema:
  34. openAPIV3Schema:
  35. description: ClusterExternalSecret is the Schema for the clusterexternalsecrets API.
  36. properties:
  37. apiVersion:
  38. description: |-
  39. APIVersion defines the versioned schema of this representation of an object.
  40. Servers should convert recognized schemas to the latest internal value, and
  41. may reject unrecognized values.
  42. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  43. type: string
  44. kind:
  45. description: |-
  46. Kind is a string value representing the REST resource this object represents.
  47. Servers may infer this from the endpoint the client submits requests to.
  48. Cannot be updated.
  49. In CamelCase.
  50. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  51. type: string
  52. metadata:
  53. type: object
  54. spec:
  55. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  56. properties:
  57. externalSecretMetadata:
  58. description: The metadata of the external secrets to be created
  59. properties:
  60. annotations:
  61. additionalProperties:
  62. type: string
  63. type: object
  64. labels:
  65. additionalProperties:
  66. type: string
  67. type: object
  68. type: object
  69. externalSecretName:
  70. description: |-
  71. The name of the external secrets to be created.
  72. Defaults to the name of the ClusterExternalSecret
  73. maxLength: 253
  74. minLength: 1
  75. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  76. type: string
  77. externalSecretSpec:
  78. description: The spec for the ExternalSecrets to be created
  79. properties:
  80. data:
  81. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  82. items:
  83. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  84. properties:
  85. remoteRef:
  86. description: |-
  87. RemoteRef points to the remote secret and defines
  88. which secret (version/property/..) to fetch.
  89. properties:
  90. conversionStrategy:
  91. default: Default
  92. description: Used to define a conversion Strategy
  93. enum:
  94. - Default
  95. - Unicode
  96. type: string
  97. decodingStrategy:
  98. default: None
  99. description: Used to define a decoding Strategy
  100. enum:
  101. - Auto
  102. - Base64
  103. - Base64URL
  104. - None
  105. type: string
  106. key:
  107. description: Key is the key used in the Provider, mandatory
  108. type: string
  109. metadataPolicy:
  110. default: None
  111. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  112. enum:
  113. - None
  114. - Fetch
  115. type: string
  116. nullBytePolicy:
  117. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  118. enum:
  119. - Ignore
  120. - Fail
  121. type: string
  122. property:
  123. description: Used to select a specific property of the Provider value (if a map), if supported
  124. type: string
  125. version:
  126. description: Used to select a specific version of the Provider value, if supported
  127. type: string
  128. required:
  129. - key
  130. type: object
  131. secretKey:
  132. description: The key in the Kubernetes Secret to store the value.
  133. maxLength: 253
  134. minLength: 1
  135. pattern: ^[-._a-zA-Z0-9]+$
  136. type: string
  137. sourceRef:
  138. description: |-
  139. SourceRef allows you to override the source
  140. from which the value will be pulled.
  141. maxProperties: 1
  142. minProperties: 1
  143. properties:
  144. generatorRef:
  145. description: |-
  146. GeneratorRef points to a generator custom resource.
  147. Deprecated: The generatorRef is not implemented in .data[].
  148. this will be removed with v1.
  149. properties:
  150. apiVersion:
  151. default: generators.external-secrets.io/v1alpha1
  152. description: Specify the apiVersion of the generator resource
  153. type: string
  154. kind:
  155. description: Specify the Kind of the generator resource
  156. enum:
  157. - ACRAccessToken
  158. - BeyondtrustWorkloadCredentialsDynamicSecret
  159. - ClusterGenerator
  160. - CloudsmithAccessToken
  161. - ECRAuthorizationToken
  162. - Fake
  163. - GCRAccessToken
  164. - GithubAccessToken
  165. - GitlabDeployToken
  166. - QuayAccessToken
  167. - Password
  168. - SSHKey
  169. - STSSessionToken
  170. - UUID
  171. - VaultDynamicSecret
  172. - Webhook
  173. - Grafana
  174. - MFA
  175. type: string
  176. name:
  177. description: Specify the name of the generator resource
  178. maxLength: 253
  179. minLength: 1
  180. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  181. type: string
  182. required:
  183. - kind
  184. - name
  185. type: object
  186. storeRef:
  187. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  188. properties:
  189. kind:
  190. description: |-
  191. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  192. Defaults to `SecretStore`
  193. enum:
  194. - SecretStore
  195. - ClusterSecretStore
  196. type: string
  197. name:
  198. description: Name of the SecretStore resource
  199. maxLength: 253
  200. minLength: 1
  201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  202. type: string
  203. type: object
  204. type: object
  205. required:
  206. - remoteRef
  207. - secretKey
  208. type: object
  209. type: array
  210. dataFrom:
  211. description: |-
  212. DataFrom is used to fetch all properties from a specific Provider data
  213. If multiple entries are specified, the Secret keys are merged in the specified order
  214. items:
  215. description: |-
  216. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  217. when using DataFrom to fetch multiple values from a Provider.
  218. properties:
  219. extract:
  220. description: |-
  221. Used to extract multiple key/value pairs from one secret
  222. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  223. properties:
  224. conversionStrategy:
  225. default: Default
  226. description: Used to define a conversion Strategy
  227. enum:
  228. - Default
  229. - Unicode
  230. type: string
  231. decodingStrategy:
  232. default: None
  233. description: Used to define a decoding Strategy
  234. enum:
  235. - Auto
  236. - Base64
  237. - Base64URL
  238. - None
  239. type: string
  240. key:
  241. description: Key is the key used in the Provider, mandatory
  242. type: string
  243. metadataPolicy:
  244. default: None
  245. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  246. enum:
  247. - None
  248. - Fetch
  249. type: string
  250. nullBytePolicy:
  251. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  252. enum:
  253. - Ignore
  254. - Fail
  255. type: string
  256. property:
  257. description: Used to select a specific property of the Provider value (if a map), if supported
  258. type: string
  259. version:
  260. description: Used to select a specific version of the Provider value, if supported
  261. type: string
  262. required:
  263. - key
  264. type: object
  265. find:
  266. description: |-
  267. Used to find secrets based on tags or regular expressions
  268. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  269. properties:
  270. conversionStrategy:
  271. default: Default
  272. description: Used to define a conversion Strategy
  273. enum:
  274. - Default
  275. - Unicode
  276. type: string
  277. decodingStrategy:
  278. default: None
  279. description: Used to define a decoding Strategy
  280. enum:
  281. - Auto
  282. - Base64
  283. - Base64URL
  284. - None
  285. type: string
  286. name:
  287. description: Finds secrets based on the name.
  288. properties:
  289. regexp:
  290. description: Finds secrets base
  291. type: string
  292. type: object
  293. nullBytePolicy:
  294. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  295. enum:
  296. - Ignore
  297. - Fail
  298. type: string
  299. path:
  300. description: A root path to start the find operations.
  301. type: string
  302. tags:
  303. additionalProperties:
  304. type: string
  305. description: Find secrets based on tags.
  306. type: object
  307. type: object
  308. rewrite:
  309. description: |-
  310. Used to rewrite secret Keys after getting them from the secret Provider
  311. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  312. items:
  313. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  314. maxProperties: 1
  315. minProperties: 1
  316. properties:
  317. merge:
  318. description: |-
  319. Used to merge key/values in one single Secret
  320. The resulting key will contain all values from the specified secrets
  321. properties:
  322. conflictPolicy:
  323. default: Error
  324. description: Used to define the policy to use in conflict resolution.
  325. enum:
  326. - Ignore
  327. - Error
  328. type: string
  329. into:
  330. default: ""
  331. description: |-
  332. Used to define the target key of the merge operation.
  333. Required if strategy is JSON. Ignored otherwise.
  334. type: string
  335. priority:
  336. description: Used to define key priority in conflict resolution.
  337. items:
  338. type: string
  339. type: array
  340. priorityPolicy:
  341. default: Strict
  342. description: Used to define the policy when a key in the priority list does not exist in the input.
  343. enum:
  344. - IgnoreNotFound
  345. - Strict
  346. type: string
  347. strategy:
  348. default: Extract
  349. description: Used to define the strategy to use in the merge operation.
  350. enum:
  351. - Extract
  352. - JSON
  353. type: string
  354. type: object
  355. regexp:
  356. description: |-
  357. Used to rewrite with regular expressions.
  358. The resulting key will be the output of a regexp.ReplaceAll operation.
  359. properties:
  360. source:
  361. description: Used to define the regular expression of a re.Compiler.
  362. type: string
  363. target:
  364. description: Used to define the target pattern of a ReplaceAll operation.
  365. type: string
  366. required:
  367. - source
  368. - target
  369. type: object
  370. transform:
  371. description: |-
  372. Used to apply string transformation on the secrets.
  373. The resulting key will be the output of the template applied by the operation.
  374. properties:
  375. template:
  376. description: |-
  377. Used to define the template to apply on the secret name.
  378. `.value ` will specify the secret name in the template.
  379. type: string
  380. required:
  381. - template
  382. type: object
  383. type: object
  384. type: array
  385. sourceRef:
  386. description: |-
  387. SourceRef points to a store or generator
  388. which contains secret values ready to use.
  389. Use this in combination with Extract or Find pull values out of
  390. a specific SecretStore.
  391. When sourceRef points to a generator Extract or Find is not supported.
  392. The generator returns a static map of values
  393. maxProperties: 1
  394. minProperties: 1
  395. properties:
  396. generatorRef:
  397. description: GeneratorRef points to a generator custom resource.
  398. properties:
  399. apiVersion:
  400. default: generators.external-secrets.io/v1alpha1
  401. description: Specify the apiVersion of the generator resource
  402. type: string
  403. kind:
  404. description: Specify the Kind of the generator resource
  405. enum:
  406. - ACRAccessToken
  407. - BeyondtrustWorkloadCredentialsDynamicSecret
  408. - ClusterGenerator
  409. - CloudsmithAccessToken
  410. - ECRAuthorizationToken
  411. - Fake
  412. - GCRAccessToken
  413. - GithubAccessToken
  414. - GitlabDeployToken
  415. - QuayAccessToken
  416. - Password
  417. - SSHKey
  418. - STSSessionToken
  419. - UUID
  420. - VaultDynamicSecret
  421. - Webhook
  422. - Grafana
  423. - MFA
  424. type: string
  425. name:
  426. description: Specify the name of the generator resource
  427. maxLength: 253
  428. minLength: 1
  429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  430. type: string
  431. required:
  432. - kind
  433. - name
  434. type: object
  435. storeRef:
  436. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  437. properties:
  438. kind:
  439. description: |-
  440. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  441. Defaults to `SecretStore`
  442. enum:
  443. - SecretStore
  444. - ClusterSecretStore
  445. type: string
  446. name:
  447. description: Name of the SecretStore resource
  448. maxLength: 253
  449. minLength: 1
  450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  451. type: string
  452. type: object
  453. type: object
  454. type: object
  455. type: array
  456. refreshInterval:
  457. default: 1h0m0s
  458. description: |-
  459. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  460. specified as Golang Duration strings.
  461. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  462. Example values: "1h0m0s", "2h30m0s", "10m0s"
  463. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  464. type: string
  465. refreshPolicy:
  466. description: |-
  467. RefreshPolicy determines how the ExternalSecret should be refreshed:
  468. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  469. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  470. No periodic updates occur if refreshInterval is 0.
  471. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  472. enum:
  473. - CreatedOnce
  474. - Periodic
  475. - OnChange
  476. type: string
  477. secretStoreRef:
  478. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  479. properties:
  480. kind:
  481. description: |-
  482. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  483. Defaults to `SecretStore`
  484. enum:
  485. - SecretStore
  486. - ClusterSecretStore
  487. type: string
  488. name:
  489. description: Name of the SecretStore resource
  490. maxLength: 253
  491. minLength: 1
  492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  493. type: string
  494. type: object
  495. syncWindows:
  496. description: |-
  497. SyncWindows optionally restricts when periodic refreshes may occur.
  498. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  499. properties:
  500. kind:
  501. description: |-
  502. Kind applies to every window in the list.
  503. "allow" -- syncs are permitted only while at least one window is active;
  504. all other times are blocked.
  505. "deny" -- syncs are blocked while any window is active;
  506. all other times are permitted.
  507. enum:
  508. - allow
  509. - deny
  510. type: string
  511. windows:
  512. description: Windows is the list of schedule+duration pairs.
  513. items:
  514. description: |-
  515. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  516. within a SyncWindows block.
  517. properties:
  518. duration:
  519. description: |-
  520. Duration specifies how long the window stays open after each Schedule
  521. firing. Example: "8h".
  522. type: string
  523. schedule:
  524. description: |-
  525. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  526. named shorthand such as @daily or @every 1h. It marks the start time of
  527. each window occurrence.
  528. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  529. minLength: 1
  530. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  531. type: string
  532. required:
  533. - duration
  534. - schedule
  535. type: object
  536. minItems: 1
  537. type: array
  538. required:
  539. - kind
  540. - windows
  541. type: object
  542. target:
  543. default:
  544. creationPolicy: Owner
  545. deletionPolicy: Retain
  546. description: |-
  547. ExternalSecretTarget defines the Kubernetes Secret to be created,
  548. there can be only one target per ExternalSecret.
  549. properties:
  550. creationPolicy:
  551. default: Owner
  552. description: |-
  553. CreationPolicy defines rules on how to create the resulting Secret.
  554. Defaults to "Owner"
  555. enum:
  556. - Owner
  557. - Orphan
  558. - Merge
  559. - None
  560. - CreateOrMerge
  561. type: string
  562. deletionPolicy:
  563. default: Retain
  564. description: |-
  565. DeletionPolicy defines rules on how to delete the resulting Secret.
  566. Defaults to "Retain"
  567. enum:
  568. - Delete
  569. - Merge
  570. - Retain
  571. type: string
  572. immutable:
  573. description: Immutable defines if the final secret will be immutable
  574. type: boolean
  575. manifest:
  576. description: |-
  577. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  578. When specified, ExternalSecret will create the resource type defined here
  579. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  580. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  581. properties:
  582. apiVersion:
  583. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  584. minLength: 1
  585. type: string
  586. kind:
  587. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  588. minLength: 1
  589. type: string
  590. required:
  591. - apiVersion
  592. - kind
  593. type: object
  594. name:
  595. description: |-
  596. The name of the Secret resource to be managed.
  597. Defaults to the .metadata.name of the ExternalSecret resource
  598. maxLength: 253
  599. minLength: 1
  600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  601. type: string
  602. template:
  603. description: Template defines a blueprint for the created Secret resource.
  604. properties:
  605. data:
  606. additionalProperties:
  607. type: string
  608. type: object
  609. engineVersion:
  610. default: v2
  611. description: |-
  612. EngineVersion specifies the template engine version
  613. that should be used to compile/execute the
  614. template specified in .data and .templateFrom[].
  615. enum:
  616. - v2
  617. type: string
  618. mergePolicy:
  619. default: Replace
  620. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  621. enum:
  622. - Replace
  623. - Merge
  624. type: string
  625. metadata:
  626. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  627. properties:
  628. annotations:
  629. additionalProperties:
  630. type: string
  631. type: object
  632. finalizers:
  633. items:
  634. type: string
  635. type: array
  636. labels:
  637. additionalProperties:
  638. type: string
  639. type: object
  640. type: object
  641. templateFrom:
  642. items:
  643. description: |-
  644. TemplateFrom specifies a source for templates.
  645. Each item in the list can either reference a ConfigMap or a Secret resource.
  646. properties:
  647. configMap:
  648. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  649. properties:
  650. items:
  651. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  652. items:
  653. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  654. properties:
  655. key:
  656. description: A key in the ConfigMap/Secret
  657. maxLength: 253
  658. minLength: 1
  659. pattern: ^[-._a-zA-Z0-9]+$
  660. type: string
  661. templateAs:
  662. default: Values
  663. description: TemplateScope specifies how the template keys should be interpreted.
  664. enum:
  665. - Values
  666. - KeysAndValues
  667. type: string
  668. required:
  669. - key
  670. type: object
  671. type: array
  672. name:
  673. description: The name of the ConfigMap/Secret resource
  674. maxLength: 253
  675. minLength: 1
  676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  677. type: string
  678. required:
  679. - items
  680. - name
  681. type: object
  682. literal:
  683. type: string
  684. secret:
  685. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  686. properties:
  687. items:
  688. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  689. items:
  690. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  691. properties:
  692. key:
  693. description: A key in the ConfigMap/Secret
  694. maxLength: 253
  695. minLength: 1
  696. pattern: ^[-._a-zA-Z0-9]+$
  697. type: string
  698. templateAs:
  699. default: Values
  700. description: TemplateScope specifies how the template keys should be interpreted.
  701. enum:
  702. - Values
  703. - KeysAndValues
  704. type: string
  705. required:
  706. - key
  707. type: object
  708. type: array
  709. name:
  710. description: The name of the ConfigMap/Secret resource
  711. maxLength: 253
  712. minLength: 1
  713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  714. type: string
  715. required:
  716. - items
  717. - name
  718. type: object
  719. target:
  720. default: Data
  721. description: |-
  722. Target specifies where to place the template result.
  723. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  724. any other value is rejected because it would allow writes to privileged Secret fields.
  725. For custom resources (when spec.target.manifest is set), this supports
  726. nested paths like "spec.database.config" or "data".
  727. type: string
  728. valuesDecodingStrategy:
  729. default: None
  730. description: Used to define a decoding Strategy for the rendered template values.
  731. enum:
  732. - Auto
  733. - Base64
  734. - Base64URL
  735. - None
  736. type: string
  737. type: object
  738. type: array
  739. type:
  740. type: string
  741. type: object
  742. type: object
  743. type: object
  744. namespaceSelector:
  745. description: |-
  746. The labels to select by to find the Namespaces to create the ExternalSecrets in.
  747. Deprecated: Use NamespaceSelectors instead.
  748. properties:
  749. matchExpressions:
  750. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  751. items:
  752. description: |-
  753. A label selector requirement is a selector that contains values, a key, and an operator that
  754. relates the key and values.
  755. properties:
  756. key:
  757. description: key is the label key that the selector applies to.
  758. type: string
  759. operator:
  760. description: |-
  761. operator represents a key's relationship to a set of values.
  762. Valid operators are In, NotIn, Exists and DoesNotExist.
  763. type: string
  764. values:
  765. description: |-
  766. values is an array of string values. If the operator is In or NotIn,
  767. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  768. the values array must be empty. This array is replaced during a strategic
  769. merge patch.
  770. items:
  771. type: string
  772. type: array
  773. x-kubernetes-list-type: atomic
  774. required:
  775. - key
  776. - operator
  777. type: object
  778. type: array
  779. x-kubernetes-list-type: atomic
  780. matchLabels:
  781. additionalProperties:
  782. type: string
  783. description: |-
  784. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  785. map is equivalent to an element of matchExpressions, whose key field is "key", the
  786. operator is "In", and the values array contains only "value". The requirements are ANDed.
  787. type: object
  788. type: object
  789. x-kubernetes-map-type: atomic
  790. namespaceSelectors:
  791. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  792. items:
  793. description: |-
  794. A label selector is a label query over a set of resources. The result of matchLabels and
  795. matchExpressions are ANDed. An empty label selector matches all objects. A null
  796. label selector matches no objects.
  797. properties:
  798. matchExpressions:
  799. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  800. items:
  801. description: |-
  802. A label selector requirement is a selector that contains values, a key, and an operator that
  803. relates the key and values.
  804. properties:
  805. key:
  806. description: key is the label key that the selector applies to.
  807. type: string
  808. operator:
  809. description: |-
  810. operator represents a key's relationship to a set of values.
  811. Valid operators are In, NotIn, Exists and DoesNotExist.
  812. type: string
  813. values:
  814. description: |-
  815. values is an array of string values. If the operator is In or NotIn,
  816. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  817. the values array must be empty. This array is replaced during a strategic
  818. merge patch.
  819. items:
  820. type: string
  821. type: array
  822. x-kubernetes-list-type: atomic
  823. required:
  824. - key
  825. - operator
  826. type: object
  827. type: array
  828. x-kubernetes-list-type: atomic
  829. matchLabels:
  830. additionalProperties:
  831. type: string
  832. description: |-
  833. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  834. map is equivalent to an element of matchExpressions, whose key field is "key", the
  835. operator is "In", and the values array contains only "value". The requirements are ANDed.
  836. type: object
  837. type: object
  838. x-kubernetes-map-type: atomic
  839. type: array
  840. namespaces:
  841. description: |-
  842. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  843. Deprecated: Use NamespaceSelectors instead.
  844. items:
  845. maxLength: 63
  846. minLength: 1
  847. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  848. type: string
  849. type: array
  850. refreshTime:
  851. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  852. type: string
  853. required:
  854. - externalSecretSpec
  855. type: object
  856. status:
  857. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  858. properties:
  859. conditions:
  860. items:
  861. description: ClusterExternalSecretStatusCondition defines the observed state of a ClusterExternalSecret resource.
  862. properties:
  863. message:
  864. type: string
  865. status:
  866. type: string
  867. type:
  868. description: ClusterExternalSecretConditionType defines a value type for ClusterExternalSecret conditions.
  869. type: string
  870. required:
  871. - status
  872. - type
  873. type: object
  874. type: array
  875. externalSecretName:
  876. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  877. type: string
  878. failedNamespaces:
  879. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  880. items:
  881. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  882. properties:
  883. namespace:
  884. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  885. type: string
  886. reason:
  887. description: Reason is why the ExternalSecret failed to apply to the namespace
  888. type: string
  889. required:
  890. - namespace
  891. type: object
  892. type: array
  893. provisionedNamespaces:
  894. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  895. items:
  896. type: string
  897. type: array
  898. type: object
  899. type: object
  900. served: true
  901. storage: true
  902. subresources:
  903. status: {}
  904. - additionalPrinterColumns:
  905. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  906. name: Store
  907. type: string
  908. - jsonPath: .spec.refreshTime
  909. name: Refresh Interval
  910. type: string
  911. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  912. name: Ready
  913. type: string
  914. deprecated: true
  915. name: v1beta1
  916. schema:
  917. openAPIV3Schema:
  918. description: ClusterExternalSecret is the schema for the clusterexternalsecrets API.
  919. properties:
  920. apiVersion:
  921. description: |-
  922. APIVersion defines the versioned schema of this representation of an object.
  923. Servers should convert recognized schemas to the latest internal value, and
  924. may reject unrecognized values.
  925. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  926. type: string
  927. kind:
  928. description: |-
  929. Kind is a string value representing the REST resource this object represents.
  930. Servers may infer this from the endpoint the client submits requests to.
  931. Cannot be updated.
  932. In CamelCase.
  933. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  934. type: string
  935. metadata:
  936. type: object
  937. spec:
  938. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  939. properties:
  940. externalSecretMetadata:
  941. description: The metadata of the external secrets to be created
  942. properties:
  943. annotations:
  944. additionalProperties:
  945. type: string
  946. type: object
  947. labels:
  948. additionalProperties:
  949. type: string
  950. type: object
  951. type: object
  952. externalSecretName:
  953. description: |-
  954. The name of the external secrets to be created.
  955. Defaults to the name of the ClusterExternalSecret
  956. maxLength: 253
  957. minLength: 1
  958. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  959. type: string
  960. externalSecretSpec:
  961. description: The spec for the ExternalSecrets to be created
  962. properties:
  963. data:
  964. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  965. items:
  966. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  967. properties:
  968. remoteRef:
  969. description: |-
  970. RemoteRef points to the remote secret and defines
  971. which secret (version/property/..) to fetch.
  972. properties:
  973. conversionStrategy:
  974. default: Default
  975. description: Used to define a conversion Strategy
  976. enum:
  977. - Default
  978. - Unicode
  979. type: string
  980. decodingStrategy:
  981. default: None
  982. description: Used to define a decoding Strategy
  983. enum:
  984. - Auto
  985. - Base64
  986. - Base64URL
  987. - None
  988. type: string
  989. key:
  990. description: Key is the key used in the Provider, mandatory
  991. type: string
  992. metadataPolicy:
  993. default: None
  994. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  995. enum:
  996. - None
  997. - Fetch
  998. type: string
  999. property:
  1000. description: Used to select a specific property of the Provider value (if a map), if supported
  1001. type: string
  1002. version:
  1003. description: Used to select a specific version of the Provider value, if supported
  1004. type: string
  1005. required:
  1006. - key
  1007. type: object
  1008. secretKey:
  1009. description: The key in the Kubernetes Secret to store the value.
  1010. maxLength: 253
  1011. minLength: 1
  1012. pattern: ^[-._a-zA-Z0-9]+$
  1013. type: string
  1014. sourceRef:
  1015. description: |-
  1016. SourceRef allows you to override the source
  1017. from which the value will be pulled.
  1018. maxProperties: 1
  1019. minProperties: 1
  1020. properties:
  1021. generatorRef:
  1022. description: |-
  1023. GeneratorRef points to a generator custom resource.
  1024. Deprecated: The generatorRef is not implemented in .data[].
  1025. this will be removed with v1.
  1026. properties:
  1027. apiVersion:
  1028. default: generators.external-secrets.io/v1alpha1
  1029. description: Specify the apiVersion of the generator resource
  1030. type: string
  1031. kind:
  1032. description: Specify the Kind of the generator resource
  1033. enum:
  1034. - ACRAccessToken
  1035. - ClusterGenerator
  1036. - ECRAuthorizationToken
  1037. - Fake
  1038. - GCRAccessToken
  1039. - GithubAccessToken
  1040. - QuayAccessToken
  1041. - Password
  1042. - SSHKey
  1043. - STSSessionToken
  1044. - UUID
  1045. - VaultDynamicSecret
  1046. - Webhook
  1047. - Grafana
  1048. type: string
  1049. name:
  1050. description: Specify the name of the generator resource
  1051. maxLength: 253
  1052. minLength: 1
  1053. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1054. type: string
  1055. required:
  1056. - kind
  1057. - name
  1058. type: object
  1059. storeRef:
  1060. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1061. properties:
  1062. kind:
  1063. description: |-
  1064. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1065. Defaults to `SecretStore`
  1066. enum:
  1067. - SecretStore
  1068. - ClusterSecretStore
  1069. type: string
  1070. name:
  1071. description: Name of the SecretStore resource
  1072. maxLength: 253
  1073. minLength: 1
  1074. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1075. type: string
  1076. type: object
  1077. type: object
  1078. required:
  1079. - remoteRef
  1080. - secretKey
  1081. type: object
  1082. type: array
  1083. dataFrom:
  1084. description: |-
  1085. DataFrom is used to fetch all properties from a specific Provider data
  1086. If multiple entries are specified, the Secret keys are merged in the specified order
  1087. items:
  1088. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  1089. properties:
  1090. extract:
  1091. description: |-
  1092. Used to extract multiple key/value pairs from one secret
  1093. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1094. properties:
  1095. conversionStrategy:
  1096. default: Default
  1097. description: Used to define a conversion Strategy
  1098. enum:
  1099. - Default
  1100. - Unicode
  1101. type: string
  1102. decodingStrategy:
  1103. default: None
  1104. description: Used to define a decoding Strategy
  1105. enum:
  1106. - Auto
  1107. - Base64
  1108. - Base64URL
  1109. - None
  1110. type: string
  1111. key:
  1112. description: Key is the key used in the Provider, mandatory
  1113. type: string
  1114. metadataPolicy:
  1115. default: None
  1116. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  1117. enum:
  1118. - None
  1119. - Fetch
  1120. type: string
  1121. property:
  1122. description: Used to select a specific property of the Provider value (if a map), if supported
  1123. type: string
  1124. version:
  1125. description: Used to select a specific version of the Provider value, if supported
  1126. type: string
  1127. required:
  1128. - key
  1129. type: object
  1130. find:
  1131. description: |-
  1132. Used to find secrets based on tags or regular expressions
  1133. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1134. properties:
  1135. conversionStrategy:
  1136. default: Default
  1137. description: Used to define a conversion Strategy
  1138. enum:
  1139. - Default
  1140. - Unicode
  1141. type: string
  1142. decodingStrategy:
  1143. default: None
  1144. description: Used to define a decoding Strategy
  1145. enum:
  1146. - Auto
  1147. - Base64
  1148. - Base64URL
  1149. - None
  1150. type: string
  1151. name:
  1152. description: Finds secrets based on the name.
  1153. properties:
  1154. regexp:
  1155. description: Finds secrets base
  1156. type: string
  1157. type: object
  1158. path:
  1159. description: A root path to start the find operations.
  1160. type: string
  1161. tags:
  1162. additionalProperties:
  1163. type: string
  1164. description: Find secrets based on tags.
  1165. type: object
  1166. type: object
  1167. rewrite:
  1168. description: |-
  1169. Used to rewrite secret Keys after getting them from the secret Provider
  1170. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  1171. items:
  1172. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  1173. maxProperties: 1
  1174. minProperties: 1
  1175. properties:
  1176. regexp:
  1177. description: |-
  1178. Used to rewrite with regular expressions.
  1179. The resulting key will be the output of a regexp.ReplaceAll operation.
  1180. properties:
  1181. source:
  1182. description: Used to define the regular expression of a re.Compiler.
  1183. type: string
  1184. target:
  1185. description: Used to define the target pattern of a ReplaceAll operation.
  1186. type: string
  1187. required:
  1188. - source
  1189. - target
  1190. type: object
  1191. transform:
  1192. description: |-
  1193. Used to apply string transformation on the secrets.
  1194. The resulting key will be the output of the template applied by the operation.
  1195. properties:
  1196. template:
  1197. description: |-
  1198. Used to define the template to apply on the secret name.
  1199. `.value ` will specify the secret name in the template.
  1200. type: string
  1201. required:
  1202. - template
  1203. type: object
  1204. type: object
  1205. type: array
  1206. sourceRef:
  1207. description: |-
  1208. SourceRef points to a store or generator
  1209. which contains secret values ready to use.
  1210. Use this in combination with Extract or Find pull values out of
  1211. a specific SecretStore.
  1212. When sourceRef points to a generator Extract or Find is not supported.
  1213. The generator returns a static map of values
  1214. maxProperties: 1
  1215. minProperties: 1
  1216. properties:
  1217. generatorRef:
  1218. description: GeneratorRef points to a generator custom resource.
  1219. properties:
  1220. apiVersion:
  1221. default: generators.external-secrets.io/v1alpha1
  1222. description: Specify the apiVersion of the generator resource
  1223. type: string
  1224. kind:
  1225. description: Specify the Kind of the generator resource
  1226. enum:
  1227. - ACRAccessToken
  1228. - ClusterGenerator
  1229. - ECRAuthorizationToken
  1230. - Fake
  1231. - GCRAccessToken
  1232. - GithubAccessToken
  1233. - QuayAccessToken
  1234. - Password
  1235. - SSHKey
  1236. - STSSessionToken
  1237. - UUID
  1238. - VaultDynamicSecret
  1239. - Webhook
  1240. - Grafana
  1241. type: string
  1242. name:
  1243. description: Specify the name of the generator resource
  1244. maxLength: 253
  1245. minLength: 1
  1246. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1247. type: string
  1248. required:
  1249. - kind
  1250. - name
  1251. type: object
  1252. storeRef:
  1253. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1254. properties:
  1255. kind:
  1256. description: |-
  1257. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1258. Defaults to `SecretStore`
  1259. enum:
  1260. - SecretStore
  1261. - ClusterSecretStore
  1262. type: string
  1263. name:
  1264. description: Name of the SecretStore resource
  1265. maxLength: 253
  1266. minLength: 1
  1267. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1268. type: string
  1269. type: object
  1270. type: object
  1271. type: object
  1272. type: array
  1273. refreshInterval:
  1274. default: 1h0m0s
  1275. description: |-
  1276. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  1277. specified as Golang Duration strings.
  1278. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  1279. Example values: "1h0m0s", "2h30m0s", "10m0s"
  1280. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  1281. type: string
  1282. refreshPolicy:
  1283. description: |-
  1284. RefreshPolicy determines how the ExternalSecret should be refreshed:
  1285. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  1286. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  1287. No periodic updates occur if refreshInterval is 0.
  1288. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  1289. enum:
  1290. - CreatedOnce
  1291. - Periodic
  1292. - OnChange
  1293. type: string
  1294. secretStoreRef:
  1295. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1296. properties:
  1297. kind:
  1298. description: |-
  1299. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1300. Defaults to `SecretStore`
  1301. enum:
  1302. - SecretStore
  1303. - ClusterSecretStore
  1304. type: string
  1305. name:
  1306. description: Name of the SecretStore resource
  1307. maxLength: 253
  1308. minLength: 1
  1309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1310. type: string
  1311. type: object
  1312. target:
  1313. default:
  1314. creationPolicy: Owner
  1315. deletionPolicy: Retain
  1316. description: |-
  1317. ExternalSecretTarget defines the Kubernetes Secret to be created
  1318. There can be only one target per ExternalSecret.
  1319. properties:
  1320. creationPolicy:
  1321. default: Owner
  1322. description: |-
  1323. CreationPolicy defines rules on how to create the resulting Secret.
  1324. Defaults to "Owner"
  1325. enum:
  1326. - Owner
  1327. - Orphan
  1328. - Merge
  1329. - None
  1330. type: string
  1331. deletionPolicy:
  1332. default: Retain
  1333. description: |-
  1334. DeletionPolicy defines rules on how to delete the resulting Secret.
  1335. Defaults to "Retain"
  1336. enum:
  1337. - Delete
  1338. - Merge
  1339. - Retain
  1340. type: string
  1341. immutable:
  1342. description: Immutable defines if the final secret will be immutable
  1343. type: boolean
  1344. name:
  1345. description: |-
  1346. The name of the Secret resource to be managed.
  1347. Defaults to the .metadata.name of the ExternalSecret resource
  1348. maxLength: 253
  1349. minLength: 1
  1350. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1351. type: string
  1352. template:
  1353. description: Template defines a blueprint for the created Secret resource.
  1354. properties:
  1355. data:
  1356. additionalProperties:
  1357. type: string
  1358. type: object
  1359. engineVersion:
  1360. default: v2
  1361. description: |-
  1362. EngineVersion specifies the template engine version
  1363. that should be used to compile/execute the
  1364. template specified in .data and .templateFrom[].
  1365. enum:
  1366. - v2
  1367. type: string
  1368. mergePolicy:
  1369. default: Replace
  1370. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  1371. enum:
  1372. - Replace
  1373. - Merge
  1374. type: string
  1375. metadata:
  1376. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  1377. properties:
  1378. annotations:
  1379. additionalProperties:
  1380. type: string
  1381. type: object
  1382. labels:
  1383. additionalProperties:
  1384. type: string
  1385. type: object
  1386. type: object
  1387. templateFrom:
  1388. items:
  1389. description: TemplateFrom defines a source for template data.
  1390. properties:
  1391. configMap:
  1392. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1393. properties:
  1394. items:
  1395. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1396. items:
  1397. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1398. properties:
  1399. key:
  1400. description: A key in the ConfigMap/Secret
  1401. maxLength: 253
  1402. minLength: 1
  1403. pattern: ^[-._a-zA-Z0-9]+$
  1404. type: string
  1405. templateAs:
  1406. default: Values
  1407. description: TemplateScope defines the scope of the template when processing template data.
  1408. enum:
  1409. - Values
  1410. - KeysAndValues
  1411. type: string
  1412. required:
  1413. - key
  1414. type: object
  1415. type: array
  1416. name:
  1417. description: The name of the ConfigMap/Secret resource
  1418. maxLength: 253
  1419. minLength: 1
  1420. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1421. type: string
  1422. required:
  1423. - items
  1424. - name
  1425. type: object
  1426. literal:
  1427. type: string
  1428. secret:
  1429. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1430. properties:
  1431. items:
  1432. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1433. items:
  1434. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1435. properties:
  1436. key:
  1437. description: A key in the ConfigMap/Secret
  1438. maxLength: 253
  1439. minLength: 1
  1440. pattern: ^[-._a-zA-Z0-9]+$
  1441. type: string
  1442. templateAs:
  1443. default: Values
  1444. description: TemplateScope defines the scope of the template when processing template data.
  1445. enum:
  1446. - Values
  1447. - KeysAndValues
  1448. type: string
  1449. required:
  1450. - key
  1451. type: object
  1452. type: array
  1453. name:
  1454. description: The name of the ConfigMap/Secret resource
  1455. maxLength: 253
  1456. minLength: 1
  1457. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1458. type: string
  1459. required:
  1460. - items
  1461. - name
  1462. type: object
  1463. target:
  1464. default: Data
  1465. description: TemplateTarget defines the target field where the template result will be stored.
  1466. enum:
  1467. - Data
  1468. - Annotations
  1469. - Labels
  1470. type: string
  1471. type: object
  1472. type: array
  1473. type:
  1474. type: string
  1475. type: object
  1476. type: object
  1477. type: object
  1478. namespaceSelector:
  1479. description: The labels to select by to find the Namespaces to create the ExternalSecrets in
  1480. properties:
  1481. matchExpressions:
  1482. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1483. items:
  1484. description: |-
  1485. A label selector requirement is a selector that contains values, a key, and an operator that
  1486. relates the key and values.
  1487. properties:
  1488. key:
  1489. description: key is the label key that the selector applies to.
  1490. type: string
  1491. operator:
  1492. description: |-
  1493. operator represents a key's relationship to a set of values.
  1494. Valid operators are In, NotIn, Exists and DoesNotExist.
  1495. type: string
  1496. values:
  1497. description: |-
  1498. values is an array of string values. If the operator is In or NotIn,
  1499. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1500. the values array must be empty. This array is replaced during a strategic
  1501. merge patch.
  1502. items:
  1503. type: string
  1504. type: array
  1505. x-kubernetes-list-type: atomic
  1506. required:
  1507. - key
  1508. - operator
  1509. type: object
  1510. type: array
  1511. x-kubernetes-list-type: atomic
  1512. matchLabels:
  1513. additionalProperties:
  1514. type: string
  1515. description: |-
  1516. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1517. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1518. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1519. type: object
  1520. type: object
  1521. x-kubernetes-map-type: atomic
  1522. namespaceSelectors:
  1523. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1524. items:
  1525. description: |-
  1526. A label selector is a label query over a set of resources. The result of matchLabels and
  1527. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1528. label selector matches no objects.
  1529. properties:
  1530. matchExpressions:
  1531. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1532. items:
  1533. description: |-
  1534. A label selector requirement is a selector that contains values, a key, and an operator that
  1535. relates the key and values.
  1536. properties:
  1537. key:
  1538. description: key is the label key that the selector applies to.
  1539. type: string
  1540. operator:
  1541. description: |-
  1542. operator represents a key's relationship to a set of values.
  1543. Valid operators are In, NotIn, Exists and DoesNotExist.
  1544. type: string
  1545. values:
  1546. description: |-
  1547. values is an array of string values. If the operator is In or NotIn,
  1548. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1549. the values array must be empty. This array is replaced during a strategic
  1550. merge patch.
  1551. items:
  1552. type: string
  1553. type: array
  1554. x-kubernetes-list-type: atomic
  1555. required:
  1556. - key
  1557. - operator
  1558. type: object
  1559. type: array
  1560. x-kubernetes-list-type: atomic
  1561. matchLabels:
  1562. additionalProperties:
  1563. type: string
  1564. description: |-
  1565. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1566. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1567. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1568. type: object
  1569. type: object
  1570. x-kubernetes-map-type: atomic
  1571. type: array
  1572. namespaces:
  1573. description: |-
  1574. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  1575. Deprecated: Use NamespaceSelectors instead.
  1576. items:
  1577. maxLength: 63
  1578. minLength: 1
  1579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1580. type: string
  1581. type: array
  1582. refreshTime:
  1583. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  1584. type: string
  1585. required:
  1586. - externalSecretSpec
  1587. type: object
  1588. status:
  1589. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  1590. properties:
  1591. conditions:
  1592. items:
  1593. description: ClusterExternalSecretStatusCondition indicates the status of the ClusterExternalSecret.
  1594. properties:
  1595. message:
  1596. type: string
  1597. status:
  1598. type: string
  1599. type:
  1600. description: ClusterExternalSecretConditionType indicates the condition of the ClusterExternalSecret.
  1601. type: string
  1602. required:
  1603. - status
  1604. - type
  1605. type: object
  1606. type: array
  1607. externalSecretName:
  1608. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  1609. type: string
  1610. failedNamespaces:
  1611. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  1612. items:
  1613. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  1614. properties:
  1615. namespace:
  1616. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  1617. type: string
  1618. reason:
  1619. description: Reason is why the ExternalSecret failed to apply to the namespace
  1620. type: string
  1621. required:
  1622. - namespace
  1623. type: object
  1624. type: array
  1625. provisionedNamespaces:
  1626. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  1627. items:
  1628. type: string
  1629. type: array
  1630. type: object
  1631. type: object
  1632. served: false
  1633. storage: false
  1634. subresources:
  1635. status: {}
  1636. ---
  1637. apiVersion: apiextensions.k8s.io/v1
  1638. kind: CustomResourceDefinition
  1639. metadata:
  1640. annotations:
  1641. controller-gen.kubebuilder.io/version: v0.19.0
  1642. labels:
  1643. external-secrets.io/component: controller
  1644. name: clusterpushsecrets.external-secrets.io
  1645. spec:
  1646. group: external-secrets.io
  1647. names:
  1648. categories:
  1649. - external-secrets
  1650. kind: ClusterPushSecret
  1651. listKind: ClusterPushSecretList
  1652. plural: clusterpushsecrets
  1653. singular: clusterpushsecret
  1654. scope: Cluster
  1655. versions:
  1656. - additionalPrinterColumns:
  1657. - jsonPath: .metadata.creationTimestamp
  1658. name: AGE
  1659. type: date
  1660. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  1661. name: Status
  1662. type: string
  1663. name: v1alpha1
  1664. schema:
  1665. openAPIV3Schema:
  1666. description: ClusterPushSecret is the Schema for the ClusterPushSecrets API that enables cluster-wide management of pushing Kubernetes secrets to external providers.
  1667. properties:
  1668. apiVersion:
  1669. description: |-
  1670. APIVersion defines the versioned schema of this representation of an object.
  1671. Servers should convert recognized schemas to the latest internal value, and
  1672. may reject unrecognized values.
  1673. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  1674. type: string
  1675. kind:
  1676. description: |-
  1677. Kind is a string value representing the REST resource this object represents.
  1678. Servers may infer this from the endpoint the client submits requests to.
  1679. Cannot be updated.
  1680. In CamelCase.
  1681. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  1682. type: string
  1683. metadata:
  1684. type: object
  1685. spec:
  1686. description: ClusterPushSecretSpec defines the configuration for a ClusterPushSecret resource.
  1687. properties:
  1688. namespaceSelectors:
  1689. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1690. items:
  1691. description: |-
  1692. A label selector is a label query over a set of resources. The result of matchLabels and
  1693. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1694. label selector matches no objects.
  1695. properties:
  1696. matchExpressions:
  1697. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1698. items:
  1699. description: |-
  1700. A label selector requirement is a selector that contains values, a key, and an operator that
  1701. relates the key and values.
  1702. properties:
  1703. key:
  1704. description: key is the label key that the selector applies to.
  1705. type: string
  1706. operator:
  1707. description: |-
  1708. operator represents a key's relationship to a set of values.
  1709. Valid operators are In, NotIn, Exists and DoesNotExist.
  1710. type: string
  1711. values:
  1712. description: |-
  1713. values is an array of string values. If the operator is In or NotIn,
  1714. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1715. the values array must be empty. This array is replaced during a strategic
  1716. merge patch.
  1717. items:
  1718. type: string
  1719. type: array
  1720. x-kubernetes-list-type: atomic
  1721. required:
  1722. - key
  1723. - operator
  1724. type: object
  1725. type: array
  1726. x-kubernetes-list-type: atomic
  1727. matchLabels:
  1728. additionalProperties:
  1729. type: string
  1730. description: |-
  1731. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1732. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1733. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1734. type: object
  1735. type: object
  1736. x-kubernetes-map-type: atomic
  1737. type: array
  1738. pushSecretMetadata:
  1739. description: The metadata of the external secrets to be created
  1740. properties:
  1741. annotations:
  1742. additionalProperties:
  1743. type: string
  1744. type: object
  1745. labels:
  1746. additionalProperties:
  1747. type: string
  1748. type: object
  1749. type: object
  1750. pushSecretName:
  1751. description: |-
  1752. The name of the push secrets to be created.
  1753. Defaults to the name of the ClusterPushSecret
  1754. maxLength: 253
  1755. minLength: 1
  1756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1757. type: string
  1758. pushSecretSpec:
  1759. description: PushSecretSpec defines what to do with the secrets.
  1760. properties:
  1761. data:
  1762. description: Secret Data that should be pushed to providers
  1763. items:
  1764. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  1765. properties:
  1766. conversionStrategy:
  1767. default: None
  1768. description: Used to define a conversion Strategy for the secret keys
  1769. enum:
  1770. - None
  1771. - ReverseUnicode
  1772. type: string
  1773. match:
  1774. description: Match a given Secret Key to be pushed to the provider.
  1775. properties:
  1776. remoteRef:
  1777. description: Remote Refs to push to providers.
  1778. properties:
  1779. property:
  1780. description: Name of the property in the resulting secret
  1781. type: string
  1782. remoteKey:
  1783. description: Name of the resulting provider secret.
  1784. type: string
  1785. required:
  1786. - remoteKey
  1787. type: object
  1788. secretKey:
  1789. description: Secret Key to be pushed
  1790. type: string
  1791. required:
  1792. - remoteRef
  1793. type: object
  1794. metadata:
  1795. description: |-
  1796. Metadata is metadata attached to the secret.
  1797. The structure of metadata is provider specific, please look it up in the provider documentation.
  1798. x-kubernetes-preserve-unknown-fields: true
  1799. required:
  1800. - match
  1801. type: object
  1802. type: array
  1803. dataTo:
  1804. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  1805. items:
  1806. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  1807. properties:
  1808. conversionStrategy:
  1809. default: None
  1810. description: Used to define a conversion Strategy for the secret keys
  1811. enum:
  1812. - None
  1813. - ReverseUnicode
  1814. type: string
  1815. match:
  1816. description: |-
  1817. Match pattern for selecting keys from the source Secret.
  1818. If not specified, all keys are selected.
  1819. properties:
  1820. regexp:
  1821. description: |-
  1822. Regexp matches keys by regular expression.
  1823. If not specified, all keys are matched.
  1824. type: string
  1825. type: object
  1826. metadata:
  1827. description: |-
  1828. Metadata is metadata attached to the secret.
  1829. The structure of metadata is provider specific, please look it up in the provider documentation.
  1830. x-kubernetes-preserve-unknown-fields: true
  1831. remoteKey:
  1832. description: |-
  1833. RemoteKey is the name of the single provider secret that will receive ALL
  1834. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  1835. When set, per-key expansion is skipped and a single push is performed.
  1836. The provider's store prefix (if any) is still prepended to this value.
  1837. When not set, each matched key is pushed as its own individual provider secret.
  1838. type: string
  1839. rewrite:
  1840. description: |-
  1841. Rewrite operations to transform keys before pushing to the provider.
  1842. Operations are applied sequentially.
  1843. items:
  1844. description: PushSecretRewrite defines how to transform secret keys before pushing.
  1845. properties:
  1846. regexp:
  1847. description: Used to rewrite with regular expressions.
  1848. properties:
  1849. source:
  1850. description: Used to define the regular expression of a re.Compiler.
  1851. type: string
  1852. target:
  1853. description: Used to define the target pattern of a ReplaceAll operation.
  1854. type: string
  1855. required:
  1856. - source
  1857. - target
  1858. type: object
  1859. transform:
  1860. description: Used to apply string transformation on the secrets.
  1861. properties:
  1862. template:
  1863. description: |-
  1864. Used to define the template to apply on the secret name.
  1865. `.value ` will specify the secret name in the template.
  1866. type: string
  1867. required:
  1868. - template
  1869. type: object
  1870. type: object
  1871. x-kubernetes-validations:
  1872. - message: exactly one of regexp or transform must be set
  1873. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  1874. type: array
  1875. storeRef:
  1876. description: StoreRef specifies which SecretStore to push to. Required.
  1877. properties:
  1878. kind:
  1879. default: SecretStore
  1880. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1881. enum:
  1882. - SecretStore
  1883. - ClusterSecretStore
  1884. type: string
  1885. labelSelector:
  1886. description: Optionally, sync to secret stores with label selector
  1887. properties:
  1888. matchExpressions:
  1889. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1890. items:
  1891. description: |-
  1892. A label selector requirement is a selector that contains values, a key, and an operator that
  1893. relates the key and values.
  1894. properties:
  1895. key:
  1896. description: key is the label key that the selector applies to.
  1897. type: string
  1898. operator:
  1899. description: |-
  1900. operator represents a key's relationship to a set of values.
  1901. Valid operators are In, NotIn, Exists and DoesNotExist.
  1902. type: string
  1903. values:
  1904. description: |-
  1905. values is an array of string values. If the operator is In or NotIn,
  1906. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1907. the values array must be empty. This array is replaced during a strategic
  1908. merge patch.
  1909. items:
  1910. type: string
  1911. type: array
  1912. x-kubernetes-list-type: atomic
  1913. required:
  1914. - key
  1915. - operator
  1916. type: object
  1917. type: array
  1918. x-kubernetes-list-type: atomic
  1919. matchLabels:
  1920. additionalProperties:
  1921. type: string
  1922. description: |-
  1923. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1924. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1925. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1926. type: object
  1927. type: object
  1928. x-kubernetes-map-type: atomic
  1929. name:
  1930. description: Optionally, sync to the SecretStore of the given name
  1931. maxLength: 253
  1932. minLength: 1
  1933. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1934. type: string
  1935. type: object
  1936. type: object
  1937. x-kubernetes-validations:
  1938. - message: storeRef must specify either name or labelSelector
  1939. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  1940. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  1941. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  1942. type: array
  1943. deletionPolicy:
  1944. default: None
  1945. description: Deletion Policy to handle Secrets in the provider.
  1946. enum:
  1947. - Delete
  1948. - None
  1949. type: string
  1950. refreshInterval:
  1951. default: 1h0m0s
  1952. description: The Interval to which External Secrets will try to push a secret definition
  1953. type: string
  1954. secretStoreRefs:
  1955. items:
  1956. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  1957. properties:
  1958. kind:
  1959. default: SecretStore
  1960. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1961. enum:
  1962. - SecretStore
  1963. - ClusterSecretStore
  1964. type: string
  1965. labelSelector:
  1966. description: Optionally, sync to secret stores with label selector
  1967. properties:
  1968. matchExpressions:
  1969. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1970. items:
  1971. description: |-
  1972. A label selector requirement is a selector that contains values, a key, and an operator that
  1973. relates the key and values.
  1974. properties:
  1975. key:
  1976. description: key is the label key that the selector applies to.
  1977. type: string
  1978. operator:
  1979. description: |-
  1980. operator represents a key's relationship to a set of values.
  1981. Valid operators are In, NotIn, Exists and DoesNotExist.
  1982. type: string
  1983. values:
  1984. description: |-
  1985. values is an array of string values. If the operator is In or NotIn,
  1986. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1987. the values array must be empty. This array is replaced during a strategic
  1988. merge patch.
  1989. items:
  1990. type: string
  1991. type: array
  1992. x-kubernetes-list-type: atomic
  1993. required:
  1994. - key
  1995. - operator
  1996. type: object
  1997. type: array
  1998. x-kubernetes-list-type: atomic
  1999. matchLabels:
  2000. additionalProperties:
  2001. type: string
  2002. description: |-
  2003. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2004. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2005. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2006. type: object
  2007. type: object
  2008. x-kubernetes-map-type: atomic
  2009. name:
  2010. description: Optionally, sync to the SecretStore of the given name
  2011. maxLength: 253
  2012. minLength: 1
  2013. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2014. type: string
  2015. type: object
  2016. type: array
  2017. selector:
  2018. description: The Secret Selector (k8s source) for the Push Secret
  2019. maxProperties: 1
  2020. minProperties: 1
  2021. properties:
  2022. generatorRef:
  2023. description: Point to a generator to create a Secret.
  2024. properties:
  2025. apiVersion:
  2026. default: generators.external-secrets.io/v1alpha1
  2027. description: Specify the apiVersion of the generator resource
  2028. type: string
  2029. kind:
  2030. description: Specify the Kind of the generator resource
  2031. enum:
  2032. - ACRAccessToken
  2033. - BeyondtrustWorkloadCredentialsDynamicSecret
  2034. - ClusterGenerator
  2035. - CloudsmithAccessToken
  2036. - ECRAuthorizationToken
  2037. - Fake
  2038. - GCRAccessToken
  2039. - GithubAccessToken
  2040. - GitlabDeployToken
  2041. - QuayAccessToken
  2042. - Password
  2043. - SSHKey
  2044. - STSSessionToken
  2045. - UUID
  2046. - VaultDynamicSecret
  2047. - Webhook
  2048. - Grafana
  2049. - MFA
  2050. type: string
  2051. name:
  2052. description: Specify the name of the generator resource
  2053. maxLength: 253
  2054. minLength: 1
  2055. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2056. type: string
  2057. required:
  2058. - kind
  2059. - name
  2060. type: object
  2061. secret:
  2062. description: Select a Secret to Push.
  2063. properties:
  2064. name:
  2065. description: |-
  2066. Name of the Secret.
  2067. The Secret must exist in the same namespace as the PushSecret manifest.
  2068. maxLength: 253
  2069. minLength: 1
  2070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2071. type: string
  2072. selector:
  2073. description: Selector chooses secrets using a labelSelector.
  2074. properties:
  2075. matchExpressions:
  2076. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2077. items:
  2078. description: |-
  2079. A label selector requirement is a selector that contains values, a key, and an operator that
  2080. relates the key and values.
  2081. properties:
  2082. key:
  2083. description: key is the label key that the selector applies to.
  2084. type: string
  2085. operator:
  2086. description: |-
  2087. operator represents a key's relationship to a set of values.
  2088. Valid operators are In, NotIn, Exists and DoesNotExist.
  2089. type: string
  2090. values:
  2091. description: |-
  2092. values is an array of string values. If the operator is In or NotIn,
  2093. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2094. the values array must be empty. This array is replaced during a strategic
  2095. merge patch.
  2096. items:
  2097. type: string
  2098. type: array
  2099. x-kubernetes-list-type: atomic
  2100. required:
  2101. - key
  2102. - operator
  2103. type: object
  2104. type: array
  2105. x-kubernetes-list-type: atomic
  2106. matchLabels:
  2107. additionalProperties:
  2108. type: string
  2109. description: |-
  2110. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2111. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2112. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2113. type: object
  2114. type: object
  2115. x-kubernetes-map-type: atomic
  2116. type: object
  2117. type: object
  2118. template:
  2119. description: Template defines a blueprint for the created Secret resource.
  2120. properties:
  2121. data:
  2122. additionalProperties:
  2123. type: string
  2124. type: object
  2125. engineVersion:
  2126. default: v2
  2127. description: |-
  2128. EngineVersion specifies the template engine version
  2129. that should be used to compile/execute the
  2130. template specified in .data and .templateFrom[].
  2131. enum:
  2132. - v2
  2133. type: string
  2134. mergePolicy:
  2135. default: Replace
  2136. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  2137. enum:
  2138. - Replace
  2139. - Merge
  2140. type: string
  2141. metadata:
  2142. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  2143. properties:
  2144. annotations:
  2145. additionalProperties:
  2146. type: string
  2147. type: object
  2148. finalizers:
  2149. items:
  2150. type: string
  2151. type: array
  2152. labels:
  2153. additionalProperties:
  2154. type: string
  2155. type: object
  2156. type: object
  2157. templateFrom:
  2158. items:
  2159. description: |-
  2160. TemplateFrom specifies a source for templates.
  2161. Each item in the list can either reference a ConfigMap or a Secret resource.
  2162. properties:
  2163. configMap:
  2164. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2165. properties:
  2166. items:
  2167. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2168. items:
  2169. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2170. properties:
  2171. key:
  2172. description: A key in the ConfigMap/Secret
  2173. maxLength: 253
  2174. minLength: 1
  2175. pattern: ^[-._a-zA-Z0-9]+$
  2176. type: string
  2177. templateAs:
  2178. default: Values
  2179. description: TemplateScope specifies how the template keys should be interpreted.
  2180. enum:
  2181. - Values
  2182. - KeysAndValues
  2183. type: string
  2184. required:
  2185. - key
  2186. type: object
  2187. type: array
  2188. name:
  2189. description: The name of the ConfigMap/Secret resource
  2190. maxLength: 253
  2191. minLength: 1
  2192. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2193. type: string
  2194. required:
  2195. - items
  2196. - name
  2197. type: object
  2198. literal:
  2199. type: string
  2200. secret:
  2201. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2202. properties:
  2203. items:
  2204. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2205. items:
  2206. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2207. properties:
  2208. key:
  2209. description: A key in the ConfigMap/Secret
  2210. maxLength: 253
  2211. minLength: 1
  2212. pattern: ^[-._a-zA-Z0-9]+$
  2213. type: string
  2214. templateAs:
  2215. default: Values
  2216. description: TemplateScope specifies how the template keys should be interpreted.
  2217. enum:
  2218. - Values
  2219. - KeysAndValues
  2220. type: string
  2221. required:
  2222. - key
  2223. type: object
  2224. type: array
  2225. name:
  2226. description: The name of the ConfigMap/Secret resource
  2227. maxLength: 253
  2228. minLength: 1
  2229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2230. type: string
  2231. required:
  2232. - items
  2233. - name
  2234. type: object
  2235. target:
  2236. default: Data
  2237. description: |-
  2238. Target specifies where to place the template result.
  2239. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  2240. any other value is rejected because it would allow writes to privileged Secret fields.
  2241. For custom resources (when spec.target.manifest is set), this supports
  2242. nested paths like "spec.database.config" or "data".
  2243. type: string
  2244. valuesDecodingStrategy:
  2245. default: None
  2246. description: Used to define a decoding Strategy for the rendered template values.
  2247. enum:
  2248. - Auto
  2249. - Base64
  2250. - Base64URL
  2251. - None
  2252. type: string
  2253. type: object
  2254. type: array
  2255. type:
  2256. type: string
  2257. type: object
  2258. updatePolicy:
  2259. default: Replace
  2260. description: UpdatePolicy to handle Secrets in the provider.
  2261. enum:
  2262. - Replace
  2263. - IfNotExists
  2264. type: string
  2265. required:
  2266. - secretStoreRefs
  2267. - selector
  2268. type: object
  2269. refreshTime:
  2270. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  2271. type: string
  2272. required:
  2273. - pushSecretSpec
  2274. type: object
  2275. status:
  2276. description: ClusterPushSecretStatus contains the status information for the ClusterPushSecret resource.
  2277. properties:
  2278. conditions:
  2279. items:
  2280. description: PushSecretStatusCondition indicates the status of the PushSecret.
  2281. properties:
  2282. lastTransitionTime:
  2283. format: date-time
  2284. type: string
  2285. message:
  2286. type: string
  2287. reason:
  2288. type: string
  2289. status:
  2290. type: string
  2291. type:
  2292. description: PushSecretConditionType indicates the condition of the PushSecret.
  2293. type: string
  2294. required:
  2295. - status
  2296. - type
  2297. type: object
  2298. type: array
  2299. failedNamespaces:
  2300. description: Failed namespaces are the namespaces that failed to apply an PushSecret
  2301. items:
  2302. description: ClusterPushSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  2303. properties:
  2304. namespace:
  2305. description: Namespace is the namespace that failed when trying to apply an PushSecret
  2306. type: string
  2307. reason:
  2308. description: Reason is why the PushSecret failed to apply to the namespace
  2309. type: string
  2310. required:
  2311. - namespace
  2312. type: object
  2313. type: array
  2314. provisionedNamespaces:
  2315. description: ProvisionedNamespaces are the namespaces where the ClusterPushSecret has secrets
  2316. items:
  2317. type: string
  2318. type: array
  2319. pushSecretName:
  2320. type: string
  2321. type: object
  2322. type: object
  2323. served: true
  2324. storage: true
  2325. subresources:
  2326. status: {}
  2327. ---
  2328. apiVersion: apiextensions.k8s.io/v1
  2329. kind: CustomResourceDefinition
  2330. metadata:
  2331. annotations:
  2332. controller-gen.kubebuilder.io/version: v0.19.0
  2333. labels:
  2334. external-secrets.io/component: controller
  2335. name: clustersecretstores.external-secrets.io
  2336. spec:
  2337. group: external-secrets.io
  2338. names:
  2339. categories:
  2340. - external-secrets
  2341. kind: ClusterSecretStore
  2342. listKind: ClusterSecretStoreList
  2343. plural: clustersecretstores
  2344. shortNames:
  2345. - css
  2346. singular: clustersecretstore
  2347. scope: Cluster
  2348. versions:
  2349. - additionalPrinterColumns:
  2350. - jsonPath: .metadata.creationTimestamp
  2351. name: AGE
  2352. type: date
  2353. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  2354. name: Status
  2355. type: string
  2356. - jsonPath: .status.capabilities
  2357. name: Capabilities
  2358. type: string
  2359. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  2360. name: Ready
  2361. type: string
  2362. name: v1
  2363. schema:
  2364. openAPIV3Schema:
  2365. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  2366. properties:
  2367. apiVersion:
  2368. description: |-
  2369. APIVersion defines the versioned schema of this representation of an object.
  2370. Servers should convert recognized schemas to the latest internal value, and
  2371. may reject unrecognized values.
  2372. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  2373. type: string
  2374. kind:
  2375. description: |-
  2376. Kind is a string value representing the REST resource this object represents.
  2377. Servers may infer this from the endpoint the client submits requests to.
  2378. Cannot be updated.
  2379. In CamelCase.
  2380. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  2381. type: string
  2382. metadata:
  2383. type: object
  2384. spec:
  2385. description: SecretStoreSpec defines the desired state of SecretStore.
  2386. properties:
  2387. conditions:
  2388. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  2389. items:
  2390. description: |-
  2391. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  2392. for a ClusterSecretStore instance.
  2393. properties:
  2394. namespaceRegexes:
  2395. description: Choose namespaces by using regex matching
  2396. items:
  2397. type: string
  2398. type: array
  2399. namespaceSelector:
  2400. description: Choose namespace using a labelSelector
  2401. properties:
  2402. matchExpressions:
  2403. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2404. items:
  2405. description: |-
  2406. A label selector requirement is a selector that contains values, a key, and an operator that
  2407. relates the key and values.
  2408. properties:
  2409. key:
  2410. description: key is the label key that the selector applies to.
  2411. type: string
  2412. operator:
  2413. description: |-
  2414. operator represents a key's relationship to a set of values.
  2415. Valid operators are In, NotIn, Exists and DoesNotExist.
  2416. type: string
  2417. values:
  2418. description: |-
  2419. values is an array of string values. If the operator is In or NotIn,
  2420. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2421. the values array must be empty. This array is replaced during a strategic
  2422. merge patch.
  2423. items:
  2424. type: string
  2425. type: array
  2426. x-kubernetes-list-type: atomic
  2427. required:
  2428. - key
  2429. - operator
  2430. type: object
  2431. type: array
  2432. x-kubernetes-list-type: atomic
  2433. matchLabels:
  2434. additionalProperties:
  2435. type: string
  2436. description: |-
  2437. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2438. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2439. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2440. type: object
  2441. type: object
  2442. x-kubernetes-map-type: atomic
  2443. namespaces:
  2444. description: Choose namespaces by name
  2445. items:
  2446. maxLength: 63
  2447. minLength: 1
  2448. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2449. type: string
  2450. type: array
  2451. type: object
  2452. type: array
  2453. controller:
  2454. description: |-
  2455. Used to select the correct ESO controller (think: ingress.ingressClassName)
  2456. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  2457. type: string
  2458. provider:
  2459. description: Used to configure the provider. Only one provider may be set
  2460. maxProperties: 1
  2461. minProperties: 1
  2462. properties:
  2463. akeyless:
  2464. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  2465. properties:
  2466. akeylessGWApiURL:
  2467. description: Akeyless GW API Url from which the secrets to be fetched from.
  2468. type: string
  2469. authSecretRef:
  2470. description: Auth configures how the operator authenticates with Akeyless.
  2471. properties:
  2472. kubernetesAuth:
  2473. description: |-
  2474. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  2475. token stored in the named Secret resource.
  2476. properties:
  2477. accessID:
  2478. description: the Akeyless Kubernetes auth-method access-id
  2479. type: string
  2480. k8sConfName:
  2481. description: Kubernetes-auth configuration name in Akeyless-Gateway
  2482. type: string
  2483. secretRef:
  2484. description: |-
  2485. Optional secret field containing a Kubernetes ServiceAccount JWT used
  2486. for authenticating with Akeyless. If a name is specified without a key,
  2487. `token` is the default. If one is not specified, the one bound to
  2488. the controller will be used.
  2489. properties:
  2490. key:
  2491. description: |-
  2492. A key in the referenced Secret.
  2493. Some instances of this field may be defaulted, in others it may be required.
  2494. maxLength: 253
  2495. minLength: 1
  2496. pattern: ^[-._a-zA-Z0-9]+$
  2497. type: string
  2498. name:
  2499. description: The name of the Secret resource being referred to.
  2500. maxLength: 253
  2501. minLength: 1
  2502. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2503. type: string
  2504. namespace:
  2505. description: |-
  2506. The namespace of the Secret resource being referred to.
  2507. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2508. maxLength: 63
  2509. minLength: 1
  2510. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2511. type: string
  2512. type: object
  2513. serviceAccountRef:
  2514. description: |-
  2515. Optional service account field containing the name of a kubernetes ServiceAccount.
  2516. If the service account is specified, the service account secret token JWT will be used
  2517. for authenticating with Akeyless. If the service account selector is not supplied,
  2518. the secretRef will be used instead.
  2519. properties:
  2520. audiences:
  2521. description: |-
  2522. Audience specifies the `aud` claim for the service account token
  2523. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2524. then this audiences will be appended to the list
  2525. items:
  2526. type: string
  2527. type: array
  2528. name:
  2529. description: The name of the ServiceAccount resource being referred to.
  2530. maxLength: 253
  2531. minLength: 1
  2532. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2533. type: string
  2534. namespace:
  2535. description: |-
  2536. Namespace of the resource being referred to.
  2537. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2538. maxLength: 63
  2539. minLength: 1
  2540. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2541. type: string
  2542. required:
  2543. - name
  2544. type: object
  2545. required:
  2546. - accessID
  2547. - k8sConfName
  2548. type: object
  2549. secretRef:
  2550. description: |-
  2551. Reference to a Secret that contains the details
  2552. to authenticate with Akeyless.
  2553. properties:
  2554. accessID:
  2555. description: The SecretAccessID is used for authentication
  2556. properties:
  2557. key:
  2558. description: |-
  2559. A key in the referenced Secret.
  2560. Some instances of this field may be defaulted, in others it may be required.
  2561. maxLength: 253
  2562. minLength: 1
  2563. pattern: ^[-._a-zA-Z0-9]+$
  2564. type: string
  2565. name:
  2566. description: The name of the Secret resource being referred to.
  2567. maxLength: 253
  2568. minLength: 1
  2569. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2570. type: string
  2571. namespace:
  2572. description: |-
  2573. The namespace of the Secret resource being referred to.
  2574. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2575. maxLength: 63
  2576. minLength: 1
  2577. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2578. type: string
  2579. type: object
  2580. accessType:
  2581. description: |-
  2582. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2583. In some instances, `key` is a required field.
  2584. properties:
  2585. key:
  2586. description: |-
  2587. A key in the referenced Secret.
  2588. Some instances of this field may be defaulted, in others it may be required.
  2589. maxLength: 253
  2590. minLength: 1
  2591. pattern: ^[-._a-zA-Z0-9]+$
  2592. type: string
  2593. name:
  2594. description: The name of the Secret resource being referred to.
  2595. maxLength: 253
  2596. minLength: 1
  2597. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2598. type: string
  2599. namespace:
  2600. description: |-
  2601. The namespace of the Secret resource being referred to.
  2602. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2603. maxLength: 63
  2604. minLength: 1
  2605. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2606. type: string
  2607. type: object
  2608. accessTypeParam:
  2609. description: |-
  2610. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2611. In some instances, `key` is a required field.
  2612. properties:
  2613. key:
  2614. description: |-
  2615. A key in the referenced Secret.
  2616. Some instances of this field may be defaulted, in others it may be required.
  2617. maxLength: 253
  2618. minLength: 1
  2619. pattern: ^[-._a-zA-Z0-9]+$
  2620. type: string
  2621. name:
  2622. description: The name of the Secret resource being referred to.
  2623. maxLength: 253
  2624. minLength: 1
  2625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2626. type: string
  2627. namespace:
  2628. description: |-
  2629. The namespace of the Secret resource being referred to.
  2630. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2631. maxLength: 63
  2632. minLength: 1
  2633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2634. type: string
  2635. type: object
  2636. type: object
  2637. serviceAccountRef:
  2638. description: |-
  2639. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  2640. authentication on AKS Workload Identity. The operator obtains a federated
  2641. identity token from this ServiceAccount via the TokenRequest API instead
  2642. of using the ESO controller pod identity. Ignored for other access types.
  2643. properties:
  2644. audiences:
  2645. description: |-
  2646. Audience specifies the `aud` claim for the service account token
  2647. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2648. then this audiences will be appended to the list
  2649. items:
  2650. type: string
  2651. type: array
  2652. name:
  2653. description: The name of the ServiceAccount resource being referred to.
  2654. maxLength: 253
  2655. minLength: 1
  2656. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2657. type: string
  2658. namespace:
  2659. description: |-
  2660. Namespace of the resource being referred to.
  2661. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2662. maxLength: 63
  2663. minLength: 1
  2664. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2665. type: string
  2666. required:
  2667. - name
  2668. type: object
  2669. type: object
  2670. caBundle:
  2671. description: |-
  2672. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  2673. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  2674. are used to validate the TLS connection.
  2675. format: byte
  2676. type: string
  2677. caProvider:
  2678. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  2679. properties:
  2680. key:
  2681. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  2682. maxLength: 253
  2683. minLength: 1
  2684. pattern: ^[-._a-zA-Z0-9]+$
  2685. type: string
  2686. name:
  2687. description: The name of the object located at the provider type.
  2688. maxLength: 253
  2689. minLength: 1
  2690. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2691. type: string
  2692. namespace:
  2693. description: |-
  2694. The namespace the Provider type is in.
  2695. Can only be defined when used in a ClusterSecretStore.
  2696. maxLength: 63
  2697. minLength: 1
  2698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2699. type: string
  2700. type:
  2701. description: The type of provider to use such as "Secret", or "ConfigMap".
  2702. enum:
  2703. - Secret
  2704. - ConfigMap
  2705. type: string
  2706. required:
  2707. - name
  2708. - type
  2709. type: object
  2710. ignoreCache:
  2711. description: |-
  2712. IgnoreCache bypasses the Gateway cache for secret reads when true.
  2713. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  2714. type: boolean
  2715. required:
  2716. - akeylessGWApiURL
  2717. - authSecretRef
  2718. type: object
  2719. aws:
  2720. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  2721. properties:
  2722. additionalRoles:
  2723. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  2724. items:
  2725. type: string
  2726. type: array
  2727. auth:
  2728. description: |-
  2729. Auth defines the information necessary to authenticate against AWS
  2730. if not set aws sdk will infer credentials from your environment
  2731. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  2732. properties:
  2733. jwt:
  2734. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  2735. properties:
  2736. serviceAccountRef:
  2737. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  2738. properties:
  2739. audiences:
  2740. description: |-
  2741. Audience specifies the `aud` claim for the service account token
  2742. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2743. then this audiences will be appended to the list
  2744. items:
  2745. type: string
  2746. type: array
  2747. name:
  2748. description: The name of the ServiceAccount resource being referred to.
  2749. maxLength: 253
  2750. minLength: 1
  2751. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2752. type: string
  2753. namespace:
  2754. description: |-
  2755. Namespace of the resource being referred to.
  2756. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2757. maxLength: 63
  2758. minLength: 1
  2759. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2760. type: string
  2761. required:
  2762. - name
  2763. type: object
  2764. type: object
  2765. secretRef:
  2766. description: |-
  2767. AWSAuthSecretRef holds secret references for AWS credentials
  2768. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  2769. properties:
  2770. accessKeyIDSecretRef:
  2771. description: The AccessKeyID is used for authentication
  2772. properties:
  2773. key:
  2774. description: |-
  2775. A key in the referenced Secret.
  2776. Some instances of this field may be defaulted, in others it may be required.
  2777. maxLength: 253
  2778. minLength: 1
  2779. pattern: ^[-._a-zA-Z0-9]+$
  2780. type: string
  2781. name:
  2782. description: The name of the Secret resource being referred to.
  2783. maxLength: 253
  2784. minLength: 1
  2785. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2786. type: string
  2787. namespace:
  2788. description: |-
  2789. The namespace of the Secret resource being referred to.
  2790. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2791. maxLength: 63
  2792. minLength: 1
  2793. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2794. type: string
  2795. type: object
  2796. secretAccessKeySecretRef:
  2797. description: The SecretAccessKey is used for authentication
  2798. properties:
  2799. key:
  2800. description: |-
  2801. A key in the referenced Secret.
  2802. Some instances of this field may be defaulted, in others it may be required.
  2803. maxLength: 253
  2804. minLength: 1
  2805. pattern: ^[-._a-zA-Z0-9]+$
  2806. type: string
  2807. name:
  2808. description: The name of the Secret resource being referred to.
  2809. maxLength: 253
  2810. minLength: 1
  2811. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2812. type: string
  2813. namespace:
  2814. description: |-
  2815. The namespace of the Secret resource being referred to.
  2816. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2817. maxLength: 63
  2818. minLength: 1
  2819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2820. type: string
  2821. type: object
  2822. sessionTokenSecretRef:
  2823. description: |-
  2824. The SessionToken used for authentication
  2825. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  2826. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  2827. properties:
  2828. key:
  2829. description: |-
  2830. A key in the referenced Secret.
  2831. Some instances of this field may be defaulted, in others it may be required.
  2832. maxLength: 253
  2833. minLength: 1
  2834. pattern: ^[-._a-zA-Z0-9]+$
  2835. type: string
  2836. name:
  2837. description: The name of the Secret resource being referred to.
  2838. maxLength: 253
  2839. minLength: 1
  2840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2841. type: string
  2842. namespace:
  2843. description: |-
  2844. The namespace of the Secret resource being referred to.
  2845. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2846. maxLength: 63
  2847. minLength: 1
  2848. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2849. type: string
  2850. type: object
  2851. type: object
  2852. type: object
  2853. customSessionTags:
  2854. additionalProperties:
  2855. type: string
  2856. description: |-
  2857. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  2858. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  2859. type: object
  2860. x-kubernetes-validations:
  2861. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  2862. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  2863. externalID:
  2864. description: AWS External ID set on assumed IAM roles
  2865. type: string
  2866. prefix:
  2867. description: Prefix adds a prefix to all retrieved values.
  2868. type: string
  2869. region:
  2870. description: AWS Region to be used for the provider
  2871. type: string
  2872. role:
  2873. description: Role is a Role ARN which the provider will assume
  2874. type: string
  2875. secretsManager:
  2876. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  2877. properties:
  2878. forceDeleteWithoutRecovery:
  2879. description: |-
  2880. Specifies whether to delete the secret without any recovery window. You
  2881. can't use both this parameter and RecoveryWindowInDays in the same call.
  2882. If you don't use either, then by default Secrets Manager uses a 30 day
  2883. recovery window.
  2884. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  2885. type: boolean
  2886. recoveryWindowInDays:
  2887. description: |-
  2888. The number of days from 7 to 30 that Secrets Manager waits before
  2889. permanently deleting the secret. You can't use both this parameter and
  2890. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  2891. then by default Secrets Manager uses a 30-day recovery window.
  2892. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  2893. format: int64
  2894. type: integer
  2895. type: object
  2896. service:
  2897. description: Service defines which service should be used to fetch the secrets
  2898. enum:
  2899. - SecretsManager
  2900. - ParameterStore
  2901. - CertificateManager
  2902. type: string
  2903. sessionTags:
  2904. description: AWS STS assume role session tags
  2905. items:
  2906. description: |-
  2907. Tag is a key-value pair that can be attached to an AWS resource.
  2908. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  2909. properties:
  2910. key:
  2911. type: string
  2912. value:
  2913. type: string
  2914. required:
  2915. - key
  2916. - value
  2917. type: object
  2918. type: array
  2919. sessionTagsPolicy:
  2920. default: None
  2921. description: |-
  2922. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  2923. None (default): no tags are added.
  2924. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  2925. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  2926. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  2927. enum:
  2928. - None
  2929. - Simple
  2930. - Custom
  2931. type: string
  2932. transitiveTagKeys:
  2933. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  2934. items:
  2935. type: string
  2936. type: array
  2937. required:
  2938. - region
  2939. - service
  2940. type: object
  2941. azurekv:
  2942. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  2943. properties:
  2944. authSecretRef:
  2945. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  2946. properties:
  2947. clientCertificate:
  2948. description: The Azure ClientCertificate of the service principle used for authentication.
  2949. properties:
  2950. key:
  2951. description: |-
  2952. A key in the referenced Secret.
  2953. Some instances of this field may be defaulted, in others it may be required.
  2954. maxLength: 253
  2955. minLength: 1
  2956. pattern: ^[-._a-zA-Z0-9]+$
  2957. type: string
  2958. name:
  2959. description: The name of the Secret resource being referred to.
  2960. maxLength: 253
  2961. minLength: 1
  2962. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2963. type: string
  2964. namespace:
  2965. description: |-
  2966. The namespace of the Secret resource being referred to.
  2967. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2968. maxLength: 63
  2969. minLength: 1
  2970. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2971. type: string
  2972. type: object
  2973. clientId:
  2974. description: The Azure clientId of the service principle or managed identity used for authentication.
  2975. properties:
  2976. key:
  2977. description: |-
  2978. A key in the referenced Secret.
  2979. Some instances of this field may be defaulted, in others it may be required.
  2980. maxLength: 253
  2981. minLength: 1
  2982. pattern: ^[-._a-zA-Z0-9]+$
  2983. type: string
  2984. name:
  2985. description: The name of the Secret resource being referred to.
  2986. maxLength: 253
  2987. minLength: 1
  2988. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2989. type: string
  2990. namespace:
  2991. description: |-
  2992. The namespace of the Secret resource being referred to.
  2993. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2994. maxLength: 63
  2995. minLength: 1
  2996. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2997. type: string
  2998. type: object
  2999. clientSecret:
  3000. description: The Azure ClientSecret of the service principle used for authentication.
  3001. properties:
  3002. key:
  3003. description: |-
  3004. A key in the referenced Secret.
  3005. Some instances of this field may be defaulted, in others it may be required.
  3006. maxLength: 253
  3007. minLength: 1
  3008. pattern: ^[-._a-zA-Z0-9]+$
  3009. type: string
  3010. name:
  3011. description: The name of the Secret resource being referred to.
  3012. maxLength: 253
  3013. minLength: 1
  3014. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3015. type: string
  3016. namespace:
  3017. description: |-
  3018. The namespace of the Secret resource being referred to.
  3019. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3020. maxLength: 63
  3021. minLength: 1
  3022. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3023. type: string
  3024. type: object
  3025. tenantId:
  3026. description: The Azure tenantId of the managed identity used for authentication.
  3027. properties:
  3028. key:
  3029. description: |-
  3030. A key in the referenced Secret.
  3031. Some instances of this field may be defaulted, in others it may be required.
  3032. maxLength: 253
  3033. minLength: 1
  3034. pattern: ^[-._a-zA-Z0-9]+$
  3035. type: string
  3036. name:
  3037. description: The name of the Secret resource being referred to.
  3038. maxLength: 253
  3039. minLength: 1
  3040. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3041. type: string
  3042. namespace:
  3043. description: |-
  3044. The namespace of the Secret resource being referred to.
  3045. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3046. maxLength: 63
  3047. minLength: 1
  3048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3049. type: string
  3050. type: object
  3051. type: object
  3052. authType:
  3053. default: ServicePrincipal
  3054. description: |-
  3055. Auth type defines how to authenticate to the keyvault service.
  3056. Valid values are:
  3057. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  3058. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  3059. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  3060. enum:
  3061. - ServicePrincipal
  3062. - ManagedIdentity
  3063. - WorkloadIdentity
  3064. type: string
  3065. customCloudConfig:
  3066. description: |-
  3067. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  3068. Required when EnvironmentType is AzureStackCloud.
  3069. Optional for other environment types - useful for Azure China when using Workload Identity
  3070. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  3071. standard China Cloud endpoint (login.chinacloudapi.cn).
  3072. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  3073. configuration is not supported with the legacy go-autorest SDK.
  3074. properties:
  3075. activeDirectoryEndpoint:
  3076. description: |-
  3077. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  3078. Required when using custom cloud configuration
  3079. type: string
  3080. keyVaultDNSSuffix:
  3081. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  3082. type: string
  3083. keyVaultEndpoint:
  3084. description: KeyVaultEndpoint is the Key Vault service endpoint
  3085. type: string
  3086. resourceManagerEndpoint:
  3087. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  3088. type: string
  3089. required:
  3090. - activeDirectoryEndpoint
  3091. type: object
  3092. environmentType:
  3093. default: PublicCloud
  3094. description: |-
  3095. EnvironmentType specifies the Azure cloud environment endpoints to use for
  3096. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  3097. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  3098. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  3099. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  3100. enum:
  3101. - PublicCloud
  3102. - USGovernmentCloud
  3103. - ChinaCloud
  3104. - GermanCloud
  3105. - AzureStackCloud
  3106. type: string
  3107. identityId:
  3108. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  3109. type: string
  3110. serviceAccountRef:
  3111. description: |-
  3112. ServiceAccountRef specified the service account
  3113. that should be used when authenticating with WorkloadIdentity.
  3114. properties:
  3115. audiences:
  3116. description: |-
  3117. Audience specifies the `aud` claim for the service account token
  3118. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  3119. then this audiences will be appended to the list
  3120. items:
  3121. type: string
  3122. type: array
  3123. name:
  3124. description: The name of the ServiceAccount resource being referred to.
  3125. maxLength: 253
  3126. minLength: 1
  3127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3128. type: string
  3129. namespace:
  3130. description: |-
  3131. Namespace of the resource being referred to.
  3132. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3133. maxLength: 63
  3134. minLength: 1
  3135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3136. type: string
  3137. required:
  3138. - name
  3139. type: object
  3140. tenantId:
  3141. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  3142. type: string
  3143. useAzureSDK:
  3144. default: false
  3145. description: |-
  3146. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  3147. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  3148. type: boolean
  3149. vaultUrl:
  3150. description: Vault Url from which the secrets to be fetched from.
  3151. type: string
  3152. required:
  3153. - vaultUrl
  3154. type: object
  3155. barbican:
  3156. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  3157. properties:
  3158. auth:
  3159. description: BarbicanAuth contains the authentication information for Barbican.
  3160. properties:
  3161. password:
  3162. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  3163. properties:
  3164. secretRef:
  3165. description: |-
  3166. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3167. In some instances, `key` is a required field.
  3168. properties:
  3169. key:
  3170. description: |-
  3171. A key in the referenced Secret.
  3172. Some instances of this field may be defaulted, in others it may be required.
  3173. maxLength: 253
  3174. minLength: 1
  3175. pattern: ^[-._a-zA-Z0-9]+$
  3176. type: string
  3177. name:
  3178. description: The name of the Secret resource being referred to.
  3179. maxLength: 253
  3180. minLength: 1
  3181. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3182. type: string
  3183. namespace:
  3184. description: |-
  3185. The namespace of the Secret resource being referred to.
  3186. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3187. maxLength: 63
  3188. minLength: 1
  3189. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3190. type: string
  3191. type: object
  3192. required:
  3193. - secretRef
  3194. type: object
  3195. username:
  3196. description: BarbicanProviderUsernameRef defines a reference to a secret containing username for the Barbican provider.
  3197. maxProperties: 1
  3198. minProperties: 1
  3199. properties:
  3200. secretRef:
  3201. description: |-
  3202. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3203. In some instances, `key` is a required field.
  3204. properties:
  3205. key:
  3206. description: |-
  3207. A key in the referenced Secret.
  3208. Some instances of this field may be defaulted, in others it may be required.
  3209. maxLength: 253
  3210. minLength: 1
  3211. pattern: ^[-._a-zA-Z0-9]+$
  3212. type: string
  3213. name:
  3214. description: The name of the Secret resource being referred to.
  3215. maxLength: 253
  3216. minLength: 1
  3217. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3218. type: string
  3219. namespace:
  3220. description: |-
  3221. The namespace of the Secret resource being referred to.
  3222. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3223. maxLength: 63
  3224. minLength: 1
  3225. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3226. type: string
  3227. type: object
  3228. value:
  3229. type: string
  3230. type: object
  3231. required:
  3232. - password
  3233. - username
  3234. type: object
  3235. authURL:
  3236. type: string
  3237. domainName:
  3238. type: string
  3239. region:
  3240. type: string
  3241. tenantName:
  3242. type: string
  3243. required:
  3244. - auth
  3245. type: object
  3246. beyondtrust:
  3247. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  3248. properties:
  3249. auth:
  3250. description: Auth configures how the operator authenticates with Beyondtrust.
  3251. properties:
  3252. apiKey:
  3253. description: APIKey If not provided then ClientID/ClientSecret become required.
  3254. properties:
  3255. secretRef:
  3256. description: SecretRef references a key in a secret that will be used as value.
  3257. properties:
  3258. key:
  3259. description: |-
  3260. A key in the referenced Secret.
  3261. Some instances of this field may be defaulted, in others it may be required.
  3262. maxLength: 253
  3263. minLength: 1
  3264. pattern: ^[-._a-zA-Z0-9]+$
  3265. type: string
  3266. name:
  3267. description: The name of the Secret resource being referred to.
  3268. maxLength: 253
  3269. minLength: 1
  3270. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3271. type: string
  3272. namespace:
  3273. description: |-
  3274. The namespace of the Secret resource being referred to.
  3275. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3276. maxLength: 63
  3277. minLength: 1
  3278. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3279. type: string
  3280. type: object
  3281. value:
  3282. description: Value can be specified directly to set a value without using a secret.
  3283. type: string
  3284. type: object
  3285. certificate:
  3286. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  3287. properties:
  3288. secretRef:
  3289. description: SecretRef references a key in a secret that will be used as value.
  3290. properties:
  3291. key:
  3292. description: |-
  3293. A key in the referenced Secret.
  3294. Some instances of this field may be defaulted, in others it may be required.
  3295. maxLength: 253
  3296. minLength: 1
  3297. pattern: ^[-._a-zA-Z0-9]+$
  3298. type: string
  3299. name:
  3300. description: The name of the Secret resource being referred to.
  3301. maxLength: 253
  3302. minLength: 1
  3303. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3304. type: string
  3305. namespace:
  3306. description: |-
  3307. The namespace of the Secret resource being referred to.
  3308. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3309. maxLength: 63
  3310. minLength: 1
  3311. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3312. type: string
  3313. type: object
  3314. value:
  3315. description: Value can be specified directly to set a value without using a secret.
  3316. type: string
  3317. type: object
  3318. certificateKey:
  3319. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  3320. properties:
  3321. secretRef:
  3322. description: SecretRef references a key in a secret that will be used as value.
  3323. properties:
  3324. key:
  3325. description: |-
  3326. A key in the referenced Secret.
  3327. Some instances of this field may be defaulted, in others it may be required.
  3328. maxLength: 253
  3329. minLength: 1
  3330. pattern: ^[-._a-zA-Z0-9]+$
  3331. type: string
  3332. name:
  3333. description: The name of the Secret resource being referred to.
  3334. maxLength: 253
  3335. minLength: 1
  3336. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3337. type: string
  3338. namespace:
  3339. description: |-
  3340. The namespace of the Secret resource being referred to.
  3341. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3342. maxLength: 63
  3343. minLength: 1
  3344. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3345. type: string
  3346. type: object
  3347. value:
  3348. description: Value can be specified directly to set a value without using a secret.
  3349. type: string
  3350. type: object
  3351. clientId:
  3352. description: ClientID is the API OAuth Client ID.
  3353. properties:
  3354. secretRef:
  3355. description: SecretRef references a key in a secret that will be used as value.
  3356. properties:
  3357. key:
  3358. description: |-
  3359. A key in the referenced Secret.
  3360. Some instances of this field may be defaulted, in others it may be required.
  3361. maxLength: 253
  3362. minLength: 1
  3363. pattern: ^[-._a-zA-Z0-9]+$
  3364. type: string
  3365. name:
  3366. description: The name of the Secret resource being referred to.
  3367. maxLength: 253
  3368. minLength: 1
  3369. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3370. type: string
  3371. namespace:
  3372. description: |-
  3373. The namespace of the Secret resource being referred to.
  3374. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3375. maxLength: 63
  3376. minLength: 1
  3377. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3378. type: string
  3379. type: object
  3380. value:
  3381. description: Value can be specified directly to set a value without using a secret.
  3382. type: string
  3383. type: object
  3384. clientSecret:
  3385. description: ClientSecret is the API OAuth Client Secret.
  3386. properties:
  3387. secretRef:
  3388. description: SecretRef references a key in a secret that will be used as value.
  3389. properties:
  3390. key:
  3391. description: |-
  3392. A key in the referenced Secret.
  3393. Some instances of this field may be defaulted, in others it may be required.
  3394. maxLength: 253
  3395. minLength: 1
  3396. pattern: ^[-._a-zA-Z0-9]+$
  3397. type: string
  3398. name:
  3399. description: The name of the Secret resource being referred to.
  3400. maxLength: 253
  3401. minLength: 1
  3402. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3403. type: string
  3404. namespace:
  3405. description: |-
  3406. The namespace of the Secret resource being referred to.
  3407. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3408. maxLength: 63
  3409. minLength: 1
  3410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3411. type: string
  3412. type: object
  3413. value:
  3414. description: Value can be specified directly to set a value without using a secret.
  3415. type: string
  3416. type: object
  3417. type: object
  3418. server:
  3419. description: Auth configures how API server works.
  3420. properties:
  3421. apiUrl:
  3422. type: string
  3423. apiVersion:
  3424. type: string
  3425. clientTimeOutSeconds:
  3426. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  3427. type: integer
  3428. decrypt:
  3429. default: true
  3430. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  3431. type: boolean
  3432. retrievalType:
  3433. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  3434. type: string
  3435. separator:
  3436. description: A character that separates the folder names.
  3437. type: string
  3438. verifyCA:
  3439. type: boolean
  3440. required:
  3441. - apiUrl
  3442. - verifyCA
  3443. type: object
  3444. required:
  3445. - auth
  3446. - server
  3447. type: object
  3448. beyondtrustworkloadcredentials:
  3449. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  3450. properties:
  3451. auth:
  3452. description: |-
  3453. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  3454. Currently supports API key authentication via Kubernetes secret reference.
  3455. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3456. properties:
  3457. apikey:
  3458. description: |-
  3459. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  3460. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  3461. properties:
  3462. token:
  3463. description: |-
  3464. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  3465. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  3466. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  3467. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3468. properties:
  3469. key:
  3470. description: |-
  3471. A key in the referenced Secret.
  3472. Some instances of this field may be defaulted, in others it may be required.
  3473. maxLength: 253
  3474. minLength: 1
  3475. pattern: ^[-._a-zA-Z0-9]+$
  3476. type: string
  3477. name:
  3478. description: The name of the Secret resource being referred to.
  3479. maxLength: 253
  3480. minLength: 1
  3481. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3482. type: string
  3483. namespace:
  3484. description: |-
  3485. The namespace of the Secret resource being referred to.
  3486. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3487. maxLength: 63
  3488. minLength: 1
  3489. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3490. type: string
  3491. type: object
  3492. required:
  3493. - token
  3494. type: object
  3495. required:
  3496. - apikey
  3497. type: object
  3498. caBundle:
  3499. description: |-
  3500. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3501. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  3502. If not set, the system's trusted root certificates are used.
  3503. format: byte
  3504. type: string
  3505. caProvider:
  3506. description: |-
  3507. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  3508. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3509. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  3510. properties:
  3511. key:
  3512. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3513. maxLength: 253
  3514. minLength: 1
  3515. pattern: ^[-._a-zA-Z0-9]+$
  3516. type: string
  3517. name:
  3518. description: The name of the object located at the provider type.
  3519. maxLength: 253
  3520. minLength: 1
  3521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3522. type: string
  3523. namespace:
  3524. description: |-
  3525. The namespace the Provider type is in.
  3526. Can only be defined when used in a ClusterSecretStore.
  3527. maxLength: 63
  3528. minLength: 1
  3529. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3530. type: string
  3531. type:
  3532. description: The type of provider to use such as "Secret", or "ConfigMap".
  3533. enum:
  3534. - Secret
  3535. - ConfigMap
  3536. type: string
  3537. required:
  3538. - name
  3539. - type
  3540. type: object
  3541. folderPath:
  3542. description: |-
  3543. FolderPath specifies the default folder path for secret retrieval.
  3544. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  3545. Example: "production/database" or "dev/api-keys"
  3546. Leave empty to retrieve secrets from the root folder.
  3547. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  3548. type: string
  3549. server:
  3550. description: |-
  3551. Server configures the BeyondTrust Workload Credentials server connection details.
  3552. Includes the API URL and Site ID for your BeyondTrust instance.
  3553. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3554. properties:
  3555. apiUrl:
  3556. description: |-
  3557. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  3558. This should be the full URL to your BeyondTrust instance.
  3559. Example: https://api.beyondtrust.io/siie
  3560. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  3561. type: string
  3562. siteId:
  3563. description: |-
  3564. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  3565. This identifier is unique to your BeyondTrust Workload Credentials instance.
  3566. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  3567. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  3568. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3569. type: string
  3570. required:
  3571. - apiUrl
  3572. - siteId
  3573. type: object
  3574. required:
  3575. - auth
  3576. - server
  3577. type: object
  3578. bitwardensecretsmanager:
  3579. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  3580. properties:
  3581. apiURL:
  3582. type: string
  3583. auth:
  3584. description: |-
  3585. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  3586. Make sure that the token being used has permissions on the given secret.
  3587. properties:
  3588. secretRef:
  3589. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  3590. properties:
  3591. credentials:
  3592. description: AccessToken used for the bitwarden instance.
  3593. properties:
  3594. key:
  3595. description: |-
  3596. A key in the referenced Secret.
  3597. Some instances of this field may be defaulted, in others it may be required.
  3598. maxLength: 253
  3599. minLength: 1
  3600. pattern: ^[-._a-zA-Z0-9]+$
  3601. type: string
  3602. name:
  3603. description: The name of the Secret resource being referred to.
  3604. maxLength: 253
  3605. minLength: 1
  3606. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3607. type: string
  3608. namespace:
  3609. description: |-
  3610. The namespace of the Secret resource being referred to.
  3611. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3612. maxLength: 63
  3613. minLength: 1
  3614. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3615. type: string
  3616. type: object
  3617. required:
  3618. - credentials
  3619. type: object
  3620. required:
  3621. - secretRef
  3622. type: object
  3623. bitwardenServerSDKURL:
  3624. type: string
  3625. caBundle:
  3626. description: |-
  3627. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  3628. can be performed.
  3629. type: string
  3630. caProvider:
  3631. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  3632. properties:
  3633. key:
  3634. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3635. maxLength: 253
  3636. minLength: 1
  3637. pattern: ^[-._a-zA-Z0-9]+$
  3638. type: string
  3639. name:
  3640. description: The name of the object located at the provider type.
  3641. maxLength: 253
  3642. minLength: 1
  3643. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3644. type: string
  3645. namespace:
  3646. description: |-
  3647. The namespace the Provider type is in.
  3648. Can only be defined when used in a ClusterSecretStore.
  3649. maxLength: 63
  3650. minLength: 1
  3651. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3652. type: string
  3653. type:
  3654. description: The type of provider to use such as "Secret", or "ConfigMap".
  3655. enum:
  3656. - Secret
  3657. - ConfigMap
  3658. type: string
  3659. required:
  3660. - name
  3661. - type
  3662. type: object
  3663. identityURL:
  3664. type: string
  3665. organizationID:
  3666. description: OrganizationID determines which organization this secret store manages.
  3667. type: string
  3668. projectID:
  3669. description: ProjectID determines which project this secret store manages.
  3670. type: string
  3671. required:
  3672. - auth
  3673. - organizationID
  3674. - projectID
  3675. type: object
  3676. chef:
  3677. description: Chef configures this store to sync secrets with chef server
  3678. properties:
  3679. auth:
  3680. description: Auth defines the information necessary to authenticate against chef Server
  3681. properties:
  3682. secretRef:
  3683. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  3684. properties:
  3685. privateKeySecretRef:
  3686. description: SecretKey is the Signing Key in PEM format, used for authentication.
  3687. properties:
  3688. key:
  3689. description: |-
  3690. A key in the referenced Secret.
  3691. Some instances of this field may be defaulted, in others it may be required.
  3692. maxLength: 253
  3693. minLength: 1
  3694. pattern: ^[-._a-zA-Z0-9]+$
  3695. type: string
  3696. name:
  3697. description: The name of the Secret resource being referred to.
  3698. maxLength: 253
  3699. minLength: 1
  3700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3701. type: string
  3702. namespace:
  3703. description: |-
  3704. The namespace of the Secret resource being referred to.
  3705. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3706. maxLength: 63
  3707. minLength: 1
  3708. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3709. type: string
  3710. type: object
  3711. required:
  3712. - privateKeySecretRef
  3713. type: object
  3714. required:
  3715. - secretRef
  3716. type: object
  3717. serverUrl:
  3718. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  3719. type: string
  3720. username:
  3721. description: UserName should be the user ID on the chef server
  3722. type: string
  3723. required:
  3724. - auth
  3725. - serverUrl
  3726. - username
  3727. type: object
  3728. cloudrusm:
  3729. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  3730. properties:
  3731. auth:
  3732. description: CSMAuth contains a secretRef for credentials.
  3733. properties:
  3734. secretRef:
  3735. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  3736. properties:
  3737. accessKeyIDSecretRef:
  3738. description: The AccessKeyID is used for authentication
  3739. properties:
  3740. key:
  3741. description: |-
  3742. A key in the referenced Secret.
  3743. Some instances of this field may be defaulted, in others it may be required.
  3744. maxLength: 253
  3745. minLength: 1
  3746. pattern: ^[-._a-zA-Z0-9]+$
  3747. type: string
  3748. name:
  3749. description: The name of the Secret resource being referred to.
  3750. maxLength: 253
  3751. minLength: 1
  3752. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3753. type: string
  3754. namespace:
  3755. description: |-
  3756. The namespace of the Secret resource being referred to.
  3757. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3758. maxLength: 63
  3759. minLength: 1
  3760. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3761. type: string
  3762. type: object
  3763. accessKeySecretSecretRef:
  3764. description: The AccessKeySecret is used for authentication
  3765. properties:
  3766. key:
  3767. description: |-
  3768. A key in the referenced Secret.
  3769. Some instances of this field may be defaulted, in others it may be required.
  3770. maxLength: 253
  3771. minLength: 1
  3772. pattern: ^[-._a-zA-Z0-9]+$
  3773. type: string
  3774. name:
  3775. description: The name of the Secret resource being referred to.
  3776. maxLength: 253
  3777. minLength: 1
  3778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3779. type: string
  3780. namespace:
  3781. description: |-
  3782. The namespace of the Secret resource being referred to.
  3783. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3784. maxLength: 63
  3785. minLength: 1
  3786. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3787. type: string
  3788. type: object
  3789. required:
  3790. - accessKeyIDSecretRef
  3791. - accessKeySecretSecretRef
  3792. type: object
  3793. type: object
  3794. projectID:
  3795. description: ProjectID is the project, which the secrets are stored in.
  3796. type: string
  3797. required:
  3798. - auth
  3799. type: object
  3800. conjur:
  3801. description: Conjur configures this store to sync secrets using conjur provider
  3802. properties:
  3803. auth:
  3804. description: Defines authentication settings for connecting to Conjur.
  3805. maxProperties: 1
  3806. minProperties: 1
  3807. properties:
  3808. apikey:
  3809. description: Authenticates with Conjur using an API key.
  3810. properties:
  3811. account:
  3812. description: Account is the Conjur organization account name.
  3813. type: string
  3814. apiKeyRef:
  3815. description: |-
  3816. A reference to a specific 'key' containing the Conjur API key
  3817. within a Secret resource. In some instances, `key` is a required field.
  3818. properties:
  3819. key:
  3820. description: |-
  3821. A key in the referenced Secret.
  3822. Some instances of this field may be defaulted, in others it may be required.
  3823. maxLength: 253
  3824. minLength: 1
  3825. pattern: ^[-._a-zA-Z0-9]+$
  3826. type: string
  3827. name:
  3828. description: The name of the Secret resource being referred to.
  3829. maxLength: 253
  3830. minLength: 1
  3831. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3832. type: string
  3833. namespace:
  3834. description: |-
  3835. The namespace of the Secret resource being referred to.
  3836. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3837. maxLength: 63
  3838. minLength: 1
  3839. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3840. type: string
  3841. type: object
  3842. userRef:
  3843. description: |-
  3844. A reference to a specific 'key' containing the Conjur username
  3845. within a Secret resource. In some instances, `key` is a required field.
  3846. properties:
  3847. key:
  3848. description: |-
  3849. A key in the referenced Secret.
  3850. Some instances of this field may be defaulted, in others it may be required.
  3851. maxLength: 253
  3852. minLength: 1
  3853. pattern: ^[-._a-zA-Z0-9]+$
  3854. type: string
  3855. name:
  3856. description: The name of the Secret resource being referred to.
  3857. maxLength: 253
  3858. minLength: 1
  3859. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3860. type: string
  3861. namespace:
  3862. description: |-
  3863. The namespace of the Secret resource being referred to.
  3864. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3865. maxLength: 63
  3866. minLength: 1
  3867. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3868. type: string
  3869. type: object
  3870. required:
  3871. - account
  3872. - apiKeyRef
  3873. - userRef
  3874. type: object
  3875. cert:
  3876. description: Cert enables certificate-based authentication using a client certificate and key.
  3877. properties:
  3878. account:
  3879. description: Account is the Conjur organization account name.
  3880. type: string
  3881. clientCertRef:
  3882. description: |-
  3883. ClientCertRef is a reference to a specific 'key' containing the client certificate
  3884. within a Secret resource. The certificate must be PEM-encoded.
  3885. properties:
  3886. key:
  3887. description: |-
  3888. A key in the referenced Secret.
  3889. Some instances of this field may be defaulted, in others it may be required.
  3890. maxLength: 253
  3891. minLength: 1
  3892. pattern: ^[-._a-zA-Z0-9]+$
  3893. type: string
  3894. name:
  3895. description: The name of the Secret resource being referred to.
  3896. maxLength: 253
  3897. minLength: 1
  3898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3899. type: string
  3900. namespace:
  3901. description: |-
  3902. The namespace of the Secret resource being referred to.
  3903. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3904. maxLength: 63
  3905. minLength: 1
  3906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3907. type: string
  3908. type: object
  3909. clientKeyRef:
  3910. description: |-
  3911. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  3912. within a Secret resource. The key must be PEM-encoded.
  3913. properties:
  3914. key:
  3915. description: |-
  3916. A key in the referenced Secret.
  3917. Some instances of this field may be defaulted, in others it may be required.
  3918. maxLength: 253
  3919. minLength: 1
  3920. pattern: ^[-._a-zA-Z0-9]+$
  3921. type: string
  3922. name:
  3923. description: The name of the Secret resource being referred to.
  3924. maxLength: 253
  3925. minLength: 1
  3926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3927. type: string
  3928. namespace:
  3929. description: |-
  3930. The namespace of the Secret resource being referred to.
  3931. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3932. maxLength: 63
  3933. minLength: 1
  3934. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3935. type: string
  3936. type: object
  3937. hostId:
  3938. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  3939. type: string
  3940. serviceID:
  3941. description: The conjur authn cert webservice id
  3942. type: string
  3943. required:
  3944. - account
  3945. - clientCertRef
  3946. - clientKeyRef
  3947. - serviceID
  3948. type: object
  3949. jwt:
  3950. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  3951. properties:
  3952. account:
  3953. description: Account is the Conjur organization account name.
  3954. type: string
  3955. hostId:
  3956. description: |-
  3957. Optional HostID for JWT authentication. This may be used depending
  3958. on how the Conjur JWT authenticator policy is configured.
  3959. type: string
  3960. secretRef:
  3961. description: |-
  3962. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  3963. authenticate with Conjur using the JWT authentication method.
  3964. properties:
  3965. key:
  3966. description: |-
  3967. A key in the referenced Secret.
  3968. Some instances of this field may be defaulted, in others it may be required.
  3969. maxLength: 253
  3970. minLength: 1
  3971. pattern: ^[-._a-zA-Z0-9]+$
  3972. type: string
  3973. name:
  3974. description: The name of the Secret resource being referred to.
  3975. maxLength: 253
  3976. minLength: 1
  3977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3978. type: string
  3979. namespace:
  3980. description: |-
  3981. The namespace of the Secret resource being referred to.
  3982. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3983. maxLength: 63
  3984. minLength: 1
  3985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3986. type: string
  3987. type: object
  3988. serviceAccountRef:
  3989. description: |-
  3990. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  3991. a token for with the `TokenRequest` API.
  3992. properties:
  3993. audiences:
  3994. description: |-
  3995. Audience specifies the `aud` claim for the service account token
  3996. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  3997. then this audiences will be appended to the list
  3998. items:
  3999. type: string
  4000. type: array
  4001. name:
  4002. description: The name of the ServiceAccount resource being referred to.
  4003. maxLength: 253
  4004. minLength: 1
  4005. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4006. type: string
  4007. namespace:
  4008. description: |-
  4009. Namespace of the resource being referred to.
  4010. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4011. maxLength: 63
  4012. minLength: 1
  4013. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4014. type: string
  4015. required:
  4016. - name
  4017. type: object
  4018. serviceID:
  4019. description: The conjur authn jwt webservice id
  4020. type: string
  4021. required:
  4022. - account
  4023. - serviceID
  4024. type: object
  4025. type: object
  4026. caBundle:
  4027. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  4028. type: string
  4029. caProvider:
  4030. description: |-
  4031. Used to provide custom certificate authority (CA) certificates
  4032. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  4033. that contains a PEM-encoded certificate.
  4034. properties:
  4035. key:
  4036. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4037. maxLength: 253
  4038. minLength: 1
  4039. pattern: ^[-._a-zA-Z0-9]+$
  4040. type: string
  4041. name:
  4042. description: The name of the object located at the provider type.
  4043. maxLength: 253
  4044. minLength: 1
  4045. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4046. type: string
  4047. namespace:
  4048. description: |-
  4049. The namespace the Provider type is in.
  4050. Can only be defined when used in a ClusterSecretStore.
  4051. maxLength: 63
  4052. minLength: 1
  4053. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4054. type: string
  4055. type:
  4056. description: The type of provider to use such as "Secret", or "ConfigMap".
  4057. enum:
  4058. - Secret
  4059. - ConfigMap
  4060. type: string
  4061. required:
  4062. - name
  4063. - type
  4064. type: object
  4065. url:
  4066. description: URL is the endpoint of the Conjur instance.
  4067. type: string
  4068. required:
  4069. - auth
  4070. - url
  4071. type: object
  4072. crd:
  4073. description: |-
  4074. CRD configures this store to sync secrets from arbitrary Kubernetes resources,
  4075. including both custom resources (CRDs) and core API resources. Resources are
  4076. selected by API group, version and kind, where group can be "" (empty string)
  4077. for core resources such as ConfigMap. Reading the core v1 Secret is
  4078. intentionally blocked — use the Kubernetes provider for that.
  4079. properties:
  4080. auth:
  4081. description: |-
  4082. Auth configures authentication to the Kubernetes API, same as the
  4083. Kubernetes provider. Required when Server.URL is set (unless using AuthRef).
  4084. maxProperties: 1
  4085. minProperties: 1
  4086. properties:
  4087. cert:
  4088. description: has both clientCert and clientKey as secretKeySelector
  4089. properties:
  4090. clientCert:
  4091. description: |-
  4092. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4093. In some instances, `key` is a required field.
  4094. properties:
  4095. key:
  4096. description: |-
  4097. A key in the referenced Secret.
  4098. Some instances of this field may be defaulted, in others it may be required.
  4099. maxLength: 253
  4100. minLength: 1
  4101. pattern: ^[-._a-zA-Z0-9]+$
  4102. type: string
  4103. name:
  4104. description: The name of the Secret resource being referred to.
  4105. maxLength: 253
  4106. minLength: 1
  4107. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4108. type: string
  4109. namespace:
  4110. description: |-
  4111. The namespace of the Secret resource being referred to.
  4112. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4113. maxLength: 63
  4114. minLength: 1
  4115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4116. type: string
  4117. type: object
  4118. clientKey:
  4119. description: |-
  4120. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4121. In some instances, `key` is a required field.
  4122. properties:
  4123. key:
  4124. description: |-
  4125. A key in the referenced Secret.
  4126. Some instances of this field may be defaulted, in others it may be required.
  4127. maxLength: 253
  4128. minLength: 1
  4129. pattern: ^[-._a-zA-Z0-9]+$
  4130. type: string
  4131. name:
  4132. description: The name of the Secret resource being referred to.
  4133. maxLength: 253
  4134. minLength: 1
  4135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4136. type: string
  4137. namespace:
  4138. description: |-
  4139. The namespace of the Secret resource being referred to.
  4140. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4141. maxLength: 63
  4142. minLength: 1
  4143. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4144. type: string
  4145. type: object
  4146. required:
  4147. - clientCert
  4148. - clientKey
  4149. type: object
  4150. serviceAccount:
  4151. description: points to a service account that should be used for authentication
  4152. properties:
  4153. audiences:
  4154. description: |-
  4155. Audience specifies the `aud` claim for the service account token
  4156. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4157. then this audiences will be appended to the list
  4158. items:
  4159. type: string
  4160. type: array
  4161. name:
  4162. description: The name of the ServiceAccount resource being referred to.
  4163. maxLength: 253
  4164. minLength: 1
  4165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4166. type: string
  4167. namespace:
  4168. description: |-
  4169. Namespace of the resource being referred to.
  4170. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4171. maxLength: 63
  4172. minLength: 1
  4173. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4174. type: string
  4175. required:
  4176. - name
  4177. type: object
  4178. token:
  4179. description: use static token to authenticate with
  4180. properties:
  4181. bearerToken:
  4182. description: |-
  4183. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4184. In some instances, `key` is a required field.
  4185. properties:
  4186. key:
  4187. description: |-
  4188. A key in the referenced Secret.
  4189. Some instances of this field may be defaulted, in others it may be required.
  4190. maxLength: 253
  4191. minLength: 1
  4192. pattern: ^[-._a-zA-Z0-9]+$
  4193. type: string
  4194. name:
  4195. description: The name of the Secret resource being referred to.
  4196. maxLength: 253
  4197. minLength: 1
  4198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4199. type: string
  4200. namespace:
  4201. description: |-
  4202. The namespace of the Secret resource being referred to.
  4203. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4204. maxLength: 63
  4205. minLength: 1
  4206. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4207. type: string
  4208. type: object
  4209. required:
  4210. - bearerToken
  4211. type: object
  4212. type: object
  4213. authRef:
  4214. description: |-
  4215. AuthRef references a Secret containing a kubeconfig. Same semantics as the
  4216. Kubernetes provider.
  4217. properties:
  4218. key:
  4219. description: |-
  4220. A key in the referenced Secret.
  4221. Some instances of this field may be defaulted, in others it may be required.
  4222. maxLength: 253
  4223. minLength: 1
  4224. pattern: ^[-._a-zA-Z0-9]+$
  4225. type: string
  4226. name:
  4227. description: The name of the Secret resource being referred to.
  4228. maxLength: 253
  4229. minLength: 1
  4230. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4231. type: string
  4232. namespace:
  4233. description: |-
  4234. The namespace of the Secret resource being referred to.
  4235. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4236. maxLength: 63
  4237. minLength: 1
  4238. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4239. type: string
  4240. type: object
  4241. resource:
  4242. description: Resource identifies the CRD by its API group, version and kind.
  4243. properties:
  4244. group:
  4245. description: |-
  4246. Group is the API group of the resource. Use "" (empty string) for core
  4247. Kubernetes resources such as ConfigMap; use e.g. "config.example.io"
  4248. for a CRD. The field is required to be present in the manifest — write
  4249. `group: ""` explicitly for core resources so typos fail at admission
  4250. time rather than later at discovery.
  4251. type: string
  4252. kind:
  4253. description: Kind is the Kubernetes resource kind (e.g. "MyCustomResource").
  4254. minLength: 1
  4255. type: string
  4256. version:
  4257. description: Version is the API version of the resource (e.g. "v1alpha1").
  4258. minLength: 1
  4259. type: string
  4260. required:
  4261. - group
  4262. - kind
  4263. - version
  4264. type: object
  4265. server:
  4266. description: |-
  4267. Server configures the Kubernetes API address and TLS trust, same as the
  4268. Kubernetes provider. When omitted, the URL defaults to the in-cluster API.
  4269. properties:
  4270. caBundle:
  4271. description: CABundle is a base64-encoded CA certificate
  4272. format: byte
  4273. type: string
  4274. caProvider:
  4275. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  4276. properties:
  4277. key:
  4278. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4279. maxLength: 253
  4280. minLength: 1
  4281. pattern: ^[-._a-zA-Z0-9]+$
  4282. type: string
  4283. name:
  4284. description: The name of the object located at the provider type.
  4285. maxLength: 253
  4286. minLength: 1
  4287. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4288. type: string
  4289. namespace:
  4290. description: |-
  4291. The namespace the Provider type is in.
  4292. Can only be defined when used in a ClusterSecretStore.
  4293. maxLength: 63
  4294. minLength: 1
  4295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4296. type: string
  4297. type:
  4298. description: The type of provider to use such as "Secret", or "ConfigMap".
  4299. enum:
  4300. - Secret
  4301. - ConfigMap
  4302. type: string
  4303. required:
  4304. - name
  4305. - type
  4306. type: object
  4307. url:
  4308. default: kubernetes.default
  4309. description: configures the Kubernetes server Address.
  4310. type: string
  4311. type: object
  4312. whitelist:
  4313. description: |-
  4314. Whitelist optionally restricts which object names and requested properties
  4315. are allowed to be read.
  4316. properties:
  4317. rules:
  4318. description: |-
  4319. Rules is a list of allow rules. If rules are set, at least one rule must
  4320. match for a request to be allowed.
  4321. items:
  4322. description: CRDProviderWhitelistRule defines a single allow rule for CRD reads.
  4323. properties:
  4324. name:
  4325. description: |-
  4326. Name is an optional regular expression matched against the bare object name.
  4327. For both SecretStore and ClusterSecretStore this is always the object name
  4328. without any namespace prefix (e.g. "my-db-spec", not "prod/my-db-spec").
  4329. type: string
  4330. namespace:
  4331. description: |-
  4332. Namespace is an optional regular expression matched against the namespace of
  4333. the object. Applies only when a ClusterSecretStore is used; it is ignored
  4334. for SecretStore (where the namespace is fixed to the store namespace).
  4335. type: string
  4336. properties:
  4337. description: |-
  4338. Properties is an optional list of regular expressions matched against
  4339. requested property keys (for example: "spec.secretValue").
  4340. items:
  4341. type: string
  4342. type: array
  4343. type: object
  4344. type: array
  4345. type: object
  4346. required:
  4347. - resource
  4348. type: object
  4349. x-kubernetes-validations:
  4350. - message: one of auth or authRef is required
  4351. rule: has(self.auth) || has(self.authRef)
  4352. - message: at most one of the fields in [auth authRef] may be set
  4353. rule: '[has(self.auth),has(self.authRef)].filter(x,x==true).size() <= 1'
  4354. delinea:
  4355. description: |-
  4356. Delinea DevOps Secrets Vault
  4357. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  4358. properties:
  4359. clientId:
  4360. description: ClientID is the non-secret part of the credential.
  4361. properties:
  4362. secretRef:
  4363. description: SecretRef references a key in a secret that will be used as value.
  4364. properties:
  4365. key:
  4366. description: |-
  4367. A key in the referenced Secret.
  4368. Some instances of this field may be defaulted, in others it may be required.
  4369. maxLength: 253
  4370. minLength: 1
  4371. pattern: ^[-._a-zA-Z0-9]+$
  4372. type: string
  4373. name:
  4374. description: The name of the Secret resource being referred to.
  4375. maxLength: 253
  4376. minLength: 1
  4377. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4378. type: string
  4379. namespace:
  4380. description: |-
  4381. The namespace of the Secret resource being referred to.
  4382. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4383. maxLength: 63
  4384. minLength: 1
  4385. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4386. type: string
  4387. type: object
  4388. value:
  4389. description: Value can be specified directly to set a value without using a secret.
  4390. type: string
  4391. type: object
  4392. clientSecret:
  4393. description: ClientSecret is the secret part of the credential.
  4394. properties:
  4395. secretRef:
  4396. description: SecretRef references a key in a secret that will be used as value.
  4397. properties:
  4398. key:
  4399. description: |-
  4400. A key in the referenced Secret.
  4401. Some instances of this field may be defaulted, in others it may be required.
  4402. maxLength: 253
  4403. minLength: 1
  4404. pattern: ^[-._a-zA-Z0-9]+$
  4405. type: string
  4406. name:
  4407. description: The name of the Secret resource being referred to.
  4408. maxLength: 253
  4409. minLength: 1
  4410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4411. type: string
  4412. namespace:
  4413. description: |-
  4414. The namespace of the Secret resource being referred to.
  4415. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4416. maxLength: 63
  4417. minLength: 1
  4418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4419. type: string
  4420. type: object
  4421. value:
  4422. description: Value can be specified directly to set a value without using a secret.
  4423. type: string
  4424. type: object
  4425. tenant:
  4426. description: Tenant is the chosen hostname / site name.
  4427. type: string
  4428. tld:
  4429. description: |-
  4430. TLD is based on the server location that was chosen during provisioning.
  4431. If unset, defaults to "com".
  4432. type: string
  4433. urlTemplate:
  4434. description: |-
  4435. URLTemplate
  4436. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  4437. type: string
  4438. required:
  4439. - clientId
  4440. - clientSecret
  4441. - tenant
  4442. type: object
  4443. doppler:
  4444. description: Doppler configures this store to sync secrets using the Doppler provider
  4445. properties:
  4446. auth:
  4447. description: Auth configures how the Operator authenticates with the Doppler API
  4448. properties:
  4449. oidcConfig:
  4450. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  4451. properties:
  4452. expirationSeconds:
  4453. default: 600
  4454. description: |-
  4455. ExpirationSeconds sets the ServiceAccount token validity duration.
  4456. Defaults to 10 minutes.
  4457. format: int64
  4458. type: integer
  4459. identity:
  4460. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  4461. type: string
  4462. serviceAccountRef:
  4463. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  4464. properties:
  4465. audiences:
  4466. description: |-
  4467. Audience specifies the `aud` claim for the service account token
  4468. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4469. then this audiences will be appended to the list
  4470. items:
  4471. type: string
  4472. type: array
  4473. name:
  4474. description: The name of the ServiceAccount resource being referred to.
  4475. maxLength: 253
  4476. minLength: 1
  4477. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4478. type: string
  4479. namespace:
  4480. description: |-
  4481. Namespace of the resource being referred to.
  4482. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4483. maxLength: 63
  4484. minLength: 1
  4485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4486. type: string
  4487. required:
  4488. - name
  4489. type: object
  4490. required:
  4491. - identity
  4492. - serviceAccountRef
  4493. type: object
  4494. secretRef:
  4495. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  4496. properties:
  4497. dopplerToken:
  4498. description: |-
  4499. The DopplerToken is used for authentication.
  4500. See https://docs.doppler.com/reference/api#authentication for auth token types.
  4501. The Key attribute defaults to dopplerToken if not specified.
  4502. properties:
  4503. key:
  4504. description: |-
  4505. A key in the referenced Secret.
  4506. Some instances of this field may be defaulted, in others it may be required.
  4507. maxLength: 253
  4508. minLength: 1
  4509. pattern: ^[-._a-zA-Z0-9]+$
  4510. type: string
  4511. name:
  4512. description: The name of the Secret resource being referred to.
  4513. maxLength: 253
  4514. minLength: 1
  4515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4516. type: string
  4517. namespace:
  4518. description: |-
  4519. The namespace of the Secret resource being referred to.
  4520. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4521. maxLength: 63
  4522. minLength: 1
  4523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4524. type: string
  4525. type: object
  4526. required:
  4527. - dopplerToken
  4528. type: object
  4529. type: object
  4530. x-kubernetes-validations:
  4531. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  4532. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  4533. config:
  4534. description: Doppler config (required if not using a Service Token)
  4535. type: string
  4536. format:
  4537. description: Format enables the downloading of secrets as a file (string)
  4538. enum:
  4539. - json
  4540. - dotnet-json
  4541. - env
  4542. - yaml
  4543. - docker
  4544. type: string
  4545. nameTransformer:
  4546. description: Environment variable compatible name transforms that change secret names to a different format
  4547. enum:
  4548. - upper-camel
  4549. - camel
  4550. - lower-snake
  4551. - tf-var
  4552. - dotnet-env
  4553. - lower-kebab
  4554. type: string
  4555. project:
  4556. description: Doppler project (required if not using a Service Token)
  4557. type: string
  4558. required:
  4559. - auth
  4560. type: object
  4561. dvls:
  4562. description: DVLS configures this store to sync secrets using Devolutions Server provider
  4563. properties:
  4564. auth:
  4565. description: Auth defines the authentication method to use.
  4566. properties:
  4567. secretRef:
  4568. description: SecretRef contains the Application ID and Application Secret for authentication.
  4569. properties:
  4570. appId:
  4571. description: AppID is the reference to the secret containing the Application ID.
  4572. properties:
  4573. key:
  4574. description: |-
  4575. A key in the referenced Secret.
  4576. Some instances of this field may be defaulted, in others it may be required.
  4577. maxLength: 253
  4578. minLength: 1
  4579. pattern: ^[-._a-zA-Z0-9]+$
  4580. type: string
  4581. name:
  4582. description: The name of the Secret resource being referred to.
  4583. maxLength: 253
  4584. minLength: 1
  4585. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4586. type: string
  4587. namespace:
  4588. description: |-
  4589. The namespace of the Secret resource being referred to.
  4590. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4591. maxLength: 63
  4592. minLength: 1
  4593. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4594. type: string
  4595. type: object
  4596. appSecret:
  4597. description: AppSecret is the reference to the secret containing the Application Secret.
  4598. properties:
  4599. key:
  4600. description: |-
  4601. A key in the referenced Secret.
  4602. Some instances of this field may be defaulted, in others it may be required.
  4603. maxLength: 253
  4604. minLength: 1
  4605. pattern: ^[-._a-zA-Z0-9]+$
  4606. type: string
  4607. name:
  4608. description: The name of the Secret resource being referred to.
  4609. maxLength: 253
  4610. minLength: 1
  4611. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4612. type: string
  4613. namespace:
  4614. description: |-
  4615. The namespace of the Secret resource being referred to.
  4616. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4617. maxLength: 63
  4618. minLength: 1
  4619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4620. type: string
  4621. type: object
  4622. required:
  4623. - appId
  4624. - appSecret
  4625. type: object
  4626. required:
  4627. - secretRef
  4628. type: object
  4629. insecure:
  4630. description: |-
  4631. Insecure allows connecting to DVLS over plain HTTP.
  4632. This is NOT RECOMMENDED for production use.
  4633. Set to true only if you understand the security implications.
  4634. type: boolean
  4635. serverUrl:
  4636. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  4637. type: string
  4638. vault:
  4639. description: |-
  4640. Vault is the name or UUID of the vault to fetch secrets from.
  4641. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  4642. type: string
  4643. required:
  4644. - auth
  4645. - serverUrl
  4646. type: object
  4647. fake:
  4648. description: Fake configures a store with static key/value pairs
  4649. properties:
  4650. data:
  4651. items:
  4652. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  4653. properties:
  4654. key:
  4655. type: string
  4656. value:
  4657. type: string
  4658. version:
  4659. type: string
  4660. required:
  4661. - key
  4662. - value
  4663. type: object
  4664. type: array
  4665. validationResult:
  4666. description: ValidationResult is defined type for the number of validation results.
  4667. type: integer
  4668. required:
  4669. - data
  4670. type: object
  4671. fortanix:
  4672. description: Fortanix configures this store to sync secrets using the Fortanix provider
  4673. properties:
  4674. apiKey:
  4675. description: APIKey is the API token to access SDKMS Applications.
  4676. properties:
  4677. secretRef:
  4678. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  4679. properties:
  4680. key:
  4681. description: |-
  4682. A key in the referenced Secret.
  4683. Some instances of this field may be defaulted, in others it may be required.
  4684. maxLength: 253
  4685. minLength: 1
  4686. pattern: ^[-._a-zA-Z0-9]+$
  4687. type: string
  4688. name:
  4689. description: The name of the Secret resource being referred to.
  4690. maxLength: 253
  4691. minLength: 1
  4692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4693. type: string
  4694. namespace:
  4695. description: |-
  4696. The namespace of the Secret resource being referred to.
  4697. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4698. maxLength: 63
  4699. minLength: 1
  4700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4701. type: string
  4702. type: object
  4703. type: object
  4704. apiUrl:
  4705. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  4706. type: string
  4707. type: object
  4708. gcpsm:
  4709. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  4710. properties:
  4711. auth:
  4712. description: Auth defines the information necessary to authenticate against GCP
  4713. properties:
  4714. secretRef:
  4715. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  4716. properties:
  4717. secretAccessKeySecretRef:
  4718. description: The SecretAccessKey is used for authentication
  4719. properties:
  4720. key:
  4721. description: |-
  4722. A key in the referenced Secret.
  4723. Some instances of this field may be defaulted, in others it may be required.
  4724. maxLength: 253
  4725. minLength: 1
  4726. pattern: ^[-._a-zA-Z0-9]+$
  4727. type: string
  4728. name:
  4729. description: The name of the Secret resource being referred to.
  4730. maxLength: 253
  4731. minLength: 1
  4732. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4733. type: string
  4734. namespace:
  4735. description: |-
  4736. The namespace of the Secret resource being referred to.
  4737. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4738. maxLength: 63
  4739. minLength: 1
  4740. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4741. type: string
  4742. type: object
  4743. type: object
  4744. workloadIdentity:
  4745. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  4746. properties:
  4747. clusterLocation:
  4748. description: |-
  4749. ClusterLocation is the location of the cluster
  4750. If not specified, it fetches information from the metadata server
  4751. type: string
  4752. clusterName:
  4753. description: |-
  4754. ClusterName is the name of the cluster
  4755. If not specified, it fetches information from the metadata server
  4756. type: string
  4757. clusterProjectID:
  4758. description: |-
  4759. ClusterProjectID is the project ID of the cluster
  4760. If not specified, it fetches information from the metadata server
  4761. type: string
  4762. serviceAccountRef:
  4763. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  4764. properties:
  4765. audiences:
  4766. description: |-
  4767. Audience specifies the `aud` claim for the service account token
  4768. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4769. then this audiences will be appended to the list
  4770. items:
  4771. type: string
  4772. type: array
  4773. name:
  4774. description: The name of the ServiceAccount resource being referred to.
  4775. maxLength: 253
  4776. minLength: 1
  4777. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4778. type: string
  4779. namespace:
  4780. description: |-
  4781. Namespace of the resource being referred to.
  4782. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4783. maxLength: 63
  4784. minLength: 1
  4785. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4786. type: string
  4787. required:
  4788. - name
  4789. type: object
  4790. required:
  4791. - serviceAccountRef
  4792. type: object
  4793. workloadIdentityFederation:
  4794. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  4795. properties:
  4796. audience:
  4797. description: |-
  4798. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  4799. If specified, Audience found in the external account credential config will be overridden with the configured value.
  4800. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  4801. type: string
  4802. awsSecurityCredentials:
  4803. description: |-
  4804. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  4805. when using the AWS metadata server is not an option.
  4806. properties:
  4807. awsCredentialsSecretRef:
  4808. description: |-
  4809. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  4810. Secret should be created with below names for keys
  4811. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  4812. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  4813. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  4814. properties:
  4815. name:
  4816. description: name of the secret.
  4817. maxLength: 253
  4818. minLength: 1
  4819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4820. type: string
  4821. namespace:
  4822. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  4823. maxLength: 63
  4824. minLength: 1
  4825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4826. type: string
  4827. required:
  4828. - name
  4829. type: object
  4830. region:
  4831. description: region is for configuring the AWS region to be used.
  4832. example: ap-south-1
  4833. maxLength: 50
  4834. minLength: 1
  4835. pattern: ^[a-z0-9-]+$
  4836. type: string
  4837. required:
  4838. - awsCredentialsSecretRef
  4839. - region
  4840. type: object
  4841. credConfig:
  4842. description: |-
  4843. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  4844. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  4845. serviceAccountRef must be used by providing operators service account details.
  4846. properties:
  4847. key:
  4848. description: key name holding the external account credential config.
  4849. maxLength: 253
  4850. minLength: 1
  4851. pattern: ^[-._a-zA-Z0-9]+$
  4852. type: string
  4853. name:
  4854. description: name of the configmap.
  4855. maxLength: 253
  4856. minLength: 1
  4857. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4858. type: string
  4859. namespace:
  4860. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  4861. maxLength: 63
  4862. minLength: 1
  4863. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4864. type: string
  4865. required:
  4866. - key
  4867. - name
  4868. type: object
  4869. externalTokenEndpoint:
  4870. description: |-
  4871. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  4872. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  4873. URL is having the expected value.
  4874. type: string
  4875. gcpServiceAccountEmail:
  4876. description: |-
  4877. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  4878. after Workload Identity Federation. Use this to grant access through the service account's
  4879. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  4880. service_account_impersonation_url in the external account JSON from credConfig;
  4881. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  4882. on that ServiceAccount.
  4883. example: my-gsa@my-project.iam.gserviceaccount.com
  4884. minLength: 1
  4885. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  4886. type: string
  4887. serviceAccountRef:
  4888. description: |-
  4889. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  4890. when Kubernetes is configured as provider in workload identity pool.
  4891. properties:
  4892. audiences:
  4893. description: |-
  4894. Audience specifies the `aud` claim for the service account token
  4895. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4896. then this audiences will be appended to the list
  4897. items:
  4898. type: string
  4899. type: array
  4900. name:
  4901. description: The name of the ServiceAccount resource being referred to.
  4902. maxLength: 253
  4903. minLength: 1
  4904. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4905. type: string
  4906. namespace:
  4907. description: |-
  4908. Namespace of the resource being referred to.
  4909. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4910. maxLength: 63
  4911. minLength: 1
  4912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4913. type: string
  4914. required:
  4915. - name
  4916. type: object
  4917. type: object
  4918. type: object
  4919. location:
  4920. description: Location optionally defines a location for a secret
  4921. type: string
  4922. projectID:
  4923. description: ProjectID project where secret is located
  4924. type: string
  4925. secretVersionSelectionPolicy:
  4926. default: LatestOrFail
  4927. description: |-
  4928. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  4929. when "latest" is disabled or destroyed.
  4930. Possible values are:
  4931. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  4932. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  4933. type: string
  4934. type: object
  4935. github:
  4936. description: |-
  4937. Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  4938. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  4939. properties:
  4940. appID:
  4941. description: appID specifies the Github APP that will be used to authenticate the client
  4942. format: int64
  4943. type: integer
  4944. auth:
  4945. description: auth configures how secret-manager authenticates with a Github instance.
  4946. properties:
  4947. privateKey:
  4948. description: |-
  4949. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4950. In some instances, `key` is a required field.
  4951. properties:
  4952. key:
  4953. description: |-
  4954. A key in the referenced Secret.
  4955. Some instances of this field may be defaulted, in others it may be required.
  4956. maxLength: 253
  4957. minLength: 1
  4958. pattern: ^[-._a-zA-Z0-9]+$
  4959. type: string
  4960. name:
  4961. description: The name of the Secret resource being referred to.
  4962. maxLength: 253
  4963. minLength: 1
  4964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4965. type: string
  4966. namespace:
  4967. description: |-
  4968. The namespace of the Secret resource being referred to.
  4969. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4970. maxLength: 63
  4971. minLength: 1
  4972. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4973. type: string
  4974. type: object
  4975. required:
  4976. - privateKey
  4977. type: object
  4978. environment:
  4979. description: environment will be used to fetch secrets from a particular environment within a github repository
  4980. type: string
  4981. installationID:
  4982. description: installationID specifies the Github APP installation that will be used to authenticate the client
  4983. format: int64
  4984. type: integer
  4985. orgSecretVisibility:
  4986. description: |-
  4987. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  4988. Valid values are "all" or "private".
  4989. When unset, new secrets are created with visibility "all" and existing secrets preserve
  4990. whatever visibility they already have in GitHub.
  4991. enum:
  4992. - all
  4993. - private
  4994. type: string
  4995. organization:
  4996. description: organization will be used to fetch secrets from the Github organization
  4997. type: string
  4998. repository:
  4999. description: repository will be used to fetch secrets from the Github repository within an organization
  5000. type: string
  5001. uploadURL:
  5002. description: Upload URL for enterprise instances. Default to URL.
  5003. type: string
  5004. url:
  5005. default: https://github.com/
  5006. description: URL configures the Github instance URL. Defaults to https://github.com/.
  5007. type: string
  5008. required:
  5009. - appID
  5010. - auth
  5011. - installationID
  5012. - organization
  5013. type: object
  5014. gitlab:
  5015. description: GitLab configures this store to sync secrets using GitLab Variables provider
  5016. properties:
  5017. auth:
  5018. description: Auth configures how secret-manager authenticates with a GitLab instance.
  5019. properties:
  5020. SecretRef:
  5021. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  5022. properties:
  5023. accessToken:
  5024. description: AccessToken is used for authentication.
  5025. properties:
  5026. key:
  5027. description: |-
  5028. A key in the referenced Secret.
  5029. Some instances of this field may be defaulted, in others it may be required.
  5030. maxLength: 253
  5031. minLength: 1
  5032. pattern: ^[-._a-zA-Z0-9]+$
  5033. type: string
  5034. name:
  5035. description: The name of the Secret resource being referred to.
  5036. maxLength: 253
  5037. minLength: 1
  5038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5039. type: string
  5040. namespace:
  5041. description: |-
  5042. The namespace of the Secret resource being referred to.
  5043. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5044. maxLength: 63
  5045. minLength: 1
  5046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5047. type: string
  5048. type: object
  5049. type: object
  5050. required:
  5051. - SecretRef
  5052. type: object
  5053. caBundle:
  5054. description: |-
  5055. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  5056. can be performed.
  5057. format: byte
  5058. type: string
  5059. caProvider:
  5060. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  5061. properties:
  5062. key:
  5063. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5064. maxLength: 253
  5065. minLength: 1
  5066. pattern: ^[-._a-zA-Z0-9]+$
  5067. type: string
  5068. name:
  5069. description: The name of the object located at the provider type.
  5070. maxLength: 253
  5071. minLength: 1
  5072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5073. type: string
  5074. namespace:
  5075. description: |-
  5076. The namespace the Provider type is in.
  5077. Can only be defined when used in a ClusterSecretStore.
  5078. maxLength: 63
  5079. minLength: 1
  5080. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5081. type: string
  5082. type:
  5083. description: The type of provider to use such as "Secret", or "ConfigMap".
  5084. enum:
  5085. - Secret
  5086. - ConfigMap
  5087. type: string
  5088. required:
  5089. - name
  5090. - type
  5091. type: object
  5092. environment:
  5093. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  5094. type: string
  5095. groupIDs:
  5096. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  5097. items:
  5098. type: string
  5099. type: array
  5100. inheritFromGroups:
  5101. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  5102. type: boolean
  5103. projectID:
  5104. description: ProjectID specifies a project where secrets are located.
  5105. type: string
  5106. url:
  5107. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  5108. type: string
  5109. required:
  5110. - auth
  5111. type: object
  5112. ibm:
  5113. description: IBM configures this store to sync secrets using IBM Cloud provider
  5114. properties:
  5115. auth:
  5116. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  5117. maxProperties: 1
  5118. minProperties: 1
  5119. properties:
  5120. containerAuth:
  5121. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  5122. properties:
  5123. iamEndpoint:
  5124. type: string
  5125. profile:
  5126. description: the IBM Trusted Profile
  5127. type: string
  5128. tokenLocation:
  5129. description: Location the token is mounted on the pod
  5130. type: string
  5131. required:
  5132. - profile
  5133. type: object
  5134. secretRef:
  5135. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  5136. properties:
  5137. iamEndpoint:
  5138. description: The IAM endpoint used to obain a token
  5139. type: string
  5140. secretApiKeySecretRef:
  5141. description: The SecretAccessKey is used for authentication
  5142. properties:
  5143. key:
  5144. description: |-
  5145. A key in the referenced Secret.
  5146. Some instances of this field may be defaulted, in others it may be required.
  5147. maxLength: 253
  5148. minLength: 1
  5149. pattern: ^[-._a-zA-Z0-9]+$
  5150. type: string
  5151. name:
  5152. description: The name of the Secret resource being referred to.
  5153. maxLength: 253
  5154. minLength: 1
  5155. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5156. type: string
  5157. namespace:
  5158. description: |-
  5159. The namespace of the Secret resource being referred to.
  5160. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5161. maxLength: 63
  5162. minLength: 1
  5163. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5164. type: string
  5165. type: object
  5166. type: object
  5167. type: object
  5168. serviceUrl:
  5169. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  5170. type: string
  5171. required:
  5172. - auth
  5173. type: object
  5174. infisical:
  5175. description: Infisical configures this store to sync secrets using the Infisical provider
  5176. properties:
  5177. auth:
  5178. description: Auth configures how the Operator authenticates with the Infisical API
  5179. properties:
  5180. awsAuthCredentials:
  5181. description: AwsAuthCredentials represents the credentials for AWS authentication.
  5182. properties:
  5183. identityId:
  5184. description: |-
  5185. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5186. In some instances, `key` is a required field.
  5187. properties:
  5188. key:
  5189. description: |-
  5190. A key in the referenced Secret.
  5191. Some instances of this field may be defaulted, in others it may be required.
  5192. maxLength: 253
  5193. minLength: 1
  5194. pattern: ^[-._a-zA-Z0-9]+$
  5195. type: string
  5196. name:
  5197. description: The name of the Secret resource being referred to.
  5198. maxLength: 253
  5199. minLength: 1
  5200. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5201. type: string
  5202. namespace:
  5203. description: |-
  5204. The namespace of the Secret resource being referred to.
  5205. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5206. maxLength: 63
  5207. minLength: 1
  5208. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5209. type: string
  5210. type: object
  5211. required:
  5212. - identityId
  5213. type: object
  5214. azureAuthCredentials:
  5215. description: AzureAuthCredentials represents the credentials for Azure authentication.
  5216. properties:
  5217. identityId:
  5218. description: |-
  5219. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5220. In some instances, `key` is a required field.
  5221. properties:
  5222. key:
  5223. description: |-
  5224. A key in the referenced Secret.
  5225. Some instances of this field may be defaulted, in others it may be required.
  5226. maxLength: 253
  5227. minLength: 1
  5228. pattern: ^[-._a-zA-Z0-9]+$
  5229. type: string
  5230. name:
  5231. description: The name of the Secret resource being referred to.
  5232. maxLength: 253
  5233. minLength: 1
  5234. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5235. type: string
  5236. namespace:
  5237. description: |-
  5238. The namespace of the Secret resource being referred to.
  5239. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5240. maxLength: 63
  5241. minLength: 1
  5242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5243. type: string
  5244. type: object
  5245. resource:
  5246. description: |-
  5247. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5248. In some instances, `key` is a required field.
  5249. properties:
  5250. key:
  5251. description: |-
  5252. A key in the referenced Secret.
  5253. Some instances of this field may be defaulted, in others it may be required.
  5254. maxLength: 253
  5255. minLength: 1
  5256. pattern: ^[-._a-zA-Z0-9]+$
  5257. type: string
  5258. name:
  5259. description: The name of the Secret resource being referred to.
  5260. maxLength: 253
  5261. minLength: 1
  5262. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5263. type: string
  5264. namespace:
  5265. description: |-
  5266. The namespace of the Secret resource being referred to.
  5267. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5268. maxLength: 63
  5269. minLength: 1
  5270. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5271. type: string
  5272. type: object
  5273. required:
  5274. - identityId
  5275. type: object
  5276. gcpIamAuthCredentials:
  5277. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  5278. properties:
  5279. identityId:
  5280. description: |-
  5281. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5282. In some instances, `key` is a required field.
  5283. properties:
  5284. key:
  5285. description: |-
  5286. A key in the referenced Secret.
  5287. Some instances of this field may be defaulted, in others it may be required.
  5288. maxLength: 253
  5289. minLength: 1
  5290. pattern: ^[-._a-zA-Z0-9]+$
  5291. type: string
  5292. name:
  5293. description: The name of the Secret resource being referred to.
  5294. maxLength: 253
  5295. minLength: 1
  5296. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5297. type: string
  5298. namespace:
  5299. description: |-
  5300. The namespace of the Secret resource being referred to.
  5301. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5302. maxLength: 63
  5303. minLength: 1
  5304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5305. type: string
  5306. type: object
  5307. serviceAccountKeyFilePath:
  5308. description: |-
  5309. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5310. In some instances, `key` is a required field.
  5311. properties:
  5312. key:
  5313. description: |-
  5314. A key in the referenced Secret.
  5315. Some instances of this field may be defaulted, in others it may be required.
  5316. maxLength: 253
  5317. minLength: 1
  5318. pattern: ^[-._a-zA-Z0-9]+$
  5319. type: string
  5320. name:
  5321. description: The name of the Secret resource being referred to.
  5322. maxLength: 253
  5323. minLength: 1
  5324. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5325. type: string
  5326. namespace:
  5327. description: |-
  5328. The namespace of the Secret resource being referred to.
  5329. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5330. maxLength: 63
  5331. minLength: 1
  5332. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5333. type: string
  5334. type: object
  5335. required:
  5336. - identityId
  5337. - serviceAccountKeyFilePath
  5338. type: object
  5339. gcpIdTokenAuthCredentials:
  5340. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  5341. properties:
  5342. identityId:
  5343. description: |-
  5344. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5345. In some instances, `key` is a required field.
  5346. properties:
  5347. key:
  5348. description: |-
  5349. A key in the referenced Secret.
  5350. Some instances of this field may be defaulted, in others it may be required.
  5351. maxLength: 253
  5352. minLength: 1
  5353. pattern: ^[-._a-zA-Z0-9]+$
  5354. type: string
  5355. name:
  5356. description: The name of the Secret resource being referred to.
  5357. maxLength: 253
  5358. minLength: 1
  5359. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5360. type: string
  5361. namespace:
  5362. description: |-
  5363. The namespace of the Secret resource being referred to.
  5364. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5365. maxLength: 63
  5366. minLength: 1
  5367. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5368. type: string
  5369. type: object
  5370. required:
  5371. - identityId
  5372. type: object
  5373. jwtAuthCredentials:
  5374. description: JwtAuthCredentials represents the credentials for JWT authentication.
  5375. properties:
  5376. identityId:
  5377. description: |-
  5378. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5379. In some instances, `key` is a required field.
  5380. properties:
  5381. key:
  5382. description: |-
  5383. A key in the referenced Secret.
  5384. Some instances of this field may be defaulted, in others it may be required.
  5385. maxLength: 253
  5386. minLength: 1
  5387. pattern: ^[-._a-zA-Z0-9]+$
  5388. type: string
  5389. name:
  5390. description: The name of the Secret resource being referred to.
  5391. maxLength: 253
  5392. minLength: 1
  5393. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5394. type: string
  5395. namespace:
  5396. description: |-
  5397. The namespace of the Secret resource being referred to.
  5398. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5399. maxLength: 63
  5400. minLength: 1
  5401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5402. type: string
  5403. type: object
  5404. jwt:
  5405. description: |-
  5406. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5407. In some instances, `key` is a required field.
  5408. properties:
  5409. key:
  5410. description: |-
  5411. A key in the referenced Secret.
  5412. Some instances of this field may be defaulted, in others it may be required.
  5413. maxLength: 253
  5414. minLength: 1
  5415. pattern: ^[-._a-zA-Z0-9]+$
  5416. type: string
  5417. name:
  5418. description: The name of the Secret resource being referred to.
  5419. maxLength: 253
  5420. minLength: 1
  5421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5422. type: string
  5423. namespace:
  5424. description: |-
  5425. The namespace of the Secret resource being referred to.
  5426. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5427. maxLength: 63
  5428. minLength: 1
  5429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5430. type: string
  5431. type: object
  5432. required:
  5433. - identityId
  5434. - jwt
  5435. type: object
  5436. kubernetesAuthCredentials:
  5437. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  5438. properties:
  5439. identityId:
  5440. description: |-
  5441. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5442. In some instances, `key` is a required field.
  5443. properties:
  5444. key:
  5445. description: |-
  5446. A key in the referenced Secret.
  5447. Some instances of this field may be defaulted, in others it may be required.
  5448. maxLength: 253
  5449. minLength: 1
  5450. pattern: ^[-._a-zA-Z0-9]+$
  5451. type: string
  5452. name:
  5453. description: The name of the Secret resource being referred to.
  5454. maxLength: 253
  5455. minLength: 1
  5456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5457. type: string
  5458. namespace:
  5459. description: |-
  5460. The namespace of the Secret resource being referred to.
  5461. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5462. maxLength: 63
  5463. minLength: 1
  5464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5465. type: string
  5466. type: object
  5467. serviceAccountTokenPath:
  5468. description: |-
  5469. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5470. In some instances, `key` is a required field.
  5471. properties:
  5472. key:
  5473. description: |-
  5474. A key in the referenced Secret.
  5475. Some instances of this field may be defaulted, in others it may be required.
  5476. maxLength: 253
  5477. minLength: 1
  5478. pattern: ^[-._a-zA-Z0-9]+$
  5479. type: string
  5480. name:
  5481. description: The name of the Secret resource being referred to.
  5482. maxLength: 253
  5483. minLength: 1
  5484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5485. type: string
  5486. namespace:
  5487. description: |-
  5488. The namespace of the Secret resource being referred to.
  5489. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5490. maxLength: 63
  5491. minLength: 1
  5492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5493. type: string
  5494. type: object
  5495. required:
  5496. - identityId
  5497. type: object
  5498. ldapAuthCredentials:
  5499. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  5500. properties:
  5501. identityId:
  5502. description: |-
  5503. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5504. In some instances, `key` is a required field.
  5505. properties:
  5506. key:
  5507. description: |-
  5508. A key in the referenced Secret.
  5509. Some instances of this field may be defaulted, in others it may be required.
  5510. maxLength: 253
  5511. minLength: 1
  5512. pattern: ^[-._a-zA-Z0-9]+$
  5513. type: string
  5514. name:
  5515. description: The name of the Secret resource being referred to.
  5516. maxLength: 253
  5517. minLength: 1
  5518. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5519. type: string
  5520. namespace:
  5521. description: |-
  5522. The namespace of the Secret resource being referred to.
  5523. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5524. maxLength: 63
  5525. minLength: 1
  5526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5527. type: string
  5528. type: object
  5529. ldapPassword:
  5530. description: |-
  5531. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5532. In some instances, `key` is a required field.
  5533. properties:
  5534. key:
  5535. description: |-
  5536. A key in the referenced Secret.
  5537. Some instances of this field may be defaulted, in others it may be required.
  5538. maxLength: 253
  5539. minLength: 1
  5540. pattern: ^[-._a-zA-Z0-9]+$
  5541. type: string
  5542. name:
  5543. description: The name of the Secret resource being referred to.
  5544. maxLength: 253
  5545. minLength: 1
  5546. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5547. type: string
  5548. namespace:
  5549. description: |-
  5550. The namespace of the Secret resource being referred to.
  5551. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5552. maxLength: 63
  5553. minLength: 1
  5554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5555. type: string
  5556. type: object
  5557. ldapUsername:
  5558. description: |-
  5559. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5560. In some instances, `key` is a required field.
  5561. properties:
  5562. key:
  5563. description: |-
  5564. A key in the referenced Secret.
  5565. Some instances of this field may be defaulted, in others it may be required.
  5566. maxLength: 253
  5567. minLength: 1
  5568. pattern: ^[-._a-zA-Z0-9]+$
  5569. type: string
  5570. name:
  5571. description: The name of the Secret resource being referred to.
  5572. maxLength: 253
  5573. minLength: 1
  5574. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5575. type: string
  5576. namespace:
  5577. description: |-
  5578. The namespace of the Secret resource being referred to.
  5579. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5580. maxLength: 63
  5581. minLength: 1
  5582. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5583. type: string
  5584. type: object
  5585. required:
  5586. - identityId
  5587. - ldapPassword
  5588. - ldapUsername
  5589. type: object
  5590. ociAuthCredentials:
  5591. description: OciAuthCredentials represents the credentials for OCI authentication.
  5592. properties:
  5593. fingerprint:
  5594. description: |-
  5595. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5596. In some instances, `key` is a required field.
  5597. properties:
  5598. key:
  5599. description: |-
  5600. A key in the referenced Secret.
  5601. Some instances of this field may be defaulted, in others it may be required.
  5602. maxLength: 253
  5603. minLength: 1
  5604. pattern: ^[-._a-zA-Z0-9]+$
  5605. type: string
  5606. name:
  5607. description: The name of the Secret resource being referred to.
  5608. maxLength: 253
  5609. minLength: 1
  5610. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5611. type: string
  5612. namespace:
  5613. description: |-
  5614. The namespace of the Secret resource being referred to.
  5615. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5616. maxLength: 63
  5617. minLength: 1
  5618. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5619. type: string
  5620. type: object
  5621. identityId:
  5622. description: |-
  5623. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5624. In some instances, `key` is a required field.
  5625. properties:
  5626. key:
  5627. description: |-
  5628. A key in the referenced Secret.
  5629. Some instances of this field may be defaulted, in others it may be required.
  5630. maxLength: 253
  5631. minLength: 1
  5632. pattern: ^[-._a-zA-Z0-9]+$
  5633. type: string
  5634. name:
  5635. description: The name of the Secret resource being referred to.
  5636. maxLength: 253
  5637. minLength: 1
  5638. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5639. type: string
  5640. namespace:
  5641. description: |-
  5642. The namespace of the Secret resource being referred to.
  5643. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5644. maxLength: 63
  5645. minLength: 1
  5646. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5647. type: string
  5648. type: object
  5649. privateKey:
  5650. description: |-
  5651. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5652. In some instances, `key` is a required field.
  5653. properties:
  5654. key:
  5655. description: |-
  5656. A key in the referenced Secret.
  5657. Some instances of this field may be defaulted, in others it may be required.
  5658. maxLength: 253
  5659. minLength: 1
  5660. pattern: ^[-._a-zA-Z0-9]+$
  5661. type: string
  5662. name:
  5663. description: The name of the Secret resource being referred to.
  5664. maxLength: 253
  5665. minLength: 1
  5666. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5667. type: string
  5668. namespace:
  5669. description: |-
  5670. The namespace of the Secret resource being referred to.
  5671. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5672. maxLength: 63
  5673. minLength: 1
  5674. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5675. type: string
  5676. type: object
  5677. privateKeyPassphrase:
  5678. description: |-
  5679. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5680. In some instances, `key` is a required field.
  5681. properties:
  5682. key:
  5683. description: |-
  5684. A key in the referenced Secret.
  5685. Some instances of this field may be defaulted, in others it may be required.
  5686. maxLength: 253
  5687. minLength: 1
  5688. pattern: ^[-._a-zA-Z0-9]+$
  5689. type: string
  5690. name:
  5691. description: The name of the Secret resource being referred to.
  5692. maxLength: 253
  5693. minLength: 1
  5694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5695. type: string
  5696. namespace:
  5697. description: |-
  5698. The namespace of the Secret resource being referred to.
  5699. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5700. maxLength: 63
  5701. minLength: 1
  5702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5703. type: string
  5704. type: object
  5705. region:
  5706. description: |-
  5707. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5708. In some instances, `key` is a required field.
  5709. properties:
  5710. key:
  5711. description: |-
  5712. A key in the referenced Secret.
  5713. Some instances of this field may be defaulted, in others it may be required.
  5714. maxLength: 253
  5715. minLength: 1
  5716. pattern: ^[-._a-zA-Z0-9]+$
  5717. type: string
  5718. name:
  5719. description: The name of the Secret resource being referred to.
  5720. maxLength: 253
  5721. minLength: 1
  5722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5723. type: string
  5724. namespace:
  5725. description: |-
  5726. The namespace of the Secret resource being referred to.
  5727. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5728. maxLength: 63
  5729. minLength: 1
  5730. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5731. type: string
  5732. type: object
  5733. tenancyId:
  5734. description: |-
  5735. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5736. In some instances, `key` is a required field.
  5737. properties:
  5738. key:
  5739. description: |-
  5740. A key in the referenced Secret.
  5741. Some instances of this field may be defaulted, in others it may be required.
  5742. maxLength: 253
  5743. minLength: 1
  5744. pattern: ^[-._a-zA-Z0-9]+$
  5745. type: string
  5746. name:
  5747. description: The name of the Secret resource being referred to.
  5748. maxLength: 253
  5749. minLength: 1
  5750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5751. type: string
  5752. namespace:
  5753. description: |-
  5754. The namespace of the Secret resource being referred to.
  5755. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5756. maxLength: 63
  5757. minLength: 1
  5758. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5759. type: string
  5760. type: object
  5761. userId:
  5762. description: |-
  5763. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5764. In some instances, `key` is a required field.
  5765. properties:
  5766. key:
  5767. description: |-
  5768. A key in the referenced Secret.
  5769. Some instances of this field may be defaulted, in others it may be required.
  5770. maxLength: 253
  5771. minLength: 1
  5772. pattern: ^[-._a-zA-Z0-9]+$
  5773. type: string
  5774. name:
  5775. description: The name of the Secret resource being referred to.
  5776. maxLength: 253
  5777. minLength: 1
  5778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5779. type: string
  5780. namespace:
  5781. description: |-
  5782. The namespace of the Secret resource being referred to.
  5783. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5784. maxLength: 63
  5785. minLength: 1
  5786. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5787. type: string
  5788. type: object
  5789. required:
  5790. - fingerprint
  5791. - identityId
  5792. - privateKey
  5793. - region
  5794. - tenancyId
  5795. - userId
  5796. type: object
  5797. tokenAuthCredentials:
  5798. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  5799. properties:
  5800. accessToken:
  5801. description: |-
  5802. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5803. In some instances, `key` is a required field.
  5804. properties:
  5805. key:
  5806. description: |-
  5807. A key in the referenced Secret.
  5808. Some instances of this field may be defaulted, in others it may be required.
  5809. maxLength: 253
  5810. minLength: 1
  5811. pattern: ^[-._a-zA-Z0-9]+$
  5812. type: string
  5813. name:
  5814. description: The name of the Secret resource being referred to.
  5815. maxLength: 253
  5816. minLength: 1
  5817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5818. type: string
  5819. namespace:
  5820. description: |-
  5821. The namespace of the Secret resource being referred to.
  5822. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5823. maxLength: 63
  5824. minLength: 1
  5825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5826. type: string
  5827. type: object
  5828. required:
  5829. - accessToken
  5830. type: object
  5831. universalAuthCredentials:
  5832. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  5833. properties:
  5834. clientId:
  5835. description: |-
  5836. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5837. In some instances, `key` is a required field.
  5838. properties:
  5839. key:
  5840. description: |-
  5841. A key in the referenced Secret.
  5842. Some instances of this field may be defaulted, in others it may be required.
  5843. maxLength: 253
  5844. minLength: 1
  5845. pattern: ^[-._a-zA-Z0-9]+$
  5846. type: string
  5847. name:
  5848. description: The name of the Secret resource being referred to.
  5849. maxLength: 253
  5850. minLength: 1
  5851. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5852. type: string
  5853. namespace:
  5854. description: |-
  5855. The namespace of the Secret resource being referred to.
  5856. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5857. maxLength: 63
  5858. minLength: 1
  5859. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5860. type: string
  5861. type: object
  5862. clientSecret:
  5863. description: |-
  5864. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5865. In some instances, `key` is a required field.
  5866. properties:
  5867. key:
  5868. description: |-
  5869. A key in the referenced Secret.
  5870. Some instances of this field may be defaulted, in others it may be required.
  5871. maxLength: 253
  5872. minLength: 1
  5873. pattern: ^[-._a-zA-Z0-9]+$
  5874. type: string
  5875. name:
  5876. description: The name of the Secret resource being referred to.
  5877. maxLength: 253
  5878. minLength: 1
  5879. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5880. type: string
  5881. namespace:
  5882. description: |-
  5883. The namespace of the Secret resource being referred to.
  5884. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5885. maxLength: 63
  5886. minLength: 1
  5887. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5888. type: string
  5889. type: object
  5890. required:
  5891. - clientId
  5892. - clientSecret
  5893. type: object
  5894. type: object
  5895. caBundle:
  5896. description: |-
  5897. CABundle is a PEM-encoded CA certificate bundle used to validate
  5898. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  5899. format: byte
  5900. type: string
  5901. caProvider:
  5902. description: |-
  5903. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  5904. The certificate is used to validate the Infisical server's TLS certificate.
  5905. Mutually exclusive with CABundle.
  5906. properties:
  5907. key:
  5908. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5909. maxLength: 253
  5910. minLength: 1
  5911. pattern: ^[-._a-zA-Z0-9]+$
  5912. type: string
  5913. name:
  5914. description: The name of the object located at the provider type.
  5915. maxLength: 253
  5916. minLength: 1
  5917. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5918. type: string
  5919. namespace:
  5920. description: |-
  5921. The namespace the Provider type is in.
  5922. Can only be defined when used in a ClusterSecretStore.
  5923. maxLength: 63
  5924. minLength: 1
  5925. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5926. type: string
  5927. type:
  5928. description: The type of provider to use such as "Secret", or "ConfigMap".
  5929. enum:
  5930. - Secret
  5931. - ConfigMap
  5932. type: string
  5933. required:
  5934. - name
  5935. - type
  5936. type: object
  5937. hostAPI:
  5938. default: https://app.infisical.com/api
  5939. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  5940. type: string
  5941. secretsScope:
  5942. description: SecretsScope defines the scope of the secrets within the workspace
  5943. properties:
  5944. environmentSlug:
  5945. description: EnvironmentSlug is the required slug identifier for the environment.
  5946. type: string
  5947. expandSecretReferences:
  5948. default: true
  5949. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  5950. type: boolean
  5951. organizationSlug:
  5952. description: |-
  5953. OrganizationSlug is the optional slug that identifies the organization that will be used
  5954. during authentication. Useful for sub-organization setups
  5955. type: string
  5956. projectSlug:
  5957. description: ProjectSlug is the required slug identifier for the project.
  5958. type: string
  5959. recursive:
  5960. default: false
  5961. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  5962. type: boolean
  5963. secretsPath:
  5964. default: /
  5965. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  5966. type: string
  5967. required:
  5968. - environmentSlug
  5969. - projectSlug
  5970. type: object
  5971. required:
  5972. - auth
  5973. - secretsScope
  5974. type: object
  5975. keepersecurity:
  5976. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  5977. properties:
  5978. authRef:
  5979. description: |-
  5980. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5981. In some instances, `key` is a required field.
  5982. properties:
  5983. key:
  5984. description: |-
  5985. A key in the referenced Secret.
  5986. Some instances of this field may be defaulted, in others it may be required.
  5987. maxLength: 253
  5988. minLength: 1
  5989. pattern: ^[-._a-zA-Z0-9]+$
  5990. type: string
  5991. name:
  5992. description: The name of the Secret resource being referred to.
  5993. maxLength: 253
  5994. minLength: 1
  5995. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5996. type: string
  5997. namespace:
  5998. description: |-
  5999. The namespace of the Secret resource being referred to.
  6000. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6001. maxLength: 63
  6002. minLength: 1
  6003. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6004. type: string
  6005. type: object
  6006. folderID:
  6007. type: string
  6008. getByTitleFallback:
  6009. type: boolean
  6010. required:
  6011. - authRef
  6012. - folderID
  6013. type: object
  6014. kubernetes:
  6015. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  6016. properties:
  6017. auth:
  6018. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  6019. maxProperties: 1
  6020. minProperties: 1
  6021. properties:
  6022. cert:
  6023. description: has both clientCert and clientKey as secretKeySelector
  6024. properties:
  6025. clientCert:
  6026. description: |-
  6027. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6028. In some instances, `key` is a required field.
  6029. properties:
  6030. key:
  6031. description: |-
  6032. A key in the referenced Secret.
  6033. Some instances of this field may be defaulted, in others it may be required.
  6034. maxLength: 253
  6035. minLength: 1
  6036. pattern: ^[-._a-zA-Z0-9]+$
  6037. type: string
  6038. name:
  6039. description: The name of the Secret resource being referred to.
  6040. maxLength: 253
  6041. minLength: 1
  6042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6043. type: string
  6044. namespace:
  6045. description: |-
  6046. The namespace of the Secret resource being referred to.
  6047. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6048. maxLength: 63
  6049. minLength: 1
  6050. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6051. type: string
  6052. type: object
  6053. clientKey:
  6054. description: |-
  6055. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6056. In some instances, `key` is a required field.
  6057. properties:
  6058. key:
  6059. description: |-
  6060. A key in the referenced Secret.
  6061. Some instances of this field may be defaulted, in others it may be required.
  6062. maxLength: 253
  6063. minLength: 1
  6064. pattern: ^[-._a-zA-Z0-9]+$
  6065. type: string
  6066. name:
  6067. description: The name of the Secret resource being referred to.
  6068. maxLength: 253
  6069. minLength: 1
  6070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6071. type: string
  6072. namespace:
  6073. description: |-
  6074. The namespace of the Secret resource being referred to.
  6075. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6076. maxLength: 63
  6077. minLength: 1
  6078. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6079. type: string
  6080. type: object
  6081. required:
  6082. - clientCert
  6083. - clientKey
  6084. type: object
  6085. serviceAccount:
  6086. description: points to a service account that should be used for authentication
  6087. properties:
  6088. audiences:
  6089. description: |-
  6090. Audience specifies the `aud` claim for the service account token
  6091. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  6092. then this audiences will be appended to the list
  6093. items:
  6094. type: string
  6095. type: array
  6096. name:
  6097. description: The name of the ServiceAccount resource being referred to.
  6098. maxLength: 253
  6099. minLength: 1
  6100. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6101. type: string
  6102. namespace:
  6103. description: |-
  6104. Namespace of the resource being referred to.
  6105. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6106. maxLength: 63
  6107. minLength: 1
  6108. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6109. type: string
  6110. required:
  6111. - name
  6112. type: object
  6113. token:
  6114. description: use static token to authenticate with
  6115. properties:
  6116. bearerToken:
  6117. description: |-
  6118. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6119. In some instances, `key` is a required field.
  6120. properties:
  6121. key:
  6122. description: |-
  6123. A key in the referenced Secret.
  6124. Some instances of this field may be defaulted, in others it may be required.
  6125. maxLength: 253
  6126. minLength: 1
  6127. pattern: ^[-._a-zA-Z0-9]+$
  6128. type: string
  6129. name:
  6130. description: The name of the Secret resource being referred to.
  6131. maxLength: 253
  6132. minLength: 1
  6133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6134. type: string
  6135. namespace:
  6136. description: |-
  6137. The namespace of the Secret resource being referred to.
  6138. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6139. maxLength: 63
  6140. minLength: 1
  6141. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6142. type: string
  6143. type: object
  6144. required:
  6145. - bearerToken
  6146. type: object
  6147. type: object
  6148. authRef:
  6149. description: A reference to a secret that contains the auth information.
  6150. properties:
  6151. key:
  6152. description: |-
  6153. A key in the referenced Secret.
  6154. Some instances of this field may be defaulted, in others it may be required.
  6155. maxLength: 253
  6156. minLength: 1
  6157. pattern: ^[-._a-zA-Z0-9]+$
  6158. type: string
  6159. name:
  6160. description: The name of the Secret resource being referred to.
  6161. maxLength: 253
  6162. minLength: 1
  6163. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6164. type: string
  6165. namespace:
  6166. description: |-
  6167. The namespace of the Secret resource being referred to.
  6168. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6169. maxLength: 63
  6170. minLength: 1
  6171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6172. type: string
  6173. type: object
  6174. remoteNamespace:
  6175. default: default
  6176. description: Remote namespace to fetch the secrets from
  6177. maxLength: 63
  6178. minLength: 1
  6179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6180. type: string
  6181. server:
  6182. description: configures the Kubernetes server Address.
  6183. properties:
  6184. caBundle:
  6185. description: CABundle is a base64-encoded CA certificate
  6186. format: byte
  6187. type: string
  6188. caProvider:
  6189. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  6190. properties:
  6191. key:
  6192. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6193. maxLength: 253
  6194. minLength: 1
  6195. pattern: ^[-._a-zA-Z0-9]+$
  6196. type: string
  6197. name:
  6198. description: The name of the object located at the provider type.
  6199. maxLength: 253
  6200. minLength: 1
  6201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6202. type: string
  6203. namespace:
  6204. description: |-
  6205. The namespace the Provider type is in.
  6206. Can only be defined when used in a ClusterSecretStore.
  6207. maxLength: 63
  6208. minLength: 1
  6209. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6210. type: string
  6211. type:
  6212. description: The type of provider to use such as "Secret", or "ConfigMap".
  6213. enum:
  6214. - Secret
  6215. - ConfigMap
  6216. type: string
  6217. required:
  6218. - name
  6219. - type
  6220. type: object
  6221. url:
  6222. default: kubernetes.default
  6223. description: configures the Kubernetes server Address.
  6224. type: string
  6225. type: object
  6226. type: object
  6227. nebiusmysterybox:
  6228. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  6229. properties:
  6230. apiDomain:
  6231. description: NebiusMysterybox API endpoint
  6232. type: string
  6233. auth:
  6234. description: Auth defines parameters to authenticate in MysteryBox
  6235. properties:
  6236. serviceAccountCredsSecretRef:
  6237. description: |-
  6238. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  6239. document with service account credentials used to get an IAM token.
  6240. Expected JSON structure:
  6241. {
  6242. "subject-credentials": {
  6243. "alg": "RS256",
  6244. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  6245. "kid": "<public-key-id>",
  6246. "iss": "<issuer-service-account-id>",
  6247. "sub": "<subject-service-account-id>"
  6248. }
  6249. }
  6250. properties:
  6251. key:
  6252. description: |-
  6253. A key in the referenced Secret.
  6254. Some instances of this field may be defaulted, in others it may be required.
  6255. maxLength: 253
  6256. minLength: 1
  6257. pattern: ^[-._a-zA-Z0-9]+$
  6258. type: string
  6259. name:
  6260. description: The name of the Secret resource being referred to.
  6261. maxLength: 253
  6262. minLength: 1
  6263. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6264. type: string
  6265. namespace:
  6266. description: |-
  6267. The namespace of the Secret resource being referred to.
  6268. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6269. maxLength: 63
  6270. minLength: 1
  6271. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6272. type: string
  6273. type: object
  6274. tokenSecretRef:
  6275. description: Token authenticates with Nebius Mysterybox by presenting a token.
  6276. properties:
  6277. key:
  6278. description: |-
  6279. A key in the referenced Secret.
  6280. Some instances of this field may be defaulted, in others it may be required.
  6281. maxLength: 253
  6282. minLength: 1
  6283. pattern: ^[-._a-zA-Z0-9]+$
  6284. type: string
  6285. name:
  6286. description: The name of the Secret resource being referred to.
  6287. maxLength: 253
  6288. minLength: 1
  6289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6290. type: string
  6291. namespace:
  6292. description: |-
  6293. The namespace of the Secret resource being referred to.
  6294. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6295. maxLength: 63
  6296. minLength: 1
  6297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6298. type: string
  6299. type: object
  6300. type: object
  6301. x-kubernetes-validations:
  6302. - message: either serviceAccountCredsSecretRef or tokenSecretRef must be set
  6303. rule: has(self.serviceAccountCredsSecretRef) || has(self.tokenSecretRef)
  6304. caProvider:
  6305. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  6306. properties:
  6307. certSecretRef:
  6308. description: |-
  6309. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6310. In some instances, `key` is a required field.
  6311. properties:
  6312. key:
  6313. description: |-
  6314. A key in the referenced Secret.
  6315. Some instances of this field may be defaulted, in others it may be required.
  6316. maxLength: 253
  6317. minLength: 1
  6318. pattern: ^[-._a-zA-Z0-9]+$
  6319. type: string
  6320. name:
  6321. description: The name of the Secret resource being referred to.
  6322. maxLength: 253
  6323. minLength: 1
  6324. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6325. type: string
  6326. namespace:
  6327. description: |-
  6328. The namespace of the Secret resource being referred to.
  6329. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6330. maxLength: 63
  6331. minLength: 1
  6332. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6333. type: string
  6334. type: object
  6335. type: object
  6336. required:
  6337. - apiDomain
  6338. - auth
  6339. type: object
  6340. ngrok:
  6341. description: Ngrok configures this store to sync secrets using the ngrok provider.
  6342. properties:
  6343. apiUrl:
  6344. default: https://api.ngrok.com
  6345. description: APIURL is the URL of the ngrok API.
  6346. type: string
  6347. auth:
  6348. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  6349. maxProperties: 1
  6350. minProperties: 1
  6351. properties:
  6352. apiKey:
  6353. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  6354. properties:
  6355. secretRef:
  6356. description: SecretRef is a reference to a secret containing the ngrok API key.
  6357. properties:
  6358. key:
  6359. description: |-
  6360. A key in the referenced Secret.
  6361. Some instances of this field may be defaulted, in others it may be required.
  6362. maxLength: 253
  6363. minLength: 1
  6364. pattern: ^[-._a-zA-Z0-9]+$
  6365. type: string
  6366. name:
  6367. description: The name of the Secret resource being referred to.
  6368. maxLength: 253
  6369. minLength: 1
  6370. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6371. type: string
  6372. namespace:
  6373. description: |-
  6374. The namespace of the Secret resource being referred to.
  6375. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6376. maxLength: 63
  6377. minLength: 1
  6378. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6379. type: string
  6380. type: object
  6381. type: object
  6382. type: object
  6383. vault:
  6384. description: Vault configures the ngrok vault to sync secrets with.
  6385. properties:
  6386. name:
  6387. description: Name is the name of the ngrok vault to sync secrets with.
  6388. type: string
  6389. required:
  6390. - name
  6391. type: object
  6392. required:
  6393. - auth
  6394. - vault
  6395. type: object
  6396. onboardbase:
  6397. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  6398. properties:
  6399. apiHost:
  6400. default: https://public.onboardbase.com/api/v1/
  6401. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  6402. type: string
  6403. auth:
  6404. description: Auth configures how the Operator authenticates with the Onboardbase API
  6405. properties:
  6406. apiKeyRef:
  6407. description: |-
  6408. OnboardbaseAPIKey is the APIKey generated by an admin account.
  6409. It is used to recognize and authorize access to a project and environment within onboardbase
  6410. properties:
  6411. key:
  6412. description: |-
  6413. A key in the referenced Secret.
  6414. Some instances of this field may be defaulted, in others it may be required.
  6415. maxLength: 253
  6416. minLength: 1
  6417. pattern: ^[-._a-zA-Z0-9]+$
  6418. type: string
  6419. name:
  6420. description: The name of the Secret resource being referred to.
  6421. maxLength: 253
  6422. minLength: 1
  6423. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6424. type: string
  6425. namespace:
  6426. description: |-
  6427. The namespace of the Secret resource being referred to.
  6428. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6429. maxLength: 63
  6430. minLength: 1
  6431. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6432. type: string
  6433. type: object
  6434. passcodeRef:
  6435. description: OnboardbasePasscode is the passcode attached to the API Key
  6436. properties:
  6437. key:
  6438. description: |-
  6439. A key in the referenced Secret.
  6440. Some instances of this field may be defaulted, in others it may be required.
  6441. maxLength: 253
  6442. minLength: 1
  6443. pattern: ^[-._a-zA-Z0-9]+$
  6444. type: string
  6445. name:
  6446. description: The name of the Secret resource being referred to.
  6447. maxLength: 253
  6448. minLength: 1
  6449. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6450. type: string
  6451. namespace:
  6452. description: |-
  6453. The namespace of the Secret resource being referred to.
  6454. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6455. maxLength: 63
  6456. minLength: 1
  6457. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6458. type: string
  6459. type: object
  6460. required:
  6461. - apiKeyRef
  6462. - passcodeRef
  6463. type: object
  6464. environment:
  6465. default: development
  6466. description: Environment is the name of an environmnent within a project to pull the secrets from
  6467. type: string
  6468. project:
  6469. default: development
  6470. description: Project is an onboardbase project that the secrets should be pulled from
  6471. type: string
  6472. required:
  6473. - apiHost
  6474. - auth
  6475. - environment
  6476. - project
  6477. type: object
  6478. onepassword:
  6479. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  6480. properties:
  6481. auth:
  6482. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  6483. properties:
  6484. secretRef:
  6485. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  6486. properties:
  6487. connectTokenSecretRef:
  6488. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  6489. properties:
  6490. key:
  6491. description: |-
  6492. A key in the referenced Secret.
  6493. Some instances of this field may be defaulted, in others it may be required.
  6494. maxLength: 253
  6495. minLength: 1
  6496. pattern: ^[-._a-zA-Z0-9]+$
  6497. type: string
  6498. name:
  6499. description: The name of the Secret resource being referred to.
  6500. maxLength: 253
  6501. minLength: 1
  6502. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6503. type: string
  6504. namespace:
  6505. description: |-
  6506. The namespace of the Secret resource being referred to.
  6507. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6508. maxLength: 63
  6509. minLength: 1
  6510. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6511. type: string
  6512. type: object
  6513. required:
  6514. - connectTokenSecretRef
  6515. type: object
  6516. required:
  6517. - secretRef
  6518. type: object
  6519. connectHost:
  6520. description: ConnectHost defines the OnePassword Connect Server to connect to
  6521. type: string
  6522. vaults:
  6523. additionalProperties:
  6524. type: integer
  6525. description: Vaults defines which OnePassword vaults to search in which order
  6526. type: object
  6527. required:
  6528. - auth
  6529. - connectHost
  6530. - vaults
  6531. type: object
  6532. onepasswordSDK:
  6533. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  6534. properties:
  6535. auth:
  6536. description: Auth defines the information necessary to authenticate against OnePassword API.
  6537. properties:
  6538. serviceAccountSecretRef:
  6539. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  6540. properties:
  6541. key:
  6542. description: |-
  6543. A key in the referenced Secret.
  6544. Some instances of this field may be defaulted, in others it may be required.
  6545. maxLength: 253
  6546. minLength: 1
  6547. pattern: ^[-._a-zA-Z0-9]+$
  6548. type: string
  6549. name:
  6550. description: The name of the Secret resource being referred to.
  6551. maxLength: 253
  6552. minLength: 1
  6553. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6554. type: string
  6555. namespace:
  6556. description: |-
  6557. The namespace of the Secret resource being referred to.
  6558. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6559. maxLength: 63
  6560. minLength: 1
  6561. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6562. type: string
  6563. type: object
  6564. required:
  6565. - serviceAccountSecretRef
  6566. type: object
  6567. cache:
  6568. description: |-
  6569. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  6570. When enabled, secrets are cached with the specified TTL.
  6571. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  6572. If omitted, caching is disabled (default).
  6573. cache: {} is a valid option to set.
  6574. properties:
  6575. maxSize:
  6576. default: 100
  6577. description: |-
  6578. MaxSize is the maximum number of secrets to cache.
  6579. When the cache is full, least-recently-used entries are evicted.
  6580. minimum: 1
  6581. type: integer
  6582. ttl:
  6583. default: 5m
  6584. description: |-
  6585. TTL is the time-to-live for cached secrets.
  6586. Format: duration string (e.g., "5m", "1h", "30s")
  6587. type: string
  6588. type: object
  6589. environment:
  6590. description: |-
  6591. Environment defines the 1Password Environment ID to read variables from.
  6592. Environments are read-only: PushSecret, DeleteSecret, and SecretExists return an error when set.
  6593. Mutually exclusive with Vault.
  6594. type: string
  6595. integrationInfo:
  6596. description: |-
  6597. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  6598. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  6599. properties:
  6600. name:
  6601. default: 1Password SDK
  6602. description: Name defaults to "1Password SDK".
  6603. type: string
  6604. version:
  6605. default: v1.0.0
  6606. description: Version defaults to "v1.0.0".
  6607. type: string
  6608. type: object
  6609. vault:
  6610. description: |-
  6611. Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  6612. Mutually exclusive with Environment.
  6613. type: string
  6614. required:
  6615. - auth
  6616. type: object
  6617. openBao:
  6618. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  6619. properties:
  6620. auth:
  6621. description: Auth configures how secret-manager authenticates with the OpenBao server.
  6622. properties:
  6623. appRole:
  6624. description: |-
  6625. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  6626. with the role and secret stored in a Kubernetes Secret resource.
  6627. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  6628. properties:
  6629. path:
  6630. default: approle
  6631. description: |-
  6632. Path where the App Role authentication backend is mounted
  6633. in OpenBao, e.g: "approle"
  6634. type: string
  6635. roleId:
  6636. description: |-
  6637. RoleID configured in the App Role authentication backend when setting
  6638. up the authentication backend in OpenBao.
  6639. minLength: 1
  6640. type: string
  6641. roleRef:
  6642. description: |-
  6643. Reference to a key in a Secret that contains the App Role ID used
  6644. to authenticate with OpenBao.
  6645. The `key` field must be specified and denotes which entry within the Secret
  6646. resource is used as the app role id.
  6647. properties:
  6648. key:
  6649. description: |-
  6650. A key in the referenced Secret.
  6651. Some instances of this field may be defaulted, in others it may be required.
  6652. maxLength: 253
  6653. minLength: 1
  6654. pattern: ^[-._a-zA-Z0-9]+$
  6655. type: string
  6656. name:
  6657. description: The name of the Secret resource being referred to.
  6658. maxLength: 253
  6659. minLength: 1
  6660. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6661. type: string
  6662. namespace:
  6663. description: |-
  6664. The namespace of the Secret resource being referred to.
  6665. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6666. maxLength: 63
  6667. minLength: 1
  6668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6669. type: string
  6670. type: object
  6671. secretRef:
  6672. description: |-
  6673. Reference to a key in a Secret that contains the App Role secret used
  6674. to authenticate with OpenBao.
  6675. The `key` field must be specified and denotes which entry within the Secret
  6676. resource is used as the app role secret.
  6677. properties:
  6678. key:
  6679. description: |-
  6680. A key in the referenced Secret.
  6681. Some instances of this field may be defaulted, in others it may be required.
  6682. maxLength: 253
  6683. minLength: 1
  6684. pattern: ^[-._a-zA-Z0-9]+$
  6685. type: string
  6686. name:
  6687. description: The name of the Secret resource being referred to.
  6688. maxLength: 253
  6689. minLength: 1
  6690. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6691. type: string
  6692. namespace:
  6693. description: |-
  6694. The namespace of the Secret resource being referred to.
  6695. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6696. maxLength: 63
  6697. minLength: 1
  6698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6699. type: string
  6700. type: object
  6701. required:
  6702. - path
  6703. - secretRef
  6704. type: object
  6705. x-kubernetes-validations:
  6706. - message: exactly one of the fields in [roleId roleRef] must be set
  6707. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  6708. namespace:
  6709. description: |-
  6710. Name of the [OpenBao Namespace] to authenticate to. This can be different
  6711. than the namespace your secret is in. Namespaces is a set of features
  6712. within OpenBao that allows OpenBao environments to support secure
  6713. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  6714. if set, or empty otherwise
  6715. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6716. type: string
  6717. tokenSecretRef:
  6718. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  6719. properties:
  6720. key:
  6721. description: |-
  6722. A key in the referenced Secret.
  6723. Some instances of this field may be defaulted, in others it may be required.
  6724. maxLength: 253
  6725. minLength: 1
  6726. pattern: ^[-._a-zA-Z0-9]+$
  6727. type: string
  6728. name:
  6729. description: The name of the Secret resource being referred to.
  6730. maxLength: 253
  6731. minLength: 1
  6732. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6733. type: string
  6734. namespace:
  6735. description: |-
  6736. The namespace of the Secret resource being referred to.
  6737. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6738. maxLength: 63
  6739. minLength: 1
  6740. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6741. type: string
  6742. type: object
  6743. userPass:
  6744. description: UserPass authenticates with OpenBao by passing a username/password pair
  6745. properties:
  6746. path:
  6747. default: userpass
  6748. description: |-
  6749. Path where the UserPassword authentication backend is mounted
  6750. in OpenBao, e.g: "userpass"
  6751. type: string
  6752. secretRef:
  6753. description: |-
  6754. SecretRef to a key in a Secret resource containing password for the user
  6755. used to authenticate with OpenBao using the [UserPass authentication
  6756. method]
  6757. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6758. properties:
  6759. key:
  6760. description: |-
  6761. A key in the referenced Secret.
  6762. Some instances of this field may be defaulted, in others it may be required.
  6763. maxLength: 253
  6764. minLength: 1
  6765. pattern: ^[-._a-zA-Z0-9]+$
  6766. type: string
  6767. name:
  6768. description: The name of the Secret resource being referred to.
  6769. maxLength: 253
  6770. minLength: 1
  6771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6772. type: string
  6773. namespace:
  6774. description: |-
  6775. The namespace of the Secret resource being referred to.
  6776. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6777. maxLength: 63
  6778. minLength: 1
  6779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6780. type: string
  6781. type: object
  6782. username:
  6783. description: |-
  6784. Username is a username used to authenticate using the [UserPass
  6785. authentication method]
  6786. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6787. type: string
  6788. required:
  6789. - path
  6790. - username
  6791. type: object
  6792. type: object
  6793. x-kubernetes-validations:
  6794. - message: exactly one of the fields in [appRole tokenSecretRef userPass] must be set
  6795. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass)].filter(x,x==true).size() == 1'
  6796. caBundle:
  6797. description: |-
  6798. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  6799. this and `caProvider` are not set the system root certificates are used
  6800. to validate the TLS connection.
  6801. format: byte
  6802. type: string
  6803. caProvider:
  6804. description: |-
  6805. The provider for the CA bundle to use to validate OpenBao server
  6806. certificate. If this and `caBundle` are not set the system root
  6807. certificates are used to validate the TLS connection.
  6808. properties:
  6809. key:
  6810. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6811. maxLength: 253
  6812. minLength: 1
  6813. pattern: ^[-._a-zA-Z0-9]+$
  6814. type: string
  6815. name:
  6816. description: The name of the object located at the provider type.
  6817. maxLength: 253
  6818. minLength: 1
  6819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6820. type: string
  6821. namespace:
  6822. description: |-
  6823. The namespace the Provider type is in.
  6824. Can only be defined when used in a ClusterSecretStore.
  6825. maxLength: 63
  6826. minLength: 1
  6827. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6828. type: string
  6829. type:
  6830. description: The type of provider to use such as "Secret", or "ConfigMap".
  6831. enum:
  6832. - Secret
  6833. - ConfigMap
  6834. type: string
  6835. required:
  6836. - name
  6837. - type
  6838. type: object
  6839. namespace:
  6840. description: |-
  6841. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  6842. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  6843. e.g: "ns1".
  6844. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6845. type: string
  6846. path:
  6847. description: |-
  6848. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  6849. "secret". The v2 KV secret engine version specific "/data" path suffix
  6850. for fetching secrets from OpenBao is optional and will be appended
  6851. if not present in specified path.
  6852. type: string
  6853. server:
  6854. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  6855. type: string
  6856. version:
  6857. default: v2
  6858. description: |-
  6859. Version is the OpenBao KV secret engine version. This can be either "v1" or
  6860. "v2". Version defaults to "v2".
  6861. enum:
  6862. - v1
  6863. - v2
  6864. type: string
  6865. required:
  6866. - server
  6867. type: object
  6868. x-kubernetes-validations:
  6869. - message: at most one of the fields in [caBundle caProvider] may be set
  6870. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  6871. oracle:
  6872. description: Oracle configures this store to sync secrets using Oracle Vault provider
  6873. properties:
  6874. auth:
  6875. description: |-
  6876. Auth configures how secret-manager authenticates with the Oracle Vault.
  6877. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  6878. properties:
  6879. secretRef:
  6880. description: SecretRef to pass through sensitive information.
  6881. properties:
  6882. fingerprint:
  6883. description: Fingerprint is the fingerprint of the API private key.
  6884. properties:
  6885. key:
  6886. description: |-
  6887. A key in the referenced Secret.
  6888. Some instances of this field may be defaulted, in others it may be required.
  6889. maxLength: 253
  6890. minLength: 1
  6891. pattern: ^[-._a-zA-Z0-9]+$
  6892. type: string
  6893. name:
  6894. description: The name of the Secret resource being referred to.
  6895. maxLength: 253
  6896. minLength: 1
  6897. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6898. type: string
  6899. namespace:
  6900. description: |-
  6901. The namespace of the Secret resource being referred to.
  6902. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6903. maxLength: 63
  6904. minLength: 1
  6905. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6906. type: string
  6907. type: object
  6908. privatekey:
  6909. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  6910. properties:
  6911. key:
  6912. description: |-
  6913. A key in the referenced Secret.
  6914. Some instances of this field may be defaulted, in others it may be required.
  6915. maxLength: 253
  6916. minLength: 1
  6917. pattern: ^[-._a-zA-Z0-9]+$
  6918. type: string
  6919. name:
  6920. description: The name of the Secret resource being referred to.
  6921. maxLength: 253
  6922. minLength: 1
  6923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6924. type: string
  6925. namespace:
  6926. description: |-
  6927. The namespace of the Secret resource being referred to.
  6928. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6929. maxLength: 63
  6930. minLength: 1
  6931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6932. type: string
  6933. type: object
  6934. required:
  6935. - fingerprint
  6936. - privatekey
  6937. type: object
  6938. tenancy:
  6939. description: Tenancy is the tenancy OCID where user is located.
  6940. type: string
  6941. user:
  6942. description: User is an access OCID specific to the account.
  6943. type: string
  6944. required:
  6945. - secretRef
  6946. - tenancy
  6947. - user
  6948. type: object
  6949. compartment:
  6950. description: |-
  6951. Compartment is the vault compartment OCID.
  6952. Required for PushSecret
  6953. type: string
  6954. encryptionKey:
  6955. description: |-
  6956. EncryptionKey is the OCID of the encryption key within the vault.
  6957. Required for PushSecret
  6958. type: string
  6959. principalType:
  6960. description: |-
  6961. The type of principal to use for authentication. If left blank, the Auth struct will
  6962. determine the principal type. This optional field must be specified if using
  6963. workload identity.
  6964. enum:
  6965. - ""
  6966. - UserPrincipal
  6967. - InstancePrincipal
  6968. - Workload
  6969. type: string
  6970. region:
  6971. description: Region is the region where vault is located.
  6972. type: string
  6973. serviceAccountRef:
  6974. description: |-
  6975. ServiceAccountRef specified the service account
  6976. that should be used when authenticating with WorkloadIdentity.
  6977. properties:
  6978. audiences:
  6979. description: |-
  6980. Audience specifies the `aud` claim for the service account token
  6981. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  6982. then this audiences will be appended to the list
  6983. items:
  6984. type: string
  6985. type: array
  6986. name:
  6987. description: The name of the ServiceAccount resource being referred to.
  6988. maxLength: 253
  6989. minLength: 1
  6990. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6991. type: string
  6992. namespace:
  6993. description: |-
  6994. Namespace of the resource being referred to.
  6995. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6996. maxLength: 63
  6997. minLength: 1
  6998. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6999. type: string
  7000. required:
  7001. - name
  7002. type: object
  7003. vault:
  7004. description: Vault is the vault's OCID of the specific vault where secret is located.
  7005. type: string
  7006. required:
  7007. - region
  7008. - vault
  7009. type: object
  7010. ovh:
  7011. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  7012. properties:
  7013. auth:
  7014. description: Authentication method (mtls or token).
  7015. properties:
  7016. mtls:
  7017. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  7018. properties:
  7019. caBundle:
  7020. format: byte
  7021. type: string
  7022. caProvider:
  7023. description: |-
  7024. CAProvider provides a custom certificate authority for accessing the provider's store.
  7025. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  7026. properties:
  7027. key:
  7028. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7029. maxLength: 253
  7030. minLength: 1
  7031. pattern: ^[-._a-zA-Z0-9]+$
  7032. type: string
  7033. name:
  7034. description: The name of the object located at the provider type.
  7035. maxLength: 253
  7036. minLength: 1
  7037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7038. type: string
  7039. namespace:
  7040. description: |-
  7041. The namespace the Provider type is in.
  7042. Can only be defined when used in a ClusterSecretStore.
  7043. maxLength: 63
  7044. minLength: 1
  7045. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7046. type: string
  7047. type:
  7048. description: The type of provider to use such as "Secret", or "ConfigMap".
  7049. enum:
  7050. - Secret
  7051. - ConfigMap
  7052. type: string
  7053. required:
  7054. - name
  7055. - type
  7056. type: object
  7057. certSecretRef:
  7058. description: |-
  7059. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7060. In some instances, `key` is a required field.
  7061. properties:
  7062. key:
  7063. description: |-
  7064. A key in the referenced Secret.
  7065. Some instances of this field may be defaulted, in others it may be required.
  7066. maxLength: 253
  7067. minLength: 1
  7068. pattern: ^[-._a-zA-Z0-9]+$
  7069. type: string
  7070. name:
  7071. description: The name of the Secret resource being referred to.
  7072. maxLength: 253
  7073. minLength: 1
  7074. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7075. type: string
  7076. namespace:
  7077. description: |-
  7078. The namespace of the Secret resource being referred to.
  7079. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7080. maxLength: 63
  7081. minLength: 1
  7082. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7083. type: string
  7084. type: object
  7085. keySecretRef:
  7086. description: |-
  7087. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7088. In some instances, `key` is a required field.
  7089. properties:
  7090. key:
  7091. description: |-
  7092. A key in the referenced Secret.
  7093. Some instances of this field may be defaulted, in others it may be required.
  7094. maxLength: 253
  7095. minLength: 1
  7096. pattern: ^[-._a-zA-Z0-9]+$
  7097. type: string
  7098. name:
  7099. description: The name of the Secret resource being referred to.
  7100. maxLength: 253
  7101. minLength: 1
  7102. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7103. type: string
  7104. namespace:
  7105. description: |-
  7106. The namespace of the Secret resource being referred to.
  7107. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7108. maxLength: 63
  7109. minLength: 1
  7110. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7111. type: string
  7112. type: object
  7113. required:
  7114. - certSecretRef
  7115. - keySecretRef
  7116. type: object
  7117. token:
  7118. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  7119. properties:
  7120. tokenSecretRef:
  7121. description: |-
  7122. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7123. In some instances, `key` is a required field.
  7124. properties:
  7125. key:
  7126. description: |-
  7127. A key in the referenced Secret.
  7128. Some instances of this field may be defaulted, in others it may be required.
  7129. maxLength: 253
  7130. minLength: 1
  7131. pattern: ^[-._a-zA-Z0-9]+$
  7132. type: string
  7133. name:
  7134. description: The name of the Secret resource being referred to.
  7135. maxLength: 253
  7136. minLength: 1
  7137. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7138. type: string
  7139. namespace:
  7140. description: |-
  7141. The namespace of the Secret resource being referred to.
  7142. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7143. maxLength: 63
  7144. minLength: 1
  7145. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7146. type: string
  7147. type: object
  7148. required:
  7149. - tokenSecretRef
  7150. type: object
  7151. type: object
  7152. casRequired:
  7153. description: 'Enables or disables check-and-set (CAS) (default: false).'
  7154. type: boolean
  7155. okmsTimeout:
  7156. default: 30
  7157. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  7158. format: int32
  7159. minimum: 1
  7160. type: integer
  7161. okmsid:
  7162. description: specifies the OKMS ID.
  7163. type: string
  7164. server:
  7165. description: specifies the OKMS server endpoint.
  7166. type: string
  7167. required:
  7168. - auth
  7169. - okmsid
  7170. - server
  7171. type: object
  7172. passbolt:
  7173. description: |-
  7174. PassboltProvider provides access to Passbolt secrets manager.
  7175. See: https://www.passbolt.com.
  7176. properties:
  7177. auth:
  7178. description: Auth defines the information necessary to authenticate against Passbolt Server
  7179. properties:
  7180. passwordSecretRef:
  7181. description: |-
  7182. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7183. In some instances, `key` is a required field.
  7184. properties:
  7185. key:
  7186. description: |-
  7187. A key in the referenced Secret.
  7188. Some instances of this field may be defaulted, in others it may be required.
  7189. maxLength: 253
  7190. minLength: 1
  7191. pattern: ^[-._a-zA-Z0-9]+$
  7192. type: string
  7193. name:
  7194. description: The name of the Secret resource being referred to.
  7195. maxLength: 253
  7196. minLength: 1
  7197. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7198. type: string
  7199. namespace:
  7200. description: |-
  7201. The namespace of the Secret resource being referred to.
  7202. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7203. maxLength: 63
  7204. minLength: 1
  7205. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7206. type: string
  7207. type: object
  7208. privateKeySecretRef:
  7209. description: |-
  7210. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7211. In some instances, `key` is a required field.
  7212. properties:
  7213. key:
  7214. description: |-
  7215. A key in the referenced Secret.
  7216. Some instances of this field may be defaulted, in others it may be required.
  7217. maxLength: 253
  7218. minLength: 1
  7219. pattern: ^[-._a-zA-Z0-9]+$
  7220. type: string
  7221. name:
  7222. description: The name of the Secret resource being referred to.
  7223. maxLength: 253
  7224. minLength: 1
  7225. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7226. type: string
  7227. namespace:
  7228. description: |-
  7229. The namespace of the Secret resource being referred to.
  7230. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7231. maxLength: 63
  7232. minLength: 1
  7233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7234. type: string
  7235. type: object
  7236. required:
  7237. - passwordSecretRef
  7238. - privateKeySecretRef
  7239. type: object
  7240. caBundle:
  7241. description: |-
  7242. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  7243. if the Host URL is using HTTPS protocol. If not set the system root certificates
  7244. are used to validate the TLS connection.
  7245. format: byte
  7246. type: string
  7247. caProvider:
  7248. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  7249. properties:
  7250. key:
  7251. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7252. maxLength: 253
  7253. minLength: 1
  7254. pattern: ^[-._a-zA-Z0-9]+$
  7255. type: string
  7256. name:
  7257. description: The name of the object located at the provider type.
  7258. maxLength: 253
  7259. minLength: 1
  7260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7261. type: string
  7262. namespace:
  7263. description: |-
  7264. The namespace the Provider type is in.
  7265. Can only be defined when used in a ClusterSecretStore.
  7266. maxLength: 63
  7267. minLength: 1
  7268. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7269. type: string
  7270. type:
  7271. description: The type of provider to use such as "Secret", or "ConfigMap".
  7272. enum:
  7273. - Secret
  7274. - ConfigMap
  7275. type: string
  7276. required:
  7277. - name
  7278. - type
  7279. type: object
  7280. host:
  7281. description: Host defines the Passbolt Server to connect to
  7282. type: string
  7283. required:
  7284. - auth
  7285. - host
  7286. type: object
  7287. passworddepot:
  7288. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  7289. properties:
  7290. auth:
  7291. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  7292. properties:
  7293. secretRef:
  7294. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  7295. properties:
  7296. credentials:
  7297. description: Username / Password is used for authentication.
  7298. properties:
  7299. key:
  7300. description: |-
  7301. A key in the referenced Secret.
  7302. Some instances of this field may be defaulted, in others it may be required.
  7303. maxLength: 253
  7304. minLength: 1
  7305. pattern: ^[-._a-zA-Z0-9]+$
  7306. type: string
  7307. name:
  7308. description: The name of the Secret resource being referred to.
  7309. maxLength: 253
  7310. minLength: 1
  7311. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7312. type: string
  7313. namespace:
  7314. description: |-
  7315. The namespace of the Secret resource being referred to.
  7316. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7317. maxLength: 63
  7318. minLength: 1
  7319. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7320. type: string
  7321. type: object
  7322. type: object
  7323. required:
  7324. - secretRef
  7325. type: object
  7326. database:
  7327. description: Database to use as source
  7328. type: string
  7329. host:
  7330. description: URL configures the Password Depot instance URL.
  7331. type: string
  7332. required:
  7333. - auth
  7334. - database
  7335. - host
  7336. type: object
  7337. previder:
  7338. description: Previder configures this store to sync secrets using the Previder provider
  7339. properties:
  7340. auth:
  7341. description: PreviderAuth contains a secretRef for credentials.
  7342. properties:
  7343. secretRef:
  7344. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  7345. properties:
  7346. accessToken:
  7347. description: The AccessToken is used for authentication
  7348. properties:
  7349. key:
  7350. description: |-
  7351. A key in the referenced Secret.
  7352. Some instances of this field may be defaulted, in others it may be required.
  7353. maxLength: 253
  7354. minLength: 1
  7355. pattern: ^[-._a-zA-Z0-9]+$
  7356. type: string
  7357. name:
  7358. description: The name of the Secret resource being referred to.
  7359. maxLength: 253
  7360. minLength: 1
  7361. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7362. type: string
  7363. namespace:
  7364. description: |-
  7365. The namespace of the Secret resource being referred to.
  7366. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7367. maxLength: 63
  7368. minLength: 1
  7369. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7370. type: string
  7371. type: object
  7372. required:
  7373. - accessToken
  7374. type: object
  7375. type: object
  7376. baseUri:
  7377. type: string
  7378. required:
  7379. - auth
  7380. type: object
  7381. pulumi:
  7382. description: Pulumi configures this store to sync secrets using the Pulumi provider
  7383. properties:
  7384. accessToken:
  7385. description: |-
  7386. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  7387. Deprecated: Use auth.accessToken instead.
  7388. properties:
  7389. secretRef:
  7390. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7391. properties:
  7392. key:
  7393. description: |-
  7394. A key in the referenced Secret.
  7395. Some instances of this field may be defaulted, in others it may be required.
  7396. maxLength: 253
  7397. minLength: 1
  7398. pattern: ^[-._a-zA-Z0-9]+$
  7399. type: string
  7400. name:
  7401. description: The name of the Secret resource being referred to.
  7402. maxLength: 253
  7403. minLength: 1
  7404. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7405. type: string
  7406. namespace:
  7407. description: |-
  7408. The namespace of the Secret resource being referred to.
  7409. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7410. maxLength: 63
  7411. minLength: 1
  7412. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7413. type: string
  7414. type: object
  7415. type: object
  7416. apiUrl:
  7417. default: https://api.pulumi.com/api/esc
  7418. description: APIURL is the URL of the Pulumi API.
  7419. type: string
  7420. auth:
  7421. description: |-
  7422. Auth configures how the Operator authenticates with the Pulumi API.
  7423. Either auth or the deprecated accessToken field must be specified.
  7424. properties:
  7425. accessToken:
  7426. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  7427. properties:
  7428. secretRef:
  7429. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7430. properties:
  7431. key:
  7432. description: |-
  7433. A key in the referenced Secret.
  7434. Some instances of this field may be defaulted, in others it may be required.
  7435. maxLength: 253
  7436. minLength: 1
  7437. pattern: ^[-._a-zA-Z0-9]+$
  7438. type: string
  7439. name:
  7440. description: The name of the Secret resource being referred to.
  7441. maxLength: 253
  7442. minLength: 1
  7443. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7444. type: string
  7445. namespace:
  7446. description: |-
  7447. The namespace of the Secret resource being referred to.
  7448. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7449. maxLength: 63
  7450. minLength: 1
  7451. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7452. type: string
  7453. type: object
  7454. type: object
  7455. oidcConfig:
  7456. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  7457. properties:
  7458. expirationSeconds:
  7459. default: 600
  7460. description: |-
  7461. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  7462. Defaults to 10 minutes.
  7463. format: int64
  7464. minimum: 600
  7465. type: integer
  7466. organization:
  7467. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  7468. type: string
  7469. serviceAccountRef:
  7470. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  7471. properties:
  7472. audiences:
  7473. description: |-
  7474. Audience specifies the `aud` claim for the service account token
  7475. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  7476. then this audiences will be appended to the list
  7477. items:
  7478. type: string
  7479. type: array
  7480. name:
  7481. description: The name of the ServiceAccount resource being referred to.
  7482. maxLength: 253
  7483. minLength: 1
  7484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7485. type: string
  7486. namespace:
  7487. description: |-
  7488. Namespace of the resource being referred to.
  7489. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7490. maxLength: 63
  7491. minLength: 1
  7492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7493. type: string
  7494. required:
  7495. - name
  7496. type: object
  7497. required:
  7498. - organization
  7499. - serviceAccountRef
  7500. type: object
  7501. type: object
  7502. x-kubernetes-validations:
  7503. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  7504. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  7505. environment:
  7506. description: |-
  7507. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  7508. dynamically retrieved values from supported providers including all major clouds,
  7509. and other Pulumi ESC environments.
  7510. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  7511. type: string
  7512. organization:
  7513. description: |-
  7514. Organization are a space to collaborate on shared projects and stacks.
  7515. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  7516. type: string
  7517. project:
  7518. description: Project is the name of the Pulumi ESC project the environment belongs to.
  7519. type: string
  7520. required:
  7521. - environment
  7522. - organization
  7523. - project
  7524. type: object
  7525. x-kubernetes-validations:
  7526. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  7527. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  7528. scaleway:
  7529. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  7530. properties:
  7531. accessKey:
  7532. description: AccessKey is the non-secret part of the api key.
  7533. properties:
  7534. secretRef:
  7535. description: SecretRef references a key in a secret that will be used as value.
  7536. properties:
  7537. key:
  7538. description: |-
  7539. A key in the referenced Secret.
  7540. Some instances of this field may be defaulted, in others it may be required.
  7541. maxLength: 253
  7542. minLength: 1
  7543. pattern: ^[-._a-zA-Z0-9]+$
  7544. type: string
  7545. name:
  7546. description: The name of the Secret resource being referred to.
  7547. maxLength: 253
  7548. minLength: 1
  7549. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7550. type: string
  7551. namespace:
  7552. description: |-
  7553. The namespace of the Secret resource being referred to.
  7554. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7555. maxLength: 63
  7556. minLength: 1
  7557. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7558. type: string
  7559. type: object
  7560. value:
  7561. description: Value can be specified directly to set a value without using a secret.
  7562. type: string
  7563. type: object
  7564. apiUrl:
  7565. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  7566. type: string
  7567. projectId:
  7568. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  7569. type: string
  7570. region:
  7571. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  7572. type: string
  7573. secretKey:
  7574. description: SecretKey is the non-secret part of the api key.
  7575. properties:
  7576. secretRef:
  7577. description: SecretRef references a key in a secret that will be used as value.
  7578. properties:
  7579. key:
  7580. description: |-
  7581. A key in the referenced Secret.
  7582. Some instances of this field may be defaulted, in others it may be required.
  7583. maxLength: 253
  7584. minLength: 1
  7585. pattern: ^[-._a-zA-Z0-9]+$
  7586. type: string
  7587. name:
  7588. description: The name of the Secret resource being referred to.
  7589. maxLength: 253
  7590. minLength: 1
  7591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7592. type: string
  7593. namespace:
  7594. description: |-
  7595. The namespace of the Secret resource being referred to.
  7596. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7597. maxLength: 63
  7598. minLength: 1
  7599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7600. type: string
  7601. type: object
  7602. value:
  7603. description: Value can be specified directly to set a value without using a secret.
  7604. type: string
  7605. type: object
  7606. required:
  7607. - accessKey
  7608. - projectId
  7609. - region
  7610. - secretKey
  7611. type: object
  7612. secretserver:
  7613. description: |-
  7614. SecretServer configures this store to sync secrets using SecretServer provider
  7615. https://docs.delinea.com/online-help/secret-server/start.htm
  7616. properties:
  7617. caBundle:
  7618. description: |-
  7619. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  7620. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  7621. are used to validate the TLS connection.
  7622. format: byte
  7623. type: string
  7624. caProvider:
  7625. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  7626. properties:
  7627. key:
  7628. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7629. maxLength: 253
  7630. minLength: 1
  7631. pattern: ^[-._a-zA-Z0-9]+$
  7632. type: string
  7633. name:
  7634. description: The name of the object located at the provider type.
  7635. maxLength: 253
  7636. minLength: 1
  7637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7638. type: string
  7639. namespace:
  7640. description: |-
  7641. The namespace the Provider type is in.
  7642. Can only be defined when used in a ClusterSecretStore.
  7643. maxLength: 63
  7644. minLength: 1
  7645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7646. type: string
  7647. type:
  7648. description: The type of provider to use such as "Secret", or "ConfigMap".
  7649. enum:
  7650. - Secret
  7651. - ConfigMap
  7652. type: string
  7653. required:
  7654. - name
  7655. - type
  7656. type: object
  7657. domain:
  7658. description: Domain is the secret server domain.
  7659. type: string
  7660. password:
  7661. description: |-
  7662. Password is the secret server account password.
  7663. Required unless Token is set.
  7664. properties:
  7665. secretRef:
  7666. description: SecretRef references a key in a secret that will be used as value.
  7667. properties:
  7668. key:
  7669. description: |-
  7670. A key in the referenced Secret.
  7671. Some instances of this field may be defaulted, in others it may be required.
  7672. maxLength: 253
  7673. minLength: 1
  7674. pattern: ^[-._a-zA-Z0-9]+$
  7675. type: string
  7676. name:
  7677. description: The name of the Secret resource being referred to.
  7678. maxLength: 253
  7679. minLength: 1
  7680. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7681. type: string
  7682. namespace:
  7683. description: |-
  7684. The namespace of the Secret resource being referred to.
  7685. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7686. maxLength: 63
  7687. minLength: 1
  7688. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7689. type: string
  7690. type: object
  7691. value:
  7692. description: Value can be specified directly to set a value without using a secret.
  7693. minLength: 1
  7694. type: string
  7695. type: object
  7696. x-kubernetes-validations:
  7697. - message: exactly one of value or secretRef must be set
  7698. rule: has(self.value) != has(self.secretRef)
  7699. serverURL:
  7700. description: |-
  7701. ServerURL
  7702. URL to your secret server installation
  7703. type: string
  7704. token:
  7705. description: |-
  7706. Token is an access token used to authenticate to the secret server,
  7707. as an alternative to Username and Password. When set, Username and
  7708. Password are not required and are ignored.
  7709. properties:
  7710. secretRef:
  7711. description: SecretRef references a key in a secret that will be used as value.
  7712. properties:
  7713. key:
  7714. description: |-
  7715. A key in the referenced Secret.
  7716. Some instances of this field may be defaulted, in others it may be required.
  7717. maxLength: 253
  7718. minLength: 1
  7719. pattern: ^[-._a-zA-Z0-9]+$
  7720. type: string
  7721. name:
  7722. description: The name of the Secret resource being referred to.
  7723. maxLength: 253
  7724. minLength: 1
  7725. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7726. type: string
  7727. namespace:
  7728. description: |-
  7729. The namespace of the Secret resource being referred to.
  7730. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7731. maxLength: 63
  7732. minLength: 1
  7733. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7734. type: string
  7735. type: object
  7736. value:
  7737. description: Value can be specified directly to set a value without using a secret.
  7738. minLength: 1
  7739. type: string
  7740. type: object
  7741. x-kubernetes-validations:
  7742. - message: exactly one of value or secretRef must be set
  7743. rule: has(self.value) != has(self.secretRef)
  7744. username:
  7745. description: |-
  7746. Username is the secret server account username.
  7747. Required unless Token is set.
  7748. properties:
  7749. secretRef:
  7750. description: SecretRef references a key in a secret that will be used as value.
  7751. properties:
  7752. key:
  7753. description: |-
  7754. A key in the referenced Secret.
  7755. Some instances of this field may be defaulted, in others it may be required.
  7756. maxLength: 253
  7757. minLength: 1
  7758. pattern: ^[-._a-zA-Z0-9]+$
  7759. type: string
  7760. name:
  7761. description: The name of the Secret resource being referred to.
  7762. maxLength: 253
  7763. minLength: 1
  7764. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7765. type: string
  7766. namespace:
  7767. description: |-
  7768. The namespace of the Secret resource being referred to.
  7769. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7770. maxLength: 63
  7771. minLength: 1
  7772. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7773. type: string
  7774. type: object
  7775. value:
  7776. description: Value can be specified directly to set a value without using a secret.
  7777. minLength: 1
  7778. type: string
  7779. type: object
  7780. x-kubernetes-validations:
  7781. - message: exactly one of value or secretRef must be set
  7782. rule: has(self.value) != has(self.secretRef)
  7783. required:
  7784. - serverURL
  7785. type: object
  7786. x-kubernetes-validations:
  7787. - message: either token, or both username and password, must be set
  7788. rule: has(self.token) || (has(self.username) && has(self.password))
  7789. senhasegura:
  7790. description: Senhasegura configures this store to sync secrets using senhasegura provider
  7791. properties:
  7792. auth:
  7793. description: Auth defines parameters to authenticate in senhasegura
  7794. properties:
  7795. clientId:
  7796. type: string
  7797. clientSecretSecretRef:
  7798. description: |-
  7799. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7800. In some instances, `key` is a required field.
  7801. properties:
  7802. key:
  7803. description: |-
  7804. A key in the referenced Secret.
  7805. Some instances of this field may be defaulted, in others it may be required.
  7806. maxLength: 253
  7807. minLength: 1
  7808. pattern: ^[-._a-zA-Z0-9]+$
  7809. type: string
  7810. name:
  7811. description: The name of the Secret resource being referred to.
  7812. maxLength: 253
  7813. minLength: 1
  7814. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7815. type: string
  7816. namespace:
  7817. description: |-
  7818. The namespace of the Secret resource being referred to.
  7819. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7820. maxLength: 63
  7821. minLength: 1
  7822. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7823. type: string
  7824. type: object
  7825. required:
  7826. - clientId
  7827. - clientSecretSecretRef
  7828. type: object
  7829. ignoreSslCertificate:
  7830. default: false
  7831. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  7832. type: boolean
  7833. module:
  7834. description: Module defines which senhasegura module should be used to get secrets
  7835. type: string
  7836. url:
  7837. description: URL of senhasegura
  7838. type: string
  7839. required:
  7840. - auth
  7841. - module
  7842. - url
  7843. type: object
  7844. vault:
  7845. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  7846. properties:
  7847. auth:
  7848. description: Auth configures how secret-manager authenticates with the Vault server.
  7849. properties:
  7850. appRole:
  7851. description: |-
  7852. AppRole authenticates with Vault using the App Role auth mechanism,
  7853. with the role and secret stored in a Kubernetes Secret resource.
  7854. properties:
  7855. path:
  7856. default: approle
  7857. description: |-
  7858. Path where the App Role authentication backend is mounted
  7859. in Vault, e.g: "approle"
  7860. type: string
  7861. roleId:
  7862. description: |-
  7863. RoleID configured in the App Role authentication backend when setting
  7864. up the authentication backend in Vault.
  7865. type: string
  7866. roleRef:
  7867. description: |-
  7868. Reference to a key in a Secret that contains the App Role ID used
  7869. to authenticate with Vault.
  7870. The `key` field must be specified and denotes which entry within the Secret
  7871. resource is used as the app role id.
  7872. properties:
  7873. key:
  7874. description: |-
  7875. A key in the referenced Secret.
  7876. Some instances of this field may be defaulted, in others it may be required.
  7877. maxLength: 253
  7878. minLength: 1
  7879. pattern: ^[-._a-zA-Z0-9]+$
  7880. type: string
  7881. name:
  7882. description: The name of the Secret resource being referred to.
  7883. maxLength: 253
  7884. minLength: 1
  7885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7886. type: string
  7887. namespace:
  7888. description: |-
  7889. The namespace of the Secret resource being referred to.
  7890. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7891. maxLength: 63
  7892. minLength: 1
  7893. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7894. type: string
  7895. type: object
  7896. secretRef:
  7897. description: |-
  7898. Reference to a key in a Secret that contains the App Role secret used
  7899. to authenticate with Vault.
  7900. The `key` field must be specified and denotes which entry within the Secret
  7901. resource is used as the app role secret.
  7902. properties:
  7903. key:
  7904. description: |-
  7905. A key in the referenced Secret.
  7906. Some instances of this field may be defaulted, in others it may be required.
  7907. maxLength: 253
  7908. minLength: 1
  7909. pattern: ^[-._a-zA-Z0-9]+$
  7910. type: string
  7911. name:
  7912. description: The name of the Secret resource being referred to.
  7913. maxLength: 253
  7914. minLength: 1
  7915. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7916. type: string
  7917. namespace:
  7918. description: |-
  7919. The namespace of the Secret resource being referred to.
  7920. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7921. maxLength: 63
  7922. minLength: 1
  7923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7924. type: string
  7925. type: object
  7926. required:
  7927. - path
  7928. - secretRef
  7929. type: object
  7930. cert:
  7931. description: |-
  7932. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  7933. Cert authentication method
  7934. properties:
  7935. clientCert:
  7936. description: |-
  7937. ClientCert is a certificate to authenticate using the Cert Vault
  7938. authentication method
  7939. properties:
  7940. key:
  7941. description: |-
  7942. A key in the referenced Secret.
  7943. Some instances of this field may be defaulted, in others it may be required.
  7944. maxLength: 253
  7945. minLength: 1
  7946. pattern: ^[-._a-zA-Z0-9]+$
  7947. type: string
  7948. name:
  7949. description: The name of the Secret resource being referred to.
  7950. maxLength: 253
  7951. minLength: 1
  7952. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7953. type: string
  7954. namespace:
  7955. description: |-
  7956. The namespace of the Secret resource being referred to.
  7957. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7958. maxLength: 63
  7959. minLength: 1
  7960. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7961. type: string
  7962. type: object
  7963. path:
  7964. default: cert
  7965. description: |-
  7966. Path where the Certificate authentication backend is mounted
  7967. in Vault, e.g: "cert"
  7968. type: string
  7969. secretRef:
  7970. description: |-
  7971. SecretRef to a key in a Secret resource containing client private key to
  7972. authenticate with Vault using the Cert authentication method
  7973. properties:
  7974. key:
  7975. description: |-
  7976. A key in the referenced Secret.
  7977. Some instances of this field may be defaulted, in others it may be required.
  7978. maxLength: 253
  7979. minLength: 1
  7980. pattern: ^[-._a-zA-Z0-9]+$
  7981. type: string
  7982. name:
  7983. description: The name of the Secret resource being referred to.
  7984. maxLength: 253
  7985. minLength: 1
  7986. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7987. type: string
  7988. namespace:
  7989. description: |-
  7990. The namespace of the Secret resource being referred to.
  7991. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7992. maxLength: 63
  7993. minLength: 1
  7994. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7995. type: string
  7996. type: object
  7997. vaultRole:
  7998. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  7999. type: string
  8000. type: object
  8001. gcp:
  8002. description: |-
  8003. Gcp authenticates with Vault using Google Cloud Platform authentication method
  8004. GCP authentication method
  8005. properties:
  8006. location:
  8007. description: Location optionally defines a location/region for the secret
  8008. type: string
  8009. path:
  8010. default: gcp
  8011. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  8012. type: string
  8013. projectID:
  8014. description: Project ID of the Google Cloud Platform project
  8015. type: string
  8016. role:
  8017. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  8018. type: string
  8019. secretRef:
  8020. description: Specify credentials in a Secret object
  8021. properties:
  8022. secretAccessKeySecretRef:
  8023. description: The SecretAccessKey is used for authentication
  8024. properties:
  8025. key:
  8026. description: |-
  8027. A key in the referenced Secret.
  8028. Some instances of this field may be defaulted, in others it may be required.
  8029. maxLength: 253
  8030. minLength: 1
  8031. pattern: ^[-._a-zA-Z0-9]+$
  8032. type: string
  8033. name:
  8034. description: The name of the Secret resource being referred to.
  8035. maxLength: 253
  8036. minLength: 1
  8037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8038. type: string
  8039. namespace:
  8040. description: |-
  8041. The namespace of the Secret resource being referred to.
  8042. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8043. maxLength: 63
  8044. minLength: 1
  8045. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8046. type: string
  8047. type: object
  8048. type: object
  8049. serviceAccountRef:
  8050. description: ServiceAccountRef to a service account for impersonation
  8051. properties:
  8052. audiences:
  8053. description: |-
  8054. Audience specifies the `aud` claim for the service account token
  8055. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8056. then this audiences will be appended to the list
  8057. items:
  8058. type: string
  8059. type: array
  8060. name:
  8061. description: The name of the ServiceAccount resource being referred to.
  8062. maxLength: 253
  8063. minLength: 1
  8064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8065. type: string
  8066. namespace:
  8067. description: |-
  8068. Namespace of the resource being referred to.
  8069. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8070. maxLength: 63
  8071. minLength: 1
  8072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8073. type: string
  8074. required:
  8075. - name
  8076. type: object
  8077. workloadIdentity:
  8078. description: Specify a service account with Workload Identity
  8079. properties:
  8080. clusterLocation:
  8081. description: |-
  8082. ClusterLocation is the location of the cluster
  8083. If not specified, it fetches information from the metadata server
  8084. type: string
  8085. clusterName:
  8086. description: |-
  8087. ClusterName is the name of the cluster
  8088. If not specified, it fetches information from the metadata server
  8089. type: string
  8090. clusterProjectID:
  8091. description: |-
  8092. ClusterProjectID is the project ID of the cluster
  8093. If not specified, it fetches information from the metadata server
  8094. type: string
  8095. serviceAccountRef:
  8096. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  8097. properties:
  8098. audiences:
  8099. description: |-
  8100. Audience specifies the `aud` claim for the service account token
  8101. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8102. then this audiences will be appended to the list
  8103. items:
  8104. type: string
  8105. type: array
  8106. name:
  8107. description: The name of the ServiceAccount resource being referred to.
  8108. maxLength: 253
  8109. minLength: 1
  8110. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8111. type: string
  8112. namespace:
  8113. description: |-
  8114. Namespace of the resource being referred to.
  8115. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8116. maxLength: 63
  8117. minLength: 1
  8118. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8119. type: string
  8120. required:
  8121. - name
  8122. type: object
  8123. required:
  8124. - serviceAccountRef
  8125. type: object
  8126. required:
  8127. - role
  8128. type: object
  8129. iam:
  8130. description: |-
  8131. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  8132. AWS IAM authentication method
  8133. properties:
  8134. externalID:
  8135. description: AWS External ID set on assumed IAM roles
  8136. type: string
  8137. jwt:
  8138. description: Specify a service account with IRSA enabled
  8139. properties:
  8140. serviceAccountRef:
  8141. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  8142. properties:
  8143. audiences:
  8144. description: |-
  8145. Audience specifies the `aud` claim for the service account token
  8146. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8147. then this audiences will be appended to the list
  8148. items:
  8149. type: string
  8150. type: array
  8151. name:
  8152. description: The name of the ServiceAccount resource being referred to.
  8153. maxLength: 253
  8154. minLength: 1
  8155. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8156. type: string
  8157. namespace:
  8158. description: |-
  8159. Namespace of the resource being referred to.
  8160. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8161. maxLength: 63
  8162. minLength: 1
  8163. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8164. type: string
  8165. required:
  8166. - name
  8167. type: object
  8168. type: object
  8169. path:
  8170. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  8171. type: string
  8172. region:
  8173. description: AWS region
  8174. type: string
  8175. role:
  8176. description: This is the AWS role to be assumed before talking to vault
  8177. type: string
  8178. secretRef:
  8179. description: Specify credentials in a Secret object
  8180. properties:
  8181. accessKeyIDSecretRef:
  8182. description: The AccessKeyID is used for authentication
  8183. properties:
  8184. key:
  8185. description: |-
  8186. A key in the referenced Secret.
  8187. Some instances of this field may be defaulted, in others it may be required.
  8188. maxLength: 253
  8189. minLength: 1
  8190. pattern: ^[-._a-zA-Z0-9]+$
  8191. type: string
  8192. name:
  8193. description: The name of the Secret resource being referred to.
  8194. maxLength: 253
  8195. minLength: 1
  8196. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8197. type: string
  8198. namespace:
  8199. description: |-
  8200. The namespace of the Secret resource being referred to.
  8201. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8202. maxLength: 63
  8203. minLength: 1
  8204. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8205. type: string
  8206. type: object
  8207. secretAccessKeySecretRef:
  8208. description: The SecretAccessKey is used for authentication
  8209. properties:
  8210. key:
  8211. description: |-
  8212. A key in the referenced Secret.
  8213. Some instances of this field may be defaulted, in others it may be required.
  8214. maxLength: 253
  8215. minLength: 1
  8216. pattern: ^[-._a-zA-Z0-9]+$
  8217. type: string
  8218. name:
  8219. description: The name of the Secret resource being referred to.
  8220. maxLength: 253
  8221. minLength: 1
  8222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8223. type: string
  8224. namespace:
  8225. description: |-
  8226. The namespace of the Secret resource being referred to.
  8227. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8228. maxLength: 63
  8229. minLength: 1
  8230. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8231. type: string
  8232. type: object
  8233. sessionTokenSecretRef:
  8234. description: |-
  8235. The SessionToken used for authentication
  8236. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  8237. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  8238. properties:
  8239. key:
  8240. description: |-
  8241. A key in the referenced Secret.
  8242. Some instances of this field may be defaulted, in others it may be required.
  8243. maxLength: 253
  8244. minLength: 1
  8245. pattern: ^[-._a-zA-Z0-9]+$
  8246. type: string
  8247. name:
  8248. description: The name of the Secret resource being referred to.
  8249. maxLength: 253
  8250. minLength: 1
  8251. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8252. type: string
  8253. namespace:
  8254. description: |-
  8255. The namespace of the Secret resource being referred to.
  8256. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8257. maxLength: 63
  8258. minLength: 1
  8259. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8260. type: string
  8261. type: object
  8262. type: object
  8263. vaultAwsIamServerID:
  8264. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  8265. type: string
  8266. vaultRole:
  8267. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  8268. type: string
  8269. required:
  8270. - vaultRole
  8271. type: object
  8272. jwt:
  8273. description: |-
  8274. Jwt authenticates with Vault by passing role and JWT token using the
  8275. JWT/OIDC authentication method
  8276. properties:
  8277. kubernetesServiceAccountToken:
  8278. description: |-
  8279. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  8280. a token for with the `TokenRequest` API.
  8281. properties:
  8282. audiences:
  8283. description: |-
  8284. Optional audiences field that will be used to request a temporary Kubernetes service
  8285. account token for the service account referenced by `serviceAccountRef`.
  8286. Defaults to a single audience `vault` it not specified.
  8287. Deprecated: use serviceAccountRef.Audiences instead
  8288. items:
  8289. type: string
  8290. type: array
  8291. expirationSeconds:
  8292. description: |-
  8293. Optional expiration time in seconds that will be used to request a temporary
  8294. Kubernetes service account token for the service account referenced by
  8295. `serviceAccountRef`.
  8296. Deprecated: this will be removed in the future.
  8297. Defaults to 10 minutes.
  8298. format: int64
  8299. type: integer
  8300. serviceAccountRef:
  8301. description: Service account field containing the name of a kubernetes ServiceAccount.
  8302. properties:
  8303. audiences:
  8304. description: |-
  8305. Audience specifies the `aud` claim for the service account token
  8306. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8307. then this audiences will be appended to the list
  8308. items:
  8309. type: string
  8310. type: array
  8311. name:
  8312. description: The name of the ServiceAccount resource being referred to.
  8313. maxLength: 253
  8314. minLength: 1
  8315. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8316. type: string
  8317. namespace:
  8318. description: |-
  8319. Namespace of the resource being referred to.
  8320. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8321. maxLength: 63
  8322. minLength: 1
  8323. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8324. type: string
  8325. required:
  8326. - name
  8327. type: object
  8328. required:
  8329. - serviceAccountRef
  8330. type: object
  8331. path:
  8332. default: jwt
  8333. description: |-
  8334. Path where the JWT authentication backend is mounted
  8335. in Vault, e.g: "jwt"
  8336. type: string
  8337. role:
  8338. description: |-
  8339. Role is a JWT role to authenticate using the JWT/OIDC Vault
  8340. authentication method
  8341. type: string
  8342. secretRef:
  8343. description: |-
  8344. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  8345. authenticate with Vault using the JWT/OIDC authentication method.
  8346. properties:
  8347. key:
  8348. description: |-
  8349. A key in the referenced Secret.
  8350. Some instances of this field may be defaulted, in others it may be required.
  8351. maxLength: 253
  8352. minLength: 1
  8353. pattern: ^[-._a-zA-Z0-9]+$
  8354. type: string
  8355. name:
  8356. description: The name of the Secret resource being referred to.
  8357. maxLength: 253
  8358. minLength: 1
  8359. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8360. type: string
  8361. namespace:
  8362. description: |-
  8363. The namespace of the Secret resource being referred to.
  8364. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8365. maxLength: 63
  8366. minLength: 1
  8367. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8368. type: string
  8369. type: object
  8370. required:
  8371. - path
  8372. type: object
  8373. kubernetes:
  8374. description: |-
  8375. Kubernetes authenticates with Vault by passing the ServiceAccount
  8376. token stored in the named Secret resource to the Vault server.
  8377. properties:
  8378. mountPath:
  8379. default: kubernetes
  8380. description: |-
  8381. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  8382. "kubernetes"
  8383. type: string
  8384. role:
  8385. description: |-
  8386. A required field containing the Vault Role to assume. A Role binds a
  8387. Kubernetes ServiceAccount with a set of Vault policies.
  8388. type: string
  8389. secretRef:
  8390. description: |-
  8391. Optional secret field containing a Kubernetes ServiceAccount JWT used
  8392. for authenticating with Vault. If a name is specified without a key,
  8393. `token` is the default. If one is not specified, the one bound to
  8394. the controller will be used.
  8395. properties:
  8396. key:
  8397. description: |-
  8398. A key in the referenced Secret.
  8399. Some instances of this field may be defaulted, in others it may be required.
  8400. maxLength: 253
  8401. minLength: 1
  8402. pattern: ^[-._a-zA-Z0-9]+$
  8403. type: string
  8404. name:
  8405. description: The name of the Secret resource being referred to.
  8406. maxLength: 253
  8407. minLength: 1
  8408. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8409. type: string
  8410. namespace:
  8411. description: |-
  8412. The namespace of the Secret resource being referred to.
  8413. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8414. maxLength: 63
  8415. minLength: 1
  8416. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8417. type: string
  8418. type: object
  8419. serviceAccountRef:
  8420. description: |-
  8421. Optional service account field containing the name of a kubernetes ServiceAccount.
  8422. If the service account is specified, the service account secret token JWT will be used
  8423. for authenticating with Vault. If the service account selector is not supplied,
  8424. the secretRef will be used instead.
  8425. properties:
  8426. audiences:
  8427. description: |-
  8428. Audience specifies the `aud` claim for the service account token
  8429. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8430. then this audiences will be appended to the list
  8431. items:
  8432. type: string
  8433. type: array
  8434. name:
  8435. description: The name of the ServiceAccount resource being referred to.
  8436. maxLength: 253
  8437. minLength: 1
  8438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8439. type: string
  8440. namespace:
  8441. description: |-
  8442. Namespace of the resource being referred to.
  8443. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8444. maxLength: 63
  8445. minLength: 1
  8446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8447. type: string
  8448. required:
  8449. - name
  8450. type: object
  8451. required:
  8452. - mountPath
  8453. - role
  8454. type: object
  8455. ldap:
  8456. description: |-
  8457. Ldap authenticates with Vault by passing username/password pair using
  8458. the LDAP authentication method
  8459. properties:
  8460. path:
  8461. default: ldap
  8462. description: |-
  8463. Path where the LDAP authentication backend is mounted
  8464. in Vault, e.g: "ldap"
  8465. type: string
  8466. secretRef:
  8467. description: |-
  8468. SecretRef to a key in a Secret resource containing password for the LDAP
  8469. user used to authenticate with Vault using the LDAP authentication
  8470. method
  8471. properties:
  8472. key:
  8473. description: |-
  8474. A key in the referenced Secret.
  8475. Some instances of this field may be defaulted, in others it may be required.
  8476. maxLength: 253
  8477. minLength: 1
  8478. pattern: ^[-._a-zA-Z0-9]+$
  8479. type: string
  8480. name:
  8481. description: The name of the Secret resource being referred to.
  8482. maxLength: 253
  8483. minLength: 1
  8484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8485. type: string
  8486. namespace:
  8487. description: |-
  8488. The namespace of the Secret resource being referred to.
  8489. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8490. maxLength: 63
  8491. minLength: 1
  8492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8493. type: string
  8494. type: object
  8495. username:
  8496. description: |-
  8497. Username is an LDAP username used to authenticate using the LDAP Vault
  8498. authentication method
  8499. type: string
  8500. required:
  8501. - path
  8502. - username
  8503. type: object
  8504. namespace:
  8505. description: |-
  8506. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  8507. Namespaces is a set of features within Vault Enterprise that allows
  8508. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8509. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8510. This will default to Vault.Namespace field if set, or empty otherwise
  8511. type: string
  8512. tokenSecretRef:
  8513. description: TokenSecretRef authenticates with Vault by presenting a token.
  8514. properties:
  8515. key:
  8516. description: |-
  8517. A key in the referenced Secret.
  8518. Some instances of this field may be defaulted, in others it may be required.
  8519. maxLength: 253
  8520. minLength: 1
  8521. pattern: ^[-._a-zA-Z0-9]+$
  8522. type: string
  8523. name:
  8524. description: The name of the Secret resource being referred to.
  8525. maxLength: 253
  8526. minLength: 1
  8527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8528. type: string
  8529. namespace:
  8530. description: |-
  8531. The namespace of the Secret resource being referred to.
  8532. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8533. maxLength: 63
  8534. minLength: 1
  8535. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8536. type: string
  8537. type: object
  8538. userPass:
  8539. description: UserPass authenticates with Vault by passing username/password pair
  8540. properties:
  8541. path:
  8542. default: userpass
  8543. description: |-
  8544. Path where the UserPassword authentication backend is mounted
  8545. in Vault, e.g: "userpass"
  8546. type: string
  8547. secretRef:
  8548. description: |-
  8549. SecretRef to a key in a Secret resource containing password for the
  8550. user used to authenticate with Vault using the UserPass authentication
  8551. method
  8552. properties:
  8553. key:
  8554. description: |-
  8555. A key in the referenced Secret.
  8556. Some instances of this field may be defaulted, in others it may be required.
  8557. maxLength: 253
  8558. minLength: 1
  8559. pattern: ^[-._a-zA-Z0-9]+$
  8560. type: string
  8561. name:
  8562. description: The name of the Secret resource being referred to.
  8563. maxLength: 253
  8564. minLength: 1
  8565. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8566. type: string
  8567. namespace:
  8568. description: |-
  8569. The namespace of the Secret resource being referred to.
  8570. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8571. maxLength: 63
  8572. minLength: 1
  8573. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8574. type: string
  8575. type: object
  8576. username:
  8577. description: |-
  8578. Username is a username used to authenticate using the UserPass Vault
  8579. authentication method
  8580. type: string
  8581. required:
  8582. - path
  8583. - username
  8584. type: object
  8585. type: object
  8586. caBundle:
  8587. description: |-
  8588. PEM encoded CA bundle used to validate Vault server certificate. Only used
  8589. if the Server URL is using HTTPS protocol. This parameter is ignored for
  8590. plain HTTP protocol connection. If not set the system root certificates
  8591. are used to validate the TLS connection.
  8592. format: byte
  8593. type: string
  8594. caProvider:
  8595. description: The provider for the CA bundle to use to validate Vault server certificate.
  8596. properties:
  8597. key:
  8598. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8599. maxLength: 253
  8600. minLength: 1
  8601. pattern: ^[-._a-zA-Z0-9]+$
  8602. type: string
  8603. name:
  8604. description: The name of the object located at the provider type.
  8605. maxLength: 253
  8606. minLength: 1
  8607. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8608. type: string
  8609. namespace:
  8610. description: |-
  8611. The namespace the Provider type is in.
  8612. Can only be defined when used in a ClusterSecretStore.
  8613. maxLength: 63
  8614. minLength: 1
  8615. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8616. type: string
  8617. type:
  8618. description: The type of provider to use such as "Secret", or "ConfigMap".
  8619. enum:
  8620. - Secret
  8621. - ConfigMap
  8622. type: string
  8623. required:
  8624. - name
  8625. - type
  8626. type: object
  8627. checkAndSet:
  8628. description: |-
  8629. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  8630. Only applies to Vault KV v2 stores. When enabled, write operations must include
  8631. the current version of the secret to prevent unintentional overwrites.
  8632. properties:
  8633. required:
  8634. description: |-
  8635. Required when true, all write operations must include a check-and-set parameter.
  8636. This helps prevent unintentional overwrites of secrets.
  8637. type: boolean
  8638. type: object
  8639. forwardInconsistent:
  8640. description: |-
  8641. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  8642. leader instead of simply retrying within a loop. This can increase performance if
  8643. the option is enabled serverside.
  8644. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  8645. type: boolean
  8646. headers:
  8647. additionalProperties:
  8648. type: string
  8649. description: Headers to be added in Vault request
  8650. type: object
  8651. namespace:
  8652. description: |-
  8653. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  8654. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8655. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8656. type: string
  8657. path:
  8658. description: |-
  8659. Path is the mount path of the Vault KV backend endpoint, e.g:
  8660. "secret". The v2 KV secret engine version specific "/data" path suffix
  8661. for fetching secrets from Vault is optional and will be appended
  8662. if not present in specified path.
  8663. type: string
  8664. readYourWrites:
  8665. description: |-
  8666. ReadYourWrites ensures isolated read-after-write semantics by
  8667. providing discovered cluster replication states in each request.
  8668. More information about eventual consistency in Vault can be found here
  8669. https://www.vaultproject.io/docs/enterprise/consistency
  8670. type: boolean
  8671. server:
  8672. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  8673. type: string
  8674. tls:
  8675. description: |-
  8676. The configuration used for client side related TLS communication, when the Vault server
  8677. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  8678. This parameter is ignored for plain HTTP protocol connection.
  8679. It's worth noting this configuration is different from the "TLS certificates auth method",
  8680. which is available under the `auth.cert` section.
  8681. properties:
  8682. certSecretRef:
  8683. description: |-
  8684. CertSecretRef is a certificate added to the transport layer
  8685. when communicating with the Vault server.
  8686. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  8687. properties:
  8688. key:
  8689. description: |-
  8690. A key in the referenced Secret.
  8691. Some instances of this field may be defaulted, in others it may be required.
  8692. maxLength: 253
  8693. minLength: 1
  8694. pattern: ^[-._a-zA-Z0-9]+$
  8695. type: string
  8696. name:
  8697. description: The name of the Secret resource being referred to.
  8698. maxLength: 253
  8699. minLength: 1
  8700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8701. type: string
  8702. namespace:
  8703. description: |-
  8704. The namespace of the Secret resource being referred to.
  8705. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8706. maxLength: 63
  8707. minLength: 1
  8708. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8709. type: string
  8710. type: object
  8711. keySecretRef:
  8712. description: |-
  8713. KeySecretRef to a key in a Secret resource containing client private key
  8714. added to the transport layer when communicating with the Vault server.
  8715. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  8716. properties:
  8717. key:
  8718. description: |-
  8719. A key in the referenced Secret.
  8720. Some instances of this field may be defaulted, in others it may be required.
  8721. maxLength: 253
  8722. minLength: 1
  8723. pattern: ^[-._a-zA-Z0-9]+$
  8724. type: string
  8725. name:
  8726. description: The name of the Secret resource being referred to.
  8727. maxLength: 253
  8728. minLength: 1
  8729. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8730. type: string
  8731. namespace:
  8732. description: |-
  8733. The namespace of the Secret resource being referred to.
  8734. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8735. maxLength: 63
  8736. minLength: 1
  8737. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8738. type: string
  8739. type: object
  8740. type: object
  8741. version:
  8742. default: v2
  8743. description: |-
  8744. Version is the Vault KV secret engine version. This can be either "v1" or
  8745. "v2". Version defaults to "v2".
  8746. enum:
  8747. - v1
  8748. - v2
  8749. type: string
  8750. required:
  8751. - server
  8752. type: object
  8753. volcengine:
  8754. description: Volcengine configures this store to sync secrets using the Volcengine provider
  8755. properties:
  8756. auth:
  8757. description: |-
  8758. Auth defines the authentication method to use.
  8759. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  8760. properties:
  8761. secretRef:
  8762. description: |-
  8763. SecretRef defines the static credentials to use for authentication.
  8764. If not set, IRSA is used.
  8765. properties:
  8766. accessKeyID:
  8767. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  8768. properties:
  8769. key:
  8770. description: |-
  8771. A key in the referenced Secret.
  8772. Some instances of this field may be defaulted, in others it may be required.
  8773. maxLength: 253
  8774. minLength: 1
  8775. pattern: ^[-._a-zA-Z0-9]+$
  8776. type: string
  8777. name:
  8778. description: The name of the Secret resource being referred to.
  8779. maxLength: 253
  8780. minLength: 1
  8781. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8782. type: string
  8783. namespace:
  8784. description: |-
  8785. The namespace of the Secret resource being referred to.
  8786. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8787. maxLength: 63
  8788. minLength: 1
  8789. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8790. type: string
  8791. type: object
  8792. secretAccessKey:
  8793. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  8794. properties:
  8795. key:
  8796. description: |-
  8797. A key in the referenced Secret.
  8798. Some instances of this field may be defaulted, in others it may be required.
  8799. maxLength: 253
  8800. minLength: 1
  8801. pattern: ^[-._a-zA-Z0-9]+$
  8802. type: string
  8803. name:
  8804. description: The name of the Secret resource being referred to.
  8805. maxLength: 253
  8806. minLength: 1
  8807. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8808. type: string
  8809. namespace:
  8810. description: |-
  8811. The namespace of the Secret resource being referred to.
  8812. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8813. maxLength: 63
  8814. minLength: 1
  8815. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8816. type: string
  8817. type: object
  8818. token:
  8819. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  8820. properties:
  8821. key:
  8822. description: |-
  8823. A key in the referenced Secret.
  8824. Some instances of this field may be defaulted, in others it may be required.
  8825. maxLength: 253
  8826. minLength: 1
  8827. pattern: ^[-._a-zA-Z0-9]+$
  8828. type: string
  8829. name:
  8830. description: The name of the Secret resource being referred to.
  8831. maxLength: 253
  8832. minLength: 1
  8833. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8834. type: string
  8835. namespace:
  8836. description: |-
  8837. The namespace of the Secret resource being referred to.
  8838. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8839. maxLength: 63
  8840. minLength: 1
  8841. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8842. type: string
  8843. type: object
  8844. required:
  8845. - accessKeyID
  8846. - secretAccessKey
  8847. type: object
  8848. type: object
  8849. region:
  8850. description: Region specifies the Volcengine region to connect to.
  8851. type: string
  8852. required:
  8853. - region
  8854. type: object
  8855. webhook:
  8856. description: Webhook configures this store to sync secrets using a generic templated webhook
  8857. properties:
  8858. auth:
  8859. description: Auth specifies a authorization protocol. Only one protocol may be set.
  8860. maxProperties: 1
  8861. minProperties: 1
  8862. properties:
  8863. ntlm:
  8864. description: NTLMProtocol configures the store to use NTLM for auth
  8865. properties:
  8866. passwordSecret:
  8867. description: |-
  8868. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8869. In some instances, `key` is a required field.
  8870. properties:
  8871. key:
  8872. description: |-
  8873. A key in the referenced Secret.
  8874. Some instances of this field may be defaulted, in others it may be required.
  8875. maxLength: 253
  8876. minLength: 1
  8877. pattern: ^[-._a-zA-Z0-9]+$
  8878. type: string
  8879. name:
  8880. description: The name of the Secret resource being referred to.
  8881. maxLength: 253
  8882. minLength: 1
  8883. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8884. type: string
  8885. namespace:
  8886. description: |-
  8887. The namespace of the Secret resource being referred to.
  8888. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8889. maxLength: 63
  8890. minLength: 1
  8891. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8892. type: string
  8893. type: object
  8894. usernameSecret:
  8895. description: |-
  8896. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8897. In some instances, `key` is a required field.
  8898. properties:
  8899. key:
  8900. description: |-
  8901. A key in the referenced Secret.
  8902. Some instances of this field may be defaulted, in others it may be required.
  8903. maxLength: 253
  8904. minLength: 1
  8905. pattern: ^[-._a-zA-Z0-9]+$
  8906. type: string
  8907. name:
  8908. description: The name of the Secret resource being referred to.
  8909. maxLength: 253
  8910. minLength: 1
  8911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8912. type: string
  8913. namespace:
  8914. description: |-
  8915. The namespace of the Secret resource being referred to.
  8916. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8917. maxLength: 63
  8918. minLength: 1
  8919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8920. type: string
  8921. type: object
  8922. required:
  8923. - passwordSecret
  8924. - usernameSecret
  8925. type: object
  8926. type: object
  8927. body:
  8928. description: Body
  8929. type: string
  8930. caBundle:
  8931. description: |-
  8932. PEM encoded CA bundle used to validate webhook server certificate. Only used
  8933. if the Server URL is using HTTPS protocol. This parameter is ignored for
  8934. plain HTTP protocol connection. If not set the system root certificates
  8935. are used to validate the TLS connection.
  8936. format: byte
  8937. type: string
  8938. caProvider:
  8939. description: The provider for the CA bundle to use to validate webhook server certificate.
  8940. properties:
  8941. key:
  8942. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8943. maxLength: 253
  8944. minLength: 1
  8945. pattern: ^[-._a-zA-Z0-9]+$
  8946. type: string
  8947. name:
  8948. description: The name of the object located at the provider type.
  8949. maxLength: 253
  8950. minLength: 1
  8951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8952. type: string
  8953. namespace:
  8954. description: The namespace the Provider type is in.
  8955. maxLength: 63
  8956. minLength: 1
  8957. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8958. type: string
  8959. type:
  8960. description: The type of provider to use such as "Secret", or "ConfigMap".
  8961. enum:
  8962. - Secret
  8963. - ConfigMap
  8964. type: string
  8965. required:
  8966. - name
  8967. - type
  8968. type: object
  8969. headers:
  8970. additionalProperties:
  8971. type: string
  8972. description: Headers
  8973. type: object
  8974. method:
  8975. description: Webhook Method
  8976. type: string
  8977. result:
  8978. description: Result formatting
  8979. properties:
  8980. jsonPath:
  8981. description: Json path of return value
  8982. type: string
  8983. type: object
  8984. secrets:
  8985. description: |-
  8986. Secrets to fill in templates
  8987. These secrets will be passed to the templating function as key value pairs under the given name
  8988. items:
  8989. description: WebhookSecret defines a secret that will be passed to the webhook request.
  8990. properties:
  8991. name:
  8992. description: Name of this secret in templates
  8993. type: string
  8994. secretRef:
  8995. description: Secret ref to fill in credentials
  8996. properties:
  8997. key:
  8998. description: |-
  8999. A key in the referenced Secret.
  9000. Some instances of this field may be defaulted, in others it may be required.
  9001. maxLength: 253
  9002. minLength: 1
  9003. pattern: ^[-._a-zA-Z0-9]+$
  9004. type: string
  9005. name:
  9006. description: The name of the Secret resource being referred to.
  9007. maxLength: 253
  9008. minLength: 1
  9009. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9010. type: string
  9011. namespace:
  9012. description: |-
  9013. The namespace of the Secret resource being referred to.
  9014. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9015. maxLength: 63
  9016. minLength: 1
  9017. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9018. type: string
  9019. type: object
  9020. required:
  9021. - name
  9022. - secretRef
  9023. type: object
  9024. type: array
  9025. timeout:
  9026. description: Timeout
  9027. type: string
  9028. url:
  9029. description: Webhook url to call
  9030. type: string
  9031. required:
  9032. - url
  9033. type: object
  9034. yandexcertificatemanager:
  9035. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  9036. properties:
  9037. apiEndpoint:
  9038. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9039. type: string
  9040. auth:
  9041. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  9042. properties:
  9043. authorizedKeySecretRef:
  9044. description: The authorized key used for authentication
  9045. properties:
  9046. key:
  9047. description: |-
  9048. A key in the referenced Secret.
  9049. Some instances of this field may be defaulted, in others it may be required.
  9050. maxLength: 253
  9051. minLength: 1
  9052. pattern: ^[-._a-zA-Z0-9]+$
  9053. type: string
  9054. name:
  9055. description: The name of the Secret resource being referred to.
  9056. maxLength: 253
  9057. minLength: 1
  9058. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9059. type: string
  9060. namespace:
  9061. description: |-
  9062. The namespace of the Secret resource being referred to.
  9063. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9064. maxLength: 63
  9065. minLength: 1
  9066. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9067. type: string
  9068. type: object
  9069. type: object
  9070. caProvider:
  9071. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9072. properties:
  9073. certSecretRef:
  9074. description: |-
  9075. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9076. In some instances, `key` is a required field.
  9077. properties:
  9078. key:
  9079. description: |-
  9080. A key in the referenced Secret.
  9081. Some instances of this field may be defaulted, in others it may be required.
  9082. maxLength: 253
  9083. minLength: 1
  9084. pattern: ^[-._a-zA-Z0-9]+$
  9085. type: string
  9086. name:
  9087. description: The name of the Secret resource being referred to.
  9088. maxLength: 253
  9089. minLength: 1
  9090. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9091. type: string
  9092. namespace:
  9093. description: |-
  9094. The namespace of the Secret resource being referred to.
  9095. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9096. maxLength: 63
  9097. minLength: 1
  9098. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9099. type: string
  9100. type: object
  9101. type: object
  9102. fetching:
  9103. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  9104. maxProperties: 1
  9105. minProperties: 1
  9106. properties:
  9107. byID:
  9108. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  9109. type: object
  9110. byName:
  9111. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  9112. properties:
  9113. folderID:
  9114. description: The folder to fetch secrets from
  9115. type: string
  9116. required:
  9117. - folderID
  9118. type: object
  9119. type: object
  9120. required:
  9121. - auth
  9122. type: object
  9123. yandexlockbox:
  9124. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  9125. properties:
  9126. apiEndpoint:
  9127. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9128. type: string
  9129. auth:
  9130. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  9131. properties:
  9132. authorizedKeySecretRef:
  9133. description: The authorized key used for authentication
  9134. properties:
  9135. key:
  9136. description: |-
  9137. A key in the referenced Secret.
  9138. Some instances of this field may be defaulted, in others it may be required.
  9139. maxLength: 253
  9140. minLength: 1
  9141. pattern: ^[-._a-zA-Z0-9]+$
  9142. type: string
  9143. name:
  9144. description: The name of the Secret resource being referred to.
  9145. maxLength: 253
  9146. minLength: 1
  9147. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9148. type: string
  9149. namespace:
  9150. description: |-
  9151. The namespace of the Secret resource being referred to.
  9152. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9153. maxLength: 63
  9154. minLength: 1
  9155. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9156. type: string
  9157. type: object
  9158. type: object
  9159. caProvider:
  9160. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9161. properties:
  9162. certSecretRef:
  9163. description: |-
  9164. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9165. In some instances, `key` is a required field.
  9166. properties:
  9167. key:
  9168. description: |-
  9169. A key in the referenced Secret.
  9170. Some instances of this field may be defaulted, in others it may be required.
  9171. maxLength: 253
  9172. minLength: 1
  9173. pattern: ^[-._a-zA-Z0-9]+$
  9174. type: string
  9175. name:
  9176. description: The name of the Secret resource being referred to.
  9177. maxLength: 253
  9178. minLength: 1
  9179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9180. type: string
  9181. namespace:
  9182. description: |-
  9183. The namespace of the Secret resource being referred to.
  9184. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9185. maxLength: 63
  9186. minLength: 1
  9187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9188. type: string
  9189. type: object
  9190. type: object
  9191. fetching:
  9192. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  9193. maxProperties: 1
  9194. minProperties: 1
  9195. properties:
  9196. byID:
  9197. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  9198. type: object
  9199. byName:
  9200. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  9201. properties:
  9202. folderID:
  9203. description: The folder to fetch secrets from
  9204. type: string
  9205. required:
  9206. - folderID
  9207. type: object
  9208. type: object
  9209. required:
  9210. - auth
  9211. type: object
  9212. type: object
  9213. refreshInterval:
  9214. anyOf:
  9215. - type: integer
  9216. - type: string
  9217. description: |-
  9218. Used to configure store refresh interval. Accepts either an integer number
  9219. of seconds (legacy) or a Go duration string such as "1h" or "5m". Empty or
  9220. 0 will default to the controller config.
  9221. x-kubernetes-int-or-string: true
  9222. retrySettings:
  9223. description: Used to configure HTTP retries on failures.
  9224. properties:
  9225. maxRetries:
  9226. format: int32
  9227. type: integer
  9228. retryInterval:
  9229. type: string
  9230. type: object
  9231. required:
  9232. - provider
  9233. type: object
  9234. status:
  9235. description: SecretStoreStatus defines the observed state of the SecretStore.
  9236. properties:
  9237. capabilities:
  9238. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  9239. type: string
  9240. conditions:
  9241. items:
  9242. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  9243. properties:
  9244. lastTransitionTime:
  9245. format: date-time
  9246. type: string
  9247. message:
  9248. type: string
  9249. reason:
  9250. type: string
  9251. status:
  9252. type: string
  9253. type:
  9254. description: SecretStoreConditionType represents the condition of the SecretStore.
  9255. type: string
  9256. required:
  9257. - status
  9258. - type
  9259. type: object
  9260. type: array
  9261. type: object
  9262. type: object
  9263. served: true
  9264. storage: true
  9265. subresources:
  9266. status: {}
  9267. - additionalPrinterColumns:
  9268. - jsonPath: .metadata.creationTimestamp
  9269. name: AGE
  9270. type: date
  9271. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  9272. name: Status
  9273. type: string
  9274. - jsonPath: .status.capabilities
  9275. name: Capabilities
  9276. type: string
  9277. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  9278. name: Ready
  9279. type: string
  9280. deprecated: true
  9281. name: v1beta1
  9282. schema:
  9283. openAPIV3Schema:
  9284. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  9285. properties:
  9286. apiVersion:
  9287. description: |-
  9288. APIVersion defines the versioned schema of this representation of an object.
  9289. Servers should convert recognized schemas to the latest internal value, and
  9290. may reject unrecognized values.
  9291. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  9292. type: string
  9293. kind:
  9294. description: |-
  9295. Kind is a string value representing the REST resource this object represents.
  9296. Servers may infer this from the endpoint the client submits requests to.
  9297. Cannot be updated.
  9298. In CamelCase.
  9299. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  9300. type: string
  9301. metadata:
  9302. type: object
  9303. spec:
  9304. description: SecretStoreSpec defines the desired state of SecretStore.
  9305. properties:
  9306. conditions:
  9307. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  9308. items:
  9309. description: |-
  9310. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  9311. for a ClusterSecretStore instance.
  9312. properties:
  9313. namespaceRegexes:
  9314. description: Choose namespaces by using regex matching
  9315. items:
  9316. type: string
  9317. type: array
  9318. namespaceSelector:
  9319. description: Choose namespace using a labelSelector
  9320. properties:
  9321. matchExpressions:
  9322. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  9323. items:
  9324. description: |-
  9325. A label selector requirement is a selector that contains values, a key, and an operator that
  9326. relates the key and values.
  9327. properties:
  9328. key:
  9329. description: key is the label key that the selector applies to.
  9330. type: string
  9331. operator:
  9332. description: |-
  9333. operator represents a key's relationship to a set of values.
  9334. Valid operators are In, NotIn, Exists and DoesNotExist.
  9335. type: string
  9336. values:
  9337. description: |-
  9338. values is an array of string values. If the operator is In or NotIn,
  9339. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  9340. the values array must be empty. This array is replaced during a strategic
  9341. merge patch.
  9342. items:
  9343. type: string
  9344. type: array
  9345. x-kubernetes-list-type: atomic
  9346. required:
  9347. - key
  9348. - operator
  9349. type: object
  9350. type: array
  9351. x-kubernetes-list-type: atomic
  9352. matchLabels:
  9353. additionalProperties:
  9354. type: string
  9355. description: |-
  9356. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  9357. map is equivalent to an element of matchExpressions, whose key field is "key", the
  9358. operator is "In", and the values array contains only "value". The requirements are ANDed.
  9359. type: object
  9360. type: object
  9361. x-kubernetes-map-type: atomic
  9362. namespaces:
  9363. description: Choose namespaces by name
  9364. items:
  9365. maxLength: 63
  9366. minLength: 1
  9367. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9368. type: string
  9369. type: array
  9370. type: object
  9371. type: array
  9372. controller:
  9373. description: |-
  9374. Used to select the correct ESO controller (think: ingress.ingressClassName)
  9375. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  9376. type: string
  9377. provider:
  9378. description: Used to configure the provider. Only one provider may be set
  9379. maxProperties: 1
  9380. minProperties: 1
  9381. properties:
  9382. akeyless:
  9383. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  9384. properties:
  9385. akeylessGWApiURL:
  9386. description: Akeyless GW API Url from which the secrets to be fetched from.
  9387. type: string
  9388. authSecretRef:
  9389. description: Auth configures how the operator authenticates with Akeyless.
  9390. properties:
  9391. kubernetesAuth:
  9392. description: |-
  9393. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  9394. token stored in the named Secret resource.
  9395. properties:
  9396. accessID:
  9397. description: the Akeyless Kubernetes auth-method access-id
  9398. type: string
  9399. k8sConfName:
  9400. description: Kubernetes-auth configuration name in Akeyless-Gateway
  9401. type: string
  9402. secretRef:
  9403. description: |-
  9404. Optional secret field containing a Kubernetes ServiceAccount JWT used
  9405. for authenticating with Akeyless. If a name is specified without a key,
  9406. `token` is the default. If one is not specified, the one bound to
  9407. the controller will be used.
  9408. properties:
  9409. key:
  9410. description: |-
  9411. A key in the referenced Secret.
  9412. Some instances of this field may be defaulted, in others it may be required.
  9413. maxLength: 253
  9414. minLength: 1
  9415. pattern: ^[-._a-zA-Z0-9]+$
  9416. type: string
  9417. name:
  9418. description: The name of the Secret resource being referred to.
  9419. maxLength: 253
  9420. minLength: 1
  9421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9422. type: string
  9423. namespace:
  9424. description: |-
  9425. The namespace of the Secret resource being referred to.
  9426. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9427. maxLength: 63
  9428. minLength: 1
  9429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9430. type: string
  9431. type: object
  9432. serviceAccountRef:
  9433. description: |-
  9434. Optional service account field containing the name of a kubernetes ServiceAccount.
  9435. If the service account is specified, the service account secret token JWT will be used
  9436. for authenticating with Akeyless. If the service account selector is not supplied,
  9437. the secretRef will be used instead.
  9438. properties:
  9439. audiences:
  9440. description: |-
  9441. Audience specifies the `aud` claim for the service account token
  9442. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  9443. then this audiences will be appended to the list
  9444. items:
  9445. type: string
  9446. type: array
  9447. name:
  9448. description: The name of the ServiceAccount resource being referred to.
  9449. maxLength: 253
  9450. minLength: 1
  9451. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9452. type: string
  9453. namespace:
  9454. description: |-
  9455. Namespace of the resource being referred to.
  9456. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9457. maxLength: 63
  9458. minLength: 1
  9459. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9460. type: string
  9461. required:
  9462. - name
  9463. type: object
  9464. required:
  9465. - accessID
  9466. - k8sConfName
  9467. type: object
  9468. secretRef:
  9469. description: |-
  9470. Reference to a Secret that contains the details
  9471. to authenticate with Akeyless.
  9472. properties:
  9473. accessID:
  9474. description: The SecretAccessID is used for authentication
  9475. properties:
  9476. key:
  9477. description: |-
  9478. A key in the referenced Secret.
  9479. Some instances of this field may be defaulted, in others it may be required.
  9480. maxLength: 253
  9481. minLength: 1
  9482. pattern: ^[-._a-zA-Z0-9]+$
  9483. type: string
  9484. name:
  9485. description: The name of the Secret resource being referred to.
  9486. maxLength: 253
  9487. minLength: 1
  9488. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9489. type: string
  9490. namespace:
  9491. description: |-
  9492. The namespace of the Secret resource being referred to.
  9493. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9494. maxLength: 63
  9495. minLength: 1
  9496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9497. type: string
  9498. type: object
  9499. accessType:
  9500. description: |-
  9501. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9502. In some instances, `key` is a required field.
  9503. properties:
  9504. key:
  9505. description: |-
  9506. A key in the referenced Secret.
  9507. Some instances of this field may be defaulted, in others it may be required.
  9508. maxLength: 253
  9509. minLength: 1
  9510. pattern: ^[-._a-zA-Z0-9]+$
  9511. type: string
  9512. name:
  9513. description: The name of the Secret resource being referred to.
  9514. maxLength: 253
  9515. minLength: 1
  9516. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9517. type: string
  9518. namespace:
  9519. description: |-
  9520. The namespace of the Secret resource being referred to.
  9521. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9522. maxLength: 63
  9523. minLength: 1
  9524. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9525. type: string
  9526. type: object
  9527. accessTypeParam:
  9528. description: |-
  9529. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9530. In some instances, `key` is a required field.
  9531. properties:
  9532. key:
  9533. description: |-
  9534. A key in the referenced Secret.
  9535. Some instances of this field may be defaulted, in others it may be required.
  9536. maxLength: 253
  9537. minLength: 1
  9538. pattern: ^[-._a-zA-Z0-9]+$
  9539. type: string
  9540. name:
  9541. description: The name of the Secret resource being referred to.
  9542. maxLength: 253
  9543. minLength: 1
  9544. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9545. type: string
  9546. namespace:
  9547. description: |-
  9548. The namespace of the Secret resource being referred to.
  9549. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9550. maxLength: 63
  9551. minLength: 1
  9552. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9553. type: string
  9554. type: object
  9555. type: object
  9556. type: object
  9557. caBundle:
  9558. description: |-
  9559. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  9560. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  9561. are used to validate the TLS connection.
  9562. format: byte
  9563. type: string
  9564. caProvider:
  9565. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  9566. properties:
  9567. key:
  9568. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9569. maxLength: 253
  9570. minLength: 1
  9571. pattern: ^[-._a-zA-Z0-9]+$
  9572. type: string
  9573. name:
  9574. description: The name of the object located at the provider type.
  9575. maxLength: 253
  9576. minLength: 1
  9577. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9578. type: string
  9579. namespace:
  9580. description: |-
  9581. The namespace the Provider type is in.
  9582. Can only be defined when used in a ClusterSecretStore.
  9583. maxLength: 63
  9584. minLength: 1
  9585. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9586. type: string
  9587. type:
  9588. description: The type of provider to use such as "Secret", or "ConfigMap".
  9589. enum:
  9590. - Secret
  9591. - ConfigMap
  9592. type: string
  9593. required:
  9594. - name
  9595. - type
  9596. type: object
  9597. required:
  9598. - akeylessGWApiURL
  9599. - authSecretRef
  9600. type: object
  9601. alibaba:
  9602. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  9603. properties:
  9604. auth:
  9605. description: AlibabaAuth contains a secretRef for credentials.
  9606. properties:
  9607. rrsa:
  9608. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  9609. properties:
  9610. oidcProviderArn:
  9611. type: string
  9612. oidcTokenFilePath:
  9613. type: string
  9614. roleArn:
  9615. type: string
  9616. sessionName:
  9617. type: string
  9618. required:
  9619. - oidcProviderArn
  9620. - oidcTokenFilePath
  9621. - roleArn
  9622. - sessionName
  9623. type: object
  9624. secretRef:
  9625. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  9626. properties:
  9627. accessKeyIDSecretRef:
  9628. description: The AccessKeyID is used for authentication
  9629. properties:
  9630. key:
  9631. description: |-
  9632. A key in the referenced Secret.
  9633. Some instances of this field may be defaulted, in others it may be required.
  9634. maxLength: 253
  9635. minLength: 1
  9636. pattern: ^[-._a-zA-Z0-9]+$
  9637. type: string
  9638. name:
  9639. description: The name of the Secret resource being referred to.
  9640. maxLength: 253
  9641. minLength: 1
  9642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9643. type: string
  9644. namespace:
  9645. description: |-
  9646. The namespace of the Secret resource being referred to.
  9647. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9648. maxLength: 63
  9649. minLength: 1
  9650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9651. type: string
  9652. type: object
  9653. accessKeySecretSecretRef:
  9654. description: The AccessKeySecret is used for authentication
  9655. properties:
  9656. key:
  9657. description: |-
  9658. A key in the referenced Secret.
  9659. Some instances of this field may be defaulted, in others it may be required.
  9660. maxLength: 253
  9661. minLength: 1
  9662. pattern: ^[-._a-zA-Z0-9]+$
  9663. type: string
  9664. name:
  9665. description: The name of the Secret resource being referred to.
  9666. maxLength: 253
  9667. minLength: 1
  9668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9669. type: string
  9670. namespace:
  9671. description: |-
  9672. The namespace of the Secret resource being referred to.
  9673. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9674. maxLength: 63
  9675. minLength: 1
  9676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9677. type: string
  9678. type: object
  9679. required:
  9680. - accessKeyIDSecretRef
  9681. - accessKeySecretSecretRef
  9682. type: object
  9683. type: object
  9684. regionID:
  9685. description: Alibaba Region to be used for the provider
  9686. type: string
  9687. required:
  9688. - auth
  9689. - regionID
  9690. type: object
  9691. aws:
  9692. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  9693. properties:
  9694. additionalRoles:
  9695. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  9696. items:
  9697. type: string
  9698. type: array
  9699. auth:
  9700. description: |-
  9701. Auth defines the information necessary to authenticate against AWS
  9702. if not set aws sdk will infer credentials from your environment
  9703. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  9704. properties:
  9705. jwt:
  9706. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  9707. properties:
  9708. serviceAccountRef:
  9709. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  9710. properties:
  9711. audiences:
  9712. description: |-
  9713. Audience specifies the `aud` claim for the service account token
  9714. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  9715. then this audiences will be appended to the list
  9716. items:
  9717. type: string
  9718. type: array
  9719. name:
  9720. description: The name of the ServiceAccount resource being referred to.
  9721. maxLength: 253
  9722. minLength: 1
  9723. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9724. type: string
  9725. namespace:
  9726. description: |-
  9727. Namespace of the resource being referred to.
  9728. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9729. maxLength: 63
  9730. minLength: 1
  9731. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9732. type: string
  9733. required:
  9734. - name
  9735. type: object
  9736. type: object
  9737. secretRef:
  9738. description: |-
  9739. AWSAuthSecretRef holds secret references for AWS credentials
  9740. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  9741. properties:
  9742. accessKeyIDSecretRef:
  9743. description: The AccessKeyID is used for authentication
  9744. properties:
  9745. key:
  9746. description: |-
  9747. A key in the referenced Secret.
  9748. Some instances of this field may be defaulted, in others it may be required.
  9749. maxLength: 253
  9750. minLength: 1
  9751. pattern: ^[-._a-zA-Z0-9]+$
  9752. type: string
  9753. name:
  9754. description: The name of the Secret resource being referred to.
  9755. maxLength: 253
  9756. minLength: 1
  9757. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9758. type: string
  9759. namespace:
  9760. description: |-
  9761. The namespace of the Secret resource being referred to.
  9762. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9763. maxLength: 63
  9764. minLength: 1
  9765. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9766. type: string
  9767. type: object
  9768. secretAccessKeySecretRef:
  9769. description: The SecretAccessKey is used for authentication
  9770. properties:
  9771. key:
  9772. description: |-
  9773. A key in the referenced Secret.
  9774. Some instances of this field may be defaulted, in others it may be required.
  9775. maxLength: 253
  9776. minLength: 1
  9777. pattern: ^[-._a-zA-Z0-9]+$
  9778. type: string
  9779. name:
  9780. description: The name of the Secret resource being referred to.
  9781. maxLength: 253
  9782. minLength: 1
  9783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9784. type: string
  9785. namespace:
  9786. description: |-
  9787. The namespace of the Secret resource being referred to.
  9788. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9789. maxLength: 63
  9790. minLength: 1
  9791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9792. type: string
  9793. type: object
  9794. sessionTokenSecretRef:
  9795. description: |-
  9796. The SessionToken used for authentication
  9797. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  9798. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  9799. properties:
  9800. key:
  9801. description: |-
  9802. A key in the referenced Secret.
  9803. Some instances of this field may be defaulted, in others it may be required.
  9804. maxLength: 253
  9805. minLength: 1
  9806. pattern: ^[-._a-zA-Z0-9]+$
  9807. type: string
  9808. name:
  9809. description: The name of the Secret resource being referred to.
  9810. maxLength: 253
  9811. minLength: 1
  9812. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9813. type: string
  9814. namespace:
  9815. description: |-
  9816. The namespace of the Secret resource being referred to.
  9817. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9818. maxLength: 63
  9819. minLength: 1
  9820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9821. type: string
  9822. type: object
  9823. type: object
  9824. type: object
  9825. externalID:
  9826. description: AWS External ID set on assumed IAM roles
  9827. type: string
  9828. prefix:
  9829. description: Prefix adds a prefix to all retrieved values.
  9830. type: string
  9831. region:
  9832. description: AWS Region to be used for the provider
  9833. type: string
  9834. role:
  9835. description: Role is a Role ARN which the provider will assume
  9836. type: string
  9837. secretsManager:
  9838. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  9839. properties:
  9840. forceDeleteWithoutRecovery:
  9841. description: |-
  9842. Specifies whether to delete the secret without any recovery window. You
  9843. can't use both this parameter and RecoveryWindowInDays in the same call.
  9844. If you don't use either, then by default Secrets Manager uses a 30 day
  9845. recovery window.
  9846. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  9847. type: boolean
  9848. recoveryWindowInDays:
  9849. description: |-
  9850. The number of days from 7 to 30 that Secrets Manager waits before
  9851. permanently deleting the secret. You can't use both this parameter and
  9852. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  9853. then by default Secrets Manager uses a 30 day recovery window.
  9854. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  9855. format: int64
  9856. type: integer
  9857. type: object
  9858. service:
  9859. description: Service defines which service should be used to fetch the secrets
  9860. enum:
  9861. - SecretsManager
  9862. - ParameterStore
  9863. type: string
  9864. sessionTags:
  9865. description: AWS STS assume role session tags
  9866. items:
  9867. description: Tag defines a tag key and value for AWS resources.
  9868. properties:
  9869. key:
  9870. type: string
  9871. value:
  9872. type: string
  9873. required:
  9874. - key
  9875. - value
  9876. type: object
  9877. type: array
  9878. transitiveTagKeys:
  9879. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  9880. items:
  9881. type: string
  9882. type: array
  9883. required:
  9884. - region
  9885. - service
  9886. type: object
  9887. azurekv:
  9888. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  9889. properties:
  9890. authSecretRef:
  9891. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  9892. properties:
  9893. clientCertificate:
  9894. description: The Azure ClientCertificate of the service principle used for authentication.
  9895. properties:
  9896. key:
  9897. description: |-
  9898. A key in the referenced Secret.
  9899. Some instances of this field may be defaulted, in others it may be required.
  9900. maxLength: 253
  9901. minLength: 1
  9902. pattern: ^[-._a-zA-Z0-9]+$
  9903. type: string
  9904. name:
  9905. description: The name of the Secret resource being referred to.
  9906. maxLength: 253
  9907. minLength: 1
  9908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9909. type: string
  9910. namespace:
  9911. description: |-
  9912. The namespace of the Secret resource being referred to.
  9913. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9914. maxLength: 63
  9915. minLength: 1
  9916. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9917. type: string
  9918. type: object
  9919. clientId:
  9920. description: The Azure clientId of the service principle or managed identity used for authentication.
  9921. properties:
  9922. key:
  9923. description: |-
  9924. A key in the referenced Secret.
  9925. Some instances of this field may be defaulted, in others it may be required.
  9926. maxLength: 253
  9927. minLength: 1
  9928. pattern: ^[-._a-zA-Z0-9]+$
  9929. type: string
  9930. name:
  9931. description: The name of the Secret resource being referred to.
  9932. maxLength: 253
  9933. minLength: 1
  9934. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9935. type: string
  9936. namespace:
  9937. description: |-
  9938. The namespace of the Secret resource being referred to.
  9939. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9940. maxLength: 63
  9941. minLength: 1
  9942. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9943. type: string
  9944. type: object
  9945. clientSecret:
  9946. description: The Azure ClientSecret of the service principle used for authentication.
  9947. properties:
  9948. key:
  9949. description: |-
  9950. A key in the referenced Secret.
  9951. Some instances of this field may be defaulted, in others it may be required.
  9952. maxLength: 253
  9953. minLength: 1
  9954. pattern: ^[-._a-zA-Z0-9]+$
  9955. type: string
  9956. name:
  9957. description: The name of the Secret resource being referred to.
  9958. maxLength: 253
  9959. minLength: 1
  9960. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9961. type: string
  9962. namespace:
  9963. description: |-
  9964. The namespace of the Secret resource being referred to.
  9965. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9966. maxLength: 63
  9967. minLength: 1
  9968. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9969. type: string
  9970. type: object
  9971. tenantId:
  9972. description: The Azure tenantId of the managed identity used for authentication.
  9973. properties:
  9974. key:
  9975. description: |-
  9976. A key in the referenced Secret.
  9977. Some instances of this field may be defaulted, in others it may be required.
  9978. maxLength: 253
  9979. minLength: 1
  9980. pattern: ^[-._a-zA-Z0-9]+$
  9981. type: string
  9982. name:
  9983. description: The name of the Secret resource being referred to.
  9984. maxLength: 253
  9985. minLength: 1
  9986. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9987. type: string
  9988. namespace:
  9989. description: |-
  9990. The namespace of the Secret resource being referred to.
  9991. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9992. maxLength: 63
  9993. minLength: 1
  9994. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9995. type: string
  9996. type: object
  9997. type: object
  9998. authType:
  9999. default: ServicePrincipal
  10000. description: |-
  10001. Auth type defines how to authenticate to the keyvault service.
  10002. Valid values are:
  10003. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  10004. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  10005. enum:
  10006. - ServicePrincipal
  10007. - ManagedIdentity
  10008. - WorkloadIdentity
  10009. type: string
  10010. environmentType:
  10011. default: PublicCloud
  10012. description: |-
  10013. EnvironmentType specifies the Azure cloud environment endpoints to use for
  10014. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  10015. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  10016. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  10017. enum:
  10018. - PublicCloud
  10019. - USGovernmentCloud
  10020. - ChinaCloud
  10021. - GermanCloud
  10022. type: string
  10023. identityId:
  10024. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  10025. type: string
  10026. serviceAccountRef:
  10027. description: |-
  10028. ServiceAccountRef specified the service account
  10029. that should be used when authenticating with WorkloadIdentity.
  10030. properties:
  10031. audiences:
  10032. description: |-
  10033. Audience specifies the `aud` claim for the service account token
  10034. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  10035. then this audiences will be appended to the list
  10036. items:
  10037. type: string
  10038. type: array
  10039. name:
  10040. description: The name of the ServiceAccount resource being referred to.
  10041. maxLength: 253
  10042. minLength: 1
  10043. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10044. type: string
  10045. namespace:
  10046. description: |-
  10047. Namespace of the resource being referred to.
  10048. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10049. maxLength: 63
  10050. minLength: 1
  10051. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10052. type: string
  10053. required:
  10054. - name
  10055. type: object
  10056. tenantId:
  10057. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  10058. type: string
  10059. vaultUrl:
  10060. description: Vault Url from which the secrets to be fetched from.
  10061. type: string
  10062. required:
  10063. - vaultUrl
  10064. type: object
  10065. beyondtrust:
  10066. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  10067. properties:
  10068. auth:
  10069. description: Auth configures how the operator authenticates with Beyondtrust.
  10070. properties:
  10071. apiKey:
  10072. description: APIKey If not provided then ClientID/ClientSecret become required.
  10073. properties:
  10074. secretRef:
  10075. description: SecretRef references a key in a secret that will be used as value.
  10076. properties:
  10077. key:
  10078. description: |-
  10079. A key in the referenced Secret.
  10080. Some instances of this field may be defaulted, in others it may be required.
  10081. maxLength: 253
  10082. minLength: 1
  10083. pattern: ^[-._a-zA-Z0-9]+$
  10084. type: string
  10085. name:
  10086. description: The name of the Secret resource being referred to.
  10087. maxLength: 253
  10088. minLength: 1
  10089. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10090. type: string
  10091. namespace:
  10092. description: |-
  10093. The namespace of the Secret resource being referred to.
  10094. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10095. maxLength: 63
  10096. minLength: 1
  10097. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10098. type: string
  10099. type: object
  10100. value:
  10101. description: Value can be specified directly to set a value without using a secret.
  10102. type: string
  10103. type: object
  10104. certificate:
  10105. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  10106. properties:
  10107. secretRef:
  10108. description: SecretRef references a key in a secret that will be used as value.
  10109. properties:
  10110. key:
  10111. description: |-
  10112. A key in the referenced Secret.
  10113. Some instances of this field may be defaulted, in others it may be required.
  10114. maxLength: 253
  10115. minLength: 1
  10116. pattern: ^[-._a-zA-Z0-9]+$
  10117. type: string
  10118. name:
  10119. description: The name of the Secret resource being referred to.
  10120. maxLength: 253
  10121. minLength: 1
  10122. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10123. type: string
  10124. namespace:
  10125. description: |-
  10126. The namespace of the Secret resource being referred to.
  10127. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10128. maxLength: 63
  10129. minLength: 1
  10130. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10131. type: string
  10132. type: object
  10133. value:
  10134. description: Value can be specified directly to set a value without using a secret.
  10135. type: string
  10136. type: object
  10137. certificateKey:
  10138. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  10139. properties:
  10140. secretRef:
  10141. description: SecretRef references a key in a secret that will be used as value.
  10142. properties:
  10143. key:
  10144. description: |-
  10145. A key in the referenced Secret.
  10146. Some instances of this field may be defaulted, in others it may be required.
  10147. maxLength: 253
  10148. minLength: 1
  10149. pattern: ^[-._a-zA-Z0-9]+$
  10150. type: string
  10151. name:
  10152. description: The name of the Secret resource being referred to.
  10153. maxLength: 253
  10154. minLength: 1
  10155. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10156. type: string
  10157. namespace:
  10158. description: |-
  10159. The namespace of the Secret resource being referred to.
  10160. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10161. maxLength: 63
  10162. minLength: 1
  10163. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10164. type: string
  10165. type: object
  10166. value:
  10167. description: Value can be specified directly to set a value without using a secret.
  10168. type: string
  10169. type: object
  10170. clientId:
  10171. description: ClientID is the API OAuth Client ID.
  10172. properties:
  10173. secretRef:
  10174. description: SecretRef references a key in a secret that will be used as value.
  10175. properties:
  10176. key:
  10177. description: |-
  10178. A key in the referenced Secret.
  10179. Some instances of this field may be defaulted, in others it may be required.
  10180. maxLength: 253
  10181. minLength: 1
  10182. pattern: ^[-._a-zA-Z0-9]+$
  10183. type: string
  10184. name:
  10185. description: The name of the Secret resource being referred to.
  10186. maxLength: 253
  10187. minLength: 1
  10188. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10189. type: string
  10190. namespace:
  10191. description: |-
  10192. The namespace of the Secret resource being referred to.
  10193. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10194. maxLength: 63
  10195. minLength: 1
  10196. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10197. type: string
  10198. type: object
  10199. value:
  10200. description: Value can be specified directly to set a value without using a secret.
  10201. type: string
  10202. type: object
  10203. clientSecret:
  10204. description: ClientSecret is the API OAuth Client Secret.
  10205. properties:
  10206. secretRef:
  10207. description: SecretRef references a key in a secret that will be used as value.
  10208. properties:
  10209. key:
  10210. description: |-
  10211. A key in the referenced Secret.
  10212. Some instances of this field may be defaulted, in others it may be required.
  10213. maxLength: 253
  10214. minLength: 1
  10215. pattern: ^[-._a-zA-Z0-9]+$
  10216. type: string
  10217. name:
  10218. description: The name of the Secret resource being referred to.
  10219. maxLength: 253
  10220. minLength: 1
  10221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10222. type: string
  10223. namespace:
  10224. description: |-
  10225. The namespace of the Secret resource being referred to.
  10226. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10227. maxLength: 63
  10228. minLength: 1
  10229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10230. type: string
  10231. type: object
  10232. value:
  10233. description: Value can be specified directly to set a value without using a secret.
  10234. type: string
  10235. type: object
  10236. type: object
  10237. server:
  10238. description: Auth configures how API server works.
  10239. properties:
  10240. apiUrl:
  10241. type: string
  10242. apiVersion:
  10243. type: string
  10244. clientTimeOutSeconds:
  10245. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  10246. type: integer
  10247. decrypt:
  10248. default: true
  10249. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  10250. type: boolean
  10251. retrievalType:
  10252. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  10253. type: string
  10254. separator:
  10255. description: A character that separates the folder names.
  10256. type: string
  10257. verifyCA:
  10258. type: boolean
  10259. required:
  10260. - apiUrl
  10261. - verifyCA
  10262. type: object
  10263. required:
  10264. - auth
  10265. - server
  10266. type: object
  10267. bitwardensecretsmanager:
  10268. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  10269. properties:
  10270. apiURL:
  10271. type: string
  10272. auth:
  10273. description: |-
  10274. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  10275. Make sure that the token being used has permissions on the given secret.
  10276. properties:
  10277. secretRef:
  10278. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  10279. properties:
  10280. credentials:
  10281. description: AccessToken used for the bitwarden instance.
  10282. properties:
  10283. key:
  10284. description: |-
  10285. A key in the referenced Secret.
  10286. Some instances of this field may be defaulted, in others it may be required.
  10287. maxLength: 253
  10288. minLength: 1
  10289. pattern: ^[-._a-zA-Z0-9]+$
  10290. type: string
  10291. name:
  10292. description: The name of the Secret resource being referred to.
  10293. maxLength: 253
  10294. minLength: 1
  10295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10296. type: string
  10297. namespace:
  10298. description: |-
  10299. The namespace of the Secret resource being referred to.
  10300. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10301. maxLength: 63
  10302. minLength: 1
  10303. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10304. type: string
  10305. type: object
  10306. required:
  10307. - credentials
  10308. type: object
  10309. required:
  10310. - secretRef
  10311. type: object
  10312. bitwardenServerSDKURL:
  10313. type: string
  10314. caBundle:
  10315. description: |-
  10316. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  10317. can be performed.
  10318. type: string
  10319. caProvider:
  10320. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  10321. properties:
  10322. key:
  10323. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10324. maxLength: 253
  10325. minLength: 1
  10326. pattern: ^[-._a-zA-Z0-9]+$
  10327. type: string
  10328. name:
  10329. description: The name of the object located at the provider type.
  10330. maxLength: 253
  10331. minLength: 1
  10332. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10333. type: string
  10334. namespace:
  10335. description: |-
  10336. The namespace the Provider type is in.
  10337. Can only be defined when used in a ClusterSecretStore.
  10338. maxLength: 63
  10339. minLength: 1
  10340. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10341. type: string
  10342. type:
  10343. description: The type of provider to use such as "Secret", or "ConfigMap".
  10344. enum:
  10345. - Secret
  10346. - ConfigMap
  10347. type: string
  10348. required:
  10349. - name
  10350. - type
  10351. type: object
  10352. identityURL:
  10353. type: string
  10354. organizationID:
  10355. description: OrganizationID determines which organization this secret store manages.
  10356. type: string
  10357. projectID:
  10358. description: ProjectID determines which project this secret store manages.
  10359. type: string
  10360. required:
  10361. - auth
  10362. - organizationID
  10363. - projectID
  10364. type: object
  10365. chef:
  10366. description: Chef configures this store to sync secrets with chef server
  10367. properties:
  10368. auth:
  10369. description: Auth defines the information necessary to authenticate against chef Server
  10370. properties:
  10371. secretRef:
  10372. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  10373. properties:
  10374. privateKeySecretRef:
  10375. description: SecretKey is the Signing Key in PEM format, used for authentication.
  10376. properties:
  10377. key:
  10378. description: |-
  10379. A key in the referenced Secret.
  10380. Some instances of this field may be defaulted, in others it may be required.
  10381. maxLength: 253
  10382. minLength: 1
  10383. pattern: ^[-._a-zA-Z0-9]+$
  10384. type: string
  10385. name:
  10386. description: The name of the Secret resource being referred to.
  10387. maxLength: 253
  10388. minLength: 1
  10389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10390. type: string
  10391. namespace:
  10392. description: |-
  10393. The namespace of the Secret resource being referred to.
  10394. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10395. maxLength: 63
  10396. minLength: 1
  10397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10398. type: string
  10399. type: object
  10400. required:
  10401. - privateKeySecretRef
  10402. type: object
  10403. required:
  10404. - secretRef
  10405. type: object
  10406. serverUrl:
  10407. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  10408. type: string
  10409. username:
  10410. description: UserName should be the user ID on the chef server
  10411. type: string
  10412. required:
  10413. - auth
  10414. - serverUrl
  10415. - username
  10416. type: object
  10417. cloudrusm:
  10418. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  10419. properties:
  10420. auth:
  10421. description: CSMAuth contains a secretRef for credentials.
  10422. properties:
  10423. secretRef:
  10424. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  10425. properties:
  10426. accessKeyIDSecretRef:
  10427. description: The AccessKeyID is used for authentication
  10428. properties:
  10429. key:
  10430. description: |-
  10431. A key in the referenced Secret.
  10432. Some instances of this field may be defaulted, in others it may be required.
  10433. maxLength: 253
  10434. minLength: 1
  10435. pattern: ^[-._a-zA-Z0-9]+$
  10436. type: string
  10437. name:
  10438. description: The name of the Secret resource being referred to.
  10439. maxLength: 253
  10440. minLength: 1
  10441. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10442. type: string
  10443. namespace:
  10444. description: |-
  10445. The namespace of the Secret resource being referred to.
  10446. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10447. maxLength: 63
  10448. minLength: 1
  10449. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10450. type: string
  10451. type: object
  10452. accessKeySecretSecretRef:
  10453. description: The AccessKeySecret is used for authentication
  10454. properties:
  10455. key:
  10456. description: |-
  10457. A key in the referenced Secret.
  10458. Some instances of this field may be defaulted, in others it may be required.
  10459. maxLength: 253
  10460. minLength: 1
  10461. pattern: ^[-._a-zA-Z0-9]+$
  10462. type: string
  10463. name:
  10464. description: The name of the Secret resource being referred to.
  10465. maxLength: 253
  10466. minLength: 1
  10467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10468. type: string
  10469. namespace:
  10470. description: |-
  10471. The namespace of the Secret resource being referred to.
  10472. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10473. maxLength: 63
  10474. minLength: 1
  10475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10476. type: string
  10477. type: object
  10478. required:
  10479. - accessKeyIDSecretRef
  10480. - accessKeySecretSecretRef
  10481. type: object
  10482. type: object
  10483. projectID:
  10484. description: ProjectID is the project, which the secrets are stored in.
  10485. type: string
  10486. required:
  10487. - auth
  10488. type: object
  10489. conjur:
  10490. description: Conjur configures this store to sync secrets using conjur provider
  10491. properties:
  10492. auth:
  10493. description: Defines authentication settings for connecting to Conjur.
  10494. properties:
  10495. apikey:
  10496. description: Authenticates with Conjur using an API key.
  10497. properties:
  10498. account:
  10499. description: Account is the Conjur organization account name.
  10500. type: string
  10501. apiKeyRef:
  10502. description: |-
  10503. A reference to a specific 'key' containing the Conjur API key
  10504. within a Secret resource. In some instances, `key` is a required field.
  10505. properties:
  10506. key:
  10507. description: |-
  10508. A key in the referenced Secret.
  10509. Some instances of this field may be defaulted, in others it may be required.
  10510. maxLength: 253
  10511. minLength: 1
  10512. pattern: ^[-._a-zA-Z0-9]+$
  10513. type: string
  10514. name:
  10515. description: The name of the Secret resource being referred to.
  10516. maxLength: 253
  10517. minLength: 1
  10518. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10519. type: string
  10520. namespace:
  10521. description: |-
  10522. The namespace of the Secret resource being referred to.
  10523. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10524. maxLength: 63
  10525. minLength: 1
  10526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10527. type: string
  10528. type: object
  10529. userRef:
  10530. description: |-
  10531. A reference to a specific 'key' containing the Conjur username
  10532. within a Secret resource. In some instances, `key` is a required field.
  10533. properties:
  10534. key:
  10535. description: |-
  10536. A key in the referenced Secret.
  10537. Some instances of this field may be defaulted, in others it may be required.
  10538. maxLength: 253
  10539. minLength: 1
  10540. pattern: ^[-._a-zA-Z0-9]+$
  10541. type: string
  10542. name:
  10543. description: The name of the Secret resource being referred to.
  10544. maxLength: 253
  10545. minLength: 1
  10546. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10547. type: string
  10548. namespace:
  10549. description: |-
  10550. The namespace of the Secret resource being referred to.
  10551. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10552. maxLength: 63
  10553. minLength: 1
  10554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10555. type: string
  10556. type: object
  10557. required:
  10558. - account
  10559. - apiKeyRef
  10560. - userRef
  10561. type: object
  10562. jwt:
  10563. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  10564. properties:
  10565. account:
  10566. description: Account is the Conjur organization account name.
  10567. type: string
  10568. hostId:
  10569. description: |-
  10570. Optional HostID for JWT authentication. This may be used depending
  10571. on how the Conjur JWT authenticator policy is configured.
  10572. type: string
  10573. secretRef:
  10574. description: |-
  10575. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  10576. authenticate with Conjur using the JWT authentication method.
  10577. properties:
  10578. key:
  10579. description: |-
  10580. A key in the referenced Secret.
  10581. Some instances of this field may be defaulted, in others it may be required.
  10582. maxLength: 253
  10583. minLength: 1
  10584. pattern: ^[-._a-zA-Z0-9]+$
  10585. type: string
  10586. name:
  10587. description: The name of the Secret resource being referred to.
  10588. maxLength: 253
  10589. minLength: 1
  10590. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10591. type: string
  10592. namespace:
  10593. description: |-
  10594. The namespace of the Secret resource being referred to.
  10595. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10596. maxLength: 63
  10597. minLength: 1
  10598. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10599. type: string
  10600. type: object
  10601. serviceAccountRef:
  10602. description: |-
  10603. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  10604. a token for with the `TokenRequest` API.
  10605. properties:
  10606. audiences:
  10607. description: |-
  10608. Audience specifies the `aud` claim for the service account token
  10609. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  10610. then this audiences will be appended to the list
  10611. items:
  10612. type: string
  10613. type: array
  10614. name:
  10615. description: The name of the ServiceAccount resource being referred to.
  10616. maxLength: 253
  10617. minLength: 1
  10618. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10619. type: string
  10620. namespace:
  10621. description: |-
  10622. Namespace of the resource being referred to.
  10623. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10624. maxLength: 63
  10625. minLength: 1
  10626. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10627. type: string
  10628. required:
  10629. - name
  10630. type: object
  10631. serviceID:
  10632. description: The conjur authn jwt webservice id
  10633. type: string
  10634. required:
  10635. - account
  10636. - serviceID
  10637. type: object
  10638. type: object
  10639. caBundle:
  10640. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  10641. type: string
  10642. caProvider:
  10643. description: |-
  10644. Used to provide custom certificate authority (CA) certificates
  10645. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  10646. that contains a PEM-encoded certificate.
  10647. properties:
  10648. key:
  10649. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10650. maxLength: 253
  10651. minLength: 1
  10652. pattern: ^[-._a-zA-Z0-9]+$
  10653. type: string
  10654. name:
  10655. description: The name of the object located at the provider type.
  10656. maxLength: 253
  10657. minLength: 1
  10658. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10659. type: string
  10660. namespace:
  10661. description: |-
  10662. The namespace the Provider type is in.
  10663. Can only be defined when used in a ClusterSecretStore.
  10664. maxLength: 63
  10665. minLength: 1
  10666. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10667. type: string
  10668. type:
  10669. description: The type of provider to use such as "Secret", or "ConfigMap".
  10670. enum:
  10671. - Secret
  10672. - ConfigMap
  10673. type: string
  10674. required:
  10675. - name
  10676. - type
  10677. type: object
  10678. url:
  10679. description: URL is the endpoint of the Conjur instance.
  10680. type: string
  10681. required:
  10682. - auth
  10683. - url
  10684. type: object
  10685. delinea:
  10686. description: |-
  10687. Delinea DevOps Secrets Vault
  10688. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  10689. properties:
  10690. clientId:
  10691. description: ClientID is the non-secret part of the credential.
  10692. properties:
  10693. secretRef:
  10694. description: SecretRef references a key in a secret that will be used as value.
  10695. properties:
  10696. key:
  10697. description: |-
  10698. A key in the referenced Secret.
  10699. Some instances of this field may be defaulted, in others it may be required.
  10700. maxLength: 253
  10701. minLength: 1
  10702. pattern: ^[-._a-zA-Z0-9]+$
  10703. type: string
  10704. name:
  10705. description: The name of the Secret resource being referred to.
  10706. maxLength: 253
  10707. minLength: 1
  10708. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10709. type: string
  10710. namespace:
  10711. description: |-
  10712. The namespace of the Secret resource being referred to.
  10713. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10714. maxLength: 63
  10715. minLength: 1
  10716. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10717. type: string
  10718. type: object
  10719. value:
  10720. description: Value can be specified directly to set a value without using a secret.
  10721. type: string
  10722. type: object
  10723. clientSecret:
  10724. description: ClientSecret is the secret part of the credential.
  10725. properties:
  10726. secretRef:
  10727. description: SecretRef references a key in a secret that will be used as value.
  10728. properties:
  10729. key:
  10730. description: |-
  10731. A key in the referenced Secret.
  10732. Some instances of this field may be defaulted, in others it may be required.
  10733. maxLength: 253
  10734. minLength: 1
  10735. pattern: ^[-._a-zA-Z0-9]+$
  10736. type: string
  10737. name:
  10738. description: The name of the Secret resource being referred to.
  10739. maxLength: 253
  10740. minLength: 1
  10741. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10742. type: string
  10743. namespace:
  10744. description: |-
  10745. The namespace of the Secret resource being referred to.
  10746. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10747. maxLength: 63
  10748. minLength: 1
  10749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10750. type: string
  10751. type: object
  10752. value:
  10753. description: Value can be specified directly to set a value without using a secret.
  10754. type: string
  10755. type: object
  10756. tenant:
  10757. description: Tenant is the chosen hostname / site name.
  10758. type: string
  10759. tld:
  10760. description: |-
  10761. TLD is based on the server location that was chosen during provisioning.
  10762. If unset, defaults to "com".
  10763. type: string
  10764. urlTemplate:
  10765. description: |-
  10766. URLTemplate
  10767. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  10768. type: string
  10769. required:
  10770. - clientId
  10771. - clientSecret
  10772. - tenant
  10773. type: object
  10774. device42:
  10775. description: Device42 configures this store to sync secrets using the Device42 provider
  10776. properties:
  10777. auth:
  10778. description: Auth configures how secret-manager authenticates with a Device42 instance.
  10779. properties:
  10780. secretRef:
  10781. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  10782. properties:
  10783. credentials:
  10784. description: Username / Password is used for authentication.
  10785. properties:
  10786. key:
  10787. description: |-
  10788. A key in the referenced Secret.
  10789. Some instances of this field may be defaulted, in others it may be required.
  10790. maxLength: 253
  10791. minLength: 1
  10792. pattern: ^[-._a-zA-Z0-9]+$
  10793. type: string
  10794. name:
  10795. description: The name of the Secret resource being referred to.
  10796. maxLength: 253
  10797. minLength: 1
  10798. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10799. type: string
  10800. namespace:
  10801. description: |-
  10802. The namespace of the Secret resource being referred to.
  10803. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10804. maxLength: 63
  10805. minLength: 1
  10806. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10807. type: string
  10808. type: object
  10809. type: object
  10810. required:
  10811. - secretRef
  10812. type: object
  10813. host:
  10814. description: URL configures the Device42 instance URL.
  10815. type: string
  10816. required:
  10817. - auth
  10818. - host
  10819. type: object
  10820. doppler:
  10821. description: Doppler configures this store to sync secrets using the Doppler provider
  10822. properties:
  10823. auth:
  10824. description: Auth configures how the Operator authenticates with the Doppler API
  10825. properties:
  10826. secretRef:
  10827. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  10828. properties:
  10829. dopplerToken:
  10830. description: |-
  10831. The DopplerToken is used for authentication.
  10832. See https://docs.doppler.com/reference/api#authentication for auth token types.
  10833. The Key attribute defaults to dopplerToken if not specified.
  10834. properties:
  10835. key:
  10836. description: |-
  10837. A key in the referenced Secret.
  10838. Some instances of this field may be defaulted, in others it may be required.
  10839. maxLength: 253
  10840. minLength: 1
  10841. pattern: ^[-._a-zA-Z0-9]+$
  10842. type: string
  10843. name:
  10844. description: The name of the Secret resource being referred to.
  10845. maxLength: 253
  10846. minLength: 1
  10847. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10848. type: string
  10849. namespace:
  10850. description: |-
  10851. The namespace of the Secret resource being referred to.
  10852. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10853. maxLength: 63
  10854. minLength: 1
  10855. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10856. type: string
  10857. type: object
  10858. required:
  10859. - dopplerToken
  10860. type: object
  10861. required:
  10862. - secretRef
  10863. type: object
  10864. config:
  10865. description: Doppler config (required if not using a Service Token)
  10866. type: string
  10867. format:
  10868. description: Format enables the downloading of secrets as a file (string)
  10869. enum:
  10870. - json
  10871. - dotnet-json
  10872. - env
  10873. - yaml
  10874. - docker
  10875. type: string
  10876. nameTransformer:
  10877. description: Environment variable compatible name transforms that change secret names to a different format
  10878. enum:
  10879. - upper-camel
  10880. - camel
  10881. - lower-snake
  10882. - tf-var
  10883. - dotnet-env
  10884. - lower-kebab
  10885. type: string
  10886. project:
  10887. description: Doppler project (required if not using a Service Token)
  10888. type: string
  10889. required:
  10890. - auth
  10891. type: object
  10892. fake:
  10893. description: Fake configures a store with static key/value pairs
  10894. properties:
  10895. data:
  10896. items:
  10897. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  10898. properties:
  10899. key:
  10900. type: string
  10901. value:
  10902. type: string
  10903. version:
  10904. type: string
  10905. required:
  10906. - key
  10907. - value
  10908. type: object
  10909. type: array
  10910. required:
  10911. - data
  10912. type: object
  10913. fortanix:
  10914. description: Fortanix configures this store to sync secrets using the Fortanix provider
  10915. properties:
  10916. apiKey:
  10917. description: APIKey is the API token to access SDKMS Applications.
  10918. properties:
  10919. secretRef:
  10920. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  10921. properties:
  10922. key:
  10923. description: |-
  10924. A key in the referenced Secret.
  10925. Some instances of this field may be defaulted, in others it may be required.
  10926. maxLength: 253
  10927. minLength: 1
  10928. pattern: ^[-._a-zA-Z0-9]+$
  10929. type: string
  10930. name:
  10931. description: The name of the Secret resource being referred to.
  10932. maxLength: 253
  10933. minLength: 1
  10934. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10935. type: string
  10936. namespace:
  10937. description: |-
  10938. The namespace of the Secret resource being referred to.
  10939. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10940. maxLength: 63
  10941. minLength: 1
  10942. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10943. type: string
  10944. type: object
  10945. type: object
  10946. apiUrl:
  10947. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  10948. type: string
  10949. type: object
  10950. gcpsm:
  10951. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  10952. properties:
  10953. auth:
  10954. description: Auth defines the information necessary to authenticate against GCP
  10955. properties:
  10956. secretRef:
  10957. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  10958. properties:
  10959. secretAccessKeySecretRef:
  10960. description: The SecretAccessKey is used for authentication
  10961. properties:
  10962. key:
  10963. description: |-
  10964. A key in the referenced Secret.
  10965. Some instances of this field may be defaulted, in others it may be required.
  10966. maxLength: 253
  10967. minLength: 1
  10968. pattern: ^[-._a-zA-Z0-9]+$
  10969. type: string
  10970. name:
  10971. description: The name of the Secret resource being referred to.
  10972. maxLength: 253
  10973. minLength: 1
  10974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10975. type: string
  10976. namespace:
  10977. description: |-
  10978. The namespace of the Secret resource being referred to.
  10979. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10980. maxLength: 63
  10981. minLength: 1
  10982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10983. type: string
  10984. type: object
  10985. type: object
  10986. workloadIdentity:
  10987. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  10988. properties:
  10989. clusterLocation:
  10990. description: |-
  10991. ClusterLocation is the location of the cluster
  10992. If not specified, it fetches information from the metadata server
  10993. type: string
  10994. clusterName:
  10995. description: |-
  10996. ClusterName is the name of the cluster
  10997. If not specified, it fetches information from the metadata server
  10998. type: string
  10999. clusterProjectID:
  11000. description: |-
  11001. ClusterProjectID is the project ID of the cluster
  11002. If not specified, it fetches information from the metadata server
  11003. type: string
  11004. serviceAccountRef:
  11005. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  11006. properties:
  11007. audiences:
  11008. description: |-
  11009. Audience specifies the `aud` claim for the service account token
  11010. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11011. then this audiences will be appended to the list
  11012. items:
  11013. type: string
  11014. type: array
  11015. name:
  11016. description: The name of the ServiceAccount resource being referred to.
  11017. maxLength: 253
  11018. minLength: 1
  11019. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11020. type: string
  11021. namespace:
  11022. description: |-
  11023. Namespace of the resource being referred to.
  11024. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11025. maxLength: 63
  11026. minLength: 1
  11027. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11028. type: string
  11029. required:
  11030. - name
  11031. type: object
  11032. required:
  11033. - serviceAccountRef
  11034. type: object
  11035. type: object
  11036. location:
  11037. description: Location optionally defines a location for a secret
  11038. type: string
  11039. projectID:
  11040. description: ProjectID project where secret is located
  11041. type: string
  11042. type: object
  11043. github:
  11044. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  11045. properties:
  11046. appID:
  11047. description: appID specifies the Github APP that will be used to authenticate the client
  11048. format: int64
  11049. type: integer
  11050. auth:
  11051. description: auth configures how secret-manager authenticates with a Github instance.
  11052. properties:
  11053. privateKey:
  11054. description: |-
  11055. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11056. In some instances, `key` is a required field.
  11057. properties:
  11058. key:
  11059. description: |-
  11060. A key in the referenced Secret.
  11061. Some instances of this field may be defaulted, in others it may be required.
  11062. maxLength: 253
  11063. minLength: 1
  11064. pattern: ^[-._a-zA-Z0-9]+$
  11065. type: string
  11066. name:
  11067. description: The name of the Secret resource being referred to.
  11068. maxLength: 253
  11069. minLength: 1
  11070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11071. type: string
  11072. namespace:
  11073. description: |-
  11074. The namespace of the Secret resource being referred to.
  11075. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11076. maxLength: 63
  11077. minLength: 1
  11078. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11079. type: string
  11080. type: object
  11081. required:
  11082. - privateKey
  11083. type: object
  11084. environment:
  11085. description: environment will be used to fetch secrets from a particular environment within a github repository
  11086. type: string
  11087. installationID:
  11088. description: installationID specifies the Github APP installation that will be used to authenticate the client
  11089. format: int64
  11090. type: integer
  11091. organization:
  11092. description: organization will be used to fetch secrets from the Github organization
  11093. type: string
  11094. repository:
  11095. description: repository will be used to fetch secrets from the Github repository within an organization
  11096. type: string
  11097. uploadURL:
  11098. description: Upload URL for enterprise instances. Default to URL.
  11099. type: string
  11100. url:
  11101. default: https://github.com/
  11102. description: URL configures the Github instance URL. Defaults to https://github.com/.
  11103. type: string
  11104. required:
  11105. - appID
  11106. - auth
  11107. - installationID
  11108. - organization
  11109. type: object
  11110. gitlab:
  11111. description: GitLab configures this store to sync secrets using GitLab Variables provider
  11112. properties:
  11113. auth:
  11114. description: Auth configures how secret-manager authenticates with a GitLab instance.
  11115. properties:
  11116. SecretRef:
  11117. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  11118. properties:
  11119. accessToken:
  11120. description: AccessToken is used for authentication.
  11121. properties:
  11122. key:
  11123. description: |-
  11124. A key in the referenced Secret.
  11125. Some instances of this field may be defaulted, in others it may be required.
  11126. maxLength: 253
  11127. minLength: 1
  11128. pattern: ^[-._a-zA-Z0-9]+$
  11129. type: string
  11130. name:
  11131. description: The name of the Secret resource being referred to.
  11132. maxLength: 253
  11133. minLength: 1
  11134. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11135. type: string
  11136. namespace:
  11137. description: |-
  11138. The namespace of the Secret resource being referred to.
  11139. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11140. maxLength: 63
  11141. minLength: 1
  11142. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11143. type: string
  11144. type: object
  11145. type: object
  11146. required:
  11147. - SecretRef
  11148. type: object
  11149. caBundle:
  11150. description: |-
  11151. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  11152. can be performed.
  11153. format: byte
  11154. type: string
  11155. caProvider:
  11156. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  11157. properties:
  11158. key:
  11159. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11160. maxLength: 253
  11161. minLength: 1
  11162. pattern: ^[-._a-zA-Z0-9]+$
  11163. type: string
  11164. name:
  11165. description: The name of the object located at the provider type.
  11166. maxLength: 253
  11167. minLength: 1
  11168. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11169. type: string
  11170. namespace:
  11171. description: |-
  11172. The namespace the Provider type is in.
  11173. Can only be defined when used in a ClusterSecretStore.
  11174. maxLength: 63
  11175. minLength: 1
  11176. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11177. type: string
  11178. type:
  11179. description: The type of provider to use such as "Secret", or "ConfigMap".
  11180. enum:
  11181. - Secret
  11182. - ConfigMap
  11183. type: string
  11184. required:
  11185. - name
  11186. - type
  11187. type: object
  11188. environment:
  11189. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  11190. type: string
  11191. groupIDs:
  11192. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  11193. items:
  11194. type: string
  11195. type: array
  11196. inheritFromGroups:
  11197. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  11198. type: boolean
  11199. projectID:
  11200. description: ProjectID specifies a project where secrets are located.
  11201. type: string
  11202. url:
  11203. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  11204. type: string
  11205. required:
  11206. - auth
  11207. type: object
  11208. ibm:
  11209. description: IBM configures this store to sync secrets using IBM Cloud provider
  11210. properties:
  11211. auth:
  11212. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  11213. maxProperties: 1
  11214. minProperties: 1
  11215. properties:
  11216. containerAuth:
  11217. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  11218. properties:
  11219. iamEndpoint:
  11220. type: string
  11221. profile:
  11222. description: the IBM Trusted Profile
  11223. type: string
  11224. tokenLocation:
  11225. description: Location the token is mounted on the pod
  11226. type: string
  11227. required:
  11228. - profile
  11229. type: object
  11230. secretRef:
  11231. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  11232. properties:
  11233. secretApiKeySecretRef:
  11234. description: The SecretAccessKey is used for authentication
  11235. properties:
  11236. key:
  11237. description: |-
  11238. A key in the referenced Secret.
  11239. Some instances of this field may be defaulted, in others it may be required.
  11240. maxLength: 253
  11241. minLength: 1
  11242. pattern: ^[-._a-zA-Z0-9]+$
  11243. type: string
  11244. name:
  11245. description: The name of the Secret resource being referred to.
  11246. maxLength: 253
  11247. minLength: 1
  11248. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11249. type: string
  11250. namespace:
  11251. description: |-
  11252. The namespace of the Secret resource being referred to.
  11253. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11254. maxLength: 63
  11255. minLength: 1
  11256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11257. type: string
  11258. type: object
  11259. type: object
  11260. type: object
  11261. serviceUrl:
  11262. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  11263. type: string
  11264. required:
  11265. - auth
  11266. type: object
  11267. infisical:
  11268. description: Infisical configures this store to sync secrets using the Infisical provider
  11269. properties:
  11270. auth:
  11271. description: Auth configures how the Operator authenticates with the Infisical API
  11272. properties:
  11273. universalAuthCredentials:
  11274. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  11275. properties:
  11276. clientId:
  11277. description: |-
  11278. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11279. In some instances, `key` is a required field.
  11280. properties:
  11281. key:
  11282. description: |-
  11283. A key in the referenced Secret.
  11284. Some instances of this field may be defaulted, in others it may be required.
  11285. maxLength: 253
  11286. minLength: 1
  11287. pattern: ^[-._a-zA-Z0-9]+$
  11288. type: string
  11289. name:
  11290. description: The name of the Secret resource being referred to.
  11291. maxLength: 253
  11292. minLength: 1
  11293. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11294. type: string
  11295. namespace:
  11296. description: |-
  11297. The namespace of the Secret resource being referred to.
  11298. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11299. maxLength: 63
  11300. minLength: 1
  11301. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11302. type: string
  11303. type: object
  11304. clientSecret:
  11305. description: |-
  11306. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11307. In some instances, `key` is a required field.
  11308. properties:
  11309. key:
  11310. description: |-
  11311. A key in the referenced Secret.
  11312. Some instances of this field may be defaulted, in others it may be required.
  11313. maxLength: 253
  11314. minLength: 1
  11315. pattern: ^[-._a-zA-Z0-9]+$
  11316. type: string
  11317. name:
  11318. description: The name of the Secret resource being referred to.
  11319. maxLength: 253
  11320. minLength: 1
  11321. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11322. type: string
  11323. namespace:
  11324. description: |-
  11325. The namespace of the Secret resource being referred to.
  11326. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11327. maxLength: 63
  11328. minLength: 1
  11329. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11330. type: string
  11331. type: object
  11332. required:
  11333. - clientId
  11334. - clientSecret
  11335. type: object
  11336. type: object
  11337. hostAPI:
  11338. default: https://app.infisical.com/api
  11339. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  11340. type: string
  11341. secretsScope:
  11342. description: SecretsScope defines the scope of the secrets within the workspace
  11343. properties:
  11344. environmentSlug:
  11345. description: EnvironmentSlug is the required slug identifier for the environment.
  11346. type: string
  11347. expandSecretReferences:
  11348. default: true
  11349. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  11350. type: boolean
  11351. projectSlug:
  11352. description: ProjectSlug is the required slug identifier for the project.
  11353. type: string
  11354. recursive:
  11355. default: false
  11356. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  11357. type: boolean
  11358. secretsPath:
  11359. default: /
  11360. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  11361. type: string
  11362. required:
  11363. - environmentSlug
  11364. - projectSlug
  11365. type: object
  11366. required:
  11367. - auth
  11368. - secretsScope
  11369. type: object
  11370. keepersecurity:
  11371. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  11372. properties:
  11373. authRef:
  11374. description: |-
  11375. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11376. In some instances, `key` is a required field.
  11377. properties:
  11378. key:
  11379. description: |-
  11380. A key in the referenced Secret.
  11381. Some instances of this field may be defaulted, in others it may be required.
  11382. maxLength: 253
  11383. minLength: 1
  11384. pattern: ^[-._a-zA-Z0-9]+$
  11385. type: string
  11386. name:
  11387. description: The name of the Secret resource being referred to.
  11388. maxLength: 253
  11389. minLength: 1
  11390. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11391. type: string
  11392. namespace:
  11393. description: |-
  11394. The namespace of the Secret resource being referred to.
  11395. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11396. maxLength: 63
  11397. minLength: 1
  11398. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11399. type: string
  11400. type: object
  11401. folderID:
  11402. type: string
  11403. required:
  11404. - authRef
  11405. - folderID
  11406. type: object
  11407. kubernetes:
  11408. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  11409. properties:
  11410. auth:
  11411. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  11412. maxProperties: 1
  11413. minProperties: 1
  11414. properties:
  11415. cert:
  11416. description: has both clientCert and clientKey as secretKeySelector
  11417. properties:
  11418. clientCert:
  11419. description: |-
  11420. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11421. In some instances, `key` is a required field.
  11422. properties:
  11423. key:
  11424. description: |-
  11425. A key in the referenced Secret.
  11426. Some instances of this field may be defaulted, in others it may be required.
  11427. maxLength: 253
  11428. minLength: 1
  11429. pattern: ^[-._a-zA-Z0-9]+$
  11430. type: string
  11431. name:
  11432. description: The name of the Secret resource being referred to.
  11433. maxLength: 253
  11434. minLength: 1
  11435. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11436. type: string
  11437. namespace:
  11438. description: |-
  11439. The namespace of the Secret resource being referred to.
  11440. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11441. maxLength: 63
  11442. minLength: 1
  11443. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11444. type: string
  11445. type: object
  11446. clientKey:
  11447. description: |-
  11448. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11449. In some instances, `key` is a required field.
  11450. properties:
  11451. key:
  11452. description: |-
  11453. A key in the referenced Secret.
  11454. Some instances of this field may be defaulted, in others it may be required.
  11455. maxLength: 253
  11456. minLength: 1
  11457. pattern: ^[-._a-zA-Z0-9]+$
  11458. type: string
  11459. name:
  11460. description: The name of the Secret resource being referred to.
  11461. maxLength: 253
  11462. minLength: 1
  11463. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11464. type: string
  11465. namespace:
  11466. description: |-
  11467. The namespace of the Secret resource being referred to.
  11468. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11469. maxLength: 63
  11470. minLength: 1
  11471. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11472. type: string
  11473. type: object
  11474. type: object
  11475. serviceAccount:
  11476. description: points to a service account that should be used for authentication
  11477. properties:
  11478. audiences:
  11479. description: |-
  11480. Audience specifies the `aud` claim for the service account token
  11481. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11482. then this audiences will be appended to the list
  11483. items:
  11484. type: string
  11485. type: array
  11486. name:
  11487. description: The name of the ServiceAccount resource being referred to.
  11488. maxLength: 253
  11489. minLength: 1
  11490. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11491. type: string
  11492. namespace:
  11493. description: |-
  11494. Namespace of the resource being referred to.
  11495. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11496. maxLength: 63
  11497. minLength: 1
  11498. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11499. type: string
  11500. required:
  11501. - name
  11502. type: object
  11503. token:
  11504. description: use static token to authenticate with
  11505. properties:
  11506. bearerToken:
  11507. description: |-
  11508. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11509. In some instances, `key` is a required field.
  11510. properties:
  11511. key:
  11512. description: |-
  11513. A key in the referenced Secret.
  11514. Some instances of this field may be defaulted, in others it may be required.
  11515. maxLength: 253
  11516. minLength: 1
  11517. pattern: ^[-._a-zA-Z0-9]+$
  11518. type: string
  11519. name:
  11520. description: The name of the Secret resource being referred to.
  11521. maxLength: 253
  11522. minLength: 1
  11523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11524. type: string
  11525. namespace:
  11526. description: |-
  11527. The namespace of the Secret resource being referred to.
  11528. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11529. maxLength: 63
  11530. minLength: 1
  11531. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11532. type: string
  11533. type: object
  11534. type: object
  11535. type: object
  11536. authRef:
  11537. description: A reference to a secret that contains the auth information.
  11538. properties:
  11539. key:
  11540. description: |-
  11541. A key in the referenced Secret.
  11542. Some instances of this field may be defaulted, in others it may be required.
  11543. maxLength: 253
  11544. minLength: 1
  11545. pattern: ^[-._a-zA-Z0-9]+$
  11546. type: string
  11547. name:
  11548. description: The name of the Secret resource being referred to.
  11549. maxLength: 253
  11550. minLength: 1
  11551. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11552. type: string
  11553. namespace:
  11554. description: |-
  11555. The namespace of the Secret resource being referred to.
  11556. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11557. maxLength: 63
  11558. minLength: 1
  11559. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11560. type: string
  11561. type: object
  11562. remoteNamespace:
  11563. default: default
  11564. description: Remote namespace to fetch the secrets from
  11565. maxLength: 63
  11566. minLength: 1
  11567. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11568. type: string
  11569. server:
  11570. description: configures the Kubernetes server Address.
  11571. properties:
  11572. caBundle:
  11573. description: CABundle is a base64-encoded CA certificate
  11574. format: byte
  11575. type: string
  11576. caProvider:
  11577. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  11578. properties:
  11579. key:
  11580. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11581. maxLength: 253
  11582. minLength: 1
  11583. pattern: ^[-._a-zA-Z0-9]+$
  11584. type: string
  11585. name:
  11586. description: The name of the object located at the provider type.
  11587. maxLength: 253
  11588. minLength: 1
  11589. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11590. type: string
  11591. namespace:
  11592. description: |-
  11593. The namespace the Provider type is in.
  11594. Can only be defined when used in a ClusterSecretStore.
  11595. maxLength: 63
  11596. minLength: 1
  11597. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11598. type: string
  11599. type:
  11600. description: The type of provider to use such as "Secret", or "ConfigMap".
  11601. enum:
  11602. - Secret
  11603. - ConfigMap
  11604. type: string
  11605. required:
  11606. - name
  11607. - type
  11608. type: object
  11609. url:
  11610. default: kubernetes.default
  11611. description: configures the Kubernetes server Address.
  11612. type: string
  11613. type: object
  11614. type: object
  11615. onboardbase:
  11616. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  11617. properties:
  11618. apiHost:
  11619. default: https://public.onboardbase.com/api/v1/
  11620. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  11621. type: string
  11622. auth:
  11623. description: Auth configures how the Operator authenticates with the Onboardbase API
  11624. properties:
  11625. apiKeyRef:
  11626. description: |-
  11627. OnboardbaseAPIKey is the APIKey generated by an admin account.
  11628. It is used to recognize and authorize access to a project and environment within onboardbase
  11629. properties:
  11630. key:
  11631. description: |-
  11632. A key in the referenced Secret.
  11633. Some instances of this field may be defaulted, in others it may be required.
  11634. maxLength: 253
  11635. minLength: 1
  11636. pattern: ^[-._a-zA-Z0-9]+$
  11637. type: string
  11638. name:
  11639. description: The name of the Secret resource being referred to.
  11640. maxLength: 253
  11641. minLength: 1
  11642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11643. type: string
  11644. namespace:
  11645. description: |-
  11646. The namespace of the Secret resource being referred to.
  11647. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11648. maxLength: 63
  11649. minLength: 1
  11650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11651. type: string
  11652. type: object
  11653. passcodeRef:
  11654. description: OnboardbasePasscode is the passcode attached to the API Key
  11655. properties:
  11656. key:
  11657. description: |-
  11658. A key in the referenced Secret.
  11659. Some instances of this field may be defaulted, in others it may be required.
  11660. maxLength: 253
  11661. minLength: 1
  11662. pattern: ^[-._a-zA-Z0-9]+$
  11663. type: string
  11664. name:
  11665. description: The name of the Secret resource being referred to.
  11666. maxLength: 253
  11667. minLength: 1
  11668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11669. type: string
  11670. namespace:
  11671. description: |-
  11672. The namespace of the Secret resource being referred to.
  11673. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11674. maxLength: 63
  11675. minLength: 1
  11676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11677. type: string
  11678. type: object
  11679. required:
  11680. - apiKeyRef
  11681. - passcodeRef
  11682. type: object
  11683. environment:
  11684. default: development
  11685. description: Environment is the name of an environmnent within a project to pull the secrets from
  11686. type: string
  11687. project:
  11688. default: development
  11689. description: Project is an onboardbase project that the secrets should be pulled from
  11690. type: string
  11691. required:
  11692. - apiHost
  11693. - auth
  11694. - environment
  11695. - project
  11696. type: object
  11697. onepassword:
  11698. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  11699. properties:
  11700. auth:
  11701. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  11702. properties:
  11703. secretRef:
  11704. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  11705. properties:
  11706. connectTokenSecretRef:
  11707. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  11708. properties:
  11709. key:
  11710. description: |-
  11711. A key in the referenced Secret.
  11712. Some instances of this field may be defaulted, in others it may be required.
  11713. maxLength: 253
  11714. minLength: 1
  11715. pattern: ^[-._a-zA-Z0-9]+$
  11716. type: string
  11717. name:
  11718. description: The name of the Secret resource being referred to.
  11719. maxLength: 253
  11720. minLength: 1
  11721. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11722. type: string
  11723. namespace:
  11724. description: |-
  11725. The namespace of the Secret resource being referred to.
  11726. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11727. maxLength: 63
  11728. minLength: 1
  11729. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11730. type: string
  11731. type: object
  11732. required:
  11733. - connectTokenSecretRef
  11734. type: object
  11735. required:
  11736. - secretRef
  11737. type: object
  11738. connectHost:
  11739. description: ConnectHost defines the OnePassword Connect Server to connect to
  11740. type: string
  11741. vaults:
  11742. additionalProperties:
  11743. type: integer
  11744. description: Vaults defines which OnePassword vaults to search in which order
  11745. type: object
  11746. required:
  11747. - auth
  11748. - connectHost
  11749. - vaults
  11750. type: object
  11751. oracle:
  11752. description: Oracle configures this store to sync secrets using Oracle Vault provider
  11753. properties:
  11754. auth:
  11755. description: |-
  11756. Auth configures how secret-manager authenticates with the Oracle Vault.
  11757. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  11758. properties:
  11759. secretRef:
  11760. description: SecretRef to pass through sensitive information.
  11761. properties:
  11762. fingerprint:
  11763. description: Fingerprint is the fingerprint of the API private key.
  11764. properties:
  11765. key:
  11766. description: |-
  11767. A key in the referenced Secret.
  11768. Some instances of this field may be defaulted, in others it may be required.
  11769. maxLength: 253
  11770. minLength: 1
  11771. pattern: ^[-._a-zA-Z0-9]+$
  11772. type: string
  11773. name:
  11774. description: The name of the Secret resource being referred to.
  11775. maxLength: 253
  11776. minLength: 1
  11777. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11778. type: string
  11779. namespace:
  11780. description: |-
  11781. The namespace of the Secret resource being referred to.
  11782. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11783. maxLength: 63
  11784. minLength: 1
  11785. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11786. type: string
  11787. type: object
  11788. privatekey:
  11789. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  11790. properties:
  11791. key:
  11792. description: |-
  11793. A key in the referenced Secret.
  11794. Some instances of this field may be defaulted, in others it may be required.
  11795. maxLength: 253
  11796. minLength: 1
  11797. pattern: ^[-._a-zA-Z0-9]+$
  11798. type: string
  11799. name:
  11800. description: The name of the Secret resource being referred to.
  11801. maxLength: 253
  11802. minLength: 1
  11803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11804. type: string
  11805. namespace:
  11806. description: |-
  11807. The namespace of the Secret resource being referred to.
  11808. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11809. maxLength: 63
  11810. minLength: 1
  11811. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11812. type: string
  11813. type: object
  11814. required:
  11815. - fingerprint
  11816. - privatekey
  11817. type: object
  11818. tenancy:
  11819. description: Tenancy is the tenancy OCID where user is located.
  11820. type: string
  11821. user:
  11822. description: User is an access OCID specific to the account.
  11823. type: string
  11824. required:
  11825. - secretRef
  11826. - tenancy
  11827. - user
  11828. type: object
  11829. compartment:
  11830. description: |-
  11831. Compartment is the vault compartment OCID.
  11832. Required for PushSecret
  11833. type: string
  11834. encryptionKey:
  11835. description: |-
  11836. EncryptionKey is the OCID of the encryption key within the vault.
  11837. Required for PushSecret
  11838. type: string
  11839. principalType:
  11840. description: |-
  11841. The type of principal to use for authentication. If left blank, the Auth struct will
  11842. determine the principal type. This optional field must be specified if using
  11843. workload identity.
  11844. enum:
  11845. - ""
  11846. - UserPrincipal
  11847. - InstancePrincipal
  11848. - Workload
  11849. type: string
  11850. region:
  11851. description: Region is the region where vault is located.
  11852. type: string
  11853. serviceAccountRef:
  11854. description: |-
  11855. ServiceAccountRef specified the service account
  11856. that should be used when authenticating with WorkloadIdentity.
  11857. properties:
  11858. audiences:
  11859. description: |-
  11860. Audience specifies the `aud` claim for the service account token
  11861. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11862. then this audiences will be appended to the list
  11863. items:
  11864. type: string
  11865. type: array
  11866. name:
  11867. description: The name of the ServiceAccount resource being referred to.
  11868. maxLength: 253
  11869. minLength: 1
  11870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11871. type: string
  11872. namespace:
  11873. description: |-
  11874. Namespace of the resource being referred to.
  11875. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11876. maxLength: 63
  11877. minLength: 1
  11878. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11879. type: string
  11880. required:
  11881. - name
  11882. type: object
  11883. vault:
  11884. description: Vault is the vault's OCID of the specific vault where secret is located.
  11885. type: string
  11886. required:
  11887. - region
  11888. - vault
  11889. type: object
  11890. passbolt:
  11891. description: PassboltProvider defines configuration for the Passbolt provider.
  11892. properties:
  11893. auth:
  11894. description: Auth defines the information necessary to authenticate against Passbolt Server
  11895. properties:
  11896. passwordSecretRef:
  11897. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  11898. properties:
  11899. key:
  11900. description: |-
  11901. A key in the referenced Secret.
  11902. Some instances of this field may be defaulted, in others it may be required.
  11903. maxLength: 253
  11904. minLength: 1
  11905. pattern: ^[-._a-zA-Z0-9]+$
  11906. type: string
  11907. name:
  11908. description: The name of the Secret resource being referred to.
  11909. maxLength: 253
  11910. minLength: 1
  11911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11912. type: string
  11913. namespace:
  11914. description: |-
  11915. The namespace of the Secret resource being referred to.
  11916. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11917. maxLength: 63
  11918. minLength: 1
  11919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11920. type: string
  11921. type: object
  11922. privateKeySecretRef:
  11923. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  11924. properties:
  11925. key:
  11926. description: |-
  11927. A key in the referenced Secret.
  11928. Some instances of this field may be defaulted, in others it may be required.
  11929. maxLength: 253
  11930. minLength: 1
  11931. pattern: ^[-._a-zA-Z0-9]+$
  11932. type: string
  11933. name:
  11934. description: The name of the Secret resource being referred to.
  11935. maxLength: 253
  11936. minLength: 1
  11937. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11938. type: string
  11939. namespace:
  11940. description: |-
  11941. The namespace of the Secret resource being referred to.
  11942. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11943. maxLength: 63
  11944. minLength: 1
  11945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11946. type: string
  11947. type: object
  11948. required:
  11949. - passwordSecretRef
  11950. - privateKeySecretRef
  11951. type: object
  11952. host:
  11953. description: Host defines the Passbolt Server to connect to
  11954. type: string
  11955. required:
  11956. - auth
  11957. - host
  11958. type: object
  11959. passworddepot:
  11960. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  11961. properties:
  11962. auth:
  11963. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  11964. properties:
  11965. secretRef:
  11966. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  11967. properties:
  11968. credentials:
  11969. description: Username / Password is used for authentication.
  11970. properties:
  11971. key:
  11972. description: |-
  11973. A key in the referenced Secret.
  11974. Some instances of this field may be defaulted, in others it may be required.
  11975. maxLength: 253
  11976. minLength: 1
  11977. pattern: ^[-._a-zA-Z0-9]+$
  11978. type: string
  11979. name:
  11980. description: The name of the Secret resource being referred to.
  11981. maxLength: 253
  11982. minLength: 1
  11983. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11984. type: string
  11985. namespace:
  11986. description: |-
  11987. The namespace of the Secret resource being referred to.
  11988. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11989. maxLength: 63
  11990. minLength: 1
  11991. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11992. type: string
  11993. type: object
  11994. type: object
  11995. required:
  11996. - secretRef
  11997. type: object
  11998. database:
  11999. description: Database to use as source
  12000. type: string
  12001. host:
  12002. description: URL configures the Password Depot instance URL.
  12003. type: string
  12004. required:
  12005. - auth
  12006. - database
  12007. - host
  12008. type: object
  12009. previder:
  12010. description: Previder configures this store to sync secrets using the Previder provider
  12011. properties:
  12012. auth:
  12013. description: PreviderAuth contains a secretRef for credentials.
  12014. properties:
  12015. secretRef:
  12016. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  12017. properties:
  12018. accessToken:
  12019. description: The AccessToken is used for authentication
  12020. properties:
  12021. key:
  12022. description: |-
  12023. A key in the referenced Secret.
  12024. Some instances of this field may be defaulted, in others it may be required.
  12025. maxLength: 253
  12026. minLength: 1
  12027. pattern: ^[-._a-zA-Z0-9]+$
  12028. type: string
  12029. name:
  12030. description: The name of the Secret resource being referred to.
  12031. maxLength: 253
  12032. minLength: 1
  12033. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12034. type: string
  12035. namespace:
  12036. description: |-
  12037. The namespace of the Secret resource being referred to.
  12038. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12039. maxLength: 63
  12040. minLength: 1
  12041. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12042. type: string
  12043. type: object
  12044. required:
  12045. - accessToken
  12046. type: object
  12047. type: object
  12048. baseUri:
  12049. type: string
  12050. required:
  12051. - auth
  12052. type: object
  12053. pulumi:
  12054. description: Pulumi configures this store to sync secrets using the Pulumi provider
  12055. properties:
  12056. accessToken:
  12057. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  12058. properties:
  12059. secretRef:
  12060. description: SecretRef is a reference to a secret containing the Pulumi API token.
  12061. properties:
  12062. key:
  12063. description: |-
  12064. A key in the referenced Secret.
  12065. Some instances of this field may be defaulted, in others it may be required.
  12066. maxLength: 253
  12067. minLength: 1
  12068. pattern: ^[-._a-zA-Z0-9]+$
  12069. type: string
  12070. name:
  12071. description: The name of the Secret resource being referred to.
  12072. maxLength: 253
  12073. minLength: 1
  12074. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12075. type: string
  12076. namespace:
  12077. description: |-
  12078. The namespace of the Secret resource being referred to.
  12079. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12080. maxLength: 63
  12081. minLength: 1
  12082. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12083. type: string
  12084. type: object
  12085. type: object
  12086. apiUrl:
  12087. default: https://api.pulumi.com/api/esc
  12088. description: APIURL is the URL of the Pulumi API.
  12089. type: string
  12090. environment:
  12091. description: |-
  12092. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  12093. dynamically retrieved values from supported providers including all major clouds,
  12094. and other Pulumi ESC environments.
  12095. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  12096. type: string
  12097. organization:
  12098. description: |-
  12099. Organization are a space to collaborate on shared projects and stacks.
  12100. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  12101. type: string
  12102. project:
  12103. description: Project is the name of the Pulumi ESC project the environment belongs to.
  12104. type: string
  12105. required:
  12106. - accessToken
  12107. - environment
  12108. - organization
  12109. - project
  12110. type: object
  12111. scaleway:
  12112. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  12113. properties:
  12114. accessKey:
  12115. description: AccessKey is the non-secret part of the api key.
  12116. properties:
  12117. secretRef:
  12118. description: SecretRef references a key in a secret that will be used as value.
  12119. properties:
  12120. key:
  12121. description: |-
  12122. A key in the referenced Secret.
  12123. Some instances of this field may be defaulted, in others it may be required.
  12124. maxLength: 253
  12125. minLength: 1
  12126. pattern: ^[-._a-zA-Z0-9]+$
  12127. type: string
  12128. name:
  12129. description: The name of the Secret resource being referred to.
  12130. maxLength: 253
  12131. minLength: 1
  12132. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12133. type: string
  12134. namespace:
  12135. description: |-
  12136. The namespace of the Secret resource being referred to.
  12137. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12138. maxLength: 63
  12139. minLength: 1
  12140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12141. type: string
  12142. type: object
  12143. value:
  12144. description: Value can be specified directly to set a value without using a secret.
  12145. type: string
  12146. type: object
  12147. apiUrl:
  12148. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  12149. type: string
  12150. projectId:
  12151. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  12152. type: string
  12153. region:
  12154. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  12155. type: string
  12156. secretKey:
  12157. description: SecretKey is the non-secret part of the api key.
  12158. properties:
  12159. secretRef:
  12160. description: SecretRef references a key in a secret that will be used as value.
  12161. properties:
  12162. key:
  12163. description: |-
  12164. A key in the referenced Secret.
  12165. Some instances of this field may be defaulted, in others it may be required.
  12166. maxLength: 253
  12167. minLength: 1
  12168. pattern: ^[-._a-zA-Z0-9]+$
  12169. type: string
  12170. name:
  12171. description: The name of the Secret resource being referred to.
  12172. maxLength: 253
  12173. minLength: 1
  12174. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12175. type: string
  12176. namespace:
  12177. description: |-
  12178. The namespace of the Secret resource being referred to.
  12179. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12180. maxLength: 63
  12181. minLength: 1
  12182. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12183. type: string
  12184. type: object
  12185. value:
  12186. description: Value can be specified directly to set a value without using a secret.
  12187. type: string
  12188. type: object
  12189. required:
  12190. - accessKey
  12191. - projectId
  12192. - region
  12193. - secretKey
  12194. type: object
  12195. secretserver:
  12196. description: |-
  12197. SecretServer configures this store to sync secrets using SecretServer provider
  12198. https://docs.delinea.com/online-help/secret-server/start.htm
  12199. properties:
  12200. password:
  12201. description: Password is the secret server account password.
  12202. properties:
  12203. secretRef:
  12204. description: SecretRef references a key in a secret that will be used as value.
  12205. properties:
  12206. key:
  12207. description: |-
  12208. A key in the referenced Secret.
  12209. Some instances of this field may be defaulted, in others it may be required.
  12210. maxLength: 253
  12211. minLength: 1
  12212. pattern: ^[-._a-zA-Z0-9]+$
  12213. type: string
  12214. name:
  12215. description: The name of the Secret resource being referred to.
  12216. maxLength: 253
  12217. minLength: 1
  12218. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12219. type: string
  12220. namespace:
  12221. description: |-
  12222. The namespace of the Secret resource being referred to.
  12223. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12224. maxLength: 63
  12225. minLength: 1
  12226. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12227. type: string
  12228. type: object
  12229. value:
  12230. description: Value can be specified directly to set a value without using a secret.
  12231. type: string
  12232. type: object
  12233. serverURL:
  12234. description: |-
  12235. ServerURL
  12236. URL to your secret server installation
  12237. type: string
  12238. username:
  12239. description: Username is the secret server account username.
  12240. properties:
  12241. secretRef:
  12242. description: SecretRef references a key in a secret that will be used as value.
  12243. properties:
  12244. key:
  12245. description: |-
  12246. A key in the referenced Secret.
  12247. Some instances of this field may be defaulted, in others it may be required.
  12248. maxLength: 253
  12249. minLength: 1
  12250. pattern: ^[-._a-zA-Z0-9]+$
  12251. type: string
  12252. name:
  12253. description: The name of the Secret resource being referred to.
  12254. maxLength: 253
  12255. minLength: 1
  12256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12257. type: string
  12258. namespace:
  12259. description: |-
  12260. The namespace of the Secret resource being referred to.
  12261. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12262. maxLength: 63
  12263. minLength: 1
  12264. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12265. type: string
  12266. type: object
  12267. value:
  12268. description: Value can be specified directly to set a value without using a secret.
  12269. type: string
  12270. type: object
  12271. required:
  12272. - password
  12273. - serverURL
  12274. - username
  12275. type: object
  12276. senhasegura:
  12277. description: Senhasegura configures this store to sync secrets using senhasegura provider
  12278. properties:
  12279. auth:
  12280. description: Auth defines parameters to authenticate in senhasegura
  12281. properties:
  12282. clientId:
  12283. type: string
  12284. clientSecretSecretRef:
  12285. description: |-
  12286. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  12287. In some instances, `key` is a required field.
  12288. properties:
  12289. key:
  12290. description: |-
  12291. A key in the referenced Secret.
  12292. Some instances of this field may be defaulted, in others it may be required.
  12293. maxLength: 253
  12294. minLength: 1
  12295. pattern: ^[-._a-zA-Z0-9]+$
  12296. type: string
  12297. name:
  12298. description: The name of the Secret resource being referred to.
  12299. maxLength: 253
  12300. minLength: 1
  12301. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12302. type: string
  12303. namespace:
  12304. description: |-
  12305. The namespace of the Secret resource being referred to.
  12306. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12307. maxLength: 63
  12308. minLength: 1
  12309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12310. type: string
  12311. type: object
  12312. required:
  12313. - clientId
  12314. - clientSecretSecretRef
  12315. type: object
  12316. ignoreSslCertificate:
  12317. default: false
  12318. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  12319. type: boolean
  12320. module:
  12321. description: Module defines which senhasegura module should be used to get secrets
  12322. type: string
  12323. url:
  12324. description: URL of senhasegura
  12325. type: string
  12326. required:
  12327. - auth
  12328. - module
  12329. - url
  12330. type: object
  12331. vault:
  12332. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  12333. properties:
  12334. auth:
  12335. description: Auth configures how secret-manager authenticates with the Vault server.
  12336. properties:
  12337. appRole:
  12338. description: |-
  12339. AppRole authenticates with Vault using the App Role auth mechanism,
  12340. with the role and secret stored in a Kubernetes Secret resource.
  12341. properties:
  12342. path:
  12343. default: approle
  12344. description: |-
  12345. Path where the App Role authentication backend is mounted
  12346. in Vault, e.g: "approle"
  12347. type: string
  12348. roleId:
  12349. description: |-
  12350. RoleID configured in the App Role authentication backend when setting
  12351. up the authentication backend in Vault.
  12352. type: string
  12353. roleRef:
  12354. description: |-
  12355. Reference to a key in a Secret that contains the App Role ID used
  12356. to authenticate with Vault.
  12357. The `key` field must be specified and denotes which entry within the Secret
  12358. resource is used as the app role id.
  12359. properties:
  12360. key:
  12361. description: |-
  12362. A key in the referenced Secret.
  12363. Some instances of this field may be defaulted, in others it may be required.
  12364. maxLength: 253
  12365. minLength: 1
  12366. pattern: ^[-._a-zA-Z0-9]+$
  12367. type: string
  12368. name:
  12369. description: The name of the Secret resource being referred to.
  12370. maxLength: 253
  12371. minLength: 1
  12372. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12373. type: string
  12374. namespace:
  12375. description: |-
  12376. The namespace of the Secret resource being referred to.
  12377. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12378. maxLength: 63
  12379. minLength: 1
  12380. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12381. type: string
  12382. type: object
  12383. secretRef:
  12384. description: |-
  12385. Reference to a key in a Secret that contains the App Role secret used
  12386. to authenticate with Vault.
  12387. The `key` field must be specified and denotes which entry within the Secret
  12388. resource is used as the app role secret.
  12389. properties:
  12390. key:
  12391. description: |-
  12392. A key in the referenced Secret.
  12393. Some instances of this field may be defaulted, in others it may be required.
  12394. maxLength: 253
  12395. minLength: 1
  12396. pattern: ^[-._a-zA-Z0-9]+$
  12397. type: string
  12398. name:
  12399. description: The name of the Secret resource being referred to.
  12400. maxLength: 253
  12401. minLength: 1
  12402. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12403. type: string
  12404. namespace:
  12405. description: |-
  12406. The namespace of the Secret resource being referred to.
  12407. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12408. maxLength: 63
  12409. minLength: 1
  12410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12411. type: string
  12412. type: object
  12413. required:
  12414. - path
  12415. - secretRef
  12416. type: object
  12417. cert:
  12418. description: |-
  12419. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  12420. Cert authentication method
  12421. properties:
  12422. clientCert:
  12423. description: |-
  12424. ClientCert is a certificate to authenticate using the Cert Vault
  12425. authentication method
  12426. properties:
  12427. key:
  12428. description: |-
  12429. A key in the referenced Secret.
  12430. Some instances of this field may be defaulted, in others it may be required.
  12431. maxLength: 253
  12432. minLength: 1
  12433. pattern: ^[-._a-zA-Z0-9]+$
  12434. type: string
  12435. name:
  12436. description: The name of the Secret resource being referred to.
  12437. maxLength: 253
  12438. minLength: 1
  12439. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12440. type: string
  12441. namespace:
  12442. description: |-
  12443. The namespace of the Secret resource being referred to.
  12444. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12445. maxLength: 63
  12446. minLength: 1
  12447. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12448. type: string
  12449. type: object
  12450. secretRef:
  12451. description: |-
  12452. SecretRef to a key in a Secret resource containing client private key to
  12453. authenticate with Vault using the Cert authentication method
  12454. properties:
  12455. key:
  12456. description: |-
  12457. A key in the referenced Secret.
  12458. Some instances of this field may be defaulted, in others it may be required.
  12459. maxLength: 253
  12460. minLength: 1
  12461. pattern: ^[-._a-zA-Z0-9]+$
  12462. type: string
  12463. name:
  12464. description: The name of the Secret resource being referred to.
  12465. maxLength: 253
  12466. minLength: 1
  12467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12468. type: string
  12469. namespace:
  12470. description: |-
  12471. The namespace of the Secret resource being referred to.
  12472. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12473. maxLength: 63
  12474. minLength: 1
  12475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12476. type: string
  12477. type: object
  12478. type: object
  12479. iam:
  12480. description: |-
  12481. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  12482. AWS IAM authentication method
  12483. properties:
  12484. externalID:
  12485. description: AWS External ID set on assumed IAM roles
  12486. type: string
  12487. jwt:
  12488. description: Specify a service account with IRSA enabled
  12489. properties:
  12490. serviceAccountRef:
  12491. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  12492. properties:
  12493. audiences:
  12494. description: |-
  12495. Audience specifies the `aud` claim for the service account token
  12496. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12497. then this audiences will be appended to the list
  12498. items:
  12499. type: string
  12500. type: array
  12501. name:
  12502. description: The name of the ServiceAccount resource being referred to.
  12503. maxLength: 253
  12504. minLength: 1
  12505. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12506. type: string
  12507. namespace:
  12508. description: |-
  12509. Namespace of the resource being referred to.
  12510. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12511. maxLength: 63
  12512. minLength: 1
  12513. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12514. type: string
  12515. required:
  12516. - name
  12517. type: object
  12518. type: object
  12519. path:
  12520. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  12521. type: string
  12522. region:
  12523. description: AWS region
  12524. type: string
  12525. role:
  12526. description: This is the AWS role to be assumed before talking to vault
  12527. type: string
  12528. secretRef:
  12529. description: Specify credentials in a Secret object
  12530. properties:
  12531. accessKeyIDSecretRef:
  12532. description: The AccessKeyID is used for authentication
  12533. properties:
  12534. key:
  12535. description: |-
  12536. A key in the referenced Secret.
  12537. Some instances of this field may be defaulted, in others it may be required.
  12538. maxLength: 253
  12539. minLength: 1
  12540. pattern: ^[-._a-zA-Z0-9]+$
  12541. type: string
  12542. name:
  12543. description: The name of the Secret resource being referred to.
  12544. maxLength: 253
  12545. minLength: 1
  12546. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12547. type: string
  12548. namespace:
  12549. description: |-
  12550. The namespace of the Secret resource being referred to.
  12551. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12552. maxLength: 63
  12553. minLength: 1
  12554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12555. type: string
  12556. type: object
  12557. secretAccessKeySecretRef:
  12558. description: The SecretAccessKey is used for authentication
  12559. properties:
  12560. key:
  12561. description: |-
  12562. A key in the referenced Secret.
  12563. Some instances of this field may be defaulted, in others it may be required.
  12564. maxLength: 253
  12565. minLength: 1
  12566. pattern: ^[-._a-zA-Z0-9]+$
  12567. type: string
  12568. name:
  12569. description: The name of the Secret resource being referred to.
  12570. maxLength: 253
  12571. minLength: 1
  12572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12573. type: string
  12574. namespace:
  12575. description: |-
  12576. The namespace of the Secret resource being referred to.
  12577. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12578. maxLength: 63
  12579. minLength: 1
  12580. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12581. type: string
  12582. type: object
  12583. sessionTokenSecretRef:
  12584. description: |-
  12585. The SessionToken used for authentication
  12586. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  12587. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  12588. properties:
  12589. key:
  12590. description: |-
  12591. A key in the referenced Secret.
  12592. Some instances of this field may be defaulted, in others it may be required.
  12593. maxLength: 253
  12594. minLength: 1
  12595. pattern: ^[-._a-zA-Z0-9]+$
  12596. type: string
  12597. name:
  12598. description: The name of the Secret resource being referred to.
  12599. maxLength: 253
  12600. minLength: 1
  12601. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12602. type: string
  12603. namespace:
  12604. description: |-
  12605. The namespace of the Secret resource being referred to.
  12606. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12607. maxLength: 63
  12608. minLength: 1
  12609. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12610. type: string
  12611. type: object
  12612. type: object
  12613. vaultAwsIamServerID:
  12614. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  12615. type: string
  12616. vaultRole:
  12617. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  12618. type: string
  12619. required:
  12620. - vaultRole
  12621. type: object
  12622. jwt:
  12623. description: |-
  12624. Jwt authenticates with Vault by passing role and JWT token using the
  12625. JWT/OIDC authentication method
  12626. properties:
  12627. kubernetesServiceAccountToken:
  12628. description: |-
  12629. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  12630. a token for with the `TokenRequest` API.
  12631. properties:
  12632. audiences:
  12633. description: |-
  12634. Optional audiences field that will be used to request a temporary Kubernetes service
  12635. account token for the service account referenced by `serviceAccountRef`.
  12636. Defaults to a single audience `vault` it not specified.
  12637. Deprecated: use serviceAccountRef.Audiences instead
  12638. items:
  12639. type: string
  12640. type: array
  12641. expirationSeconds:
  12642. description: |-
  12643. Optional expiration time in seconds that will be used to request a temporary
  12644. Kubernetes service account token for the service account referenced by
  12645. `serviceAccountRef`.
  12646. Deprecated: this will be removed in the future.
  12647. Defaults to 10 minutes.
  12648. format: int64
  12649. type: integer
  12650. serviceAccountRef:
  12651. description: Service account field containing the name of a kubernetes ServiceAccount.
  12652. properties:
  12653. audiences:
  12654. description: |-
  12655. Audience specifies the `aud` claim for the service account token
  12656. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12657. then this audiences will be appended to the list
  12658. items:
  12659. type: string
  12660. type: array
  12661. name:
  12662. description: The name of the ServiceAccount resource being referred to.
  12663. maxLength: 253
  12664. minLength: 1
  12665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12666. type: string
  12667. namespace:
  12668. description: |-
  12669. Namespace of the resource being referred to.
  12670. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12671. maxLength: 63
  12672. minLength: 1
  12673. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12674. type: string
  12675. required:
  12676. - name
  12677. type: object
  12678. required:
  12679. - serviceAccountRef
  12680. type: object
  12681. path:
  12682. default: jwt
  12683. description: |-
  12684. Path where the JWT authentication backend is mounted
  12685. in Vault, e.g: "jwt"
  12686. type: string
  12687. role:
  12688. description: |-
  12689. Role is a JWT role to authenticate using the JWT/OIDC Vault
  12690. authentication method
  12691. type: string
  12692. secretRef:
  12693. description: |-
  12694. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  12695. authenticate with Vault using the JWT/OIDC authentication method.
  12696. properties:
  12697. key:
  12698. description: |-
  12699. A key in the referenced Secret.
  12700. Some instances of this field may be defaulted, in others it may be required.
  12701. maxLength: 253
  12702. minLength: 1
  12703. pattern: ^[-._a-zA-Z0-9]+$
  12704. type: string
  12705. name:
  12706. description: The name of the Secret resource being referred to.
  12707. maxLength: 253
  12708. minLength: 1
  12709. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12710. type: string
  12711. namespace:
  12712. description: |-
  12713. The namespace of the Secret resource being referred to.
  12714. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12715. maxLength: 63
  12716. minLength: 1
  12717. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12718. type: string
  12719. type: object
  12720. required:
  12721. - path
  12722. type: object
  12723. kubernetes:
  12724. description: |-
  12725. Kubernetes authenticates with Vault by passing the ServiceAccount
  12726. token stored in the named Secret resource to the Vault server.
  12727. properties:
  12728. mountPath:
  12729. default: kubernetes
  12730. description: |-
  12731. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  12732. "kubernetes"
  12733. type: string
  12734. role:
  12735. description: |-
  12736. A required field containing the Vault Role to assume. A Role binds a
  12737. Kubernetes ServiceAccount with a set of Vault policies.
  12738. type: string
  12739. secretRef:
  12740. description: |-
  12741. Optional secret field containing a Kubernetes ServiceAccount JWT used
  12742. for authenticating with Vault. If a name is specified without a key,
  12743. `token` is the default. If one is not specified, the one bound to
  12744. the controller will be used.
  12745. properties:
  12746. key:
  12747. description: |-
  12748. A key in the referenced Secret.
  12749. Some instances of this field may be defaulted, in others it may be required.
  12750. maxLength: 253
  12751. minLength: 1
  12752. pattern: ^[-._a-zA-Z0-9]+$
  12753. type: string
  12754. name:
  12755. description: The name of the Secret resource being referred to.
  12756. maxLength: 253
  12757. minLength: 1
  12758. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12759. type: string
  12760. namespace:
  12761. description: |-
  12762. The namespace of the Secret resource being referred to.
  12763. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12764. maxLength: 63
  12765. minLength: 1
  12766. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12767. type: string
  12768. type: object
  12769. serviceAccountRef:
  12770. description: |-
  12771. Optional service account field containing the name of a kubernetes ServiceAccount.
  12772. If the service account is specified, the service account secret token JWT will be used
  12773. for authenticating with Vault. If the service account selector is not supplied,
  12774. the secretRef will be used instead.
  12775. properties:
  12776. audiences:
  12777. description: |-
  12778. Audience specifies the `aud` claim for the service account token
  12779. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12780. then this audiences will be appended to the list
  12781. items:
  12782. type: string
  12783. type: array
  12784. name:
  12785. description: The name of the ServiceAccount resource being referred to.
  12786. maxLength: 253
  12787. minLength: 1
  12788. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12789. type: string
  12790. namespace:
  12791. description: |-
  12792. Namespace of the resource being referred to.
  12793. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12794. maxLength: 63
  12795. minLength: 1
  12796. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12797. type: string
  12798. required:
  12799. - name
  12800. type: object
  12801. required:
  12802. - mountPath
  12803. - role
  12804. type: object
  12805. ldap:
  12806. description: |-
  12807. Ldap authenticates with Vault by passing username/password pair using
  12808. the LDAP authentication method
  12809. properties:
  12810. path:
  12811. default: ldap
  12812. description: |-
  12813. Path where the LDAP authentication backend is mounted
  12814. in Vault, e.g: "ldap"
  12815. type: string
  12816. secretRef:
  12817. description: |-
  12818. SecretRef to a key in a Secret resource containing password for the LDAP
  12819. user used to authenticate with Vault using the LDAP authentication
  12820. method
  12821. properties:
  12822. key:
  12823. description: |-
  12824. A key in the referenced Secret.
  12825. Some instances of this field may be defaulted, in others it may be required.
  12826. maxLength: 253
  12827. minLength: 1
  12828. pattern: ^[-._a-zA-Z0-9]+$
  12829. type: string
  12830. name:
  12831. description: The name of the Secret resource being referred to.
  12832. maxLength: 253
  12833. minLength: 1
  12834. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12835. type: string
  12836. namespace:
  12837. description: |-
  12838. The namespace of the Secret resource being referred to.
  12839. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12840. maxLength: 63
  12841. minLength: 1
  12842. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12843. type: string
  12844. type: object
  12845. username:
  12846. description: |-
  12847. Username is an LDAP username used to authenticate using the LDAP Vault
  12848. authentication method
  12849. type: string
  12850. required:
  12851. - path
  12852. - username
  12853. type: object
  12854. namespace:
  12855. description: |-
  12856. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  12857. Namespaces is a set of features within Vault Enterprise that allows
  12858. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  12859. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  12860. This will default to Vault.Namespace field if set, or empty otherwise
  12861. type: string
  12862. tokenSecretRef:
  12863. description: TokenSecretRef authenticates with Vault by presenting a token.
  12864. properties:
  12865. key:
  12866. description: |-
  12867. A key in the referenced Secret.
  12868. Some instances of this field may be defaulted, in others it may be required.
  12869. maxLength: 253
  12870. minLength: 1
  12871. pattern: ^[-._a-zA-Z0-9]+$
  12872. type: string
  12873. name:
  12874. description: The name of the Secret resource being referred to.
  12875. maxLength: 253
  12876. minLength: 1
  12877. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12878. type: string
  12879. namespace:
  12880. description: |-
  12881. The namespace of the Secret resource being referred to.
  12882. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12883. maxLength: 63
  12884. minLength: 1
  12885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12886. type: string
  12887. type: object
  12888. userPass:
  12889. description: UserPass authenticates with Vault by passing username/password pair
  12890. properties:
  12891. path:
  12892. default: userpass
  12893. description: |-
  12894. Path where the UserPassword authentication backend is mounted
  12895. in Vault, e.g: "userpass"
  12896. type: string
  12897. secretRef:
  12898. description: |-
  12899. SecretRef to a key in a Secret resource containing password for the
  12900. user used to authenticate with Vault using the UserPass authentication
  12901. method
  12902. properties:
  12903. key:
  12904. description: |-
  12905. A key in the referenced Secret.
  12906. Some instances of this field may be defaulted, in others it may be required.
  12907. maxLength: 253
  12908. minLength: 1
  12909. pattern: ^[-._a-zA-Z0-9]+$
  12910. type: string
  12911. name:
  12912. description: The name of the Secret resource being referred to.
  12913. maxLength: 253
  12914. minLength: 1
  12915. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12916. type: string
  12917. namespace:
  12918. description: |-
  12919. The namespace of the Secret resource being referred to.
  12920. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12921. maxLength: 63
  12922. minLength: 1
  12923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12924. type: string
  12925. type: object
  12926. username:
  12927. description: |-
  12928. Username is a username used to authenticate using the UserPass Vault
  12929. authentication method
  12930. type: string
  12931. required:
  12932. - path
  12933. - username
  12934. type: object
  12935. type: object
  12936. caBundle:
  12937. description: |-
  12938. PEM encoded CA bundle used to validate Vault server certificate. Only used
  12939. if the Server URL is using HTTPS protocol. This parameter is ignored for
  12940. plain HTTP protocol connection. If not set the system root certificates
  12941. are used to validate the TLS connection.
  12942. format: byte
  12943. type: string
  12944. caProvider:
  12945. description: The provider for the CA bundle to use to validate Vault server certificate.
  12946. properties:
  12947. key:
  12948. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  12949. maxLength: 253
  12950. minLength: 1
  12951. pattern: ^[-._a-zA-Z0-9]+$
  12952. type: string
  12953. name:
  12954. description: The name of the object located at the provider type.
  12955. maxLength: 253
  12956. minLength: 1
  12957. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12958. type: string
  12959. namespace:
  12960. description: |-
  12961. The namespace the Provider type is in.
  12962. Can only be defined when used in a ClusterSecretStore.
  12963. maxLength: 63
  12964. minLength: 1
  12965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12966. type: string
  12967. type:
  12968. description: The type of provider to use such as "Secret", or "ConfigMap".
  12969. enum:
  12970. - Secret
  12971. - ConfigMap
  12972. type: string
  12973. required:
  12974. - name
  12975. - type
  12976. type: object
  12977. forwardInconsistent:
  12978. description: |-
  12979. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  12980. leader instead of simply retrying within a loop. This can increase performance if
  12981. the option is enabled serverside.
  12982. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  12983. type: boolean
  12984. headers:
  12985. additionalProperties:
  12986. type: string
  12987. description: Headers to be added in Vault request
  12988. type: object
  12989. namespace:
  12990. description: |-
  12991. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  12992. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  12993. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  12994. type: string
  12995. path:
  12996. description: |-
  12997. Path is the mount path of the Vault KV backend endpoint, e.g:
  12998. "secret". The v2 KV secret engine version specific "/data" path suffix
  12999. for fetching secrets from Vault is optional and will be appended
  13000. if not present in specified path.
  13001. type: string
  13002. readYourWrites:
  13003. description: |-
  13004. ReadYourWrites ensures isolated read-after-write semantics by
  13005. providing discovered cluster replication states in each request.
  13006. More information about eventual consistency in Vault can be found here
  13007. https://www.vaultproject.io/docs/enterprise/consistency
  13008. type: boolean
  13009. server:
  13010. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  13011. type: string
  13012. tls:
  13013. description: |-
  13014. The configuration used for client side related TLS communication, when the Vault server
  13015. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  13016. This parameter is ignored for plain HTTP protocol connection.
  13017. It's worth noting this configuration is different from the "TLS certificates auth method",
  13018. which is available under the `auth.cert` section.
  13019. properties:
  13020. certSecretRef:
  13021. description: |-
  13022. CertSecretRef is a certificate added to the transport layer
  13023. when communicating with the Vault server.
  13024. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  13025. properties:
  13026. key:
  13027. description: |-
  13028. A key in the referenced Secret.
  13029. Some instances of this field may be defaulted, in others it may be required.
  13030. maxLength: 253
  13031. minLength: 1
  13032. pattern: ^[-._a-zA-Z0-9]+$
  13033. type: string
  13034. name:
  13035. description: The name of the Secret resource being referred to.
  13036. maxLength: 253
  13037. minLength: 1
  13038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13039. type: string
  13040. namespace:
  13041. description: |-
  13042. The namespace of the Secret resource being referred to.
  13043. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13044. maxLength: 63
  13045. minLength: 1
  13046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13047. type: string
  13048. type: object
  13049. keySecretRef:
  13050. description: |-
  13051. KeySecretRef to a key in a Secret resource containing client private key
  13052. added to the transport layer when communicating with the Vault server.
  13053. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  13054. properties:
  13055. key:
  13056. description: |-
  13057. A key in the referenced Secret.
  13058. Some instances of this field may be defaulted, in others it may be required.
  13059. maxLength: 253
  13060. minLength: 1
  13061. pattern: ^[-._a-zA-Z0-9]+$
  13062. type: string
  13063. name:
  13064. description: The name of the Secret resource being referred to.
  13065. maxLength: 253
  13066. minLength: 1
  13067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13068. type: string
  13069. namespace:
  13070. description: |-
  13071. The namespace of the Secret resource being referred to.
  13072. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13073. maxLength: 63
  13074. minLength: 1
  13075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13076. type: string
  13077. type: object
  13078. type: object
  13079. version:
  13080. default: v2
  13081. description: |-
  13082. Version is the Vault KV secret engine version. This can be either "v1" or
  13083. "v2". Version defaults to "v2".
  13084. enum:
  13085. - v1
  13086. - v2
  13087. type: string
  13088. required:
  13089. - server
  13090. type: object
  13091. webhook:
  13092. description: Webhook configures this store to sync secrets using a generic templated webhook
  13093. properties:
  13094. auth:
  13095. description: Auth specifies a authorization protocol. Only one protocol may be set.
  13096. maxProperties: 1
  13097. minProperties: 1
  13098. properties:
  13099. ntlm:
  13100. description: NTLMProtocol configures the store to use NTLM for auth
  13101. properties:
  13102. passwordSecret:
  13103. description: |-
  13104. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13105. In some instances, `key` is a required field.
  13106. properties:
  13107. key:
  13108. description: |-
  13109. A key in the referenced Secret.
  13110. Some instances of this field may be defaulted, in others it may be required.
  13111. maxLength: 253
  13112. minLength: 1
  13113. pattern: ^[-._a-zA-Z0-9]+$
  13114. type: string
  13115. name:
  13116. description: The name of the Secret resource being referred to.
  13117. maxLength: 253
  13118. minLength: 1
  13119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13120. type: string
  13121. namespace:
  13122. description: |-
  13123. The namespace of the Secret resource being referred to.
  13124. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13125. maxLength: 63
  13126. minLength: 1
  13127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13128. type: string
  13129. type: object
  13130. usernameSecret:
  13131. description: |-
  13132. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13133. In some instances, `key` is a required field.
  13134. properties:
  13135. key:
  13136. description: |-
  13137. A key in the referenced Secret.
  13138. Some instances of this field may be defaulted, in others it may be required.
  13139. maxLength: 253
  13140. minLength: 1
  13141. pattern: ^[-._a-zA-Z0-9]+$
  13142. type: string
  13143. name:
  13144. description: The name of the Secret resource being referred to.
  13145. maxLength: 253
  13146. minLength: 1
  13147. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13148. type: string
  13149. namespace:
  13150. description: |-
  13151. The namespace of the Secret resource being referred to.
  13152. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13153. maxLength: 63
  13154. minLength: 1
  13155. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13156. type: string
  13157. type: object
  13158. required:
  13159. - passwordSecret
  13160. - usernameSecret
  13161. type: object
  13162. type: object
  13163. body:
  13164. description: Body
  13165. type: string
  13166. caBundle:
  13167. description: |-
  13168. PEM encoded CA bundle used to validate webhook server certificate. Only used
  13169. if the Server URL is using HTTPS protocol. This parameter is ignored for
  13170. plain HTTP protocol connection. If not set the system root certificates
  13171. are used to validate the TLS connection.
  13172. format: byte
  13173. type: string
  13174. caProvider:
  13175. description: The provider for the CA bundle to use to validate webhook server certificate.
  13176. properties:
  13177. key:
  13178. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  13179. maxLength: 253
  13180. minLength: 1
  13181. pattern: ^[-._a-zA-Z0-9]+$
  13182. type: string
  13183. name:
  13184. description: The name of the object located at the provider type.
  13185. maxLength: 253
  13186. minLength: 1
  13187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13188. type: string
  13189. namespace:
  13190. description: The namespace the Provider type is in.
  13191. maxLength: 63
  13192. minLength: 1
  13193. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13194. type: string
  13195. type:
  13196. description: The type of provider to use such as "Secret", or "ConfigMap".
  13197. enum:
  13198. - Secret
  13199. - ConfigMap
  13200. type: string
  13201. required:
  13202. - name
  13203. - type
  13204. type: object
  13205. headers:
  13206. additionalProperties:
  13207. type: string
  13208. description: Headers
  13209. type: object
  13210. method:
  13211. description: Webhook Method
  13212. type: string
  13213. result:
  13214. description: Result formatting
  13215. properties:
  13216. jsonPath:
  13217. description: Json path of return value
  13218. type: string
  13219. type: object
  13220. secrets:
  13221. description: |-
  13222. Secrets to fill in templates
  13223. These secrets will be passed to the templating function as key value pairs under the given name
  13224. items:
  13225. description: WebhookSecret defines a secret to be used in webhook templates.
  13226. properties:
  13227. name:
  13228. description: Name of this secret in templates
  13229. type: string
  13230. secretRef:
  13231. description: Secret ref to fill in credentials
  13232. properties:
  13233. key:
  13234. description: |-
  13235. A key in the referenced Secret.
  13236. Some instances of this field may be defaulted, in others it may be required.
  13237. maxLength: 253
  13238. minLength: 1
  13239. pattern: ^[-._a-zA-Z0-9]+$
  13240. type: string
  13241. name:
  13242. description: The name of the Secret resource being referred to.
  13243. maxLength: 253
  13244. minLength: 1
  13245. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13246. type: string
  13247. namespace:
  13248. description: |-
  13249. The namespace of the Secret resource being referred to.
  13250. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13251. maxLength: 63
  13252. minLength: 1
  13253. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13254. type: string
  13255. type: object
  13256. required:
  13257. - name
  13258. - secretRef
  13259. type: object
  13260. type: array
  13261. timeout:
  13262. description: Timeout
  13263. type: string
  13264. url:
  13265. description: Webhook url to call
  13266. type: string
  13267. required:
  13268. - result
  13269. - url
  13270. type: object
  13271. yandexcertificatemanager:
  13272. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  13273. properties:
  13274. apiEndpoint:
  13275. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13276. type: string
  13277. auth:
  13278. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  13279. properties:
  13280. authorizedKeySecretRef:
  13281. description: The authorized key used for authentication
  13282. properties:
  13283. key:
  13284. description: |-
  13285. A key in the referenced Secret.
  13286. Some instances of this field may be defaulted, in others it may be required.
  13287. maxLength: 253
  13288. minLength: 1
  13289. pattern: ^[-._a-zA-Z0-9]+$
  13290. type: string
  13291. name:
  13292. description: The name of the Secret resource being referred to.
  13293. maxLength: 253
  13294. minLength: 1
  13295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13296. type: string
  13297. namespace:
  13298. description: |-
  13299. The namespace of the Secret resource being referred to.
  13300. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13301. maxLength: 63
  13302. minLength: 1
  13303. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13304. type: string
  13305. type: object
  13306. type: object
  13307. caProvider:
  13308. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13309. properties:
  13310. certSecretRef:
  13311. description: |-
  13312. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13313. In some instances, `key` is a required field.
  13314. properties:
  13315. key:
  13316. description: |-
  13317. A key in the referenced Secret.
  13318. Some instances of this field may be defaulted, in others it may be required.
  13319. maxLength: 253
  13320. minLength: 1
  13321. pattern: ^[-._a-zA-Z0-9]+$
  13322. type: string
  13323. name:
  13324. description: The name of the Secret resource being referred to.
  13325. maxLength: 253
  13326. minLength: 1
  13327. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13328. type: string
  13329. namespace:
  13330. description: |-
  13331. The namespace of the Secret resource being referred to.
  13332. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13333. maxLength: 63
  13334. minLength: 1
  13335. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13336. type: string
  13337. type: object
  13338. type: object
  13339. required:
  13340. - auth
  13341. type: object
  13342. yandexlockbox:
  13343. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  13344. properties:
  13345. apiEndpoint:
  13346. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13347. type: string
  13348. auth:
  13349. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  13350. properties:
  13351. authorizedKeySecretRef:
  13352. description: The authorized key used for authentication
  13353. properties:
  13354. key:
  13355. description: |-
  13356. A key in the referenced Secret.
  13357. Some instances of this field may be defaulted, in others it may be required.
  13358. maxLength: 253
  13359. minLength: 1
  13360. pattern: ^[-._a-zA-Z0-9]+$
  13361. type: string
  13362. name:
  13363. description: The name of the Secret resource being referred to.
  13364. maxLength: 253
  13365. minLength: 1
  13366. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13367. type: string
  13368. namespace:
  13369. description: |-
  13370. The namespace of the Secret resource being referred to.
  13371. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13372. maxLength: 63
  13373. minLength: 1
  13374. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13375. type: string
  13376. type: object
  13377. type: object
  13378. caProvider:
  13379. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13380. properties:
  13381. certSecretRef:
  13382. description: |-
  13383. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13384. In some instances, `key` is a required field.
  13385. properties:
  13386. key:
  13387. description: |-
  13388. A key in the referenced Secret.
  13389. Some instances of this field may be defaulted, in others it may be required.
  13390. maxLength: 253
  13391. minLength: 1
  13392. pattern: ^[-._a-zA-Z0-9]+$
  13393. type: string
  13394. name:
  13395. description: The name of the Secret resource being referred to.
  13396. maxLength: 253
  13397. minLength: 1
  13398. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13399. type: string
  13400. namespace:
  13401. description: |-
  13402. The namespace of the Secret resource being referred to.
  13403. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13404. maxLength: 63
  13405. minLength: 1
  13406. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13407. type: string
  13408. type: object
  13409. type: object
  13410. required:
  13411. - auth
  13412. type: object
  13413. type: object
  13414. refreshInterval:
  13415. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  13416. type: integer
  13417. retrySettings:
  13418. description: Used to configure HTTP retries on failures.
  13419. properties:
  13420. maxRetries:
  13421. description: MaxRetries is the maximum number of retry attempts.
  13422. format: int32
  13423. type: integer
  13424. retryInterval:
  13425. description: RetryInterval is the interval between retry attempts.
  13426. type: string
  13427. type: object
  13428. required:
  13429. - provider
  13430. type: object
  13431. status:
  13432. description: SecretStoreStatus defines the observed state of the SecretStore.
  13433. properties:
  13434. capabilities:
  13435. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  13436. type: string
  13437. conditions:
  13438. items:
  13439. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  13440. properties:
  13441. lastTransitionTime:
  13442. format: date-time
  13443. type: string
  13444. message:
  13445. type: string
  13446. reason:
  13447. type: string
  13448. status:
  13449. type: string
  13450. type:
  13451. description: SecretStoreConditionType represents the condition type of the SecretStore.
  13452. type: string
  13453. required:
  13454. - status
  13455. - type
  13456. type: object
  13457. type: array
  13458. type: object
  13459. type: object
  13460. served: false
  13461. storage: false
  13462. subresources:
  13463. status: {}
  13464. ---
  13465. apiVersion: apiextensions.k8s.io/v1
  13466. kind: CustomResourceDefinition
  13467. metadata:
  13468. annotations:
  13469. controller-gen.kubebuilder.io/version: v0.19.0
  13470. labels:
  13471. external-secrets.io/component: controller
  13472. name: externalsecrets.external-secrets.io
  13473. spec:
  13474. group: external-secrets.io
  13475. names:
  13476. categories:
  13477. - external-secrets
  13478. kind: ExternalSecret
  13479. listKind: ExternalSecretList
  13480. plural: externalsecrets
  13481. shortNames:
  13482. - es
  13483. singular: externalsecret
  13484. scope: Namespaced
  13485. versions:
  13486. - additionalPrinterColumns:
  13487. - jsonPath: .spec.secretStoreRef.kind
  13488. name: StoreType
  13489. type: string
  13490. - jsonPath: .spec.secretStoreRef.name
  13491. name: Store
  13492. type: string
  13493. - jsonPath: .spec.refreshInterval
  13494. name: Refresh Interval
  13495. type: string
  13496. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  13497. name: Status
  13498. type: string
  13499. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  13500. name: Ready
  13501. type: string
  13502. - jsonPath: .status.refreshTime
  13503. name: Last Sync
  13504. type: date
  13505. name: v1
  13506. schema:
  13507. openAPIV3Schema:
  13508. description: |-
  13509. ExternalSecret is the Schema for the external-secrets API.
  13510. It defines how to fetch data from external APIs and make it available as Kubernetes Secrets.
  13511. properties:
  13512. apiVersion:
  13513. description: |-
  13514. APIVersion defines the versioned schema of this representation of an object.
  13515. Servers should convert recognized schemas to the latest internal value, and
  13516. may reject unrecognized values.
  13517. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  13518. type: string
  13519. kind:
  13520. description: |-
  13521. Kind is a string value representing the REST resource this object represents.
  13522. Servers may infer this from the endpoint the client submits requests to.
  13523. Cannot be updated.
  13524. In CamelCase.
  13525. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  13526. type: string
  13527. metadata:
  13528. type: object
  13529. spec:
  13530. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  13531. properties:
  13532. data:
  13533. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  13534. items:
  13535. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  13536. properties:
  13537. remoteRef:
  13538. description: |-
  13539. RemoteRef points to the remote secret and defines
  13540. which secret (version/property/..) to fetch.
  13541. properties:
  13542. conversionStrategy:
  13543. default: Default
  13544. description: Used to define a conversion Strategy
  13545. enum:
  13546. - Default
  13547. - Unicode
  13548. type: string
  13549. decodingStrategy:
  13550. default: None
  13551. description: Used to define a decoding Strategy
  13552. enum:
  13553. - Auto
  13554. - Base64
  13555. - Base64URL
  13556. - None
  13557. type: string
  13558. key:
  13559. description: Key is the key used in the Provider, mandatory
  13560. type: string
  13561. metadataPolicy:
  13562. default: None
  13563. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13564. enum:
  13565. - None
  13566. - Fetch
  13567. type: string
  13568. nullBytePolicy:
  13569. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13570. enum:
  13571. - Ignore
  13572. - Fail
  13573. type: string
  13574. property:
  13575. description: Used to select a specific property of the Provider value (if a map), if supported
  13576. type: string
  13577. version:
  13578. description: Used to select a specific version of the Provider value, if supported
  13579. type: string
  13580. required:
  13581. - key
  13582. type: object
  13583. secretKey:
  13584. description: The key in the Kubernetes Secret to store the value.
  13585. maxLength: 253
  13586. minLength: 1
  13587. pattern: ^[-._a-zA-Z0-9]+$
  13588. type: string
  13589. sourceRef:
  13590. description: |-
  13591. SourceRef allows you to override the source
  13592. from which the value will be pulled.
  13593. maxProperties: 1
  13594. minProperties: 1
  13595. properties:
  13596. generatorRef:
  13597. description: |-
  13598. GeneratorRef points to a generator custom resource.
  13599. Deprecated: The generatorRef is not implemented in .data[].
  13600. this will be removed with v1.
  13601. properties:
  13602. apiVersion:
  13603. default: generators.external-secrets.io/v1alpha1
  13604. description: Specify the apiVersion of the generator resource
  13605. type: string
  13606. kind:
  13607. description: Specify the Kind of the generator resource
  13608. enum:
  13609. - ACRAccessToken
  13610. - BeyondtrustWorkloadCredentialsDynamicSecret
  13611. - ClusterGenerator
  13612. - CloudsmithAccessToken
  13613. - ECRAuthorizationToken
  13614. - Fake
  13615. - GCRAccessToken
  13616. - GithubAccessToken
  13617. - GitlabDeployToken
  13618. - QuayAccessToken
  13619. - Password
  13620. - SSHKey
  13621. - STSSessionToken
  13622. - UUID
  13623. - VaultDynamicSecret
  13624. - Webhook
  13625. - Grafana
  13626. - MFA
  13627. type: string
  13628. name:
  13629. description: Specify the name of the generator resource
  13630. maxLength: 253
  13631. minLength: 1
  13632. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13633. type: string
  13634. required:
  13635. - kind
  13636. - name
  13637. type: object
  13638. storeRef:
  13639. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13640. properties:
  13641. kind:
  13642. description: |-
  13643. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13644. Defaults to `SecretStore`
  13645. enum:
  13646. - SecretStore
  13647. - ClusterSecretStore
  13648. type: string
  13649. name:
  13650. description: Name of the SecretStore resource
  13651. maxLength: 253
  13652. minLength: 1
  13653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13654. type: string
  13655. type: object
  13656. type: object
  13657. required:
  13658. - remoteRef
  13659. - secretKey
  13660. type: object
  13661. type: array
  13662. dataFrom:
  13663. description: |-
  13664. DataFrom is used to fetch all properties from a specific Provider data
  13665. If multiple entries are specified, the Secret keys are merged in the specified order
  13666. items:
  13667. description: |-
  13668. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  13669. when using DataFrom to fetch multiple values from a Provider.
  13670. properties:
  13671. extract:
  13672. description: |-
  13673. Used to extract multiple key/value pairs from one secret
  13674. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13675. properties:
  13676. conversionStrategy:
  13677. default: Default
  13678. description: Used to define a conversion Strategy
  13679. enum:
  13680. - Default
  13681. - Unicode
  13682. type: string
  13683. decodingStrategy:
  13684. default: None
  13685. description: Used to define a decoding Strategy
  13686. enum:
  13687. - Auto
  13688. - Base64
  13689. - Base64URL
  13690. - None
  13691. type: string
  13692. key:
  13693. description: Key is the key used in the Provider, mandatory
  13694. type: string
  13695. metadataPolicy:
  13696. default: None
  13697. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13698. enum:
  13699. - None
  13700. - Fetch
  13701. type: string
  13702. nullBytePolicy:
  13703. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13704. enum:
  13705. - Ignore
  13706. - Fail
  13707. type: string
  13708. property:
  13709. description: Used to select a specific property of the Provider value (if a map), if supported
  13710. type: string
  13711. version:
  13712. description: Used to select a specific version of the Provider value, if supported
  13713. type: string
  13714. required:
  13715. - key
  13716. type: object
  13717. find:
  13718. description: |-
  13719. Used to find secrets based on tags or regular expressions
  13720. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13721. properties:
  13722. conversionStrategy:
  13723. default: Default
  13724. description: Used to define a conversion Strategy
  13725. enum:
  13726. - Default
  13727. - Unicode
  13728. type: string
  13729. decodingStrategy:
  13730. default: None
  13731. description: Used to define a decoding Strategy
  13732. enum:
  13733. - Auto
  13734. - Base64
  13735. - Base64URL
  13736. - None
  13737. type: string
  13738. name:
  13739. description: Finds secrets based on the name.
  13740. properties:
  13741. regexp:
  13742. description: Finds secrets base
  13743. type: string
  13744. type: object
  13745. nullBytePolicy:
  13746. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  13747. enum:
  13748. - Ignore
  13749. - Fail
  13750. type: string
  13751. path:
  13752. description: A root path to start the find operations.
  13753. type: string
  13754. tags:
  13755. additionalProperties:
  13756. type: string
  13757. description: Find secrets based on tags.
  13758. type: object
  13759. type: object
  13760. rewrite:
  13761. description: |-
  13762. Used to rewrite secret Keys after getting them from the secret Provider
  13763. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  13764. items:
  13765. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  13766. maxProperties: 1
  13767. minProperties: 1
  13768. properties:
  13769. merge:
  13770. description: |-
  13771. Used to merge key/values in one single Secret
  13772. The resulting key will contain all values from the specified secrets
  13773. properties:
  13774. conflictPolicy:
  13775. default: Error
  13776. description: Used to define the policy to use in conflict resolution.
  13777. enum:
  13778. - Ignore
  13779. - Error
  13780. type: string
  13781. into:
  13782. default: ""
  13783. description: |-
  13784. Used to define the target key of the merge operation.
  13785. Required if strategy is JSON. Ignored otherwise.
  13786. type: string
  13787. priority:
  13788. description: Used to define key priority in conflict resolution.
  13789. items:
  13790. type: string
  13791. type: array
  13792. priorityPolicy:
  13793. default: Strict
  13794. description: Used to define the policy when a key in the priority list does not exist in the input.
  13795. enum:
  13796. - IgnoreNotFound
  13797. - Strict
  13798. type: string
  13799. strategy:
  13800. default: Extract
  13801. description: Used to define the strategy to use in the merge operation.
  13802. enum:
  13803. - Extract
  13804. - JSON
  13805. type: string
  13806. type: object
  13807. regexp:
  13808. description: |-
  13809. Used to rewrite with regular expressions.
  13810. The resulting key will be the output of a regexp.ReplaceAll operation.
  13811. properties:
  13812. source:
  13813. description: Used to define the regular expression of a re.Compiler.
  13814. type: string
  13815. target:
  13816. description: Used to define the target pattern of a ReplaceAll operation.
  13817. type: string
  13818. required:
  13819. - source
  13820. - target
  13821. type: object
  13822. transform:
  13823. description: |-
  13824. Used to apply string transformation on the secrets.
  13825. The resulting key will be the output of the template applied by the operation.
  13826. properties:
  13827. template:
  13828. description: |-
  13829. Used to define the template to apply on the secret name.
  13830. `.value ` will specify the secret name in the template.
  13831. type: string
  13832. required:
  13833. - template
  13834. type: object
  13835. type: object
  13836. type: array
  13837. sourceRef:
  13838. description: |-
  13839. SourceRef points to a store or generator
  13840. which contains secret values ready to use.
  13841. Use this in combination with Extract or Find pull values out of
  13842. a specific SecretStore.
  13843. When sourceRef points to a generator Extract or Find is not supported.
  13844. The generator returns a static map of values
  13845. maxProperties: 1
  13846. minProperties: 1
  13847. properties:
  13848. generatorRef:
  13849. description: GeneratorRef points to a generator custom resource.
  13850. properties:
  13851. apiVersion:
  13852. default: generators.external-secrets.io/v1alpha1
  13853. description: Specify the apiVersion of the generator resource
  13854. type: string
  13855. kind:
  13856. description: Specify the Kind of the generator resource
  13857. enum:
  13858. - ACRAccessToken
  13859. - BeyondtrustWorkloadCredentialsDynamicSecret
  13860. - ClusterGenerator
  13861. - CloudsmithAccessToken
  13862. - ECRAuthorizationToken
  13863. - Fake
  13864. - GCRAccessToken
  13865. - GithubAccessToken
  13866. - GitlabDeployToken
  13867. - QuayAccessToken
  13868. - Password
  13869. - SSHKey
  13870. - STSSessionToken
  13871. - UUID
  13872. - VaultDynamicSecret
  13873. - Webhook
  13874. - Grafana
  13875. - MFA
  13876. type: string
  13877. name:
  13878. description: Specify the name of the generator resource
  13879. maxLength: 253
  13880. minLength: 1
  13881. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13882. type: string
  13883. required:
  13884. - kind
  13885. - name
  13886. type: object
  13887. storeRef:
  13888. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13889. properties:
  13890. kind:
  13891. description: |-
  13892. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13893. Defaults to `SecretStore`
  13894. enum:
  13895. - SecretStore
  13896. - ClusterSecretStore
  13897. type: string
  13898. name:
  13899. description: Name of the SecretStore resource
  13900. maxLength: 253
  13901. minLength: 1
  13902. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13903. type: string
  13904. type: object
  13905. type: object
  13906. type: object
  13907. type: array
  13908. refreshInterval:
  13909. default: 1h0m0s
  13910. description: |-
  13911. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  13912. specified as Golang Duration strings.
  13913. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  13914. Example values: "1h0m0s", "2h30m0s", "10m0s"
  13915. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  13916. type: string
  13917. refreshPolicy:
  13918. description: |-
  13919. RefreshPolicy determines how the ExternalSecret should be refreshed:
  13920. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  13921. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  13922. No periodic updates occur if refreshInterval is 0.
  13923. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  13924. enum:
  13925. - CreatedOnce
  13926. - Periodic
  13927. - OnChange
  13928. type: string
  13929. secretStoreRef:
  13930. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13931. properties:
  13932. kind:
  13933. description: |-
  13934. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13935. Defaults to `SecretStore`
  13936. enum:
  13937. - SecretStore
  13938. - ClusterSecretStore
  13939. type: string
  13940. name:
  13941. description: Name of the SecretStore resource
  13942. maxLength: 253
  13943. minLength: 1
  13944. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13945. type: string
  13946. type: object
  13947. syncWindows:
  13948. description: |-
  13949. SyncWindows optionally restricts when periodic refreshes may occur.
  13950. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  13951. properties:
  13952. kind:
  13953. description: |-
  13954. Kind applies to every window in the list.
  13955. "allow" -- syncs are permitted only while at least one window is active;
  13956. all other times are blocked.
  13957. "deny" -- syncs are blocked while any window is active;
  13958. all other times are permitted.
  13959. enum:
  13960. - allow
  13961. - deny
  13962. type: string
  13963. windows:
  13964. description: Windows is the list of schedule+duration pairs.
  13965. items:
  13966. description: |-
  13967. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  13968. within a SyncWindows block.
  13969. properties:
  13970. duration:
  13971. description: |-
  13972. Duration specifies how long the window stays open after each Schedule
  13973. firing. Example: "8h".
  13974. type: string
  13975. schedule:
  13976. description: |-
  13977. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  13978. named shorthand such as @daily or @every 1h. It marks the start time of
  13979. each window occurrence.
  13980. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  13981. minLength: 1
  13982. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  13983. type: string
  13984. required:
  13985. - duration
  13986. - schedule
  13987. type: object
  13988. minItems: 1
  13989. type: array
  13990. required:
  13991. - kind
  13992. - windows
  13993. type: object
  13994. target:
  13995. default:
  13996. creationPolicy: Owner
  13997. deletionPolicy: Retain
  13998. description: |-
  13999. ExternalSecretTarget defines the Kubernetes Secret to be created,
  14000. there can be only one target per ExternalSecret.
  14001. properties:
  14002. creationPolicy:
  14003. default: Owner
  14004. description: |-
  14005. CreationPolicy defines rules on how to create the resulting Secret.
  14006. Defaults to "Owner"
  14007. enum:
  14008. - Owner
  14009. - Orphan
  14010. - Merge
  14011. - None
  14012. - CreateOrMerge
  14013. type: string
  14014. deletionPolicy:
  14015. default: Retain
  14016. description: |-
  14017. DeletionPolicy defines rules on how to delete the resulting Secret.
  14018. Defaults to "Retain"
  14019. enum:
  14020. - Delete
  14021. - Merge
  14022. - Retain
  14023. type: string
  14024. immutable:
  14025. description: Immutable defines if the final secret will be immutable
  14026. type: boolean
  14027. manifest:
  14028. description: |-
  14029. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  14030. When specified, ExternalSecret will create the resource type defined here
  14031. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  14032. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  14033. properties:
  14034. apiVersion:
  14035. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  14036. minLength: 1
  14037. type: string
  14038. kind:
  14039. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  14040. minLength: 1
  14041. type: string
  14042. required:
  14043. - apiVersion
  14044. - kind
  14045. type: object
  14046. name:
  14047. description: |-
  14048. The name of the Secret resource to be managed.
  14049. Defaults to the .metadata.name of the ExternalSecret resource
  14050. maxLength: 253
  14051. minLength: 1
  14052. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14053. type: string
  14054. template:
  14055. description: Template defines a blueprint for the created Secret resource.
  14056. properties:
  14057. data:
  14058. additionalProperties:
  14059. type: string
  14060. type: object
  14061. engineVersion:
  14062. default: v2
  14063. description: |-
  14064. EngineVersion specifies the template engine version
  14065. that should be used to compile/execute the
  14066. template specified in .data and .templateFrom[].
  14067. enum:
  14068. - v2
  14069. type: string
  14070. mergePolicy:
  14071. default: Replace
  14072. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  14073. enum:
  14074. - Replace
  14075. - Merge
  14076. type: string
  14077. metadata:
  14078. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14079. properties:
  14080. annotations:
  14081. additionalProperties:
  14082. type: string
  14083. type: object
  14084. finalizers:
  14085. items:
  14086. type: string
  14087. type: array
  14088. labels:
  14089. additionalProperties:
  14090. type: string
  14091. type: object
  14092. type: object
  14093. templateFrom:
  14094. items:
  14095. description: |-
  14096. TemplateFrom specifies a source for templates.
  14097. Each item in the list can either reference a ConfigMap or a Secret resource.
  14098. properties:
  14099. configMap:
  14100. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14101. properties:
  14102. items:
  14103. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14104. items:
  14105. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14106. properties:
  14107. key:
  14108. description: A key in the ConfigMap/Secret
  14109. maxLength: 253
  14110. minLength: 1
  14111. pattern: ^[-._a-zA-Z0-9]+$
  14112. type: string
  14113. templateAs:
  14114. default: Values
  14115. description: TemplateScope specifies how the template keys should be interpreted.
  14116. enum:
  14117. - Values
  14118. - KeysAndValues
  14119. type: string
  14120. required:
  14121. - key
  14122. type: object
  14123. type: array
  14124. name:
  14125. description: The name of the ConfigMap/Secret resource
  14126. maxLength: 253
  14127. minLength: 1
  14128. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14129. type: string
  14130. required:
  14131. - items
  14132. - name
  14133. type: object
  14134. literal:
  14135. type: string
  14136. secret:
  14137. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14138. properties:
  14139. items:
  14140. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14141. items:
  14142. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14143. properties:
  14144. key:
  14145. description: A key in the ConfigMap/Secret
  14146. maxLength: 253
  14147. minLength: 1
  14148. pattern: ^[-._a-zA-Z0-9]+$
  14149. type: string
  14150. templateAs:
  14151. default: Values
  14152. description: TemplateScope specifies how the template keys should be interpreted.
  14153. enum:
  14154. - Values
  14155. - KeysAndValues
  14156. type: string
  14157. required:
  14158. - key
  14159. type: object
  14160. type: array
  14161. name:
  14162. description: The name of the ConfigMap/Secret resource
  14163. maxLength: 253
  14164. minLength: 1
  14165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14166. type: string
  14167. required:
  14168. - items
  14169. - name
  14170. type: object
  14171. target:
  14172. default: Data
  14173. description: |-
  14174. Target specifies where to place the template result.
  14175. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  14176. any other value is rejected because it would allow writes to privileged Secret fields.
  14177. For custom resources (when spec.target.manifest is set), this supports
  14178. nested paths like "spec.database.config" or "data".
  14179. type: string
  14180. valuesDecodingStrategy:
  14181. default: None
  14182. description: Used to define a decoding Strategy for the rendered template values.
  14183. enum:
  14184. - Auto
  14185. - Base64
  14186. - Base64URL
  14187. - None
  14188. type: string
  14189. type: object
  14190. type: array
  14191. type:
  14192. type: string
  14193. type: object
  14194. type: object
  14195. type: object
  14196. status:
  14197. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  14198. properties:
  14199. binding:
  14200. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  14201. properties:
  14202. name:
  14203. default: ""
  14204. description: |-
  14205. Name of the referent.
  14206. This field is effectively required, but due to backwards compatibility is
  14207. allowed to be empty. Instances of this type with an empty value here are
  14208. almost certainly wrong.
  14209. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  14210. type: string
  14211. type: object
  14212. x-kubernetes-map-type: atomic
  14213. conditions:
  14214. items:
  14215. description: ExternalSecretStatusCondition defines a status condition of an ExternalSecret resource.
  14216. properties:
  14217. lastTransitionTime:
  14218. format: date-time
  14219. type: string
  14220. message:
  14221. type: string
  14222. reason:
  14223. type: string
  14224. status:
  14225. type: string
  14226. type:
  14227. description: ExternalSecretConditionType defines a value type for ExternalSecret conditions.
  14228. enum:
  14229. - Ready
  14230. - Deleted
  14231. type: string
  14232. required:
  14233. - status
  14234. - type
  14235. type: object
  14236. type: array
  14237. refreshTime:
  14238. description: |-
  14239. refreshTime is the time and date the external secret was fetched and
  14240. the target secret updated
  14241. format: date-time
  14242. nullable: true
  14243. type: string
  14244. syncedResourceVersion:
  14245. description: SyncedResourceVersion keeps track of the last synced version
  14246. type: string
  14247. type: object
  14248. type: object
  14249. selectableFields:
  14250. - jsonPath: .spec.secretStoreRef.name
  14251. - jsonPath: .spec.secretStoreRef.kind
  14252. - jsonPath: .spec.target.name
  14253. - jsonPath: .spec.refreshInterval
  14254. served: true
  14255. storage: true
  14256. subresources:
  14257. status: {}
  14258. - additionalPrinterColumns:
  14259. - jsonPath: .spec.secretStoreRef.kind
  14260. name: StoreType
  14261. type: string
  14262. - jsonPath: .spec.secretStoreRef.name
  14263. name: Store
  14264. type: string
  14265. - jsonPath: .spec.refreshInterval
  14266. name: Refresh Interval
  14267. type: string
  14268. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  14269. name: Status
  14270. type: string
  14271. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  14272. name: Ready
  14273. type: string
  14274. - jsonPath: .status.refreshTime
  14275. name: Last Sync
  14276. type: date
  14277. deprecated: true
  14278. name: v1beta1
  14279. schema:
  14280. openAPIV3Schema:
  14281. description: ExternalSecret is the schema for the external-secrets API.
  14282. properties:
  14283. apiVersion:
  14284. description: |-
  14285. APIVersion defines the versioned schema of this representation of an object.
  14286. Servers should convert recognized schemas to the latest internal value, and
  14287. may reject unrecognized values.
  14288. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  14289. type: string
  14290. kind:
  14291. description: |-
  14292. Kind is a string value representing the REST resource this object represents.
  14293. Servers may infer this from the endpoint the client submits requests to.
  14294. Cannot be updated.
  14295. In CamelCase.
  14296. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  14297. type: string
  14298. metadata:
  14299. type: object
  14300. spec:
  14301. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  14302. properties:
  14303. data:
  14304. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  14305. items:
  14306. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  14307. properties:
  14308. remoteRef:
  14309. description: |-
  14310. RemoteRef points to the remote secret and defines
  14311. which secret (version/property/..) to fetch.
  14312. properties:
  14313. conversionStrategy:
  14314. default: Default
  14315. description: Used to define a conversion Strategy
  14316. enum:
  14317. - Default
  14318. - Unicode
  14319. type: string
  14320. decodingStrategy:
  14321. default: None
  14322. description: Used to define a decoding Strategy
  14323. enum:
  14324. - Auto
  14325. - Base64
  14326. - Base64URL
  14327. - None
  14328. type: string
  14329. key:
  14330. description: Key is the key used in the Provider, mandatory
  14331. type: string
  14332. metadataPolicy:
  14333. default: None
  14334. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14335. enum:
  14336. - None
  14337. - Fetch
  14338. type: string
  14339. property:
  14340. description: Used to select a specific property of the Provider value (if a map), if supported
  14341. type: string
  14342. version:
  14343. description: Used to select a specific version of the Provider value, if supported
  14344. type: string
  14345. required:
  14346. - key
  14347. type: object
  14348. secretKey:
  14349. description: The key in the Kubernetes Secret to store the value.
  14350. maxLength: 253
  14351. minLength: 1
  14352. pattern: ^[-._a-zA-Z0-9]+$
  14353. type: string
  14354. sourceRef:
  14355. description: |-
  14356. SourceRef allows you to override the source
  14357. from which the value will be pulled.
  14358. maxProperties: 1
  14359. minProperties: 1
  14360. properties:
  14361. generatorRef:
  14362. description: |-
  14363. GeneratorRef points to a generator custom resource.
  14364. Deprecated: The generatorRef is not implemented in .data[].
  14365. this will be removed with v1.
  14366. properties:
  14367. apiVersion:
  14368. default: generators.external-secrets.io/v1alpha1
  14369. description: Specify the apiVersion of the generator resource
  14370. type: string
  14371. kind:
  14372. description: Specify the Kind of the generator resource
  14373. enum:
  14374. - ACRAccessToken
  14375. - ClusterGenerator
  14376. - ECRAuthorizationToken
  14377. - Fake
  14378. - GCRAccessToken
  14379. - GithubAccessToken
  14380. - QuayAccessToken
  14381. - Password
  14382. - SSHKey
  14383. - STSSessionToken
  14384. - UUID
  14385. - VaultDynamicSecret
  14386. - Webhook
  14387. - Grafana
  14388. type: string
  14389. name:
  14390. description: Specify the name of the generator resource
  14391. maxLength: 253
  14392. minLength: 1
  14393. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14394. type: string
  14395. required:
  14396. - kind
  14397. - name
  14398. type: object
  14399. storeRef:
  14400. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14401. properties:
  14402. kind:
  14403. description: |-
  14404. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14405. Defaults to `SecretStore`
  14406. enum:
  14407. - SecretStore
  14408. - ClusterSecretStore
  14409. type: string
  14410. name:
  14411. description: Name of the SecretStore resource
  14412. maxLength: 253
  14413. minLength: 1
  14414. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14415. type: string
  14416. type: object
  14417. type: object
  14418. required:
  14419. - remoteRef
  14420. - secretKey
  14421. type: object
  14422. type: array
  14423. dataFrom:
  14424. description: |-
  14425. DataFrom is used to fetch all properties from a specific Provider data
  14426. If multiple entries are specified, the Secret keys are merged in the specified order
  14427. items:
  14428. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  14429. properties:
  14430. extract:
  14431. description: |-
  14432. Used to extract multiple key/value pairs from one secret
  14433. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14434. properties:
  14435. conversionStrategy:
  14436. default: Default
  14437. description: Used to define a conversion Strategy
  14438. enum:
  14439. - Default
  14440. - Unicode
  14441. type: string
  14442. decodingStrategy:
  14443. default: None
  14444. description: Used to define a decoding Strategy
  14445. enum:
  14446. - Auto
  14447. - Base64
  14448. - Base64URL
  14449. - None
  14450. type: string
  14451. key:
  14452. description: Key is the key used in the Provider, mandatory
  14453. type: string
  14454. metadataPolicy:
  14455. default: None
  14456. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14457. enum:
  14458. - None
  14459. - Fetch
  14460. type: string
  14461. property:
  14462. description: Used to select a specific property of the Provider value (if a map), if supported
  14463. type: string
  14464. version:
  14465. description: Used to select a specific version of the Provider value, if supported
  14466. type: string
  14467. required:
  14468. - key
  14469. type: object
  14470. find:
  14471. description: |-
  14472. Used to find secrets based on tags or regular expressions
  14473. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14474. properties:
  14475. conversionStrategy:
  14476. default: Default
  14477. description: Used to define a conversion Strategy
  14478. enum:
  14479. - Default
  14480. - Unicode
  14481. type: string
  14482. decodingStrategy:
  14483. default: None
  14484. description: Used to define a decoding Strategy
  14485. enum:
  14486. - Auto
  14487. - Base64
  14488. - Base64URL
  14489. - None
  14490. type: string
  14491. name:
  14492. description: Finds secrets based on the name.
  14493. properties:
  14494. regexp:
  14495. description: Finds secrets base
  14496. type: string
  14497. type: object
  14498. path:
  14499. description: A root path to start the find operations.
  14500. type: string
  14501. tags:
  14502. additionalProperties:
  14503. type: string
  14504. description: Find secrets based on tags.
  14505. type: object
  14506. type: object
  14507. rewrite:
  14508. description: |-
  14509. Used to rewrite secret Keys after getting them from the secret Provider
  14510. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  14511. items:
  14512. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  14513. maxProperties: 1
  14514. minProperties: 1
  14515. properties:
  14516. regexp:
  14517. description: |-
  14518. Used to rewrite with regular expressions.
  14519. The resulting key will be the output of a regexp.ReplaceAll operation.
  14520. properties:
  14521. source:
  14522. description: Used to define the regular expression of a re.Compiler.
  14523. type: string
  14524. target:
  14525. description: Used to define the target pattern of a ReplaceAll operation.
  14526. type: string
  14527. required:
  14528. - source
  14529. - target
  14530. type: object
  14531. transform:
  14532. description: |-
  14533. Used to apply string transformation on the secrets.
  14534. The resulting key will be the output of the template applied by the operation.
  14535. properties:
  14536. template:
  14537. description: |-
  14538. Used to define the template to apply on the secret name.
  14539. `.value ` will specify the secret name in the template.
  14540. type: string
  14541. required:
  14542. - template
  14543. type: object
  14544. type: object
  14545. type: array
  14546. sourceRef:
  14547. description: |-
  14548. SourceRef points to a store or generator
  14549. which contains secret values ready to use.
  14550. Use this in combination with Extract or Find pull values out of
  14551. a specific SecretStore.
  14552. When sourceRef points to a generator Extract or Find is not supported.
  14553. The generator returns a static map of values
  14554. maxProperties: 1
  14555. minProperties: 1
  14556. properties:
  14557. generatorRef:
  14558. description: GeneratorRef points to a generator custom resource.
  14559. properties:
  14560. apiVersion:
  14561. default: generators.external-secrets.io/v1alpha1
  14562. description: Specify the apiVersion of the generator resource
  14563. type: string
  14564. kind:
  14565. description: Specify the Kind of the generator resource
  14566. enum:
  14567. - ACRAccessToken
  14568. - ClusterGenerator
  14569. - ECRAuthorizationToken
  14570. - Fake
  14571. - GCRAccessToken
  14572. - GithubAccessToken
  14573. - QuayAccessToken
  14574. - Password
  14575. - SSHKey
  14576. - STSSessionToken
  14577. - UUID
  14578. - VaultDynamicSecret
  14579. - Webhook
  14580. - Grafana
  14581. type: string
  14582. name:
  14583. description: Specify the name of the generator resource
  14584. maxLength: 253
  14585. minLength: 1
  14586. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14587. type: string
  14588. required:
  14589. - kind
  14590. - name
  14591. type: object
  14592. storeRef:
  14593. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14594. properties:
  14595. kind:
  14596. description: |-
  14597. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14598. Defaults to `SecretStore`
  14599. enum:
  14600. - SecretStore
  14601. - ClusterSecretStore
  14602. type: string
  14603. name:
  14604. description: Name of the SecretStore resource
  14605. maxLength: 253
  14606. minLength: 1
  14607. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14608. type: string
  14609. type: object
  14610. type: object
  14611. type: object
  14612. type: array
  14613. refreshInterval:
  14614. default: 1h0m0s
  14615. description: |-
  14616. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  14617. specified as Golang Duration strings.
  14618. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  14619. Example values: "1h0m0s", "2h30m0s", "10m0s"
  14620. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  14621. type: string
  14622. refreshPolicy:
  14623. description: |-
  14624. RefreshPolicy determines how the ExternalSecret should be refreshed:
  14625. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  14626. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  14627. No periodic updates occur if refreshInterval is 0.
  14628. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  14629. enum:
  14630. - CreatedOnce
  14631. - Periodic
  14632. - OnChange
  14633. type: string
  14634. secretStoreRef:
  14635. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14636. properties:
  14637. kind:
  14638. description: |-
  14639. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14640. Defaults to `SecretStore`
  14641. enum:
  14642. - SecretStore
  14643. - ClusterSecretStore
  14644. type: string
  14645. name:
  14646. description: Name of the SecretStore resource
  14647. maxLength: 253
  14648. minLength: 1
  14649. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14650. type: string
  14651. type: object
  14652. target:
  14653. default:
  14654. creationPolicy: Owner
  14655. deletionPolicy: Retain
  14656. description: |-
  14657. ExternalSecretTarget defines the Kubernetes Secret to be created
  14658. There can be only one target per ExternalSecret.
  14659. properties:
  14660. creationPolicy:
  14661. default: Owner
  14662. description: |-
  14663. CreationPolicy defines rules on how to create the resulting Secret.
  14664. Defaults to "Owner"
  14665. enum:
  14666. - Owner
  14667. - Orphan
  14668. - Merge
  14669. - None
  14670. type: string
  14671. deletionPolicy:
  14672. default: Retain
  14673. description: |-
  14674. DeletionPolicy defines rules on how to delete the resulting Secret.
  14675. Defaults to "Retain"
  14676. enum:
  14677. - Delete
  14678. - Merge
  14679. - Retain
  14680. type: string
  14681. immutable:
  14682. description: Immutable defines if the final secret will be immutable
  14683. type: boolean
  14684. name:
  14685. description: |-
  14686. The name of the Secret resource to be managed.
  14687. Defaults to the .metadata.name of the ExternalSecret resource
  14688. maxLength: 253
  14689. minLength: 1
  14690. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14691. type: string
  14692. template:
  14693. description: Template defines a blueprint for the created Secret resource.
  14694. properties:
  14695. data:
  14696. additionalProperties:
  14697. type: string
  14698. type: object
  14699. engineVersion:
  14700. default: v2
  14701. description: |-
  14702. EngineVersion specifies the template engine version
  14703. that should be used to compile/execute the
  14704. template specified in .data and .templateFrom[].
  14705. enum:
  14706. - v2
  14707. type: string
  14708. mergePolicy:
  14709. default: Replace
  14710. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  14711. enum:
  14712. - Replace
  14713. - Merge
  14714. type: string
  14715. metadata:
  14716. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14717. properties:
  14718. annotations:
  14719. additionalProperties:
  14720. type: string
  14721. type: object
  14722. labels:
  14723. additionalProperties:
  14724. type: string
  14725. type: object
  14726. type: object
  14727. templateFrom:
  14728. items:
  14729. description: TemplateFrom defines a source for template data.
  14730. properties:
  14731. configMap:
  14732. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14733. properties:
  14734. items:
  14735. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14736. items:
  14737. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14738. properties:
  14739. key:
  14740. description: A key in the ConfigMap/Secret
  14741. maxLength: 253
  14742. minLength: 1
  14743. pattern: ^[-._a-zA-Z0-9]+$
  14744. type: string
  14745. templateAs:
  14746. default: Values
  14747. description: TemplateScope defines the scope of the template when processing template data.
  14748. enum:
  14749. - Values
  14750. - KeysAndValues
  14751. type: string
  14752. required:
  14753. - key
  14754. type: object
  14755. type: array
  14756. name:
  14757. description: The name of the ConfigMap/Secret resource
  14758. maxLength: 253
  14759. minLength: 1
  14760. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14761. type: string
  14762. required:
  14763. - items
  14764. - name
  14765. type: object
  14766. literal:
  14767. type: string
  14768. secret:
  14769. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14770. properties:
  14771. items:
  14772. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14773. items:
  14774. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14775. properties:
  14776. key:
  14777. description: A key in the ConfigMap/Secret
  14778. maxLength: 253
  14779. minLength: 1
  14780. pattern: ^[-._a-zA-Z0-9]+$
  14781. type: string
  14782. templateAs:
  14783. default: Values
  14784. description: TemplateScope defines the scope of the template when processing template data.
  14785. enum:
  14786. - Values
  14787. - KeysAndValues
  14788. type: string
  14789. required:
  14790. - key
  14791. type: object
  14792. type: array
  14793. name:
  14794. description: The name of the ConfigMap/Secret resource
  14795. maxLength: 253
  14796. minLength: 1
  14797. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14798. type: string
  14799. required:
  14800. - items
  14801. - name
  14802. type: object
  14803. target:
  14804. default: Data
  14805. description: TemplateTarget defines the target field where the template result will be stored.
  14806. enum:
  14807. - Data
  14808. - Annotations
  14809. - Labels
  14810. type: string
  14811. type: object
  14812. type: array
  14813. type:
  14814. type: string
  14815. type: object
  14816. type: object
  14817. type: object
  14818. status:
  14819. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  14820. properties:
  14821. binding:
  14822. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  14823. properties:
  14824. name:
  14825. default: ""
  14826. description: |-
  14827. Name of the referent.
  14828. This field is effectively required, but due to backwards compatibility is
  14829. allowed to be empty. Instances of this type with an empty value here are
  14830. almost certainly wrong.
  14831. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  14832. type: string
  14833. type: object
  14834. x-kubernetes-map-type: atomic
  14835. conditions:
  14836. items:
  14837. description: ExternalSecretStatusCondition contains condition information for an ExternalSecret.
  14838. properties:
  14839. lastTransitionTime:
  14840. format: date-time
  14841. type: string
  14842. message:
  14843. type: string
  14844. reason:
  14845. type: string
  14846. status:
  14847. type: string
  14848. type:
  14849. description: ExternalSecretConditionType defines the condition type for an ExternalSecret.
  14850. type: string
  14851. required:
  14852. - status
  14853. - type
  14854. type: object
  14855. type: array
  14856. refreshTime:
  14857. description: |-
  14858. refreshTime is the time and date the external secret was fetched and
  14859. the target secret updated
  14860. format: date-time
  14861. nullable: true
  14862. type: string
  14863. syncedResourceVersion:
  14864. description: SyncedResourceVersion keeps track of the last synced version
  14865. type: string
  14866. type: object
  14867. type: object
  14868. served: false
  14869. storage: false
  14870. subresources:
  14871. status: {}
  14872. ---
  14873. apiVersion: apiextensions.k8s.io/v1
  14874. kind: CustomResourceDefinition
  14875. metadata:
  14876. annotations:
  14877. controller-gen.kubebuilder.io/version: v0.19.0
  14878. labels:
  14879. external-secrets.io/component: controller
  14880. name: pushsecrets.external-secrets.io
  14881. spec:
  14882. group: external-secrets.io
  14883. names:
  14884. categories:
  14885. - external-secrets
  14886. kind: PushSecret
  14887. listKind: PushSecretList
  14888. plural: pushsecrets
  14889. shortNames:
  14890. - ps
  14891. singular: pushsecret
  14892. scope: Namespaced
  14893. versions:
  14894. - additionalPrinterColumns:
  14895. - jsonPath: .metadata.creationTimestamp
  14896. name: AGE
  14897. type: date
  14898. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  14899. name: Status
  14900. type: string
  14901. - jsonPath: .status.refreshTime
  14902. name: Last Sync
  14903. type: date
  14904. name: v1alpha1
  14905. schema:
  14906. openAPIV3Schema:
  14907. description: PushSecret is the Schema for the PushSecrets API that enables pushing Kubernetes secrets to external secret providers.
  14908. properties:
  14909. apiVersion:
  14910. description: |-
  14911. APIVersion defines the versioned schema of this representation of an object.
  14912. Servers should convert recognized schemas to the latest internal value, and
  14913. may reject unrecognized values.
  14914. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  14915. type: string
  14916. kind:
  14917. description: |-
  14918. Kind is a string value representing the REST resource this object represents.
  14919. Servers may infer this from the endpoint the client submits requests to.
  14920. Cannot be updated.
  14921. In CamelCase.
  14922. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  14923. type: string
  14924. metadata:
  14925. type: object
  14926. spec:
  14927. description: PushSecretSpec configures the behavior of the PushSecret.
  14928. properties:
  14929. data:
  14930. description: Secret Data that should be pushed to providers
  14931. items:
  14932. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  14933. properties:
  14934. conversionStrategy:
  14935. default: None
  14936. description: Used to define a conversion Strategy for the secret keys
  14937. enum:
  14938. - None
  14939. - ReverseUnicode
  14940. type: string
  14941. match:
  14942. description: Match a given Secret Key to be pushed to the provider.
  14943. properties:
  14944. remoteRef:
  14945. description: Remote Refs to push to providers.
  14946. properties:
  14947. property:
  14948. description: Name of the property in the resulting secret
  14949. type: string
  14950. remoteKey:
  14951. description: Name of the resulting provider secret.
  14952. type: string
  14953. required:
  14954. - remoteKey
  14955. type: object
  14956. secretKey:
  14957. description: Secret Key to be pushed
  14958. type: string
  14959. required:
  14960. - remoteRef
  14961. type: object
  14962. metadata:
  14963. description: |-
  14964. Metadata is metadata attached to the secret.
  14965. The structure of metadata is provider specific, please look it up in the provider documentation.
  14966. x-kubernetes-preserve-unknown-fields: true
  14967. required:
  14968. - match
  14969. type: object
  14970. type: array
  14971. dataTo:
  14972. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  14973. items:
  14974. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  14975. properties:
  14976. conversionStrategy:
  14977. default: None
  14978. description: Used to define a conversion Strategy for the secret keys
  14979. enum:
  14980. - None
  14981. - ReverseUnicode
  14982. type: string
  14983. match:
  14984. description: |-
  14985. Match pattern for selecting keys from the source Secret.
  14986. If not specified, all keys are selected.
  14987. properties:
  14988. regexp:
  14989. description: |-
  14990. Regexp matches keys by regular expression.
  14991. If not specified, all keys are matched.
  14992. type: string
  14993. type: object
  14994. metadata:
  14995. description: |-
  14996. Metadata is metadata attached to the secret.
  14997. The structure of metadata is provider specific, please look it up in the provider documentation.
  14998. x-kubernetes-preserve-unknown-fields: true
  14999. remoteKey:
  15000. description: |-
  15001. RemoteKey is the name of the single provider secret that will receive ALL
  15002. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  15003. When set, per-key expansion is skipped and a single push is performed.
  15004. The provider's store prefix (if any) is still prepended to this value.
  15005. When not set, each matched key is pushed as its own individual provider secret.
  15006. type: string
  15007. rewrite:
  15008. description: |-
  15009. Rewrite operations to transform keys before pushing to the provider.
  15010. Operations are applied sequentially.
  15011. items:
  15012. description: PushSecretRewrite defines how to transform secret keys before pushing.
  15013. properties:
  15014. regexp:
  15015. description: Used to rewrite with regular expressions.
  15016. properties:
  15017. source:
  15018. description: Used to define the regular expression of a re.Compiler.
  15019. type: string
  15020. target:
  15021. description: Used to define the target pattern of a ReplaceAll operation.
  15022. type: string
  15023. required:
  15024. - source
  15025. - target
  15026. type: object
  15027. transform:
  15028. description: Used to apply string transformation on the secrets.
  15029. properties:
  15030. template:
  15031. description: |-
  15032. Used to define the template to apply on the secret name.
  15033. `.value ` will specify the secret name in the template.
  15034. type: string
  15035. required:
  15036. - template
  15037. type: object
  15038. type: object
  15039. x-kubernetes-validations:
  15040. - message: exactly one of regexp or transform must be set
  15041. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  15042. type: array
  15043. storeRef:
  15044. description: StoreRef specifies which SecretStore to push to. Required.
  15045. properties:
  15046. kind:
  15047. default: SecretStore
  15048. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  15049. enum:
  15050. - SecretStore
  15051. - ClusterSecretStore
  15052. type: string
  15053. labelSelector:
  15054. description: Optionally, sync to secret stores with label selector
  15055. properties:
  15056. matchExpressions:
  15057. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15058. items:
  15059. description: |-
  15060. A label selector requirement is a selector that contains values, a key, and an operator that
  15061. relates the key and values.
  15062. properties:
  15063. key:
  15064. description: key is the label key that the selector applies to.
  15065. type: string
  15066. operator:
  15067. description: |-
  15068. operator represents a key's relationship to a set of values.
  15069. Valid operators are In, NotIn, Exists and DoesNotExist.
  15070. type: string
  15071. values:
  15072. description: |-
  15073. values is an array of string values. If the operator is In or NotIn,
  15074. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15075. the values array must be empty. This array is replaced during a strategic
  15076. merge patch.
  15077. items:
  15078. type: string
  15079. type: array
  15080. x-kubernetes-list-type: atomic
  15081. required:
  15082. - key
  15083. - operator
  15084. type: object
  15085. type: array
  15086. x-kubernetes-list-type: atomic
  15087. matchLabels:
  15088. additionalProperties:
  15089. type: string
  15090. description: |-
  15091. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15092. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15093. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15094. type: object
  15095. type: object
  15096. x-kubernetes-map-type: atomic
  15097. name:
  15098. description: Optionally, sync to the SecretStore of the given name
  15099. maxLength: 253
  15100. minLength: 1
  15101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15102. type: string
  15103. type: object
  15104. type: object
  15105. x-kubernetes-validations:
  15106. - message: storeRef must specify either name or labelSelector
  15107. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  15108. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  15109. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  15110. type: array
  15111. deletionPolicy:
  15112. default: None
  15113. description: Deletion Policy to handle Secrets in the provider.
  15114. enum:
  15115. - Delete
  15116. - None
  15117. type: string
  15118. refreshInterval:
  15119. default: 1h0m0s
  15120. description: The Interval to which External Secrets will try to push a secret definition
  15121. type: string
  15122. secretStoreRefs:
  15123. items:
  15124. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  15125. properties:
  15126. kind:
  15127. default: SecretStore
  15128. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  15129. enum:
  15130. - SecretStore
  15131. - ClusterSecretStore
  15132. type: string
  15133. labelSelector:
  15134. description: Optionally, sync to secret stores with label selector
  15135. properties:
  15136. matchExpressions:
  15137. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15138. items:
  15139. description: |-
  15140. A label selector requirement is a selector that contains values, a key, and an operator that
  15141. relates the key and values.
  15142. properties:
  15143. key:
  15144. description: key is the label key that the selector applies to.
  15145. type: string
  15146. operator:
  15147. description: |-
  15148. operator represents a key's relationship to a set of values.
  15149. Valid operators are In, NotIn, Exists and DoesNotExist.
  15150. type: string
  15151. values:
  15152. description: |-
  15153. values is an array of string values. If the operator is In or NotIn,
  15154. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15155. the values array must be empty. This array is replaced during a strategic
  15156. merge patch.
  15157. items:
  15158. type: string
  15159. type: array
  15160. x-kubernetes-list-type: atomic
  15161. required:
  15162. - key
  15163. - operator
  15164. type: object
  15165. type: array
  15166. x-kubernetes-list-type: atomic
  15167. matchLabels:
  15168. additionalProperties:
  15169. type: string
  15170. description: |-
  15171. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15172. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15173. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15174. type: object
  15175. type: object
  15176. x-kubernetes-map-type: atomic
  15177. name:
  15178. description: Optionally, sync to the SecretStore of the given name
  15179. maxLength: 253
  15180. minLength: 1
  15181. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15182. type: string
  15183. type: object
  15184. type: array
  15185. selector:
  15186. description: The Secret Selector (k8s source) for the Push Secret
  15187. maxProperties: 1
  15188. minProperties: 1
  15189. properties:
  15190. generatorRef:
  15191. description: Point to a generator to create a Secret.
  15192. properties:
  15193. apiVersion:
  15194. default: generators.external-secrets.io/v1alpha1
  15195. description: Specify the apiVersion of the generator resource
  15196. type: string
  15197. kind:
  15198. description: Specify the Kind of the generator resource
  15199. enum:
  15200. - ACRAccessToken
  15201. - BeyondtrustWorkloadCredentialsDynamicSecret
  15202. - ClusterGenerator
  15203. - CloudsmithAccessToken
  15204. - ECRAuthorizationToken
  15205. - Fake
  15206. - GCRAccessToken
  15207. - GithubAccessToken
  15208. - GitlabDeployToken
  15209. - QuayAccessToken
  15210. - Password
  15211. - SSHKey
  15212. - STSSessionToken
  15213. - UUID
  15214. - VaultDynamicSecret
  15215. - Webhook
  15216. - Grafana
  15217. - MFA
  15218. type: string
  15219. name:
  15220. description: Specify the name of the generator resource
  15221. maxLength: 253
  15222. minLength: 1
  15223. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15224. type: string
  15225. required:
  15226. - kind
  15227. - name
  15228. type: object
  15229. secret:
  15230. description: Select a Secret to Push.
  15231. properties:
  15232. name:
  15233. description: |-
  15234. Name of the Secret.
  15235. The Secret must exist in the same namespace as the PushSecret manifest.
  15236. maxLength: 253
  15237. minLength: 1
  15238. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15239. type: string
  15240. selector:
  15241. description: Selector chooses secrets using a labelSelector.
  15242. properties:
  15243. matchExpressions:
  15244. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15245. items:
  15246. description: |-
  15247. A label selector requirement is a selector that contains values, a key, and an operator that
  15248. relates the key and values.
  15249. properties:
  15250. key:
  15251. description: key is the label key that the selector applies to.
  15252. type: string
  15253. operator:
  15254. description: |-
  15255. operator represents a key's relationship to a set of values.
  15256. Valid operators are In, NotIn, Exists and DoesNotExist.
  15257. type: string
  15258. values:
  15259. description: |-
  15260. values is an array of string values. If the operator is In or NotIn,
  15261. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15262. the values array must be empty. This array is replaced during a strategic
  15263. merge patch.
  15264. items:
  15265. type: string
  15266. type: array
  15267. x-kubernetes-list-type: atomic
  15268. required:
  15269. - key
  15270. - operator
  15271. type: object
  15272. type: array
  15273. x-kubernetes-list-type: atomic
  15274. matchLabels:
  15275. additionalProperties:
  15276. type: string
  15277. description: |-
  15278. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15279. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15280. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15281. type: object
  15282. type: object
  15283. x-kubernetes-map-type: atomic
  15284. type: object
  15285. type: object
  15286. template:
  15287. description: Template defines a blueprint for the created Secret resource.
  15288. properties:
  15289. data:
  15290. additionalProperties:
  15291. type: string
  15292. type: object
  15293. engineVersion:
  15294. default: v2
  15295. description: |-
  15296. EngineVersion specifies the template engine version
  15297. that should be used to compile/execute the
  15298. template specified in .data and .templateFrom[].
  15299. enum:
  15300. - v2
  15301. type: string
  15302. mergePolicy:
  15303. default: Replace
  15304. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  15305. enum:
  15306. - Replace
  15307. - Merge
  15308. type: string
  15309. metadata:
  15310. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  15311. properties:
  15312. annotations:
  15313. additionalProperties:
  15314. type: string
  15315. type: object
  15316. finalizers:
  15317. items:
  15318. type: string
  15319. type: array
  15320. labels:
  15321. additionalProperties:
  15322. type: string
  15323. type: object
  15324. type: object
  15325. templateFrom:
  15326. items:
  15327. description: |-
  15328. TemplateFrom specifies a source for templates.
  15329. Each item in the list can either reference a ConfigMap or a Secret resource.
  15330. properties:
  15331. configMap:
  15332. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15333. properties:
  15334. items:
  15335. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15336. items:
  15337. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15338. properties:
  15339. key:
  15340. description: A key in the ConfigMap/Secret
  15341. maxLength: 253
  15342. minLength: 1
  15343. pattern: ^[-._a-zA-Z0-9]+$
  15344. type: string
  15345. templateAs:
  15346. default: Values
  15347. description: TemplateScope specifies how the template keys should be interpreted.
  15348. enum:
  15349. - Values
  15350. - KeysAndValues
  15351. type: string
  15352. required:
  15353. - key
  15354. type: object
  15355. type: array
  15356. name:
  15357. description: The name of the ConfigMap/Secret resource
  15358. maxLength: 253
  15359. minLength: 1
  15360. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15361. type: string
  15362. required:
  15363. - items
  15364. - name
  15365. type: object
  15366. literal:
  15367. type: string
  15368. secret:
  15369. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15370. properties:
  15371. items:
  15372. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15373. items:
  15374. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15375. properties:
  15376. key:
  15377. description: A key in the ConfigMap/Secret
  15378. maxLength: 253
  15379. minLength: 1
  15380. pattern: ^[-._a-zA-Z0-9]+$
  15381. type: string
  15382. templateAs:
  15383. default: Values
  15384. description: TemplateScope specifies how the template keys should be interpreted.
  15385. enum:
  15386. - Values
  15387. - KeysAndValues
  15388. type: string
  15389. required:
  15390. - key
  15391. type: object
  15392. type: array
  15393. name:
  15394. description: The name of the ConfigMap/Secret resource
  15395. maxLength: 253
  15396. minLength: 1
  15397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15398. type: string
  15399. required:
  15400. - items
  15401. - name
  15402. type: object
  15403. target:
  15404. default: Data
  15405. description: |-
  15406. Target specifies where to place the template result.
  15407. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  15408. any other value is rejected because it would allow writes to privileged Secret fields.
  15409. For custom resources (when spec.target.manifest is set), this supports
  15410. nested paths like "spec.database.config" or "data".
  15411. type: string
  15412. valuesDecodingStrategy:
  15413. default: None
  15414. description: Used to define a decoding Strategy for the rendered template values.
  15415. enum:
  15416. - Auto
  15417. - Base64
  15418. - Base64URL
  15419. - None
  15420. type: string
  15421. type: object
  15422. type: array
  15423. type:
  15424. type: string
  15425. type: object
  15426. updatePolicy:
  15427. default: Replace
  15428. description: UpdatePolicy to handle Secrets in the provider.
  15429. enum:
  15430. - Replace
  15431. - IfNotExists
  15432. type: string
  15433. required:
  15434. - secretStoreRefs
  15435. - selector
  15436. type: object
  15437. status:
  15438. description: PushSecretStatus indicates the history of the status of PushSecret.
  15439. properties:
  15440. conditions:
  15441. items:
  15442. description: PushSecretStatusCondition indicates the status of the PushSecret.
  15443. properties:
  15444. lastTransitionTime:
  15445. format: date-time
  15446. type: string
  15447. message:
  15448. type: string
  15449. reason:
  15450. type: string
  15451. status:
  15452. type: string
  15453. type:
  15454. description: PushSecretConditionType indicates the condition of the PushSecret.
  15455. type: string
  15456. required:
  15457. - status
  15458. - type
  15459. type: object
  15460. type: array
  15461. refreshTime:
  15462. description: |-
  15463. refreshTime is the time and date the external secret was fetched and
  15464. the target secret updated
  15465. format: date-time
  15466. nullable: true
  15467. type: string
  15468. syncedPushSecrets:
  15469. additionalProperties:
  15470. additionalProperties:
  15471. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  15472. properties:
  15473. conversionStrategy:
  15474. default: None
  15475. description: Used to define a conversion Strategy for the secret keys
  15476. enum:
  15477. - None
  15478. - ReverseUnicode
  15479. type: string
  15480. match:
  15481. description: Match a given Secret Key to be pushed to the provider.
  15482. properties:
  15483. remoteRef:
  15484. description: Remote Refs to push to providers.
  15485. properties:
  15486. property:
  15487. description: Name of the property in the resulting secret
  15488. type: string
  15489. remoteKey:
  15490. description: Name of the resulting provider secret.
  15491. type: string
  15492. required:
  15493. - remoteKey
  15494. type: object
  15495. secretKey:
  15496. description: Secret Key to be pushed
  15497. type: string
  15498. required:
  15499. - remoteRef
  15500. type: object
  15501. metadata:
  15502. description: |-
  15503. Metadata is metadata attached to the secret.
  15504. The structure of metadata is provider specific, please look it up in the provider documentation.
  15505. x-kubernetes-preserve-unknown-fields: true
  15506. required:
  15507. - match
  15508. type: object
  15509. type: object
  15510. description: |-
  15511. Synced PushSecrets, including secrets that already exist in provider.
  15512. Matches secret stores to PushSecretData that was stored to that secret store.
  15513. type: object
  15514. syncedResourceVersion:
  15515. description: SyncedResourceVersion keeps track of the last synced version.
  15516. type: string
  15517. type: object
  15518. type: object
  15519. served: true
  15520. storage: true
  15521. subresources:
  15522. status: {}
  15523. ---
  15524. apiVersion: apiextensions.k8s.io/v1
  15525. kind: CustomResourceDefinition
  15526. metadata:
  15527. annotations:
  15528. controller-gen.kubebuilder.io/version: v0.19.0
  15529. labels:
  15530. external-secrets.io/component: controller
  15531. name: secretstores.external-secrets.io
  15532. spec:
  15533. group: external-secrets.io
  15534. names:
  15535. categories:
  15536. - external-secrets
  15537. kind: SecretStore
  15538. listKind: SecretStoreList
  15539. plural: secretstores
  15540. shortNames:
  15541. - ss
  15542. singular: secretstore
  15543. scope: Namespaced
  15544. versions:
  15545. - additionalPrinterColumns:
  15546. - jsonPath: .metadata.creationTimestamp
  15547. name: AGE
  15548. type: date
  15549. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  15550. name: Status
  15551. type: string
  15552. - jsonPath: .status.capabilities
  15553. name: Capabilities
  15554. type: string
  15555. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  15556. name: Ready
  15557. type: string
  15558. name: v1
  15559. schema:
  15560. openAPIV3Schema:
  15561. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  15562. properties:
  15563. apiVersion:
  15564. description: |-
  15565. APIVersion defines the versioned schema of this representation of an object.
  15566. Servers should convert recognized schemas to the latest internal value, and
  15567. may reject unrecognized values.
  15568. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15569. type: string
  15570. kind:
  15571. description: |-
  15572. Kind is a string value representing the REST resource this object represents.
  15573. Servers may infer this from the endpoint the client submits requests to.
  15574. Cannot be updated.
  15575. In CamelCase.
  15576. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15577. type: string
  15578. metadata:
  15579. type: object
  15580. spec:
  15581. description: SecretStoreSpec defines the desired state of SecretStore.
  15582. properties:
  15583. conditions:
  15584. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  15585. items:
  15586. description: |-
  15587. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  15588. for a ClusterSecretStore instance.
  15589. properties:
  15590. namespaceRegexes:
  15591. description: Choose namespaces by using regex matching
  15592. items:
  15593. type: string
  15594. type: array
  15595. namespaceSelector:
  15596. description: Choose namespace using a labelSelector
  15597. properties:
  15598. matchExpressions:
  15599. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15600. items:
  15601. description: |-
  15602. A label selector requirement is a selector that contains values, a key, and an operator that
  15603. relates the key and values.
  15604. properties:
  15605. key:
  15606. description: key is the label key that the selector applies to.
  15607. type: string
  15608. operator:
  15609. description: |-
  15610. operator represents a key's relationship to a set of values.
  15611. Valid operators are In, NotIn, Exists and DoesNotExist.
  15612. type: string
  15613. values:
  15614. description: |-
  15615. values is an array of string values. If the operator is In or NotIn,
  15616. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15617. the values array must be empty. This array is replaced during a strategic
  15618. merge patch.
  15619. items:
  15620. type: string
  15621. type: array
  15622. x-kubernetes-list-type: atomic
  15623. required:
  15624. - key
  15625. - operator
  15626. type: object
  15627. type: array
  15628. x-kubernetes-list-type: atomic
  15629. matchLabels:
  15630. additionalProperties:
  15631. type: string
  15632. description: |-
  15633. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15634. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15635. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15636. type: object
  15637. type: object
  15638. x-kubernetes-map-type: atomic
  15639. namespaces:
  15640. description: Choose namespaces by name
  15641. items:
  15642. maxLength: 63
  15643. minLength: 1
  15644. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15645. type: string
  15646. type: array
  15647. type: object
  15648. type: array
  15649. controller:
  15650. description: |-
  15651. Used to select the correct ESO controller (think: ingress.ingressClassName)
  15652. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  15653. type: string
  15654. provider:
  15655. description: Used to configure the provider. Only one provider may be set
  15656. maxProperties: 1
  15657. minProperties: 1
  15658. properties:
  15659. akeyless:
  15660. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  15661. properties:
  15662. akeylessGWApiURL:
  15663. description: Akeyless GW API Url from which the secrets to be fetched from.
  15664. type: string
  15665. authSecretRef:
  15666. description: Auth configures how the operator authenticates with Akeyless.
  15667. properties:
  15668. kubernetesAuth:
  15669. description: |-
  15670. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  15671. token stored in the named Secret resource.
  15672. properties:
  15673. accessID:
  15674. description: the Akeyless Kubernetes auth-method access-id
  15675. type: string
  15676. k8sConfName:
  15677. description: Kubernetes-auth configuration name in Akeyless-Gateway
  15678. type: string
  15679. secretRef:
  15680. description: |-
  15681. Optional secret field containing a Kubernetes ServiceAccount JWT used
  15682. for authenticating with Akeyless. If a name is specified without a key,
  15683. `token` is the default. If one is not specified, the one bound to
  15684. the controller will be used.
  15685. properties:
  15686. key:
  15687. description: |-
  15688. A key in the referenced Secret.
  15689. Some instances of this field may be defaulted, in others it may be required.
  15690. maxLength: 253
  15691. minLength: 1
  15692. pattern: ^[-._a-zA-Z0-9]+$
  15693. type: string
  15694. name:
  15695. description: The name of the Secret resource being referred to.
  15696. maxLength: 253
  15697. minLength: 1
  15698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15699. type: string
  15700. namespace:
  15701. description: |-
  15702. The namespace of the Secret resource being referred to.
  15703. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15704. maxLength: 63
  15705. minLength: 1
  15706. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15707. type: string
  15708. type: object
  15709. serviceAccountRef:
  15710. description: |-
  15711. Optional service account field containing the name of a kubernetes ServiceAccount.
  15712. If the service account is specified, the service account secret token JWT will be used
  15713. for authenticating with Akeyless. If the service account selector is not supplied,
  15714. the secretRef will be used instead.
  15715. properties:
  15716. audiences:
  15717. description: |-
  15718. Audience specifies the `aud` claim for the service account token
  15719. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15720. then this audiences will be appended to the list
  15721. items:
  15722. type: string
  15723. type: array
  15724. name:
  15725. description: The name of the ServiceAccount resource being referred to.
  15726. maxLength: 253
  15727. minLength: 1
  15728. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15729. type: string
  15730. namespace:
  15731. description: |-
  15732. Namespace of the resource being referred to.
  15733. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15734. maxLength: 63
  15735. minLength: 1
  15736. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15737. type: string
  15738. required:
  15739. - name
  15740. type: object
  15741. required:
  15742. - accessID
  15743. - k8sConfName
  15744. type: object
  15745. secretRef:
  15746. description: |-
  15747. Reference to a Secret that contains the details
  15748. to authenticate with Akeyless.
  15749. properties:
  15750. accessID:
  15751. description: The SecretAccessID is used for authentication
  15752. properties:
  15753. key:
  15754. description: |-
  15755. A key in the referenced Secret.
  15756. Some instances of this field may be defaulted, in others it may be required.
  15757. maxLength: 253
  15758. minLength: 1
  15759. pattern: ^[-._a-zA-Z0-9]+$
  15760. type: string
  15761. name:
  15762. description: The name of the Secret resource being referred to.
  15763. maxLength: 253
  15764. minLength: 1
  15765. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15766. type: string
  15767. namespace:
  15768. description: |-
  15769. The namespace of the Secret resource being referred to.
  15770. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15771. maxLength: 63
  15772. minLength: 1
  15773. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15774. type: string
  15775. type: object
  15776. accessType:
  15777. description: |-
  15778. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15779. In some instances, `key` is a required field.
  15780. properties:
  15781. key:
  15782. description: |-
  15783. A key in the referenced Secret.
  15784. Some instances of this field may be defaulted, in others it may be required.
  15785. maxLength: 253
  15786. minLength: 1
  15787. pattern: ^[-._a-zA-Z0-9]+$
  15788. type: string
  15789. name:
  15790. description: The name of the Secret resource being referred to.
  15791. maxLength: 253
  15792. minLength: 1
  15793. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15794. type: string
  15795. namespace:
  15796. description: |-
  15797. The namespace of the Secret resource being referred to.
  15798. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15799. maxLength: 63
  15800. minLength: 1
  15801. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15802. type: string
  15803. type: object
  15804. accessTypeParam:
  15805. description: |-
  15806. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15807. In some instances, `key` is a required field.
  15808. properties:
  15809. key:
  15810. description: |-
  15811. A key in the referenced Secret.
  15812. Some instances of this field may be defaulted, in others it may be required.
  15813. maxLength: 253
  15814. minLength: 1
  15815. pattern: ^[-._a-zA-Z0-9]+$
  15816. type: string
  15817. name:
  15818. description: The name of the Secret resource being referred to.
  15819. maxLength: 253
  15820. minLength: 1
  15821. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15822. type: string
  15823. namespace:
  15824. description: |-
  15825. The namespace of the Secret resource being referred to.
  15826. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15827. maxLength: 63
  15828. minLength: 1
  15829. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15830. type: string
  15831. type: object
  15832. type: object
  15833. serviceAccountRef:
  15834. description: |-
  15835. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  15836. authentication on AKS Workload Identity. The operator obtains a federated
  15837. identity token from this ServiceAccount via the TokenRequest API instead
  15838. of using the ESO controller pod identity. Ignored for other access types.
  15839. properties:
  15840. audiences:
  15841. description: |-
  15842. Audience specifies the `aud` claim for the service account token
  15843. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15844. then this audiences will be appended to the list
  15845. items:
  15846. type: string
  15847. type: array
  15848. name:
  15849. description: The name of the ServiceAccount resource being referred to.
  15850. maxLength: 253
  15851. minLength: 1
  15852. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15853. type: string
  15854. namespace:
  15855. description: |-
  15856. Namespace of the resource being referred to.
  15857. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15858. maxLength: 63
  15859. minLength: 1
  15860. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15861. type: string
  15862. required:
  15863. - name
  15864. type: object
  15865. type: object
  15866. caBundle:
  15867. description: |-
  15868. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  15869. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  15870. are used to validate the TLS connection.
  15871. format: byte
  15872. type: string
  15873. caProvider:
  15874. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  15875. properties:
  15876. key:
  15877. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  15878. maxLength: 253
  15879. minLength: 1
  15880. pattern: ^[-._a-zA-Z0-9]+$
  15881. type: string
  15882. name:
  15883. description: The name of the object located at the provider type.
  15884. maxLength: 253
  15885. minLength: 1
  15886. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15887. type: string
  15888. namespace:
  15889. description: |-
  15890. The namespace the Provider type is in.
  15891. Can only be defined when used in a ClusterSecretStore.
  15892. maxLength: 63
  15893. minLength: 1
  15894. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15895. type: string
  15896. type:
  15897. description: The type of provider to use such as "Secret", or "ConfigMap".
  15898. enum:
  15899. - Secret
  15900. - ConfigMap
  15901. type: string
  15902. required:
  15903. - name
  15904. - type
  15905. type: object
  15906. ignoreCache:
  15907. description: |-
  15908. IgnoreCache bypasses the Gateway cache for secret reads when true.
  15909. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  15910. type: boolean
  15911. required:
  15912. - akeylessGWApiURL
  15913. - authSecretRef
  15914. type: object
  15915. aws:
  15916. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  15917. properties:
  15918. additionalRoles:
  15919. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  15920. items:
  15921. type: string
  15922. type: array
  15923. auth:
  15924. description: |-
  15925. Auth defines the information necessary to authenticate against AWS
  15926. if not set aws sdk will infer credentials from your environment
  15927. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  15928. properties:
  15929. jwt:
  15930. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  15931. properties:
  15932. serviceAccountRef:
  15933. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  15934. properties:
  15935. audiences:
  15936. description: |-
  15937. Audience specifies the `aud` claim for the service account token
  15938. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15939. then this audiences will be appended to the list
  15940. items:
  15941. type: string
  15942. type: array
  15943. name:
  15944. description: The name of the ServiceAccount resource being referred to.
  15945. maxLength: 253
  15946. minLength: 1
  15947. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15948. type: string
  15949. namespace:
  15950. description: |-
  15951. Namespace of the resource being referred to.
  15952. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15953. maxLength: 63
  15954. minLength: 1
  15955. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15956. type: string
  15957. required:
  15958. - name
  15959. type: object
  15960. type: object
  15961. secretRef:
  15962. description: |-
  15963. AWSAuthSecretRef holds secret references for AWS credentials
  15964. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  15965. properties:
  15966. accessKeyIDSecretRef:
  15967. description: The AccessKeyID is used for authentication
  15968. properties:
  15969. key:
  15970. description: |-
  15971. A key in the referenced Secret.
  15972. Some instances of this field may be defaulted, in others it may be required.
  15973. maxLength: 253
  15974. minLength: 1
  15975. pattern: ^[-._a-zA-Z0-9]+$
  15976. type: string
  15977. name:
  15978. description: The name of the Secret resource being referred to.
  15979. maxLength: 253
  15980. minLength: 1
  15981. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15982. type: string
  15983. namespace:
  15984. description: |-
  15985. The namespace of the Secret resource being referred to.
  15986. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15987. maxLength: 63
  15988. minLength: 1
  15989. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15990. type: string
  15991. type: object
  15992. secretAccessKeySecretRef:
  15993. description: The SecretAccessKey is used for authentication
  15994. properties:
  15995. key:
  15996. description: |-
  15997. A key in the referenced Secret.
  15998. Some instances of this field may be defaulted, in others it may be required.
  15999. maxLength: 253
  16000. minLength: 1
  16001. pattern: ^[-._a-zA-Z0-9]+$
  16002. type: string
  16003. name:
  16004. description: The name of the Secret resource being referred to.
  16005. maxLength: 253
  16006. minLength: 1
  16007. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16008. type: string
  16009. namespace:
  16010. description: |-
  16011. The namespace of the Secret resource being referred to.
  16012. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16013. maxLength: 63
  16014. minLength: 1
  16015. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16016. type: string
  16017. type: object
  16018. sessionTokenSecretRef:
  16019. description: |-
  16020. The SessionToken used for authentication
  16021. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  16022. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  16023. properties:
  16024. key:
  16025. description: |-
  16026. A key in the referenced Secret.
  16027. Some instances of this field may be defaulted, in others it may be required.
  16028. maxLength: 253
  16029. minLength: 1
  16030. pattern: ^[-._a-zA-Z0-9]+$
  16031. type: string
  16032. name:
  16033. description: The name of the Secret resource being referred to.
  16034. maxLength: 253
  16035. minLength: 1
  16036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16037. type: string
  16038. namespace:
  16039. description: |-
  16040. The namespace of the Secret resource being referred to.
  16041. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16042. maxLength: 63
  16043. minLength: 1
  16044. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16045. type: string
  16046. type: object
  16047. type: object
  16048. type: object
  16049. customSessionTags:
  16050. additionalProperties:
  16051. type: string
  16052. description: |-
  16053. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  16054. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  16055. type: object
  16056. x-kubernetes-validations:
  16057. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  16058. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  16059. externalID:
  16060. description: AWS External ID set on assumed IAM roles
  16061. type: string
  16062. prefix:
  16063. description: Prefix adds a prefix to all retrieved values.
  16064. type: string
  16065. region:
  16066. description: AWS Region to be used for the provider
  16067. type: string
  16068. role:
  16069. description: Role is a Role ARN which the provider will assume
  16070. type: string
  16071. secretsManager:
  16072. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  16073. properties:
  16074. forceDeleteWithoutRecovery:
  16075. description: |-
  16076. Specifies whether to delete the secret without any recovery window. You
  16077. can't use both this parameter and RecoveryWindowInDays in the same call.
  16078. If you don't use either, then by default Secrets Manager uses a 30 day
  16079. recovery window.
  16080. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  16081. type: boolean
  16082. recoveryWindowInDays:
  16083. description: |-
  16084. The number of days from 7 to 30 that Secrets Manager waits before
  16085. permanently deleting the secret. You can't use both this parameter and
  16086. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  16087. then by default Secrets Manager uses a 30-day recovery window.
  16088. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  16089. format: int64
  16090. type: integer
  16091. type: object
  16092. service:
  16093. description: Service defines which service should be used to fetch the secrets
  16094. enum:
  16095. - SecretsManager
  16096. - ParameterStore
  16097. - CertificateManager
  16098. type: string
  16099. sessionTags:
  16100. description: AWS STS assume role session tags
  16101. items:
  16102. description: |-
  16103. Tag is a key-value pair that can be attached to an AWS resource.
  16104. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  16105. properties:
  16106. key:
  16107. type: string
  16108. value:
  16109. type: string
  16110. required:
  16111. - key
  16112. - value
  16113. type: object
  16114. type: array
  16115. sessionTagsPolicy:
  16116. default: None
  16117. description: |-
  16118. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  16119. None (default): no tags are added.
  16120. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  16121. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  16122. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  16123. enum:
  16124. - None
  16125. - Simple
  16126. - Custom
  16127. type: string
  16128. transitiveTagKeys:
  16129. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  16130. items:
  16131. type: string
  16132. type: array
  16133. required:
  16134. - region
  16135. - service
  16136. type: object
  16137. azurekv:
  16138. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  16139. properties:
  16140. authSecretRef:
  16141. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16142. properties:
  16143. clientCertificate:
  16144. description: The Azure ClientCertificate of the service principle used for authentication.
  16145. properties:
  16146. key:
  16147. description: |-
  16148. A key in the referenced Secret.
  16149. Some instances of this field may be defaulted, in others it may be required.
  16150. maxLength: 253
  16151. minLength: 1
  16152. pattern: ^[-._a-zA-Z0-9]+$
  16153. type: string
  16154. name:
  16155. description: The name of the Secret resource being referred to.
  16156. maxLength: 253
  16157. minLength: 1
  16158. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16159. type: string
  16160. namespace:
  16161. description: |-
  16162. The namespace of the Secret resource being referred to.
  16163. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16164. maxLength: 63
  16165. minLength: 1
  16166. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16167. type: string
  16168. type: object
  16169. clientId:
  16170. description: The Azure clientId of the service principle or managed identity used for authentication.
  16171. properties:
  16172. key:
  16173. description: |-
  16174. A key in the referenced Secret.
  16175. Some instances of this field may be defaulted, in others it may be required.
  16176. maxLength: 253
  16177. minLength: 1
  16178. pattern: ^[-._a-zA-Z0-9]+$
  16179. type: string
  16180. name:
  16181. description: The name of the Secret resource being referred to.
  16182. maxLength: 253
  16183. minLength: 1
  16184. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16185. type: string
  16186. namespace:
  16187. description: |-
  16188. The namespace of the Secret resource being referred to.
  16189. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16190. maxLength: 63
  16191. minLength: 1
  16192. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16193. type: string
  16194. type: object
  16195. clientSecret:
  16196. description: The Azure ClientSecret of the service principle used for authentication.
  16197. properties:
  16198. key:
  16199. description: |-
  16200. A key in the referenced Secret.
  16201. Some instances of this field may be defaulted, in others it may be required.
  16202. maxLength: 253
  16203. minLength: 1
  16204. pattern: ^[-._a-zA-Z0-9]+$
  16205. type: string
  16206. name:
  16207. description: The name of the Secret resource being referred to.
  16208. maxLength: 253
  16209. minLength: 1
  16210. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16211. type: string
  16212. namespace:
  16213. description: |-
  16214. The namespace of the Secret resource being referred to.
  16215. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16216. maxLength: 63
  16217. minLength: 1
  16218. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16219. type: string
  16220. type: object
  16221. tenantId:
  16222. description: The Azure tenantId of the managed identity used for authentication.
  16223. properties:
  16224. key:
  16225. description: |-
  16226. A key in the referenced Secret.
  16227. Some instances of this field may be defaulted, in others it may be required.
  16228. maxLength: 253
  16229. minLength: 1
  16230. pattern: ^[-._a-zA-Z0-9]+$
  16231. type: string
  16232. name:
  16233. description: The name of the Secret resource being referred to.
  16234. maxLength: 253
  16235. minLength: 1
  16236. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16237. type: string
  16238. namespace:
  16239. description: |-
  16240. The namespace of the Secret resource being referred to.
  16241. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16242. maxLength: 63
  16243. minLength: 1
  16244. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16245. type: string
  16246. type: object
  16247. type: object
  16248. authType:
  16249. default: ServicePrincipal
  16250. description: |-
  16251. Auth type defines how to authenticate to the keyvault service.
  16252. Valid values are:
  16253. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  16254. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  16255. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  16256. enum:
  16257. - ServicePrincipal
  16258. - ManagedIdentity
  16259. - WorkloadIdentity
  16260. type: string
  16261. customCloudConfig:
  16262. description: |-
  16263. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  16264. Required when EnvironmentType is AzureStackCloud.
  16265. Optional for other environment types - useful for Azure China when using Workload Identity
  16266. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  16267. standard China Cloud endpoint (login.chinacloudapi.cn).
  16268. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  16269. configuration is not supported with the legacy go-autorest SDK.
  16270. properties:
  16271. activeDirectoryEndpoint:
  16272. description: |-
  16273. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  16274. Required when using custom cloud configuration
  16275. type: string
  16276. keyVaultDNSSuffix:
  16277. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  16278. type: string
  16279. keyVaultEndpoint:
  16280. description: KeyVaultEndpoint is the Key Vault service endpoint
  16281. type: string
  16282. resourceManagerEndpoint:
  16283. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  16284. type: string
  16285. required:
  16286. - activeDirectoryEndpoint
  16287. type: object
  16288. environmentType:
  16289. default: PublicCloud
  16290. description: |-
  16291. EnvironmentType specifies the Azure cloud environment endpoints to use for
  16292. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  16293. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  16294. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  16295. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  16296. enum:
  16297. - PublicCloud
  16298. - USGovernmentCloud
  16299. - ChinaCloud
  16300. - GermanCloud
  16301. - AzureStackCloud
  16302. type: string
  16303. identityId:
  16304. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  16305. type: string
  16306. serviceAccountRef:
  16307. description: |-
  16308. ServiceAccountRef specified the service account
  16309. that should be used when authenticating with WorkloadIdentity.
  16310. properties:
  16311. audiences:
  16312. description: |-
  16313. Audience specifies the `aud` claim for the service account token
  16314. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  16315. then this audiences will be appended to the list
  16316. items:
  16317. type: string
  16318. type: array
  16319. name:
  16320. description: The name of the ServiceAccount resource being referred to.
  16321. maxLength: 253
  16322. minLength: 1
  16323. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16324. type: string
  16325. namespace:
  16326. description: |-
  16327. Namespace of the resource being referred to.
  16328. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16329. maxLength: 63
  16330. minLength: 1
  16331. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16332. type: string
  16333. required:
  16334. - name
  16335. type: object
  16336. tenantId:
  16337. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16338. type: string
  16339. useAzureSDK:
  16340. default: false
  16341. description: |-
  16342. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  16343. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  16344. type: boolean
  16345. vaultUrl:
  16346. description: Vault Url from which the secrets to be fetched from.
  16347. type: string
  16348. required:
  16349. - vaultUrl
  16350. type: object
  16351. barbican:
  16352. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  16353. properties:
  16354. auth:
  16355. description: BarbicanAuth contains the authentication information for Barbican.
  16356. properties:
  16357. password:
  16358. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  16359. properties:
  16360. secretRef:
  16361. description: |-
  16362. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16363. In some instances, `key` is a required field.
  16364. properties:
  16365. key:
  16366. description: |-
  16367. A key in the referenced Secret.
  16368. Some instances of this field may be defaulted, in others it may be required.
  16369. maxLength: 253
  16370. minLength: 1
  16371. pattern: ^[-._a-zA-Z0-9]+$
  16372. type: string
  16373. name:
  16374. description: The name of the Secret resource being referred to.
  16375. maxLength: 253
  16376. minLength: 1
  16377. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16378. type: string
  16379. namespace:
  16380. description: |-
  16381. The namespace of the Secret resource being referred to.
  16382. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16383. maxLength: 63
  16384. minLength: 1
  16385. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16386. type: string
  16387. type: object
  16388. required:
  16389. - secretRef
  16390. type: object
  16391. username:
  16392. description: BarbicanProviderUsernameRef defines a reference to a secret containing username for the Barbican provider.
  16393. maxProperties: 1
  16394. minProperties: 1
  16395. properties:
  16396. secretRef:
  16397. description: |-
  16398. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16399. In some instances, `key` is a required field.
  16400. properties:
  16401. key:
  16402. description: |-
  16403. A key in the referenced Secret.
  16404. Some instances of this field may be defaulted, in others it may be required.
  16405. maxLength: 253
  16406. minLength: 1
  16407. pattern: ^[-._a-zA-Z0-9]+$
  16408. type: string
  16409. name:
  16410. description: The name of the Secret resource being referred to.
  16411. maxLength: 253
  16412. minLength: 1
  16413. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16414. type: string
  16415. namespace:
  16416. description: |-
  16417. The namespace of the Secret resource being referred to.
  16418. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16419. maxLength: 63
  16420. minLength: 1
  16421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16422. type: string
  16423. type: object
  16424. value:
  16425. type: string
  16426. type: object
  16427. required:
  16428. - password
  16429. - username
  16430. type: object
  16431. authURL:
  16432. type: string
  16433. domainName:
  16434. type: string
  16435. region:
  16436. type: string
  16437. tenantName:
  16438. type: string
  16439. required:
  16440. - auth
  16441. type: object
  16442. beyondtrust:
  16443. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  16444. properties:
  16445. auth:
  16446. description: Auth configures how the operator authenticates with Beyondtrust.
  16447. properties:
  16448. apiKey:
  16449. description: APIKey If not provided then ClientID/ClientSecret become required.
  16450. properties:
  16451. secretRef:
  16452. description: SecretRef references a key in a secret that will be used as value.
  16453. properties:
  16454. key:
  16455. description: |-
  16456. A key in the referenced Secret.
  16457. Some instances of this field may be defaulted, in others it may be required.
  16458. maxLength: 253
  16459. minLength: 1
  16460. pattern: ^[-._a-zA-Z0-9]+$
  16461. type: string
  16462. name:
  16463. description: The name of the Secret resource being referred to.
  16464. maxLength: 253
  16465. minLength: 1
  16466. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16467. type: string
  16468. namespace:
  16469. description: |-
  16470. The namespace of the Secret resource being referred to.
  16471. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16472. maxLength: 63
  16473. minLength: 1
  16474. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16475. type: string
  16476. type: object
  16477. value:
  16478. description: Value can be specified directly to set a value without using a secret.
  16479. type: string
  16480. type: object
  16481. certificate:
  16482. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  16483. properties:
  16484. secretRef:
  16485. description: SecretRef references a key in a secret that will be used as value.
  16486. properties:
  16487. key:
  16488. description: |-
  16489. A key in the referenced Secret.
  16490. Some instances of this field may be defaulted, in others it may be required.
  16491. maxLength: 253
  16492. minLength: 1
  16493. pattern: ^[-._a-zA-Z0-9]+$
  16494. type: string
  16495. name:
  16496. description: The name of the Secret resource being referred to.
  16497. maxLength: 253
  16498. minLength: 1
  16499. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16500. type: string
  16501. namespace:
  16502. description: |-
  16503. The namespace of the Secret resource being referred to.
  16504. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16505. maxLength: 63
  16506. minLength: 1
  16507. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16508. type: string
  16509. type: object
  16510. value:
  16511. description: Value can be specified directly to set a value without using a secret.
  16512. type: string
  16513. type: object
  16514. certificateKey:
  16515. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  16516. properties:
  16517. secretRef:
  16518. description: SecretRef references a key in a secret that will be used as value.
  16519. properties:
  16520. key:
  16521. description: |-
  16522. A key in the referenced Secret.
  16523. Some instances of this field may be defaulted, in others it may be required.
  16524. maxLength: 253
  16525. minLength: 1
  16526. pattern: ^[-._a-zA-Z0-9]+$
  16527. type: string
  16528. name:
  16529. description: The name of the Secret resource being referred to.
  16530. maxLength: 253
  16531. minLength: 1
  16532. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16533. type: string
  16534. namespace:
  16535. description: |-
  16536. The namespace of the Secret resource being referred to.
  16537. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16538. maxLength: 63
  16539. minLength: 1
  16540. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16541. type: string
  16542. type: object
  16543. value:
  16544. description: Value can be specified directly to set a value without using a secret.
  16545. type: string
  16546. type: object
  16547. clientId:
  16548. description: ClientID is the API OAuth Client ID.
  16549. properties:
  16550. secretRef:
  16551. description: SecretRef references a key in a secret that will be used as value.
  16552. properties:
  16553. key:
  16554. description: |-
  16555. A key in the referenced Secret.
  16556. Some instances of this field may be defaulted, in others it may be required.
  16557. maxLength: 253
  16558. minLength: 1
  16559. pattern: ^[-._a-zA-Z0-9]+$
  16560. type: string
  16561. name:
  16562. description: The name of the Secret resource being referred to.
  16563. maxLength: 253
  16564. minLength: 1
  16565. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16566. type: string
  16567. namespace:
  16568. description: |-
  16569. The namespace of the Secret resource being referred to.
  16570. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16571. maxLength: 63
  16572. minLength: 1
  16573. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16574. type: string
  16575. type: object
  16576. value:
  16577. description: Value can be specified directly to set a value without using a secret.
  16578. type: string
  16579. type: object
  16580. clientSecret:
  16581. description: ClientSecret is the API OAuth Client Secret.
  16582. properties:
  16583. secretRef:
  16584. description: SecretRef references a key in a secret that will be used as value.
  16585. properties:
  16586. key:
  16587. description: |-
  16588. A key in the referenced Secret.
  16589. Some instances of this field may be defaulted, in others it may be required.
  16590. maxLength: 253
  16591. minLength: 1
  16592. pattern: ^[-._a-zA-Z0-9]+$
  16593. type: string
  16594. name:
  16595. description: The name of the Secret resource being referred to.
  16596. maxLength: 253
  16597. minLength: 1
  16598. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16599. type: string
  16600. namespace:
  16601. description: |-
  16602. The namespace of the Secret resource being referred to.
  16603. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16604. maxLength: 63
  16605. minLength: 1
  16606. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16607. type: string
  16608. type: object
  16609. value:
  16610. description: Value can be specified directly to set a value without using a secret.
  16611. type: string
  16612. type: object
  16613. type: object
  16614. server:
  16615. description: Auth configures how API server works.
  16616. properties:
  16617. apiUrl:
  16618. type: string
  16619. apiVersion:
  16620. type: string
  16621. clientTimeOutSeconds:
  16622. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  16623. type: integer
  16624. decrypt:
  16625. default: true
  16626. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  16627. type: boolean
  16628. retrievalType:
  16629. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  16630. type: string
  16631. separator:
  16632. description: A character that separates the folder names.
  16633. type: string
  16634. verifyCA:
  16635. type: boolean
  16636. required:
  16637. - apiUrl
  16638. - verifyCA
  16639. type: object
  16640. required:
  16641. - auth
  16642. - server
  16643. type: object
  16644. beyondtrustworkloadcredentials:
  16645. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  16646. properties:
  16647. auth:
  16648. description: |-
  16649. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  16650. Currently supports API key authentication via Kubernetes secret reference.
  16651. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16652. properties:
  16653. apikey:
  16654. description: |-
  16655. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  16656. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  16657. properties:
  16658. token:
  16659. description: |-
  16660. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  16661. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  16662. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  16663. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16664. properties:
  16665. key:
  16666. description: |-
  16667. A key in the referenced Secret.
  16668. Some instances of this field may be defaulted, in others it may be required.
  16669. maxLength: 253
  16670. minLength: 1
  16671. pattern: ^[-._a-zA-Z0-9]+$
  16672. type: string
  16673. name:
  16674. description: The name of the Secret resource being referred to.
  16675. maxLength: 253
  16676. minLength: 1
  16677. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16678. type: string
  16679. namespace:
  16680. description: |-
  16681. The namespace of the Secret resource being referred to.
  16682. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16683. maxLength: 63
  16684. minLength: 1
  16685. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16686. type: string
  16687. type: object
  16688. required:
  16689. - token
  16690. type: object
  16691. required:
  16692. - apikey
  16693. type: object
  16694. caBundle:
  16695. description: |-
  16696. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  16697. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  16698. If not set, the system's trusted root certificates are used.
  16699. format: byte
  16700. type: string
  16701. caProvider:
  16702. description: |-
  16703. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  16704. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  16705. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  16706. properties:
  16707. key:
  16708. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16709. maxLength: 253
  16710. minLength: 1
  16711. pattern: ^[-._a-zA-Z0-9]+$
  16712. type: string
  16713. name:
  16714. description: The name of the object located at the provider type.
  16715. maxLength: 253
  16716. minLength: 1
  16717. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16718. type: string
  16719. namespace:
  16720. description: |-
  16721. The namespace the Provider type is in.
  16722. Can only be defined when used in a ClusterSecretStore.
  16723. maxLength: 63
  16724. minLength: 1
  16725. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16726. type: string
  16727. type:
  16728. description: The type of provider to use such as "Secret", or "ConfigMap".
  16729. enum:
  16730. - Secret
  16731. - ConfigMap
  16732. type: string
  16733. required:
  16734. - name
  16735. - type
  16736. type: object
  16737. folderPath:
  16738. description: |-
  16739. FolderPath specifies the default folder path for secret retrieval.
  16740. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  16741. Example: "production/database" or "dev/api-keys"
  16742. Leave empty to retrieve secrets from the root folder.
  16743. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  16744. type: string
  16745. server:
  16746. description: |-
  16747. Server configures the BeyondTrust Workload Credentials server connection details.
  16748. Includes the API URL and Site ID for your BeyondTrust instance.
  16749. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  16750. properties:
  16751. apiUrl:
  16752. description: |-
  16753. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  16754. This should be the full URL to your BeyondTrust instance.
  16755. Example: https://api.beyondtrust.io/siie
  16756. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  16757. type: string
  16758. siteId:
  16759. description: |-
  16760. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  16761. This identifier is unique to your BeyondTrust Workload Credentials instance.
  16762. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  16763. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  16764. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  16765. type: string
  16766. required:
  16767. - apiUrl
  16768. - siteId
  16769. type: object
  16770. required:
  16771. - auth
  16772. - server
  16773. type: object
  16774. bitwardensecretsmanager:
  16775. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  16776. properties:
  16777. apiURL:
  16778. type: string
  16779. auth:
  16780. description: |-
  16781. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  16782. Make sure that the token being used has permissions on the given secret.
  16783. properties:
  16784. secretRef:
  16785. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  16786. properties:
  16787. credentials:
  16788. description: AccessToken used for the bitwarden instance.
  16789. properties:
  16790. key:
  16791. description: |-
  16792. A key in the referenced Secret.
  16793. Some instances of this field may be defaulted, in others it may be required.
  16794. maxLength: 253
  16795. minLength: 1
  16796. pattern: ^[-._a-zA-Z0-9]+$
  16797. type: string
  16798. name:
  16799. description: The name of the Secret resource being referred to.
  16800. maxLength: 253
  16801. minLength: 1
  16802. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16803. type: string
  16804. namespace:
  16805. description: |-
  16806. The namespace of the Secret resource being referred to.
  16807. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16808. maxLength: 63
  16809. minLength: 1
  16810. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16811. type: string
  16812. type: object
  16813. required:
  16814. - credentials
  16815. type: object
  16816. required:
  16817. - secretRef
  16818. type: object
  16819. bitwardenServerSDKURL:
  16820. type: string
  16821. caBundle:
  16822. description: |-
  16823. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  16824. can be performed.
  16825. type: string
  16826. caProvider:
  16827. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  16828. properties:
  16829. key:
  16830. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16831. maxLength: 253
  16832. minLength: 1
  16833. pattern: ^[-._a-zA-Z0-9]+$
  16834. type: string
  16835. name:
  16836. description: The name of the object located at the provider type.
  16837. maxLength: 253
  16838. minLength: 1
  16839. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16840. type: string
  16841. namespace:
  16842. description: |-
  16843. The namespace the Provider type is in.
  16844. Can only be defined when used in a ClusterSecretStore.
  16845. maxLength: 63
  16846. minLength: 1
  16847. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16848. type: string
  16849. type:
  16850. description: The type of provider to use such as "Secret", or "ConfigMap".
  16851. enum:
  16852. - Secret
  16853. - ConfigMap
  16854. type: string
  16855. required:
  16856. - name
  16857. - type
  16858. type: object
  16859. identityURL:
  16860. type: string
  16861. organizationID:
  16862. description: OrganizationID determines which organization this secret store manages.
  16863. type: string
  16864. projectID:
  16865. description: ProjectID determines which project this secret store manages.
  16866. type: string
  16867. required:
  16868. - auth
  16869. - organizationID
  16870. - projectID
  16871. type: object
  16872. chef:
  16873. description: Chef configures this store to sync secrets with chef server
  16874. properties:
  16875. auth:
  16876. description: Auth defines the information necessary to authenticate against chef Server
  16877. properties:
  16878. secretRef:
  16879. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  16880. properties:
  16881. privateKeySecretRef:
  16882. description: SecretKey is the Signing Key in PEM format, used for authentication.
  16883. properties:
  16884. key:
  16885. description: |-
  16886. A key in the referenced Secret.
  16887. Some instances of this field may be defaulted, in others it may be required.
  16888. maxLength: 253
  16889. minLength: 1
  16890. pattern: ^[-._a-zA-Z0-9]+$
  16891. type: string
  16892. name:
  16893. description: The name of the Secret resource being referred to.
  16894. maxLength: 253
  16895. minLength: 1
  16896. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16897. type: string
  16898. namespace:
  16899. description: |-
  16900. The namespace of the Secret resource being referred to.
  16901. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16902. maxLength: 63
  16903. minLength: 1
  16904. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16905. type: string
  16906. type: object
  16907. required:
  16908. - privateKeySecretRef
  16909. type: object
  16910. required:
  16911. - secretRef
  16912. type: object
  16913. serverUrl:
  16914. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  16915. type: string
  16916. username:
  16917. description: UserName should be the user ID on the chef server
  16918. type: string
  16919. required:
  16920. - auth
  16921. - serverUrl
  16922. - username
  16923. type: object
  16924. cloudrusm:
  16925. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  16926. properties:
  16927. auth:
  16928. description: CSMAuth contains a secretRef for credentials.
  16929. properties:
  16930. secretRef:
  16931. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  16932. properties:
  16933. accessKeyIDSecretRef:
  16934. description: The AccessKeyID is used for authentication
  16935. properties:
  16936. key:
  16937. description: |-
  16938. A key in the referenced Secret.
  16939. Some instances of this field may be defaulted, in others it may be required.
  16940. maxLength: 253
  16941. minLength: 1
  16942. pattern: ^[-._a-zA-Z0-9]+$
  16943. type: string
  16944. name:
  16945. description: The name of the Secret resource being referred to.
  16946. maxLength: 253
  16947. minLength: 1
  16948. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16949. type: string
  16950. namespace:
  16951. description: |-
  16952. The namespace of the Secret resource being referred to.
  16953. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16954. maxLength: 63
  16955. minLength: 1
  16956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16957. type: string
  16958. type: object
  16959. accessKeySecretSecretRef:
  16960. description: The AccessKeySecret is used for authentication
  16961. properties:
  16962. key:
  16963. description: |-
  16964. A key in the referenced Secret.
  16965. Some instances of this field may be defaulted, in others it may be required.
  16966. maxLength: 253
  16967. minLength: 1
  16968. pattern: ^[-._a-zA-Z0-9]+$
  16969. type: string
  16970. name:
  16971. description: The name of the Secret resource being referred to.
  16972. maxLength: 253
  16973. minLength: 1
  16974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16975. type: string
  16976. namespace:
  16977. description: |-
  16978. The namespace of the Secret resource being referred to.
  16979. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16980. maxLength: 63
  16981. minLength: 1
  16982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16983. type: string
  16984. type: object
  16985. required:
  16986. - accessKeyIDSecretRef
  16987. - accessKeySecretSecretRef
  16988. type: object
  16989. type: object
  16990. projectID:
  16991. description: ProjectID is the project, which the secrets are stored in.
  16992. type: string
  16993. required:
  16994. - auth
  16995. type: object
  16996. conjur:
  16997. description: Conjur configures this store to sync secrets using conjur provider
  16998. properties:
  16999. auth:
  17000. description: Defines authentication settings for connecting to Conjur.
  17001. maxProperties: 1
  17002. minProperties: 1
  17003. properties:
  17004. apikey:
  17005. description: Authenticates with Conjur using an API key.
  17006. properties:
  17007. account:
  17008. description: Account is the Conjur organization account name.
  17009. type: string
  17010. apiKeyRef:
  17011. description: |-
  17012. A reference to a specific 'key' containing the Conjur API key
  17013. within a Secret resource. In some instances, `key` is a required field.
  17014. properties:
  17015. key:
  17016. description: |-
  17017. A key in the referenced Secret.
  17018. Some instances of this field may be defaulted, in others it may be required.
  17019. maxLength: 253
  17020. minLength: 1
  17021. pattern: ^[-._a-zA-Z0-9]+$
  17022. type: string
  17023. name:
  17024. description: The name of the Secret resource being referred to.
  17025. maxLength: 253
  17026. minLength: 1
  17027. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17028. type: string
  17029. namespace:
  17030. description: |-
  17031. The namespace of the Secret resource being referred to.
  17032. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17033. maxLength: 63
  17034. minLength: 1
  17035. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17036. type: string
  17037. type: object
  17038. userRef:
  17039. description: |-
  17040. A reference to a specific 'key' containing the Conjur username
  17041. within a Secret resource. In some instances, `key` is a required field.
  17042. properties:
  17043. key:
  17044. description: |-
  17045. A key in the referenced Secret.
  17046. Some instances of this field may be defaulted, in others it may be required.
  17047. maxLength: 253
  17048. minLength: 1
  17049. pattern: ^[-._a-zA-Z0-9]+$
  17050. type: string
  17051. name:
  17052. description: The name of the Secret resource being referred to.
  17053. maxLength: 253
  17054. minLength: 1
  17055. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17056. type: string
  17057. namespace:
  17058. description: |-
  17059. The namespace of the Secret resource being referred to.
  17060. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17061. maxLength: 63
  17062. minLength: 1
  17063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17064. type: string
  17065. type: object
  17066. required:
  17067. - account
  17068. - apiKeyRef
  17069. - userRef
  17070. type: object
  17071. cert:
  17072. description: Cert enables certificate-based authentication using a client certificate and key.
  17073. properties:
  17074. account:
  17075. description: Account is the Conjur organization account name.
  17076. type: string
  17077. clientCertRef:
  17078. description: |-
  17079. ClientCertRef is a reference to a specific 'key' containing the client certificate
  17080. within a Secret resource. The certificate must be PEM-encoded.
  17081. properties:
  17082. key:
  17083. description: |-
  17084. A key in the referenced Secret.
  17085. Some instances of this field may be defaulted, in others it may be required.
  17086. maxLength: 253
  17087. minLength: 1
  17088. pattern: ^[-._a-zA-Z0-9]+$
  17089. type: string
  17090. name:
  17091. description: The name of the Secret resource being referred to.
  17092. maxLength: 253
  17093. minLength: 1
  17094. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17095. type: string
  17096. namespace:
  17097. description: |-
  17098. The namespace of the Secret resource being referred to.
  17099. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17100. maxLength: 63
  17101. minLength: 1
  17102. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17103. type: string
  17104. type: object
  17105. clientKeyRef:
  17106. description: |-
  17107. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  17108. within a Secret resource. The key must be PEM-encoded.
  17109. properties:
  17110. key:
  17111. description: |-
  17112. A key in the referenced Secret.
  17113. Some instances of this field may be defaulted, in others it may be required.
  17114. maxLength: 253
  17115. minLength: 1
  17116. pattern: ^[-._a-zA-Z0-9]+$
  17117. type: string
  17118. name:
  17119. description: The name of the Secret resource being referred to.
  17120. maxLength: 253
  17121. minLength: 1
  17122. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17123. type: string
  17124. namespace:
  17125. description: |-
  17126. The namespace of the Secret resource being referred to.
  17127. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17128. maxLength: 63
  17129. minLength: 1
  17130. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17131. type: string
  17132. type: object
  17133. hostId:
  17134. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  17135. type: string
  17136. serviceID:
  17137. description: The conjur authn cert webservice id
  17138. type: string
  17139. required:
  17140. - account
  17141. - clientCertRef
  17142. - clientKeyRef
  17143. - serviceID
  17144. type: object
  17145. jwt:
  17146. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  17147. properties:
  17148. account:
  17149. description: Account is the Conjur organization account name.
  17150. type: string
  17151. hostId:
  17152. description: |-
  17153. Optional HostID for JWT authentication. This may be used depending
  17154. on how the Conjur JWT authenticator policy is configured.
  17155. type: string
  17156. secretRef:
  17157. description: |-
  17158. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  17159. authenticate with Conjur using the JWT authentication method.
  17160. properties:
  17161. key:
  17162. description: |-
  17163. A key in the referenced Secret.
  17164. Some instances of this field may be defaulted, in others it may be required.
  17165. maxLength: 253
  17166. minLength: 1
  17167. pattern: ^[-._a-zA-Z0-9]+$
  17168. type: string
  17169. name:
  17170. description: The name of the Secret resource being referred to.
  17171. maxLength: 253
  17172. minLength: 1
  17173. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17174. type: string
  17175. namespace:
  17176. description: |-
  17177. The namespace of the Secret resource being referred to.
  17178. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17179. maxLength: 63
  17180. minLength: 1
  17181. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17182. type: string
  17183. type: object
  17184. serviceAccountRef:
  17185. description: |-
  17186. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  17187. a token for with the `TokenRequest` API.
  17188. properties:
  17189. audiences:
  17190. description: |-
  17191. Audience specifies the `aud` claim for the service account token
  17192. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17193. then this audiences will be appended to the list
  17194. items:
  17195. type: string
  17196. type: array
  17197. name:
  17198. description: The name of the ServiceAccount resource being referred to.
  17199. maxLength: 253
  17200. minLength: 1
  17201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17202. type: string
  17203. namespace:
  17204. description: |-
  17205. Namespace of the resource being referred to.
  17206. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17207. maxLength: 63
  17208. minLength: 1
  17209. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17210. type: string
  17211. required:
  17212. - name
  17213. type: object
  17214. serviceID:
  17215. description: The conjur authn jwt webservice id
  17216. type: string
  17217. required:
  17218. - account
  17219. - serviceID
  17220. type: object
  17221. type: object
  17222. caBundle:
  17223. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  17224. type: string
  17225. caProvider:
  17226. description: |-
  17227. Used to provide custom certificate authority (CA) certificates
  17228. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  17229. that contains a PEM-encoded certificate.
  17230. properties:
  17231. key:
  17232. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17233. maxLength: 253
  17234. minLength: 1
  17235. pattern: ^[-._a-zA-Z0-9]+$
  17236. type: string
  17237. name:
  17238. description: The name of the object located at the provider type.
  17239. maxLength: 253
  17240. minLength: 1
  17241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17242. type: string
  17243. namespace:
  17244. description: |-
  17245. The namespace the Provider type is in.
  17246. Can only be defined when used in a ClusterSecretStore.
  17247. maxLength: 63
  17248. minLength: 1
  17249. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17250. type: string
  17251. type:
  17252. description: The type of provider to use such as "Secret", or "ConfigMap".
  17253. enum:
  17254. - Secret
  17255. - ConfigMap
  17256. type: string
  17257. required:
  17258. - name
  17259. - type
  17260. type: object
  17261. url:
  17262. description: URL is the endpoint of the Conjur instance.
  17263. type: string
  17264. required:
  17265. - auth
  17266. - url
  17267. type: object
  17268. crd:
  17269. description: |-
  17270. CRD configures this store to sync secrets from arbitrary Kubernetes resources,
  17271. including both custom resources (CRDs) and core API resources. Resources are
  17272. selected by API group, version and kind, where group can be "" (empty string)
  17273. for core resources such as ConfigMap. Reading the core v1 Secret is
  17274. intentionally blocked — use the Kubernetes provider for that.
  17275. properties:
  17276. auth:
  17277. description: |-
  17278. Auth configures authentication to the Kubernetes API, same as the
  17279. Kubernetes provider. Required when Server.URL is set (unless using AuthRef).
  17280. maxProperties: 1
  17281. minProperties: 1
  17282. properties:
  17283. cert:
  17284. description: has both clientCert and clientKey as secretKeySelector
  17285. properties:
  17286. clientCert:
  17287. description: |-
  17288. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17289. In some instances, `key` is a required field.
  17290. properties:
  17291. key:
  17292. description: |-
  17293. A key in the referenced Secret.
  17294. Some instances of this field may be defaulted, in others it may be required.
  17295. maxLength: 253
  17296. minLength: 1
  17297. pattern: ^[-._a-zA-Z0-9]+$
  17298. type: string
  17299. name:
  17300. description: The name of the Secret resource being referred to.
  17301. maxLength: 253
  17302. minLength: 1
  17303. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17304. type: string
  17305. namespace:
  17306. description: |-
  17307. The namespace of the Secret resource being referred to.
  17308. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17309. maxLength: 63
  17310. minLength: 1
  17311. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17312. type: string
  17313. type: object
  17314. clientKey:
  17315. description: |-
  17316. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17317. In some instances, `key` is a required field.
  17318. properties:
  17319. key:
  17320. description: |-
  17321. A key in the referenced Secret.
  17322. Some instances of this field may be defaulted, in others it may be required.
  17323. maxLength: 253
  17324. minLength: 1
  17325. pattern: ^[-._a-zA-Z0-9]+$
  17326. type: string
  17327. name:
  17328. description: The name of the Secret resource being referred to.
  17329. maxLength: 253
  17330. minLength: 1
  17331. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17332. type: string
  17333. namespace:
  17334. description: |-
  17335. The namespace of the Secret resource being referred to.
  17336. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17337. maxLength: 63
  17338. minLength: 1
  17339. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17340. type: string
  17341. type: object
  17342. required:
  17343. - clientCert
  17344. - clientKey
  17345. type: object
  17346. serviceAccount:
  17347. description: points to a service account that should be used for authentication
  17348. properties:
  17349. audiences:
  17350. description: |-
  17351. Audience specifies the `aud` claim for the service account token
  17352. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17353. then this audiences will be appended to the list
  17354. items:
  17355. type: string
  17356. type: array
  17357. name:
  17358. description: The name of the ServiceAccount resource being referred to.
  17359. maxLength: 253
  17360. minLength: 1
  17361. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17362. type: string
  17363. namespace:
  17364. description: |-
  17365. Namespace of the resource being referred to.
  17366. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17367. maxLength: 63
  17368. minLength: 1
  17369. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17370. type: string
  17371. required:
  17372. - name
  17373. type: object
  17374. token:
  17375. description: use static token to authenticate with
  17376. properties:
  17377. bearerToken:
  17378. description: |-
  17379. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17380. In some instances, `key` is a required field.
  17381. properties:
  17382. key:
  17383. description: |-
  17384. A key in the referenced Secret.
  17385. Some instances of this field may be defaulted, in others it may be required.
  17386. maxLength: 253
  17387. minLength: 1
  17388. pattern: ^[-._a-zA-Z0-9]+$
  17389. type: string
  17390. name:
  17391. description: The name of the Secret resource being referred to.
  17392. maxLength: 253
  17393. minLength: 1
  17394. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17395. type: string
  17396. namespace:
  17397. description: |-
  17398. The namespace of the Secret resource being referred to.
  17399. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17400. maxLength: 63
  17401. minLength: 1
  17402. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17403. type: string
  17404. type: object
  17405. required:
  17406. - bearerToken
  17407. type: object
  17408. type: object
  17409. authRef:
  17410. description: |-
  17411. AuthRef references a Secret containing a kubeconfig. Same semantics as the
  17412. Kubernetes provider.
  17413. properties:
  17414. key:
  17415. description: |-
  17416. A key in the referenced Secret.
  17417. Some instances of this field may be defaulted, in others it may be required.
  17418. maxLength: 253
  17419. minLength: 1
  17420. pattern: ^[-._a-zA-Z0-9]+$
  17421. type: string
  17422. name:
  17423. description: The name of the Secret resource being referred to.
  17424. maxLength: 253
  17425. minLength: 1
  17426. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17427. type: string
  17428. namespace:
  17429. description: |-
  17430. The namespace of the Secret resource being referred to.
  17431. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17432. maxLength: 63
  17433. minLength: 1
  17434. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17435. type: string
  17436. type: object
  17437. resource:
  17438. description: Resource identifies the CRD by its API group, version and kind.
  17439. properties:
  17440. group:
  17441. description: |-
  17442. Group is the API group of the resource. Use "" (empty string) for core
  17443. Kubernetes resources such as ConfigMap; use e.g. "config.example.io"
  17444. for a CRD. The field is required to be present in the manifest — write
  17445. `group: ""` explicitly for core resources so typos fail at admission
  17446. time rather than later at discovery.
  17447. type: string
  17448. kind:
  17449. description: Kind is the Kubernetes resource kind (e.g. "MyCustomResource").
  17450. minLength: 1
  17451. type: string
  17452. version:
  17453. description: Version is the API version of the resource (e.g. "v1alpha1").
  17454. minLength: 1
  17455. type: string
  17456. required:
  17457. - group
  17458. - kind
  17459. - version
  17460. type: object
  17461. server:
  17462. description: |-
  17463. Server configures the Kubernetes API address and TLS trust, same as the
  17464. Kubernetes provider. When omitted, the URL defaults to the in-cluster API.
  17465. properties:
  17466. caBundle:
  17467. description: CABundle is a base64-encoded CA certificate
  17468. format: byte
  17469. type: string
  17470. caProvider:
  17471. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  17472. properties:
  17473. key:
  17474. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17475. maxLength: 253
  17476. minLength: 1
  17477. pattern: ^[-._a-zA-Z0-9]+$
  17478. type: string
  17479. name:
  17480. description: The name of the object located at the provider type.
  17481. maxLength: 253
  17482. minLength: 1
  17483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17484. type: string
  17485. namespace:
  17486. description: |-
  17487. The namespace the Provider type is in.
  17488. Can only be defined when used in a ClusterSecretStore.
  17489. maxLength: 63
  17490. minLength: 1
  17491. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17492. type: string
  17493. type:
  17494. description: The type of provider to use such as "Secret", or "ConfigMap".
  17495. enum:
  17496. - Secret
  17497. - ConfigMap
  17498. type: string
  17499. required:
  17500. - name
  17501. - type
  17502. type: object
  17503. url:
  17504. default: kubernetes.default
  17505. description: configures the Kubernetes server Address.
  17506. type: string
  17507. type: object
  17508. whitelist:
  17509. description: |-
  17510. Whitelist optionally restricts which object names and requested properties
  17511. are allowed to be read.
  17512. properties:
  17513. rules:
  17514. description: |-
  17515. Rules is a list of allow rules. If rules are set, at least one rule must
  17516. match for a request to be allowed.
  17517. items:
  17518. description: CRDProviderWhitelistRule defines a single allow rule for CRD reads.
  17519. properties:
  17520. name:
  17521. description: |-
  17522. Name is an optional regular expression matched against the bare object name.
  17523. For both SecretStore and ClusterSecretStore this is always the object name
  17524. without any namespace prefix (e.g. "my-db-spec", not "prod/my-db-spec").
  17525. type: string
  17526. namespace:
  17527. description: |-
  17528. Namespace is an optional regular expression matched against the namespace of
  17529. the object. Applies only when a ClusterSecretStore is used; it is ignored
  17530. for SecretStore (where the namespace is fixed to the store namespace).
  17531. type: string
  17532. properties:
  17533. description: |-
  17534. Properties is an optional list of regular expressions matched against
  17535. requested property keys (for example: "spec.secretValue").
  17536. items:
  17537. type: string
  17538. type: array
  17539. type: object
  17540. type: array
  17541. type: object
  17542. required:
  17543. - resource
  17544. type: object
  17545. x-kubernetes-validations:
  17546. - message: one of auth or authRef is required
  17547. rule: has(self.auth) || has(self.authRef)
  17548. - message: at most one of the fields in [auth authRef] may be set
  17549. rule: '[has(self.auth),has(self.authRef)].filter(x,x==true).size() <= 1'
  17550. delinea:
  17551. description: |-
  17552. Delinea DevOps Secrets Vault
  17553. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  17554. properties:
  17555. clientId:
  17556. description: ClientID is the non-secret part of the credential.
  17557. properties:
  17558. secretRef:
  17559. description: SecretRef references a key in a secret that will be used as value.
  17560. properties:
  17561. key:
  17562. description: |-
  17563. A key in the referenced Secret.
  17564. Some instances of this field may be defaulted, in others it may be required.
  17565. maxLength: 253
  17566. minLength: 1
  17567. pattern: ^[-._a-zA-Z0-9]+$
  17568. type: string
  17569. name:
  17570. description: The name of the Secret resource being referred to.
  17571. maxLength: 253
  17572. minLength: 1
  17573. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17574. type: string
  17575. namespace:
  17576. description: |-
  17577. The namespace of the Secret resource being referred to.
  17578. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17579. maxLength: 63
  17580. minLength: 1
  17581. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17582. type: string
  17583. type: object
  17584. value:
  17585. description: Value can be specified directly to set a value without using a secret.
  17586. type: string
  17587. type: object
  17588. clientSecret:
  17589. description: ClientSecret is the secret part of the credential.
  17590. properties:
  17591. secretRef:
  17592. description: SecretRef references a key in a secret that will be used as value.
  17593. properties:
  17594. key:
  17595. description: |-
  17596. A key in the referenced Secret.
  17597. Some instances of this field may be defaulted, in others it may be required.
  17598. maxLength: 253
  17599. minLength: 1
  17600. pattern: ^[-._a-zA-Z0-9]+$
  17601. type: string
  17602. name:
  17603. description: The name of the Secret resource being referred to.
  17604. maxLength: 253
  17605. minLength: 1
  17606. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17607. type: string
  17608. namespace:
  17609. description: |-
  17610. The namespace of the Secret resource being referred to.
  17611. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17612. maxLength: 63
  17613. minLength: 1
  17614. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17615. type: string
  17616. type: object
  17617. value:
  17618. description: Value can be specified directly to set a value without using a secret.
  17619. type: string
  17620. type: object
  17621. tenant:
  17622. description: Tenant is the chosen hostname / site name.
  17623. type: string
  17624. tld:
  17625. description: |-
  17626. TLD is based on the server location that was chosen during provisioning.
  17627. If unset, defaults to "com".
  17628. type: string
  17629. urlTemplate:
  17630. description: |-
  17631. URLTemplate
  17632. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  17633. type: string
  17634. required:
  17635. - clientId
  17636. - clientSecret
  17637. - tenant
  17638. type: object
  17639. doppler:
  17640. description: Doppler configures this store to sync secrets using the Doppler provider
  17641. properties:
  17642. auth:
  17643. description: Auth configures how the Operator authenticates with the Doppler API
  17644. properties:
  17645. oidcConfig:
  17646. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  17647. properties:
  17648. expirationSeconds:
  17649. default: 600
  17650. description: |-
  17651. ExpirationSeconds sets the ServiceAccount token validity duration.
  17652. Defaults to 10 minutes.
  17653. format: int64
  17654. type: integer
  17655. identity:
  17656. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  17657. type: string
  17658. serviceAccountRef:
  17659. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  17660. properties:
  17661. audiences:
  17662. description: |-
  17663. Audience specifies the `aud` claim for the service account token
  17664. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17665. then this audiences will be appended to the list
  17666. items:
  17667. type: string
  17668. type: array
  17669. name:
  17670. description: The name of the ServiceAccount resource being referred to.
  17671. maxLength: 253
  17672. minLength: 1
  17673. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17674. type: string
  17675. namespace:
  17676. description: |-
  17677. Namespace of the resource being referred to.
  17678. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17679. maxLength: 63
  17680. minLength: 1
  17681. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17682. type: string
  17683. required:
  17684. - name
  17685. type: object
  17686. required:
  17687. - identity
  17688. - serviceAccountRef
  17689. type: object
  17690. secretRef:
  17691. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  17692. properties:
  17693. dopplerToken:
  17694. description: |-
  17695. The DopplerToken is used for authentication.
  17696. See https://docs.doppler.com/reference/api#authentication for auth token types.
  17697. The Key attribute defaults to dopplerToken if not specified.
  17698. properties:
  17699. key:
  17700. description: |-
  17701. A key in the referenced Secret.
  17702. Some instances of this field may be defaulted, in others it may be required.
  17703. maxLength: 253
  17704. minLength: 1
  17705. pattern: ^[-._a-zA-Z0-9]+$
  17706. type: string
  17707. name:
  17708. description: The name of the Secret resource being referred to.
  17709. maxLength: 253
  17710. minLength: 1
  17711. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17712. type: string
  17713. namespace:
  17714. description: |-
  17715. The namespace of the Secret resource being referred to.
  17716. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17717. maxLength: 63
  17718. minLength: 1
  17719. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17720. type: string
  17721. type: object
  17722. required:
  17723. - dopplerToken
  17724. type: object
  17725. type: object
  17726. x-kubernetes-validations:
  17727. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  17728. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  17729. config:
  17730. description: Doppler config (required if not using a Service Token)
  17731. type: string
  17732. format:
  17733. description: Format enables the downloading of secrets as a file (string)
  17734. enum:
  17735. - json
  17736. - dotnet-json
  17737. - env
  17738. - yaml
  17739. - docker
  17740. type: string
  17741. nameTransformer:
  17742. description: Environment variable compatible name transforms that change secret names to a different format
  17743. enum:
  17744. - upper-camel
  17745. - camel
  17746. - lower-snake
  17747. - tf-var
  17748. - dotnet-env
  17749. - lower-kebab
  17750. type: string
  17751. project:
  17752. description: Doppler project (required if not using a Service Token)
  17753. type: string
  17754. required:
  17755. - auth
  17756. type: object
  17757. dvls:
  17758. description: DVLS configures this store to sync secrets using Devolutions Server provider
  17759. properties:
  17760. auth:
  17761. description: Auth defines the authentication method to use.
  17762. properties:
  17763. secretRef:
  17764. description: SecretRef contains the Application ID and Application Secret for authentication.
  17765. properties:
  17766. appId:
  17767. description: AppID is the reference to the secret containing the Application ID.
  17768. properties:
  17769. key:
  17770. description: |-
  17771. A key in the referenced Secret.
  17772. Some instances of this field may be defaulted, in others it may be required.
  17773. maxLength: 253
  17774. minLength: 1
  17775. pattern: ^[-._a-zA-Z0-9]+$
  17776. type: string
  17777. name:
  17778. description: The name of the Secret resource being referred to.
  17779. maxLength: 253
  17780. minLength: 1
  17781. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17782. type: string
  17783. namespace:
  17784. description: |-
  17785. The namespace of the Secret resource being referred to.
  17786. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17787. maxLength: 63
  17788. minLength: 1
  17789. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17790. type: string
  17791. type: object
  17792. appSecret:
  17793. description: AppSecret is the reference to the secret containing the Application Secret.
  17794. properties:
  17795. key:
  17796. description: |-
  17797. A key in the referenced Secret.
  17798. Some instances of this field may be defaulted, in others it may be required.
  17799. maxLength: 253
  17800. minLength: 1
  17801. pattern: ^[-._a-zA-Z0-9]+$
  17802. type: string
  17803. name:
  17804. description: The name of the Secret resource being referred to.
  17805. maxLength: 253
  17806. minLength: 1
  17807. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17808. type: string
  17809. namespace:
  17810. description: |-
  17811. The namespace of the Secret resource being referred to.
  17812. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17813. maxLength: 63
  17814. minLength: 1
  17815. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17816. type: string
  17817. type: object
  17818. required:
  17819. - appId
  17820. - appSecret
  17821. type: object
  17822. required:
  17823. - secretRef
  17824. type: object
  17825. insecure:
  17826. description: |-
  17827. Insecure allows connecting to DVLS over plain HTTP.
  17828. This is NOT RECOMMENDED for production use.
  17829. Set to true only if you understand the security implications.
  17830. type: boolean
  17831. serverUrl:
  17832. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  17833. type: string
  17834. vault:
  17835. description: |-
  17836. Vault is the name or UUID of the vault to fetch secrets from.
  17837. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  17838. type: string
  17839. required:
  17840. - auth
  17841. - serverUrl
  17842. type: object
  17843. fake:
  17844. description: Fake configures a store with static key/value pairs
  17845. properties:
  17846. data:
  17847. items:
  17848. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  17849. properties:
  17850. key:
  17851. type: string
  17852. value:
  17853. type: string
  17854. version:
  17855. type: string
  17856. required:
  17857. - key
  17858. - value
  17859. type: object
  17860. type: array
  17861. validationResult:
  17862. description: ValidationResult is defined type for the number of validation results.
  17863. type: integer
  17864. required:
  17865. - data
  17866. type: object
  17867. fortanix:
  17868. description: Fortanix configures this store to sync secrets using the Fortanix provider
  17869. properties:
  17870. apiKey:
  17871. description: APIKey is the API token to access SDKMS Applications.
  17872. properties:
  17873. secretRef:
  17874. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  17875. properties:
  17876. key:
  17877. description: |-
  17878. A key in the referenced Secret.
  17879. Some instances of this field may be defaulted, in others it may be required.
  17880. maxLength: 253
  17881. minLength: 1
  17882. pattern: ^[-._a-zA-Z0-9]+$
  17883. type: string
  17884. name:
  17885. description: The name of the Secret resource being referred to.
  17886. maxLength: 253
  17887. minLength: 1
  17888. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17889. type: string
  17890. namespace:
  17891. description: |-
  17892. The namespace of the Secret resource being referred to.
  17893. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17894. maxLength: 63
  17895. minLength: 1
  17896. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17897. type: string
  17898. type: object
  17899. type: object
  17900. apiUrl:
  17901. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  17902. type: string
  17903. type: object
  17904. gcpsm:
  17905. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  17906. properties:
  17907. auth:
  17908. description: Auth defines the information necessary to authenticate against GCP
  17909. properties:
  17910. secretRef:
  17911. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  17912. properties:
  17913. secretAccessKeySecretRef:
  17914. description: The SecretAccessKey is used for authentication
  17915. properties:
  17916. key:
  17917. description: |-
  17918. A key in the referenced Secret.
  17919. Some instances of this field may be defaulted, in others it may be required.
  17920. maxLength: 253
  17921. minLength: 1
  17922. pattern: ^[-._a-zA-Z0-9]+$
  17923. type: string
  17924. name:
  17925. description: The name of the Secret resource being referred to.
  17926. maxLength: 253
  17927. minLength: 1
  17928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17929. type: string
  17930. namespace:
  17931. description: |-
  17932. The namespace of the Secret resource being referred to.
  17933. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17934. maxLength: 63
  17935. minLength: 1
  17936. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17937. type: string
  17938. type: object
  17939. type: object
  17940. workloadIdentity:
  17941. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  17942. properties:
  17943. clusterLocation:
  17944. description: |-
  17945. ClusterLocation is the location of the cluster
  17946. If not specified, it fetches information from the metadata server
  17947. type: string
  17948. clusterName:
  17949. description: |-
  17950. ClusterName is the name of the cluster
  17951. If not specified, it fetches information from the metadata server
  17952. type: string
  17953. clusterProjectID:
  17954. description: |-
  17955. ClusterProjectID is the project ID of the cluster
  17956. If not specified, it fetches information from the metadata server
  17957. type: string
  17958. serviceAccountRef:
  17959. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  17960. properties:
  17961. audiences:
  17962. description: |-
  17963. Audience specifies the `aud` claim for the service account token
  17964. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17965. then this audiences will be appended to the list
  17966. items:
  17967. type: string
  17968. type: array
  17969. name:
  17970. description: The name of the ServiceAccount resource being referred to.
  17971. maxLength: 253
  17972. minLength: 1
  17973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17974. type: string
  17975. namespace:
  17976. description: |-
  17977. Namespace of the resource being referred to.
  17978. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17979. maxLength: 63
  17980. minLength: 1
  17981. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17982. type: string
  17983. required:
  17984. - name
  17985. type: object
  17986. required:
  17987. - serviceAccountRef
  17988. type: object
  17989. workloadIdentityFederation:
  17990. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  17991. properties:
  17992. audience:
  17993. description: |-
  17994. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  17995. If specified, Audience found in the external account credential config will be overridden with the configured value.
  17996. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  17997. type: string
  17998. awsSecurityCredentials:
  17999. description: |-
  18000. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  18001. when using the AWS metadata server is not an option.
  18002. properties:
  18003. awsCredentialsSecretRef:
  18004. description: |-
  18005. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  18006. Secret should be created with below names for keys
  18007. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  18008. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  18009. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  18010. properties:
  18011. name:
  18012. description: name of the secret.
  18013. maxLength: 253
  18014. minLength: 1
  18015. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18016. type: string
  18017. namespace:
  18018. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  18019. maxLength: 63
  18020. minLength: 1
  18021. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18022. type: string
  18023. required:
  18024. - name
  18025. type: object
  18026. region:
  18027. description: region is for configuring the AWS region to be used.
  18028. example: ap-south-1
  18029. maxLength: 50
  18030. minLength: 1
  18031. pattern: ^[a-z0-9-]+$
  18032. type: string
  18033. required:
  18034. - awsCredentialsSecretRef
  18035. - region
  18036. type: object
  18037. credConfig:
  18038. description: |-
  18039. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  18040. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  18041. serviceAccountRef must be used by providing operators service account details.
  18042. properties:
  18043. key:
  18044. description: key name holding the external account credential config.
  18045. maxLength: 253
  18046. minLength: 1
  18047. pattern: ^[-._a-zA-Z0-9]+$
  18048. type: string
  18049. name:
  18050. description: name of the configmap.
  18051. maxLength: 253
  18052. minLength: 1
  18053. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18054. type: string
  18055. namespace:
  18056. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  18057. maxLength: 63
  18058. minLength: 1
  18059. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18060. type: string
  18061. required:
  18062. - key
  18063. - name
  18064. type: object
  18065. externalTokenEndpoint:
  18066. description: |-
  18067. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  18068. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  18069. URL is having the expected value.
  18070. type: string
  18071. gcpServiceAccountEmail:
  18072. description: |-
  18073. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  18074. after Workload Identity Federation. Use this to grant access through the service account's
  18075. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  18076. service_account_impersonation_url in the external account JSON from credConfig;
  18077. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  18078. on that ServiceAccount.
  18079. example: my-gsa@my-project.iam.gserviceaccount.com
  18080. minLength: 1
  18081. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  18082. type: string
  18083. serviceAccountRef:
  18084. description: |-
  18085. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  18086. when Kubernetes is configured as provider in workload identity pool.
  18087. properties:
  18088. audiences:
  18089. description: |-
  18090. Audience specifies the `aud` claim for the service account token
  18091. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  18092. then this audiences will be appended to the list
  18093. items:
  18094. type: string
  18095. type: array
  18096. name:
  18097. description: The name of the ServiceAccount resource being referred to.
  18098. maxLength: 253
  18099. minLength: 1
  18100. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18101. type: string
  18102. namespace:
  18103. description: |-
  18104. Namespace of the resource being referred to.
  18105. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18106. maxLength: 63
  18107. minLength: 1
  18108. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18109. type: string
  18110. required:
  18111. - name
  18112. type: object
  18113. type: object
  18114. type: object
  18115. location:
  18116. description: Location optionally defines a location for a secret
  18117. type: string
  18118. projectID:
  18119. description: ProjectID project where secret is located
  18120. type: string
  18121. secretVersionSelectionPolicy:
  18122. default: LatestOrFail
  18123. description: |-
  18124. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  18125. when "latest" is disabled or destroyed.
  18126. Possible values are:
  18127. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  18128. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  18129. type: string
  18130. type: object
  18131. github:
  18132. description: |-
  18133. Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  18134. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  18135. properties:
  18136. appID:
  18137. description: appID specifies the Github APP that will be used to authenticate the client
  18138. format: int64
  18139. type: integer
  18140. auth:
  18141. description: auth configures how secret-manager authenticates with a Github instance.
  18142. properties:
  18143. privateKey:
  18144. description: |-
  18145. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18146. In some instances, `key` is a required field.
  18147. properties:
  18148. key:
  18149. description: |-
  18150. A key in the referenced Secret.
  18151. Some instances of this field may be defaulted, in others it may be required.
  18152. maxLength: 253
  18153. minLength: 1
  18154. pattern: ^[-._a-zA-Z0-9]+$
  18155. type: string
  18156. name:
  18157. description: The name of the Secret resource being referred to.
  18158. maxLength: 253
  18159. minLength: 1
  18160. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18161. type: string
  18162. namespace:
  18163. description: |-
  18164. The namespace of the Secret resource being referred to.
  18165. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18166. maxLength: 63
  18167. minLength: 1
  18168. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18169. type: string
  18170. type: object
  18171. required:
  18172. - privateKey
  18173. type: object
  18174. environment:
  18175. description: environment will be used to fetch secrets from a particular environment within a github repository
  18176. type: string
  18177. installationID:
  18178. description: installationID specifies the Github APP installation that will be used to authenticate the client
  18179. format: int64
  18180. type: integer
  18181. orgSecretVisibility:
  18182. description: |-
  18183. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  18184. Valid values are "all" or "private".
  18185. When unset, new secrets are created with visibility "all" and existing secrets preserve
  18186. whatever visibility they already have in GitHub.
  18187. enum:
  18188. - all
  18189. - private
  18190. type: string
  18191. organization:
  18192. description: organization will be used to fetch secrets from the Github organization
  18193. type: string
  18194. repository:
  18195. description: repository will be used to fetch secrets from the Github repository within an organization
  18196. type: string
  18197. uploadURL:
  18198. description: Upload URL for enterprise instances. Default to URL.
  18199. type: string
  18200. url:
  18201. default: https://github.com/
  18202. description: URL configures the Github instance URL. Defaults to https://github.com/.
  18203. type: string
  18204. required:
  18205. - appID
  18206. - auth
  18207. - installationID
  18208. - organization
  18209. type: object
  18210. gitlab:
  18211. description: GitLab configures this store to sync secrets using GitLab Variables provider
  18212. properties:
  18213. auth:
  18214. description: Auth configures how secret-manager authenticates with a GitLab instance.
  18215. properties:
  18216. SecretRef:
  18217. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  18218. properties:
  18219. accessToken:
  18220. description: AccessToken is used for authentication.
  18221. properties:
  18222. key:
  18223. description: |-
  18224. A key in the referenced Secret.
  18225. Some instances of this field may be defaulted, in others it may be required.
  18226. maxLength: 253
  18227. minLength: 1
  18228. pattern: ^[-._a-zA-Z0-9]+$
  18229. type: string
  18230. name:
  18231. description: The name of the Secret resource being referred to.
  18232. maxLength: 253
  18233. minLength: 1
  18234. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18235. type: string
  18236. namespace:
  18237. description: |-
  18238. The namespace of the Secret resource being referred to.
  18239. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18240. maxLength: 63
  18241. minLength: 1
  18242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18243. type: string
  18244. type: object
  18245. type: object
  18246. required:
  18247. - SecretRef
  18248. type: object
  18249. caBundle:
  18250. description: |-
  18251. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  18252. can be performed.
  18253. format: byte
  18254. type: string
  18255. caProvider:
  18256. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  18257. properties:
  18258. key:
  18259. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  18260. maxLength: 253
  18261. minLength: 1
  18262. pattern: ^[-._a-zA-Z0-9]+$
  18263. type: string
  18264. name:
  18265. description: The name of the object located at the provider type.
  18266. maxLength: 253
  18267. minLength: 1
  18268. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18269. type: string
  18270. namespace:
  18271. description: |-
  18272. The namespace the Provider type is in.
  18273. Can only be defined when used in a ClusterSecretStore.
  18274. maxLength: 63
  18275. minLength: 1
  18276. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18277. type: string
  18278. type:
  18279. description: The type of provider to use such as "Secret", or "ConfigMap".
  18280. enum:
  18281. - Secret
  18282. - ConfigMap
  18283. type: string
  18284. required:
  18285. - name
  18286. - type
  18287. type: object
  18288. environment:
  18289. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  18290. type: string
  18291. groupIDs:
  18292. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  18293. items:
  18294. type: string
  18295. type: array
  18296. inheritFromGroups:
  18297. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  18298. type: boolean
  18299. projectID:
  18300. description: ProjectID specifies a project where secrets are located.
  18301. type: string
  18302. url:
  18303. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  18304. type: string
  18305. required:
  18306. - auth
  18307. type: object
  18308. ibm:
  18309. description: IBM configures this store to sync secrets using IBM Cloud provider
  18310. properties:
  18311. auth:
  18312. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  18313. maxProperties: 1
  18314. minProperties: 1
  18315. properties:
  18316. containerAuth:
  18317. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  18318. properties:
  18319. iamEndpoint:
  18320. type: string
  18321. profile:
  18322. description: the IBM Trusted Profile
  18323. type: string
  18324. tokenLocation:
  18325. description: Location the token is mounted on the pod
  18326. type: string
  18327. required:
  18328. - profile
  18329. type: object
  18330. secretRef:
  18331. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  18332. properties:
  18333. iamEndpoint:
  18334. description: The IAM endpoint used to obain a token
  18335. type: string
  18336. secretApiKeySecretRef:
  18337. description: The SecretAccessKey is used for authentication
  18338. properties:
  18339. key:
  18340. description: |-
  18341. A key in the referenced Secret.
  18342. Some instances of this field may be defaulted, in others it may be required.
  18343. maxLength: 253
  18344. minLength: 1
  18345. pattern: ^[-._a-zA-Z0-9]+$
  18346. type: string
  18347. name:
  18348. description: The name of the Secret resource being referred to.
  18349. maxLength: 253
  18350. minLength: 1
  18351. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18352. type: string
  18353. namespace:
  18354. description: |-
  18355. The namespace of the Secret resource being referred to.
  18356. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18357. maxLength: 63
  18358. minLength: 1
  18359. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18360. type: string
  18361. type: object
  18362. type: object
  18363. type: object
  18364. serviceUrl:
  18365. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  18366. type: string
  18367. required:
  18368. - auth
  18369. type: object
  18370. infisical:
  18371. description: Infisical configures this store to sync secrets using the Infisical provider
  18372. properties:
  18373. auth:
  18374. description: Auth configures how the Operator authenticates with the Infisical API
  18375. properties:
  18376. awsAuthCredentials:
  18377. description: AwsAuthCredentials represents the credentials for AWS authentication.
  18378. properties:
  18379. identityId:
  18380. description: |-
  18381. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18382. In some instances, `key` is a required field.
  18383. properties:
  18384. key:
  18385. description: |-
  18386. A key in the referenced Secret.
  18387. Some instances of this field may be defaulted, in others it may be required.
  18388. maxLength: 253
  18389. minLength: 1
  18390. pattern: ^[-._a-zA-Z0-9]+$
  18391. type: string
  18392. name:
  18393. description: The name of the Secret resource being referred to.
  18394. maxLength: 253
  18395. minLength: 1
  18396. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18397. type: string
  18398. namespace:
  18399. description: |-
  18400. The namespace of the Secret resource being referred to.
  18401. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18402. maxLength: 63
  18403. minLength: 1
  18404. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18405. type: string
  18406. type: object
  18407. required:
  18408. - identityId
  18409. type: object
  18410. azureAuthCredentials:
  18411. description: AzureAuthCredentials represents the credentials for Azure authentication.
  18412. properties:
  18413. identityId:
  18414. description: |-
  18415. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18416. In some instances, `key` is a required field.
  18417. properties:
  18418. key:
  18419. description: |-
  18420. A key in the referenced Secret.
  18421. Some instances of this field may be defaulted, in others it may be required.
  18422. maxLength: 253
  18423. minLength: 1
  18424. pattern: ^[-._a-zA-Z0-9]+$
  18425. type: string
  18426. name:
  18427. description: The name of the Secret resource being referred to.
  18428. maxLength: 253
  18429. minLength: 1
  18430. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18431. type: string
  18432. namespace:
  18433. description: |-
  18434. The namespace of the Secret resource being referred to.
  18435. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18436. maxLength: 63
  18437. minLength: 1
  18438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18439. type: string
  18440. type: object
  18441. resource:
  18442. description: |-
  18443. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18444. In some instances, `key` is a required field.
  18445. properties:
  18446. key:
  18447. description: |-
  18448. A key in the referenced Secret.
  18449. Some instances of this field may be defaulted, in others it may be required.
  18450. maxLength: 253
  18451. minLength: 1
  18452. pattern: ^[-._a-zA-Z0-9]+$
  18453. type: string
  18454. name:
  18455. description: The name of the Secret resource being referred to.
  18456. maxLength: 253
  18457. minLength: 1
  18458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18459. type: string
  18460. namespace:
  18461. description: |-
  18462. The namespace of the Secret resource being referred to.
  18463. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18464. maxLength: 63
  18465. minLength: 1
  18466. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18467. type: string
  18468. type: object
  18469. required:
  18470. - identityId
  18471. type: object
  18472. gcpIamAuthCredentials:
  18473. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  18474. properties:
  18475. identityId:
  18476. description: |-
  18477. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18478. In some instances, `key` is a required field.
  18479. properties:
  18480. key:
  18481. description: |-
  18482. A key in the referenced Secret.
  18483. Some instances of this field may be defaulted, in others it may be required.
  18484. maxLength: 253
  18485. minLength: 1
  18486. pattern: ^[-._a-zA-Z0-9]+$
  18487. type: string
  18488. name:
  18489. description: The name of the Secret resource being referred to.
  18490. maxLength: 253
  18491. minLength: 1
  18492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18493. type: string
  18494. namespace:
  18495. description: |-
  18496. The namespace of the Secret resource being referred to.
  18497. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18498. maxLength: 63
  18499. minLength: 1
  18500. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18501. type: string
  18502. type: object
  18503. serviceAccountKeyFilePath:
  18504. description: |-
  18505. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18506. In some instances, `key` is a required field.
  18507. properties:
  18508. key:
  18509. description: |-
  18510. A key in the referenced Secret.
  18511. Some instances of this field may be defaulted, in others it may be required.
  18512. maxLength: 253
  18513. minLength: 1
  18514. pattern: ^[-._a-zA-Z0-9]+$
  18515. type: string
  18516. name:
  18517. description: The name of the Secret resource being referred to.
  18518. maxLength: 253
  18519. minLength: 1
  18520. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18521. type: string
  18522. namespace:
  18523. description: |-
  18524. The namespace of the Secret resource being referred to.
  18525. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18526. maxLength: 63
  18527. minLength: 1
  18528. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18529. type: string
  18530. type: object
  18531. required:
  18532. - identityId
  18533. - serviceAccountKeyFilePath
  18534. type: object
  18535. gcpIdTokenAuthCredentials:
  18536. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  18537. properties:
  18538. identityId:
  18539. description: |-
  18540. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18541. In some instances, `key` is a required field.
  18542. properties:
  18543. key:
  18544. description: |-
  18545. A key in the referenced Secret.
  18546. Some instances of this field may be defaulted, in others it may be required.
  18547. maxLength: 253
  18548. minLength: 1
  18549. pattern: ^[-._a-zA-Z0-9]+$
  18550. type: string
  18551. name:
  18552. description: The name of the Secret resource being referred to.
  18553. maxLength: 253
  18554. minLength: 1
  18555. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18556. type: string
  18557. namespace:
  18558. description: |-
  18559. The namespace of the Secret resource being referred to.
  18560. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18561. maxLength: 63
  18562. minLength: 1
  18563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18564. type: string
  18565. type: object
  18566. required:
  18567. - identityId
  18568. type: object
  18569. jwtAuthCredentials:
  18570. description: JwtAuthCredentials represents the credentials for JWT authentication.
  18571. properties:
  18572. identityId:
  18573. description: |-
  18574. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18575. In some instances, `key` is a required field.
  18576. properties:
  18577. key:
  18578. description: |-
  18579. A key in the referenced Secret.
  18580. Some instances of this field may be defaulted, in others it may be required.
  18581. maxLength: 253
  18582. minLength: 1
  18583. pattern: ^[-._a-zA-Z0-9]+$
  18584. type: string
  18585. name:
  18586. description: The name of the Secret resource being referred to.
  18587. maxLength: 253
  18588. minLength: 1
  18589. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18590. type: string
  18591. namespace:
  18592. description: |-
  18593. The namespace of the Secret resource being referred to.
  18594. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18595. maxLength: 63
  18596. minLength: 1
  18597. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18598. type: string
  18599. type: object
  18600. jwt:
  18601. description: |-
  18602. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18603. In some instances, `key` is a required field.
  18604. properties:
  18605. key:
  18606. description: |-
  18607. A key in the referenced Secret.
  18608. Some instances of this field may be defaulted, in others it may be required.
  18609. maxLength: 253
  18610. minLength: 1
  18611. pattern: ^[-._a-zA-Z0-9]+$
  18612. type: string
  18613. name:
  18614. description: The name of the Secret resource being referred to.
  18615. maxLength: 253
  18616. minLength: 1
  18617. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18618. type: string
  18619. namespace:
  18620. description: |-
  18621. The namespace of the Secret resource being referred to.
  18622. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18623. maxLength: 63
  18624. minLength: 1
  18625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18626. type: string
  18627. type: object
  18628. required:
  18629. - identityId
  18630. - jwt
  18631. type: object
  18632. kubernetesAuthCredentials:
  18633. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  18634. properties:
  18635. identityId:
  18636. description: |-
  18637. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18638. In some instances, `key` is a required field.
  18639. properties:
  18640. key:
  18641. description: |-
  18642. A key in the referenced Secret.
  18643. Some instances of this field may be defaulted, in others it may be required.
  18644. maxLength: 253
  18645. minLength: 1
  18646. pattern: ^[-._a-zA-Z0-9]+$
  18647. type: string
  18648. name:
  18649. description: The name of the Secret resource being referred to.
  18650. maxLength: 253
  18651. minLength: 1
  18652. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18653. type: string
  18654. namespace:
  18655. description: |-
  18656. The namespace of the Secret resource being referred to.
  18657. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18658. maxLength: 63
  18659. minLength: 1
  18660. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18661. type: string
  18662. type: object
  18663. serviceAccountTokenPath:
  18664. description: |-
  18665. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18666. In some instances, `key` is a required field.
  18667. properties:
  18668. key:
  18669. description: |-
  18670. A key in the referenced Secret.
  18671. Some instances of this field may be defaulted, in others it may be required.
  18672. maxLength: 253
  18673. minLength: 1
  18674. pattern: ^[-._a-zA-Z0-9]+$
  18675. type: string
  18676. name:
  18677. description: The name of the Secret resource being referred to.
  18678. maxLength: 253
  18679. minLength: 1
  18680. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18681. type: string
  18682. namespace:
  18683. description: |-
  18684. The namespace of the Secret resource being referred to.
  18685. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18686. maxLength: 63
  18687. minLength: 1
  18688. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18689. type: string
  18690. type: object
  18691. required:
  18692. - identityId
  18693. type: object
  18694. ldapAuthCredentials:
  18695. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  18696. properties:
  18697. identityId:
  18698. description: |-
  18699. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18700. In some instances, `key` is a required field.
  18701. properties:
  18702. key:
  18703. description: |-
  18704. A key in the referenced Secret.
  18705. Some instances of this field may be defaulted, in others it may be required.
  18706. maxLength: 253
  18707. minLength: 1
  18708. pattern: ^[-._a-zA-Z0-9]+$
  18709. type: string
  18710. name:
  18711. description: The name of the Secret resource being referred to.
  18712. maxLength: 253
  18713. minLength: 1
  18714. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18715. type: string
  18716. namespace:
  18717. description: |-
  18718. The namespace of the Secret resource being referred to.
  18719. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18720. maxLength: 63
  18721. minLength: 1
  18722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18723. type: string
  18724. type: object
  18725. ldapPassword:
  18726. description: |-
  18727. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18728. In some instances, `key` is a required field.
  18729. properties:
  18730. key:
  18731. description: |-
  18732. A key in the referenced Secret.
  18733. Some instances of this field may be defaulted, in others it may be required.
  18734. maxLength: 253
  18735. minLength: 1
  18736. pattern: ^[-._a-zA-Z0-9]+$
  18737. type: string
  18738. name:
  18739. description: The name of the Secret resource being referred to.
  18740. maxLength: 253
  18741. minLength: 1
  18742. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18743. type: string
  18744. namespace:
  18745. description: |-
  18746. The namespace of the Secret resource being referred to.
  18747. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18748. maxLength: 63
  18749. minLength: 1
  18750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18751. type: string
  18752. type: object
  18753. ldapUsername:
  18754. description: |-
  18755. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18756. In some instances, `key` is a required field.
  18757. properties:
  18758. key:
  18759. description: |-
  18760. A key in the referenced Secret.
  18761. Some instances of this field may be defaulted, in others it may be required.
  18762. maxLength: 253
  18763. minLength: 1
  18764. pattern: ^[-._a-zA-Z0-9]+$
  18765. type: string
  18766. name:
  18767. description: The name of the Secret resource being referred to.
  18768. maxLength: 253
  18769. minLength: 1
  18770. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18771. type: string
  18772. namespace:
  18773. description: |-
  18774. The namespace of the Secret resource being referred to.
  18775. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18776. maxLength: 63
  18777. minLength: 1
  18778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18779. type: string
  18780. type: object
  18781. required:
  18782. - identityId
  18783. - ldapPassword
  18784. - ldapUsername
  18785. type: object
  18786. ociAuthCredentials:
  18787. description: OciAuthCredentials represents the credentials for OCI authentication.
  18788. properties:
  18789. fingerprint:
  18790. description: |-
  18791. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18792. In some instances, `key` is a required field.
  18793. properties:
  18794. key:
  18795. description: |-
  18796. A key in the referenced Secret.
  18797. Some instances of this field may be defaulted, in others it may be required.
  18798. maxLength: 253
  18799. minLength: 1
  18800. pattern: ^[-._a-zA-Z0-9]+$
  18801. type: string
  18802. name:
  18803. description: The name of the Secret resource being referred to.
  18804. maxLength: 253
  18805. minLength: 1
  18806. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18807. type: string
  18808. namespace:
  18809. description: |-
  18810. The namespace of the Secret resource being referred to.
  18811. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18812. maxLength: 63
  18813. minLength: 1
  18814. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18815. type: string
  18816. type: object
  18817. identityId:
  18818. description: |-
  18819. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18820. In some instances, `key` is a required field.
  18821. properties:
  18822. key:
  18823. description: |-
  18824. A key in the referenced Secret.
  18825. Some instances of this field may be defaulted, in others it may be required.
  18826. maxLength: 253
  18827. minLength: 1
  18828. pattern: ^[-._a-zA-Z0-9]+$
  18829. type: string
  18830. name:
  18831. description: The name of the Secret resource being referred to.
  18832. maxLength: 253
  18833. minLength: 1
  18834. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18835. type: string
  18836. namespace:
  18837. description: |-
  18838. The namespace of the Secret resource being referred to.
  18839. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18840. maxLength: 63
  18841. minLength: 1
  18842. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18843. type: string
  18844. type: object
  18845. privateKey:
  18846. description: |-
  18847. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18848. In some instances, `key` is a required field.
  18849. properties:
  18850. key:
  18851. description: |-
  18852. A key in the referenced Secret.
  18853. Some instances of this field may be defaulted, in others it may be required.
  18854. maxLength: 253
  18855. minLength: 1
  18856. pattern: ^[-._a-zA-Z0-9]+$
  18857. type: string
  18858. name:
  18859. description: The name of the Secret resource being referred to.
  18860. maxLength: 253
  18861. minLength: 1
  18862. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18863. type: string
  18864. namespace:
  18865. description: |-
  18866. The namespace of the Secret resource being referred to.
  18867. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18868. maxLength: 63
  18869. minLength: 1
  18870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18871. type: string
  18872. type: object
  18873. privateKeyPassphrase:
  18874. description: |-
  18875. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18876. In some instances, `key` is a required field.
  18877. properties:
  18878. key:
  18879. description: |-
  18880. A key in the referenced Secret.
  18881. Some instances of this field may be defaulted, in others it may be required.
  18882. maxLength: 253
  18883. minLength: 1
  18884. pattern: ^[-._a-zA-Z0-9]+$
  18885. type: string
  18886. name:
  18887. description: The name of the Secret resource being referred to.
  18888. maxLength: 253
  18889. minLength: 1
  18890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18891. type: string
  18892. namespace:
  18893. description: |-
  18894. The namespace of the Secret resource being referred to.
  18895. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18896. maxLength: 63
  18897. minLength: 1
  18898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18899. type: string
  18900. type: object
  18901. region:
  18902. description: |-
  18903. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18904. In some instances, `key` is a required field.
  18905. properties:
  18906. key:
  18907. description: |-
  18908. A key in the referenced Secret.
  18909. Some instances of this field may be defaulted, in others it may be required.
  18910. maxLength: 253
  18911. minLength: 1
  18912. pattern: ^[-._a-zA-Z0-9]+$
  18913. type: string
  18914. name:
  18915. description: The name of the Secret resource being referred to.
  18916. maxLength: 253
  18917. minLength: 1
  18918. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18919. type: string
  18920. namespace:
  18921. description: |-
  18922. The namespace of the Secret resource being referred to.
  18923. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18924. maxLength: 63
  18925. minLength: 1
  18926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18927. type: string
  18928. type: object
  18929. tenancyId:
  18930. description: |-
  18931. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18932. In some instances, `key` is a required field.
  18933. properties:
  18934. key:
  18935. description: |-
  18936. A key in the referenced Secret.
  18937. Some instances of this field may be defaulted, in others it may be required.
  18938. maxLength: 253
  18939. minLength: 1
  18940. pattern: ^[-._a-zA-Z0-9]+$
  18941. type: string
  18942. name:
  18943. description: The name of the Secret resource being referred to.
  18944. maxLength: 253
  18945. minLength: 1
  18946. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18947. type: string
  18948. namespace:
  18949. description: |-
  18950. The namespace of the Secret resource being referred to.
  18951. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18952. maxLength: 63
  18953. minLength: 1
  18954. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18955. type: string
  18956. type: object
  18957. userId:
  18958. description: |-
  18959. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18960. In some instances, `key` is a required field.
  18961. properties:
  18962. key:
  18963. description: |-
  18964. A key in the referenced Secret.
  18965. Some instances of this field may be defaulted, in others it may be required.
  18966. maxLength: 253
  18967. minLength: 1
  18968. pattern: ^[-._a-zA-Z0-9]+$
  18969. type: string
  18970. name:
  18971. description: The name of the Secret resource being referred to.
  18972. maxLength: 253
  18973. minLength: 1
  18974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18975. type: string
  18976. namespace:
  18977. description: |-
  18978. The namespace of the Secret resource being referred to.
  18979. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18980. maxLength: 63
  18981. minLength: 1
  18982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18983. type: string
  18984. type: object
  18985. required:
  18986. - fingerprint
  18987. - identityId
  18988. - privateKey
  18989. - region
  18990. - tenancyId
  18991. - userId
  18992. type: object
  18993. tokenAuthCredentials:
  18994. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  18995. properties:
  18996. accessToken:
  18997. description: |-
  18998. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18999. In some instances, `key` is a required field.
  19000. properties:
  19001. key:
  19002. description: |-
  19003. A key in the referenced Secret.
  19004. Some instances of this field may be defaulted, in others it may be required.
  19005. maxLength: 253
  19006. minLength: 1
  19007. pattern: ^[-._a-zA-Z0-9]+$
  19008. type: string
  19009. name:
  19010. description: The name of the Secret resource being referred to.
  19011. maxLength: 253
  19012. minLength: 1
  19013. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19014. type: string
  19015. namespace:
  19016. description: |-
  19017. The namespace of the Secret resource being referred to.
  19018. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19019. maxLength: 63
  19020. minLength: 1
  19021. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19022. type: string
  19023. type: object
  19024. required:
  19025. - accessToken
  19026. type: object
  19027. universalAuthCredentials:
  19028. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  19029. properties:
  19030. clientId:
  19031. description: |-
  19032. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19033. In some instances, `key` is a required field.
  19034. properties:
  19035. key:
  19036. description: |-
  19037. A key in the referenced Secret.
  19038. Some instances of this field may be defaulted, in others it may be required.
  19039. maxLength: 253
  19040. minLength: 1
  19041. pattern: ^[-._a-zA-Z0-9]+$
  19042. type: string
  19043. name:
  19044. description: The name of the Secret resource being referred to.
  19045. maxLength: 253
  19046. minLength: 1
  19047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19048. type: string
  19049. namespace:
  19050. description: |-
  19051. The namespace of the Secret resource being referred to.
  19052. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19053. maxLength: 63
  19054. minLength: 1
  19055. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19056. type: string
  19057. type: object
  19058. clientSecret:
  19059. description: |-
  19060. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19061. In some instances, `key` is a required field.
  19062. properties:
  19063. key:
  19064. description: |-
  19065. A key in the referenced Secret.
  19066. Some instances of this field may be defaulted, in others it may be required.
  19067. maxLength: 253
  19068. minLength: 1
  19069. pattern: ^[-._a-zA-Z0-9]+$
  19070. type: string
  19071. name:
  19072. description: The name of the Secret resource being referred to.
  19073. maxLength: 253
  19074. minLength: 1
  19075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19076. type: string
  19077. namespace:
  19078. description: |-
  19079. The namespace of the Secret resource being referred to.
  19080. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19081. maxLength: 63
  19082. minLength: 1
  19083. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19084. type: string
  19085. type: object
  19086. required:
  19087. - clientId
  19088. - clientSecret
  19089. type: object
  19090. type: object
  19091. caBundle:
  19092. description: |-
  19093. CABundle is a PEM-encoded CA certificate bundle used to validate
  19094. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  19095. format: byte
  19096. type: string
  19097. caProvider:
  19098. description: |-
  19099. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  19100. The certificate is used to validate the Infisical server's TLS certificate.
  19101. Mutually exclusive with CABundle.
  19102. properties:
  19103. key:
  19104. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19105. maxLength: 253
  19106. minLength: 1
  19107. pattern: ^[-._a-zA-Z0-9]+$
  19108. type: string
  19109. name:
  19110. description: The name of the object located at the provider type.
  19111. maxLength: 253
  19112. minLength: 1
  19113. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19114. type: string
  19115. namespace:
  19116. description: |-
  19117. The namespace the Provider type is in.
  19118. Can only be defined when used in a ClusterSecretStore.
  19119. maxLength: 63
  19120. minLength: 1
  19121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19122. type: string
  19123. type:
  19124. description: The type of provider to use such as "Secret", or "ConfigMap".
  19125. enum:
  19126. - Secret
  19127. - ConfigMap
  19128. type: string
  19129. required:
  19130. - name
  19131. - type
  19132. type: object
  19133. hostAPI:
  19134. default: https://app.infisical.com/api
  19135. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  19136. type: string
  19137. secretsScope:
  19138. description: SecretsScope defines the scope of the secrets within the workspace
  19139. properties:
  19140. environmentSlug:
  19141. description: EnvironmentSlug is the required slug identifier for the environment.
  19142. type: string
  19143. expandSecretReferences:
  19144. default: true
  19145. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  19146. type: boolean
  19147. organizationSlug:
  19148. description: |-
  19149. OrganizationSlug is the optional slug that identifies the organization that will be used
  19150. during authentication. Useful for sub-organization setups
  19151. type: string
  19152. projectSlug:
  19153. description: ProjectSlug is the required slug identifier for the project.
  19154. type: string
  19155. recursive:
  19156. default: false
  19157. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  19158. type: boolean
  19159. secretsPath:
  19160. default: /
  19161. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  19162. type: string
  19163. required:
  19164. - environmentSlug
  19165. - projectSlug
  19166. type: object
  19167. required:
  19168. - auth
  19169. - secretsScope
  19170. type: object
  19171. keepersecurity:
  19172. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  19173. properties:
  19174. authRef:
  19175. description: |-
  19176. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19177. In some instances, `key` is a required field.
  19178. properties:
  19179. key:
  19180. description: |-
  19181. A key in the referenced Secret.
  19182. Some instances of this field may be defaulted, in others it may be required.
  19183. maxLength: 253
  19184. minLength: 1
  19185. pattern: ^[-._a-zA-Z0-9]+$
  19186. type: string
  19187. name:
  19188. description: The name of the Secret resource being referred to.
  19189. maxLength: 253
  19190. minLength: 1
  19191. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19192. type: string
  19193. namespace:
  19194. description: |-
  19195. The namespace of the Secret resource being referred to.
  19196. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19197. maxLength: 63
  19198. minLength: 1
  19199. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19200. type: string
  19201. type: object
  19202. folderID:
  19203. type: string
  19204. getByTitleFallback:
  19205. type: boolean
  19206. required:
  19207. - authRef
  19208. - folderID
  19209. type: object
  19210. kubernetes:
  19211. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  19212. properties:
  19213. auth:
  19214. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  19215. maxProperties: 1
  19216. minProperties: 1
  19217. properties:
  19218. cert:
  19219. description: has both clientCert and clientKey as secretKeySelector
  19220. properties:
  19221. clientCert:
  19222. description: |-
  19223. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19224. In some instances, `key` is a required field.
  19225. properties:
  19226. key:
  19227. description: |-
  19228. A key in the referenced Secret.
  19229. Some instances of this field may be defaulted, in others it may be required.
  19230. maxLength: 253
  19231. minLength: 1
  19232. pattern: ^[-._a-zA-Z0-9]+$
  19233. type: string
  19234. name:
  19235. description: The name of the Secret resource being referred to.
  19236. maxLength: 253
  19237. minLength: 1
  19238. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19239. type: string
  19240. namespace:
  19241. description: |-
  19242. The namespace of the Secret resource being referred to.
  19243. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19244. maxLength: 63
  19245. minLength: 1
  19246. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19247. type: string
  19248. type: object
  19249. clientKey:
  19250. description: |-
  19251. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19252. In some instances, `key` is a required field.
  19253. properties:
  19254. key:
  19255. description: |-
  19256. A key in the referenced Secret.
  19257. Some instances of this field may be defaulted, in others it may be required.
  19258. maxLength: 253
  19259. minLength: 1
  19260. pattern: ^[-._a-zA-Z0-9]+$
  19261. type: string
  19262. name:
  19263. description: The name of the Secret resource being referred to.
  19264. maxLength: 253
  19265. minLength: 1
  19266. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19267. type: string
  19268. namespace:
  19269. description: |-
  19270. The namespace of the Secret resource being referred to.
  19271. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19272. maxLength: 63
  19273. minLength: 1
  19274. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19275. type: string
  19276. type: object
  19277. required:
  19278. - clientCert
  19279. - clientKey
  19280. type: object
  19281. serviceAccount:
  19282. description: points to a service account that should be used for authentication
  19283. properties:
  19284. audiences:
  19285. description: |-
  19286. Audience specifies the `aud` claim for the service account token
  19287. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  19288. then this audiences will be appended to the list
  19289. items:
  19290. type: string
  19291. type: array
  19292. name:
  19293. description: The name of the ServiceAccount resource being referred to.
  19294. maxLength: 253
  19295. minLength: 1
  19296. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19297. type: string
  19298. namespace:
  19299. description: |-
  19300. Namespace of the resource being referred to.
  19301. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19302. maxLength: 63
  19303. minLength: 1
  19304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19305. type: string
  19306. required:
  19307. - name
  19308. type: object
  19309. token:
  19310. description: use static token to authenticate with
  19311. properties:
  19312. bearerToken:
  19313. description: |-
  19314. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19315. In some instances, `key` is a required field.
  19316. properties:
  19317. key:
  19318. description: |-
  19319. A key in the referenced Secret.
  19320. Some instances of this field may be defaulted, in others it may be required.
  19321. maxLength: 253
  19322. minLength: 1
  19323. pattern: ^[-._a-zA-Z0-9]+$
  19324. type: string
  19325. name:
  19326. description: The name of the Secret resource being referred to.
  19327. maxLength: 253
  19328. minLength: 1
  19329. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19330. type: string
  19331. namespace:
  19332. description: |-
  19333. The namespace of the Secret resource being referred to.
  19334. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19335. maxLength: 63
  19336. minLength: 1
  19337. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19338. type: string
  19339. type: object
  19340. required:
  19341. - bearerToken
  19342. type: object
  19343. type: object
  19344. authRef:
  19345. description: A reference to a secret that contains the auth information.
  19346. properties:
  19347. key:
  19348. description: |-
  19349. A key in the referenced Secret.
  19350. Some instances of this field may be defaulted, in others it may be required.
  19351. maxLength: 253
  19352. minLength: 1
  19353. pattern: ^[-._a-zA-Z0-9]+$
  19354. type: string
  19355. name:
  19356. description: The name of the Secret resource being referred to.
  19357. maxLength: 253
  19358. minLength: 1
  19359. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19360. type: string
  19361. namespace:
  19362. description: |-
  19363. The namespace of the Secret resource being referred to.
  19364. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19365. maxLength: 63
  19366. minLength: 1
  19367. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19368. type: string
  19369. type: object
  19370. remoteNamespace:
  19371. default: default
  19372. description: Remote namespace to fetch the secrets from
  19373. maxLength: 63
  19374. minLength: 1
  19375. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19376. type: string
  19377. server:
  19378. description: configures the Kubernetes server Address.
  19379. properties:
  19380. caBundle:
  19381. description: CABundle is a base64-encoded CA certificate
  19382. format: byte
  19383. type: string
  19384. caProvider:
  19385. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  19386. properties:
  19387. key:
  19388. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19389. maxLength: 253
  19390. minLength: 1
  19391. pattern: ^[-._a-zA-Z0-9]+$
  19392. type: string
  19393. name:
  19394. description: The name of the object located at the provider type.
  19395. maxLength: 253
  19396. minLength: 1
  19397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19398. type: string
  19399. namespace:
  19400. description: |-
  19401. The namespace the Provider type is in.
  19402. Can only be defined when used in a ClusterSecretStore.
  19403. maxLength: 63
  19404. minLength: 1
  19405. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19406. type: string
  19407. type:
  19408. description: The type of provider to use such as "Secret", or "ConfigMap".
  19409. enum:
  19410. - Secret
  19411. - ConfigMap
  19412. type: string
  19413. required:
  19414. - name
  19415. - type
  19416. type: object
  19417. url:
  19418. default: kubernetes.default
  19419. description: configures the Kubernetes server Address.
  19420. type: string
  19421. type: object
  19422. type: object
  19423. nebiusmysterybox:
  19424. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  19425. properties:
  19426. apiDomain:
  19427. description: NebiusMysterybox API endpoint
  19428. type: string
  19429. auth:
  19430. description: Auth defines parameters to authenticate in MysteryBox
  19431. properties:
  19432. serviceAccountCredsSecretRef:
  19433. description: |-
  19434. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  19435. document with service account credentials used to get an IAM token.
  19436. Expected JSON structure:
  19437. {
  19438. "subject-credentials": {
  19439. "alg": "RS256",
  19440. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  19441. "kid": "<public-key-id>",
  19442. "iss": "<issuer-service-account-id>",
  19443. "sub": "<subject-service-account-id>"
  19444. }
  19445. }
  19446. properties:
  19447. key:
  19448. description: |-
  19449. A key in the referenced Secret.
  19450. Some instances of this field may be defaulted, in others it may be required.
  19451. maxLength: 253
  19452. minLength: 1
  19453. pattern: ^[-._a-zA-Z0-9]+$
  19454. type: string
  19455. name:
  19456. description: The name of the Secret resource being referred to.
  19457. maxLength: 253
  19458. minLength: 1
  19459. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19460. type: string
  19461. namespace:
  19462. description: |-
  19463. The namespace of the Secret resource being referred to.
  19464. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19465. maxLength: 63
  19466. minLength: 1
  19467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19468. type: string
  19469. type: object
  19470. tokenSecretRef:
  19471. description: Token authenticates with Nebius Mysterybox by presenting a token.
  19472. properties:
  19473. key:
  19474. description: |-
  19475. A key in the referenced Secret.
  19476. Some instances of this field may be defaulted, in others it may be required.
  19477. maxLength: 253
  19478. minLength: 1
  19479. pattern: ^[-._a-zA-Z0-9]+$
  19480. type: string
  19481. name:
  19482. description: The name of the Secret resource being referred to.
  19483. maxLength: 253
  19484. minLength: 1
  19485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19486. type: string
  19487. namespace:
  19488. description: |-
  19489. The namespace of the Secret resource being referred to.
  19490. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19491. maxLength: 63
  19492. minLength: 1
  19493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19494. type: string
  19495. type: object
  19496. type: object
  19497. x-kubernetes-validations:
  19498. - message: either serviceAccountCredsSecretRef or tokenSecretRef must be set
  19499. rule: has(self.serviceAccountCredsSecretRef) || has(self.tokenSecretRef)
  19500. caProvider:
  19501. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  19502. properties:
  19503. certSecretRef:
  19504. description: |-
  19505. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19506. In some instances, `key` is a required field.
  19507. properties:
  19508. key:
  19509. description: |-
  19510. A key in the referenced Secret.
  19511. Some instances of this field may be defaulted, in others it may be required.
  19512. maxLength: 253
  19513. minLength: 1
  19514. pattern: ^[-._a-zA-Z0-9]+$
  19515. type: string
  19516. name:
  19517. description: The name of the Secret resource being referred to.
  19518. maxLength: 253
  19519. minLength: 1
  19520. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19521. type: string
  19522. namespace:
  19523. description: |-
  19524. The namespace of the Secret resource being referred to.
  19525. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19526. maxLength: 63
  19527. minLength: 1
  19528. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19529. type: string
  19530. type: object
  19531. type: object
  19532. required:
  19533. - apiDomain
  19534. - auth
  19535. type: object
  19536. ngrok:
  19537. description: Ngrok configures this store to sync secrets using the ngrok provider.
  19538. properties:
  19539. apiUrl:
  19540. default: https://api.ngrok.com
  19541. description: APIURL is the URL of the ngrok API.
  19542. type: string
  19543. auth:
  19544. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  19545. maxProperties: 1
  19546. minProperties: 1
  19547. properties:
  19548. apiKey:
  19549. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  19550. properties:
  19551. secretRef:
  19552. description: SecretRef is a reference to a secret containing the ngrok API key.
  19553. properties:
  19554. key:
  19555. description: |-
  19556. A key in the referenced Secret.
  19557. Some instances of this field may be defaulted, in others it may be required.
  19558. maxLength: 253
  19559. minLength: 1
  19560. pattern: ^[-._a-zA-Z0-9]+$
  19561. type: string
  19562. name:
  19563. description: The name of the Secret resource being referred to.
  19564. maxLength: 253
  19565. minLength: 1
  19566. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19567. type: string
  19568. namespace:
  19569. description: |-
  19570. The namespace of the Secret resource being referred to.
  19571. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19572. maxLength: 63
  19573. minLength: 1
  19574. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19575. type: string
  19576. type: object
  19577. type: object
  19578. type: object
  19579. vault:
  19580. description: Vault configures the ngrok vault to sync secrets with.
  19581. properties:
  19582. name:
  19583. description: Name is the name of the ngrok vault to sync secrets with.
  19584. type: string
  19585. required:
  19586. - name
  19587. type: object
  19588. required:
  19589. - auth
  19590. - vault
  19591. type: object
  19592. onboardbase:
  19593. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  19594. properties:
  19595. apiHost:
  19596. default: https://public.onboardbase.com/api/v1/
  19597. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  19598. type: string
  19599. auth:
  19600. description: Auth configures how the Operator authenticates with the Onboardbase API
  19601. properties:
  19602. apiKeyRef:
  19603. description: |-
  19604. OnboardbaseAPIKey is the APIKey generated by an admin account.
  19605. It is used to recognize and authorize access to a project and environment within onboardbase
  19606. properties:
  19607. key:
  19608. description: |-
  19609. A key in the referenced Secret.
  19610. Some instances of this field may be defaulted, in others it may be required.
  19611. maxLength: 253
  19612. minLength: 1
  19613. pattern: ^[-._a-zA-Z0-9]+$
  19614. type: string
  19615. name:
  19616. description: The name of the Secret resource being referred to.
  19617. maxLength: 253
  19618. minLength: 1
  19619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19620. type: string
  19621. namespace:
  19622. description: |-
  19623. The namespace of the Secret resource being referred to.
  19624. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19625. maxLength: 63
  19626. minLength: 1
  19627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19628. type: string
  19629. type: object
  19630. passcodeRef:
  19631. description: OnboardbasePasscode is the passcode attached to the API Key
  19632. properties:
  19633. key:
  19634. description: |-
  19635. A key in the referenced Secret.
  19636. Some instances of this field may be defaulted, in others it may be required.
  19637. maxLength: 253
  19638. minLength: 1
  19639. pattern: ^[-._a-zA-Z0-9]+$
  19640. type: string
  19641. name:
  19642. description: The name of the Secret resource being referred to.
  19643. maxLength: 253
  19644. minLength: 1
  19645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19646. type: string
  19647. namespace:
  19648. description: |-
  19649. The namespace of the Secret resource being referred to.
  19650. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19651. maxLength: 63
  19652. minLength: 1
  19653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19654. type: string
  19655. type: object
  19656. required:
  19657. - apiKeyRef
  19658. - passcodeRef
  19659. type: object
  19660. environment:
  19661. default: development
  19662. description: Environment is the name of an environmnent within a project to pull the secrets from
  19663. type: string
  19664. project:
  19665. default: development
  19666. description: Project is an onboardbase project that the secrets should be pulled from
  19667. type: string
  19668. required:
  19669. - apiHost
  19670. - auth
  19671. - environment
  19672. - project
  19673. type: object
  19674. onepassword:
  19675. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  19676. properties:
  19677. auth:
  19678. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  19679. properties:
  19680. secretRef:
  19681. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  19682. properties:
  19683. connectTokenSecretRef:
  19684. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  19685. properties:
  19686. key:
  19687. description: |-
  19688. A key in the referenced Secret.
  19689. Some instances of this field may be defaulted, in others it may be required.
  19690. maxLength: 253
  19691. minLength: 1
  19692. pattern: ^[-._a-zA-Z0-9]+$
  19693. type: string
  19694. name:
  19695. description: The name of the Secret resource being referred to.
  19696. maxLength: 253
  19697. minLength: 1
  19698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19699. type: string
  19700. namespace:
  19701. description: |-
  19702. The namespace of the Secret resource being referred to.
  19703. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19704. maxLength: 63
  19705. minLength: 1
  19706. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19707. type: string
  19708. type: object
  19709. required:
  19710. - connectTokenSecretRef
  19711. type: object
  19712. required:
  19713. - secretRef
  19714. type: object
  19715. connectHost:
  19716. description: ConnectHost defines the OnePassword Connect Server to connect to
  19717. type: string
  19718. vaults:
  19719. additionalProperties:
  19720. type: integer
  19721. description: Vaults defines which OnePassword vaults to search in which order
  19722. type: object
  19723. required:
  19724. - auth
  19725. - connectHost
  19726. - vaults
  19727. type: object
  19728. onepasswordSDK:
  19729. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  19730. properties:
  19731. auth:
  19732. description: Auth defines the information necessary to authenticate against OnePassword API.
  19733. properties:
  19734. serviceAccountSecretRef:
  19735. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  19736. properties:
  19737. key:
  19738. description: |-
  19739. A key in the referenced Secret.
  19740. Some instances of this field may be defaulted, in others it may be required.
  19741. maxLength: 253
  19742. minLength: 1
  19743. pattern: ^[-._a-zA-Z0-9]+$
  19744. type: string
  19745. name:
  19746. description: The name of the Secret resource being referred to.
  19747. maxLength: 253
  19748. minLength: 1
  19749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19750. type: string
  19751. namespace:
  19752. description: |-
  19753. The namespace of the Secret resource being referred to.
  19754. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19755. maxLength: 63
  19756. minLength: 1
  19757. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19758. type: string
  19759. type: object
  19760. required:
  19761. - serviceAccountSecretRef
  19762. type: object
  19763. cache:
  19764. description: |-
  19765. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  19766. When enabled, secrets are cached with the specified TTL.
  19767. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  19768. If omitted, caching is disabled (default).
  19769. cache: {} is a valid option to set.
  19770. properties:
  19771. maxSize:
  19772. default: 100
  19773. description: |-
  19774. MaxSize is the maximum number of secrets to cache.
  19775. When the cache is full, least-recently-used entries are evicted.
  19776. minimum: 1
  19777. type: integer
  19778. ttl:
  19779. default: 5m
  19780. description: |-
  19781. TTL is the time-to-live for cached secrets.
  19782. Format: duration string (e.g., "5m", "1h", "30s")
  19783. type: string
  19784. type: object
  19785. environment:
  19786. description: |-
  19787. Environment defines the 1Password Environment ID to read variables from.
  19788. Environments are read-only: PushSecret, DeleteSecret, and SecretExists return an error when set.
  19789. Mutually exclusive with Vault.
  19790. type: string
  19791. integrationInfo:
  19792. description: |-
  19793. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  19794. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  19795. properties:
  19796. name:
  19797. default: 1Password SDK
  19798. description: Name defaults to "1Password SDK".
  19799. type: string
  19800. version:
  19801. default: v1.0.0
  19802. description: Version defaults to "v1.0.0".
  19803. type: string
  19804. type: object
  19805. vault:
  19806. description: |-
  19807. Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  19808. Mutually exclusive with Environment.
  19809. type: string
  19810. required:
  19811. - auth
  19812. type: object
  19813. openBao:
  19814. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  19815. properties:
  19816. auth:
  19817. description: Auth configures how secret-manager authenticates with the OpenBao server.
  19818. properties:
  19819. appRole:
  19820. description: |-
  19821. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  19822. with the role and secret stored in a Kubernetes Secret resource.
  19823. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  19824. properties:
  19825. path:
  19826. default: approle
  19827. description: |-
  19828. Path where the App Role authentication backend is mounted
  19829. in OpenBao, e.g: "approle"
  19830. type: string
  19831. roleId:
  19832. description: |-
  19833. RoleID configured in the App Role authentication backend when setting
  19834. up the authentication backend in OpenBao.
  19835. minLength: 1
  19836. type: string
  19837. roleRef:
  19838. description: |-
  19839. Reference to a key in a Secret that contains the App Role ID used
  19840. to authenticate with OpenBao.
  19841. The `key` field must be specified and denotes which entry within the Secret
  19842. resource is used as the app role id.
  19843. properties:
  19844. key:
  19845. description: |-
  19846. A key in the referenced Secret.
  19847. Some instances of this field may be defaulted, in others it may be required.
  19848. maxLength: 253
  19849. minLength: 1
  19850. pattern: ^[-._a-zA-Z0-9]+$
  19851. type: string
  19852. name:
  19853. description: The name of the Secret resource being referred to.
  19854. maxLength: 253
  19855. minLength: 1
  19856. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19857. type: string
  19858. namespace:
  19859. description: |-
  19860. The namespace of the Secret resource being referred to.
  19861. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19862. maxLength: 63
  19863. minLength: 1
  19864. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19865. type: string
  19866. type: object
  19867. secretRef:
  19868. description: |-
  19869. Reference to a key in a Secret that contains the App Role secret used
  19870. to authenticate with OpenBao.
  19871. The `key` field must be specified and denotes which entry within the Secret
  19872. resource is used as the app role secret.
  19873. properties:
  19874. key:
  19875. description: |-
  19876. A key in the referenced Secret.
  19877. Some instances of this field may be defaulted, in others it may be required.
  19878. maxLength: 253
  19879. minLength: 1
  19880. pattern: ^[-._a-zA-Z0-9]+$
  19881. type: string
  19882. name:
  19883. description: The name of the Secret resource being referred to.
  19884. maxLength: 253
  19885. minLength: 1
  19886. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19887. type: string
  19888. namespace:
  19889. description: |-
  19890. The namespace of the Secret resource being referred to.
  19891. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19892. maxLength: 63
  19893. minLength: 1
  19894. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19895. type: string
  19896. type: object
  19897. required:
  19898. - path
  19899. - secretRef
  19900. type: object
  19901. x-kubernetes-validations:
  19902. - message: exactly one of the fields in [roleId roleRef] must be set
  19903. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  19904. namespace:
  19905. description: |-
  19906. Name of the [OpenBao Namespace] to authenticate to. This can be different
  19907. than the namespace your secret is in. Namespaces is a set of features
  19908. within OpenBao that allows OpenBao environments to support secure
  19909. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  19910. if set, or empty otherwise
  19911. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  19912. type: string
  19913. tokenSecretRef:
  19914. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  19915. properties:
  19916. key:
  19917. description: |-
  19918. A key in the referenced Secret.
  19919. Some instances of this field may be defaulted, in others it may be required.
  19920. maxLength: 253
  19921. minLength: 1
  19922. pattern: ^[-._a-zA-Z0-9]+$
  19923. type: string
  19924. name:
  19925. description: The name of the Secret resource being referred to.
  19926. maxLength: 253
  19927. minLength: 1
  19928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19929. type: string
  19930. namespace:
  19931. description: |-
  19932. The namespace of the Secret resource being referred to.
  19933. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19934. maxLength: 63
  19935. minLength: 1
  19936. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19937. type: string
  19938. type: object
  19939. userPass:
  19940. description: UserPass authenticates with OpenBao by passing a username/password pair
  19941. properties:
  19942. path:
  19943. default: userpass
  19944. description: |-
  19945. Path where the UserPassword authentication backend is mounted
  19946. in OpenBao, e.g: "userpass"
  19947. type: string
  19948. secretRef:
  19949. description: |-
  19950. SecretRef to a key in a Secret resource containing password for the user
  19951. used to authenticate with OpenBao using the [UserPass authentication
  19952. method]
  19953. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  19954. properties:
  19955. key:
  19956. description: |-
  19957. A key in the referenced Secret.
  19958. Some instances of this field may be defaulted, in others it may be required.
  19959. maxLength: 253
  19960. minLength: 1
  19961. pattern: ^[-._a-zA-Z0-9]+$
  19962. type: string
  19963. name:
  19964. description: The name of the Secret resource being referred to.
  19965. maxLength: 253
  19966. minLength: 1
  19967. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19968. type: string
  19969. namespace:
  19970. description: |-
  19971. The namespace of the Secret resource being referred to.
  19972. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19973. maxLength: 63
  19974. minLength: 1
  19975. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19976. type: string
  19977. type: object
  19978. username:
  19979. description: |-
  19980. Username is a username used to authenticate using the [UserPass
  19981. authentication method]
  19982. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  19983. type: string
  19984. required:
  19985. - path
  19986. - username
  19987. type: object
  19988. type: object
  19989. x-kubernetes-validations:
  19990. - message: exactly one of the fields in [appRole tokenSecretRef userPass] must be set
  19991. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass)].filter(x,x==true).size() == 1'
  19992. caBundle:
  19993. description: |-
  19994. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  19995. this and `caProvider` are not set the system root certificates are used
  19996. to validate the TLS connection.
  19997. format: byte
  19998. type: string
  19999. caProvider:
  20000. description: |-
  20001. The provider for the CA bundle to use to validate OpenBao server
  20002. certificate. If this and `caBundle` are not set the system root
  20003. certificates are used to validate the TLS connection.
  20004. properties:
  20005. key:
  20006. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20007. maxLength: 253
  20008. minLength: 1
  20009. pattern: ^[-._a-zA-Z0-9]+$
  20010. type: string
  20011. name:
  20012. description: The name of the object located at the provider type.
  20013. maxLength: 253
  20014. minLength: 1
  20015. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20016. type: string
  20017. namespace:
  20018. description: |-
  20019. The namespace the Provider type is in.
  20020. Can only be defined when used in a ClusterSecretStore.
  20021. maxLength: 63
  20022. minLength: 1
  20023. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20024. type: string
  20025. type:
  20026. description: The type of provider to use such as "Secret", or "ConfigMap".
  20027. enum:
  20028. - Secret
  20029. - ConfigMap
  20030. type: string
  20031. required:
  20032. - name
  20033. - type
  20034. type: object
  20035. namespace:
  20036. description: |-
  20037. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  20038. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  20039. e.g: "ns1".
  20040. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  20041. type: string
  20042. path:
  20043. description: |-
  20044. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  20045. "secret". The v2 KV secret engine version specific "/data" path suffix
  20046. for fetching secrets from OpenBao is optional and will be appended
  20047. if not present in specified path.
  20048. type: string
  20049. server:
  20050. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  20051. type: string
  20052. version:
  20053. default: v2
  20054. description: |-
  20055. Version is the OpenBao KV secret engine version. This can be either "v1" or
  20056. "v2". Version defaults to "v2".
  20057. enum:
  20058. - v1
  20059. - v2
  20060. type: string
  20061. required:
  20062. - server
  20063. type: object
  20064. x-kubernetes-validations:
  20065. - message: at most one of the fields in [caBundle caProvider] may be set
  20066. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  20067. oracle:
  20068. description: Oracle configures this store to sync secrets using Oracle Vault provider
  20069. properties:
  20070. auth:
  20071. description: |-
  20072. Auth configures how secret-manager authenticates with the Oracle Vault.
  20073. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  20074. properties:
  20075. secretRef:
  20076. description: SecretRef to pass through sensitive information.
  20077. properties:
  20078. fingerprint:
  20079. description: Fingerprint is the fingerprint of the API private key.
  20080. properties:
  20081. key:
  20082. description: |-
  20083. A key in the referenced Secret.
  20084. Some instances of this field may be defaulted, in others it may be required.
  20085. maxLength: 253
  20086. minLength: 1
  20087. pattern: ^[-._a-zA-Z0-9]+$
  20088. type: string
  20089. name:
  20090. description: The name of the Secret resource being referred to.
  20091. maxLength: 253
  20092. minLength: 1
  20093. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20094. type: string
  20095. namespace:
  20096. description: |-
  20097. The namespace of the Secret resource being referred to.
  20098. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20099. maxLength: 63
  20100. minLength: 1
  20101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20102. type: string
  20103. type: object
  20104. privatekey:
  20105. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  20106. properties:
  20107. key:
  20108. description: |-
  20109. A key in the referenced Secret.
  20110. Some instances of this field may be defaulted, in others it may be required.
  20111. maxLength: 253
  20112. minLength: 1
  20113. pattern: ^[-._a-zA-Z0-9]+$
  20114. type: string
  20115. name:
  20116. description: The name of the Secret resource being referred to.
  20117. maxLength: 253
  20118. minLength: 1
  20119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20120. type: string
  20121. namespace:
  20122. description: |-
  20123. The namespace of the Secret resource being referred to.
  20124. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20125. maxLength: 63
  20126. minLength: 1
  20127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20128. type: string
  20129. type: object
  20130. required:
  20131. - fingerprint
  20132. - privatekey
  20133. type: object
  20134. tenancy:
  20135. description: Tenancy is the tenancy OCID where user is located.
  20136. type: string
  20137. user:
  20138. description: User is an access OCID specific to the account.
  20139. type: string
  20140. required:
  20141. - secretRef
  20142. - tenancy
  20143. - user
  20144. type: object
  20145. compartment:
  20146. description: |-
  20147. Compartment is the vault compartment OCID.
  20148. Required for PushSecret
  20149. type: string
  20150. encryptionKey:
  20151. description: |-
  20152. EncryptionKey is the OCID of the encryption key within the vault.
  20153. Required for PushSecret
  20154. type: string
  20155. principalType:
  20156. description: |-
  20157. The type of principal to use for authentication. If left blank, the Auth struct will
  20158. determine the principal type. This optional field must be specified if using
  20159. workload identity.
  20160. enum:
  20161. - ""
  20162. - UserPrincipal
  20163. - InstancePrincipal
  20164. - Workload
  20165. type: string
  20166. region:
  20167. description: Region is the region where vault is located.
  20168. type: string
  20169. serviceAccountRef:
  20170. description: |-
  20171. ServiceAccountRef specified the service account
  20172. that should be used when authenticating with WorkloadIdentity.
  20173. properties:
  20174. audiences:
  20175. description: |-
  20176. Audience specifies the `aud` claim for the service account token
  20177. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20178. then this audiences will be appended to the list
  20179. items:
  20180. type: string
  20181. type: array
  20182. name:
  20183. description: The name of the ServiceAccount resource being referred to.
  20184. maxLength: 253
  20185. minLength: 1
  20186. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20187. type: string
  20188. namespace:
  20189. description: |-
  20190. Namespace of the resource being referred to.
  20191. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20192. maxLength: 63
  20193. minLength: 1
  20194. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20195. type: string
  20196. required:
  20197. - name
  20198. type: object
  20199. vault:
  20200. description: Vault is the vault's OCID of the specific vault where secret is located.
  20201. type: string
  20202. required:
  20203. - region
  20204. - vault
  20205. type: object
  20206. ovh:
  20207. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  20208. properties:
  20209. auth:
  20210. description: Authentication method (mtls or token).
  20211. properties:
  20212. mtls:
  20213. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  20214. properties:
  20215. caBundle:
  20216. format: byte
  20217. type: string
  20218. caProvider:
  20219. description: |-
  20220. CAProvider provides a custom certificate authority for accessing the provider's store.
  20221. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  20222. properties:
  20223. key:
  20224. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20225. maxLength: 253
  20226. minLength: 1
  20227. pattern: ^[-._a-zA-Z0-9]+$
  20228. type: string
  20229. name:
  20230. description: The name of the object located at the provider type.
  20231. maxLength: 253
  20232. minLength: 1
  20233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20234. type: string
  20235. namespace:
  20236. description: |-
  20237. The namespace the Provider type is in.
  20238. Can only be defined when used in a ClusterSecretStore.
  20239. maxLength: 63
  20240. minLength: 1
  20241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20242. type: string
  20243. type:
  20244. description: The type of provider to use such as "Secret", or "ConfigMap".
  20245. enum:
  20246. - Secret
  20247. - ConfigMap
  20248. type: string
  20249. required:
  20250. - name
  20251. - type
  20252. type: object
  20253. certSecretRef:
  20254. description: |-
  20255. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20256. In some instances, `key` is a required field.
  20257. properties:
  20258. key:
  20259. description: |-
  20260. A key in the referenced Secret.
  20261. Some instances of this field may be defaulted, in others it may be required.
  20262. maxLength: 253
  20263. minLength: 1
  20264. pattern: ^[-._a-zA-Z0-9]+$
  20265. type: string
  20266. name:
  20267. description: The name of the Secret resource being referred to.
  20268. maxLength: 253
  20269. minLength: 1
  20270. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20271. type: string
  20272. namespace:
  20273. description: |-
  20274. The namespace of the Secret resource being referred to.
  20275. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20276. maxLength: 63
  20277. minLength: 1
  20278. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20279. type: string
  20280. type: object
  20281. keySecretRef:
  20282. description: |-
  20283. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20284. In some instances, `key` is a required field.
  20285. properties:
  20286. key:
  20287. description: |-
  20288. A key in the referenced Secret.
  20289. Some instances of this field may be defaulted, in others it may be required.
  20290. maxLength: 253
  20291. minLength: 1
  20292. pattern: ^[-._a-zA-Z0-9]+$
  20293. type: string
  20294. name:
  20295. description: The name of the Secret resource being referred to.
  20296. maxLength: 253
  20297. minLength: 1
  20298. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20299. type: string
  20300. namespace:
  20301. description: |-
  20302. The namespace of the Secret resource being referred to.
  20303. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20304. maxLength: 63
  20305. minLength: 1
  20306. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20307. type: string
  20308. type: object
  20309. required:
  20310. - certSecretRef
  20311. - keySecretRef
  20312. type: object
  20313. token:
  20314. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  20315. properties:
  20316. tokenSecretRef:
  20317. description: |-
  20318. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20319. In some instances, `key` is a required field.
  20320. properties:
  20321. key:
  20322. description: |-
  20323. A key in the referenced Secret.
  20324. Some instances of this field may be defaulted, in others it may be required.
  20325. maxLength: 253
  20326. minLength: 1
  20327. pattern: ^[-._a-zA-Z0-9]+$
  20328. type: string
  20329. name:
  20330. description: The name of the Secret resource being referred to.
  20331. maxLength: 253
  20332. minLength: 1
  20333. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20334. type: string
  20335. namespace:
  20336. description: |-
  20337. The namespace of the Secret resource being referred to.
  20338. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20339. maxLength: 63
  20340. minLength: 1
  20341. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20342. type: string
  20343. type: object
  20344. required:
  20345. - tokenSecretRef
  20346. type: object
  20347. type: object
  20348. casRequired:
  20349. description: 'Enables or disables check-and-set (CAS) (default: false).'
  20350. type: boolean
  20351. okmsTimeout:
  20352. default: 30
  20353. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  20354. format: int32
  20355. minimum: 1
  20356. type: integer
  20357. okmsid:
  20358. description: specifies the OKMS ID.
  20359. type: string
  20360. server:
  20361. description: specifies the OKMS server endpoint.
  20362. type: string
  20363. required:
  20364. - auth
  20365. - okmsid
  20366. - server
  20367. type: object
  20368. passbolt:
  20369. description: |-
  20370. PassboltProvider provides access to Passbolt secrets manager.
  20371. See: https://www.passbolt.com.
  20372. properties:
  20373. auth:
  20374. description: Auth defines the information necessary to authenticate against Passbolt Server
  20375. properties:
  20376. passwordSecretRef:
  20377. description: |-
  20378. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20379. In some instances, `key` is a required field.
  20380. properties:
  20381. key:
  20382. description: |-
  20383. A key in the referenced Secret.
  20384. Some instances of this field may be defaulted, in others it may be required.
  20385. maxLength: 253
  20386. minLength: 1
  20387. pattern: ^[-._a-zA-Z0-9]+$
  20388. type: string
  20389. name:
  20390. description: The name of the Secret resource being referred to.
  20391. maxLength: 253
  20392. minLength: 1
  20393. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20394. type: string
  20395. namespace:
  20396. description: |-
  20397. The namespace of the Secret resource being referred to.
  20398. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20399. maxLength: 63
  20400. minLength: 1
  20401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20402. type: string
  20403. type: object
  20404. privateKeySecretRef:
  20405. description: |-
  20406. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20407. In some instances, `key` is a required field.
  20408. properties:
  20409. key:
  20410. description: |-
  20411. A key in the referenced Secret.
  20412. Some instances of this field may be defaulted, in others it may be required.
  20413. maxLength: 253
  20414. minLength: 1
  20415. pattern: ^[-._a-zA-Z0-9]+$
  20416. type: string
  20417. name:
  20418. description: The name of the Secret resource being referred to.
  20419. maxLength: 253
  20420. minLength: 1
  20421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20422. type: string
  20423. namespace:
  20424. description: |-
  20425. The namespace of the Secret resource being referred to.
  20426. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20427. maxLength: 63
  20428. minLength: 1
  20429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20430. type: string
  20431. type: object
  20432. required:
  20433. - passwordSecretRef
  20434. - privateKeySecretRef
  20435. type: object
  20436. caBundle:
  20437. description: |-
  20438. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  20439. if the Host URL is using HTTPS protocol. If not set the system root certificates
  20440. are used to validate the TLS connection.
  20441. format: byte
  20442. type: string
  20443. caProvider:
  20444. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  20445. properties:
  20446. key:
  20447. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20448. maxLength: 253
  20449. minLength: 1
  20450. pattern: ^[-._a-zA-Z0-9]+$
  20451. type: string
  20452. name:
  20453. description: The name of the object located at the provider type.
  20454. maxLength: 253
  20455. minLength: 1
  20456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20457. type: string
  20458. namespace:
  20459. description: |-
  20460. The namespace the Provider type is in.
  20461. Can only be defined when used in a ClusterSecretStore.
  20462. maxLength: 63
  20463. minLength: 1
  20464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20465. type: string
  20466. type:
  20467. description: The type of provider to use such as "Secret", or "ConfigMap".
  20468. enum:
  20469. - Secret
  20470. - ConfigMap
  20471. type: string
  20472. required:
  20473. - name
  20474. - type
  20475. type: object
  20476. host:
  20477. description: Host defines the Passbolt Server to connect to
  20478. type: string
  20479. required:
  20480. - auth
  20481. - host
  20482. type: object
  20483. passworddepot:
  20484. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  20485. properties:
  20486. auth:
  20487. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  20488. properties:
  20489. secretRef:
  20490. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  20491. properties:
  20492. credentials:
  20493. description: Username / Password is used for authentication.
  20494. properties:
  20495. key:
  20496. description: |-
  20497. A key in the referenced Secret.
  20498. Some instances of this field may be defaulted, in others it may be required.
  20499. maxLength: 253
  20500. minLength: 1
  20501. pattern: ^[-._a-zA-Z0-9]+$
  20502. type: string
  20503. name:
  20504. description: The name of the Secret resource being referred to.
  20505. maxLength: 253
  20506. minLength: 1
  20507. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20508. type: string
  20509. namespace:
  20510. description: |-
  20511. The namespace of the Secret resource being referred to.
  20512. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20513. maxLength: 63
  20514. minLength: 1
  20515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20516. type: string
  20517. type: object
  20518. type: object
  20519. required:
  20520. - secretRef
  20521. type: object
  20522. database:
  20523. description: Database to use as source
  20524. type: string
  20525. host:
  20526. description: URL configures the Password Depot instance URL.
  20527. type: string
  20528. required:
  20529. - auth
  20530. - database
  20531. - host
  20532. type: object
  20533. previder:
  20534. description: Previder configures this store to sync secrets using the Previder provider
  20535. properties:
  20536. auth:
  20537. description: PreviderAuth contains a secretRef for credentials.
  20538. properties:
  20539. secretRef:
  20540. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  20541. properties:
  20542. accessToken:
  20543. description: The AccessToken is used for authentication
  20544. properties:
  20545. key:
  20546. description: |-
  20547. A key in the referenced Secret.
  20548. Some instances of this field may be defaulted, in others it may be required.
  20549. maxLength: 253
  20550. minLength: 1
  20551. pattern: ^[-._a-zA-Z0-9]+$
  20552. type: string
  20553. name:
  20554. description: The name of the Secret resource being referred to.
  20555. maxLength: 253
  20556. minLength: 1
  20557. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20558. type: string
  20559. namespace:
  20560. description: |-
  20561. The namespace of the Secret resource being referred to.
  20562. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20563. maxLength: 63
  20564. minLength: 1
  20565. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20566. type: string
  20567. type: object
  20568. required:
  20569. - accessToken
  20570. type: object
  20571. type: object
  20572. baseUri:
  20573. type: string
  20574. required:
  20575. - auth
  20576. type: object
  20577. pulumi:
  20578. description: Pulumi configures this store to sync secrets using the Pulumi provider
  20579. properties:
  20580. accessToken:
  20581. description: |-
  20582. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  20583. Deprecated: Use auth.accessToken instead.
  20584. properties:
  20585. secretRef:
  20586. description: SecretRef is a reference to a secret containing the Pulumi API token.
  20587. properties:
  20588. key:
  20589. description: |-
  20590. A key in the referenced Secret.
  20591. Some instances of this field may be defaulted, in others it may be required.
  20592. maxLength: 253
  20593. minLength: 1
  20594. pattern: ^[-._a-zA-Z0-9]+$
  20595. type: string
  20596. name:
  20597. description: The name of the Secret resource being referred to.
  20598. maxLength: 253
  20599. minLength: 1
  20600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20601. type: string
  20602. namespace:
  20603. description: |-
  20604. The namespace of the Secret resource being referred to.
  20605. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20606. maxLength: 63
  20607. minLength: 1
  20608. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20609. type: string
  20610. type: object
  20611. type: object
  20612. apiUrl:
  20613. default: https://api.pulumi.com/api/esc
  20614. description: APIURL is the URL of the Pulumi API.
  20615. type: string
  20616. auth:
  20617. description: |-
  20618. Auth configures how the Operator authenticates with the Pulumi API.
  20619. Either auth or the deprecated accessToken field must be specified.
  20620. properties:
  20621. accessToken:
  20622. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  20623. properties:
  20624. secretRef:
  20625. description: SecretRef is a reference to a secret containing the Pulumi API token.
  20626. properties:
  20627. key:
  20628. description: |-
  20629. A key in the referenced Secret.
  20630. Some instances of this field may be defaulted, in others it may be required.
  20631. maxLength: 253
  20632. minLength: 1
  20633. pattern: ^[-._a-zA-Z0-9]+$
  20634. type: string
  20635. name:
  20636. description: The name of the Secret resource being referred to.
  20637. maxLength: 253
  20638. minLength: 1
  20639. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20640. type: string
  20641. namespace:
  20642. description: |-
  20643. The namespace of the Secret resource being referred to.
  20644. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20645. maxLength: 63
  20646. minLength: 1
  20647. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20648. type: string
  20649. type: object
  20650. type: object
  20651. oidcConfig:
  20652. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  20653. properties:
  20654. expirationSeconds:
  20655. default: 600
  20656. description: |-
  20657. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  20658. Defaults to 10 minutes.
  20659. format: int64
  20660. minimum: 600
  20661. type: integer
  20662. organization:
  20663. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  20664. type: string
  20665. serviceAccountRef:
  20666. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  20667. properties:
  20668. audiences:
  20669. description: |-
  20670. Audience specifies the `aud` claim for the service account token
  20671. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20672. then this audiences will be appended to the list
  20673. items:
  20674. type: string
  20675. type: array
  20676. name:
  20677. description: The name of the ServiceAccount resource being referred to.
  20678. maxLength: 253
  20679. minLength: 1
  20680. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20681. type: string
  20682. namespace:
  20683. description: |-
  20684. Namespace of the resource being referred to.
  20685. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20686. maxLength: 63
  20687. minLength: 1
  20688. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20689. type: string
  20690. required:
  20691. - name
  20692. type: object
  20693. required:
  20694. - organization
  20695. - serviceAccountRef
  20696. type: object
  20697. type: object
  20698. x-kubernetes-validations:
  20699. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  20700. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  20701. environment:
  20702. description: |-
  20703. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  20704. dynamically retrieved values from supported providers including all major clouds,
  20705. and other Pulumi ESC environments.
  20706. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  20707. type: string
  20708. organization:
  20709. description: |-
  20710. Organization are a space to collaborate on shared projects and stacks.
  20711. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  20712. type: string
  20713. project:
  20714. description: Project is the name of the Pulumi ESC project the environment belongs to.
  20715. type: string
  20716. required:
  20717. - environment
  20718. - organization
  20719. - project
  20720. type: object
  20721. x-kubernetes-validations:
  20722. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  20723. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  20724. scaleway:
  20725. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  20726. properties:
  20727. accessKey:
  20728. description: AccessKey is the non-secret part of the api key.
  20729. properties:
  20730. secretRef:
  20731. description: SecretRef references a key in a secret that will be used as value.
  20732. properties:
  20733. key:
  20734. description: |-
  20735. A key in the referenced Secret.
  20736. Some instances of this field may be defaulted, in others it may be required.
  20737. maxLength: 253
  20738. minLength: 1
  20739. pattern: ^[-._a-zA-Z0-9]+$
  20740. type: string
  20741. name:
  20742. description: The name of the Secret resource being referred to.
  20743. maxLength: 253
  20744. minLength: 1
  20745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20746. type: string
  20747. namespace:
  20748. description: |-
  20749. The namespace of the Secret resource being referred to.
  20750. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20751. maxLength: 63
  20752. minLength: 1
  20753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20754. type: string
  20755. type: object
  20756. value:
  20757. description: Value can be specified directly to set a value without using a secret.
  20758. type: string
  20759. type: object
  20760. apiUrl:
  20761. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  20762. type: string
  20763. projectId:
  20764. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  20765. type: string
  20766. region:
  20767. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  20768. type: string
  20769. secretKey:
  20770. description: SecretKey is the non-secret part of the api key.
  20771. properties:
  20772. secretRef:
  20773. description: SecretRef references a key in a secret that will be used as value.
  20774. properties:
  20775. key:
  20776. description: |-
  20777. A key in the referenced Secret.
  20778. Some instances of this field may be defaulted, in others it may be required.
  20779. maxLength: 253
  20780. minLength: 1
  20781. pattern: ^[-._a-zA-Z0-9]+$
  20782. type: string
  20783. name:
  20784. description: The name of the Secret resource being referred to.
  20785. maxLength: 253
  20786. minLength: 1
  20787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20788. type: string
  20789. namespace:
  20790. description: |-
  20791. The namespace of the Secret resource being referred to.
  20792. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20793. maxLength: 63
  20794. minLength: 1
  20795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20796. type: string
  20797. type: object
  20798. value:
  20799. description: Value can be specified directly to set a value without using a secret.
  20800. type: string
  20801. type: object
  20802. required:
  20803. - accessKey
  20804. - projectId
  20805. - region
  20806. - secretKey
  20807. type: object
  20808. secretserver:
  20809. description: |-
  20810. SecretServer configures this store to sync secrets using SecretServer provider
  20811. https://docs.delinea.com/online-help/secret-server/start.htm
  20812. properties:
  20813. caBundle:
  20814. description: |-
  20815. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  20816. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  20817. are used to validate the TLS connection.
  20818. format: byte
  20819. type: string
  20820. caProvider:
  20821. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  20822. properties:
  20823. key:
  20824. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20825. maxLength: 253
  20826. minLength: 1
  20827. pattern: ^[-._a-zA-Z0-9]+$
  20828. type: string
  20829. name:
  20830. description: The name of the object located at the provider type.
  20831. maxLength: 253
  20832. minLength: 1
  20833. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20834. type: string
  20835. namespace:
  20836. description: |-
  20837. The namespace the Provider type is in.
  20838. Can only be defined when used in a ClusterSecretStore.
  20839. maxLength: 63
  20840. minLength: 1
  20841. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20842. type: string
  20843. type:
  20844. description: The type of provider to use such as "Secret", or "ConfigMap".
  20845. enum:
  20846. - Secret
  20847. - ConfigMap
  20848. type: string
  20849. required:
  20850. - name
  20851. - type
  20852. type: object
  20853. domain:
  20854. description: Domain is the secret server domain.
  20855. type: string
  20856. password:
  20857. description: |-
  20858. Password is the secret server account password.
  20859. Required unless Token is set.
  20860. properties:
  20861. secretRef:
  20862. description: SecretRef references a key in a secret that will be used as value.
  20863. properties:
  20864. key:
  20865. description: |-
  20866. A key in the referenced Secret.
  20867. Some instances of this field may be defaulted, in others it may be required.
  20868. maxLength: 253
  20869. minLength: 1
  20870. pattern: ^[-._a-zA-Z0-9]+$
  20871. type: string
  20872. name:
  20873. description: The name of the Secret resource being referred to.
  20874. maxLength: 253
  20875. minLength: 1
  20876. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20877. type: string
  20878. namespace:
  20879. description: |-
  20880. The namespace of the Secret resource being referred to.
  20881. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20882. maxLength: 63
  20883. minLength: 1
  20884. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20885. type: string
  20886. type: object
  20887. value:
  20888. description: Value can be specified directly to set a value without using a secret.
  20889. minLength: 1
  20890. type: string
  20891. type: object
  20892. x-kubernetes-validations:
  20893. - message: exactly one of value or secretRef must be set
  20894. rule: has(self.value) != has(self.secretRef)
  20895. serverURL:
  20896. description: |-
  20897. ServerURL
  20898. URL to your secret server installation
  20899. type: string
  20900. token:
  20901. description: |-
  20902. Token is an access token used to authenticate to the secret server,
  20903. as an alternative to Username and Password. When set, Username and
  20904. Password are not required and are ignored.
  20905. properties:
  20906. secretRef:
  20907. description: SecretRef references a key in a secret that will be used as value.
  20908. properties:
  20909. key:
  20910. description: |-
  20911. A key in the referenced Secret.
  20912. Some instances of this field may be defaulted, in others it may be required.
  20913. maxLength: 253
  20914. minLength: 1
  20915. pattern: ^[-._a-zA-Z0-9]+$
  20916. type: string
  20917. name:
  20918. description: The name of the Secret resource being referred to.
  20919. maxLength: 253
  20920. minLength: 1
  20921. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20922. type: string
  20923. namespace:
  20924. description: |-
  20925. The namespace of the Secret resource being referred to.
  20926. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20927. maxLength: 63
  20928. minLength: 1
  20929. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20930. type: string
  20931. type: object
  20932. value:
  20933. description: Value can be specified directly to set a value without using a secret.
  20934. minLength: 1
  20935. type: string
  20936. type: object
  20937. x-kubernetes-validations:
  20938. - message: exactly one of value or secretRef must be set
  20939. rule: has(self.value) != has(self.secretRef)
  20940. username:
  20941. description: |-
  20942. Username is the secret server account username.
  20943. Required unless Token is set.
  20944. properties:
  20945. secretRef:
  20946. description: SecretRef references a key in a secret that will be used as value.
  20947. properties:
  20948. key:
  20949. description: |-
  20950. A key in the referenced Secret.
  20951. Some instances of this field may be defaulted, in others it may be required.
  20952. maxLength: 253
  20953. minLength: 1
  20954. pattern: ^[-._a-zA-Z0-9]+$
  20955. type: string
  20956. name:
  20957. description: The name of the Secret resource being referred to.
  20958. maxLength: 253
  20959. minLength: 1
  20960. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20961. type: string
  20962. namespace:
  20963. description: |-
  20964. The namespace of the Secret resource being referred to.
  20965. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20966. maxLength: 63
  20967. minLength: 1
  20968. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20969. type: string
  20970. type: object
  20971. value:
  20972. description: Value can be specified directly to set a value without using a secret.
  20973. minLength: 1
  20974. type: string
  20975. type: object
  20976. x-kubernetes-validations:
  20977. - message: exactly one of value or secretRef must be set
  20978. rule: has(self.value) != has(self.secretRef)
  20979. required:
  20980. - serverURL
  20981. type: object
  20982. x-kubernetes-validations:
  20983. - message: either token, or both username and password, must be set
  20984. rule: has(self.token) || (has(self.username) && has(self.password))
  20985. senhasegura:
  20986. description: Senhasegura configures this store to sync secrets using senhasegura provider
  20987. properties:
  20988. auth:
  20989. description: Auth defines parameters to authenticate in senhasegura
  20990. properties:
  20991. clientId:
  20992. type: string
  20993. clientSecretSecretRef:
  20994. description: |-
  20995. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20996. In some instances, `key` is a required field.
  20997. properties:
  20998. key:
  20999. description: |-
  21000. A key in the referenced Secret.
  21001. Some instances of this field may be defaulted, in others it may be required.
  21002. maxLength: 253
  21003. minLength: 1
  21004. pattern: ^[-._a-zA-Z0-9]+$
  21005. type: string
  21006. name:
  21007. description: The name of the Secret resource being referred to.
  21008. maxLength: 253
  21009. minLength: 1
  21010. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21011. type: string
  21012. namespace:
  21013. description: |-
  21014. The namespace of the Secret resource being referred to.
  21015. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21016. maxLength: 63
  21017. minLength: 1
  21018. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21019. type: string
  21020. type: object
  21021. required:
  21022. - clientId
  21023. - clientSecretSecretRef
  21024. type: object
  21025. ignoreSslCertificate:
  21026. default: false
  21027. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  21028. type: boolean
  21029. module:
  21030. description: Module defines which senhasegura module should be used to get secrets
  21031. type: string
  21032. url:
  21033. description: URL of senhasegura
  21034. type: string
  21035. required:
  21036. - auth
  21037. - module
  21038. - url
  21039. type: object
  21040. vault:
  21041. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  21042. properties:
  21043. auth:
  21044. description: Auth configures how secret-manager authenticates with the Vault server.
  21045. properties:
  21046. appRole:
  21047. description: |-
  21048. AppRole authenticates with Vault using the App Role auth mechanism,
  21049. with the role and secret stored in a Kubernetes Secret resource.
  21050. properties:
  21051. path:
  21052. default: approle
  21053. description: |-
  21054. Path where the App Role authentication backend is mounted
  21055. in Vault, e.g: "approle"
  21056. type: string
  21057. roleId:
  21058. description: |-
  21059. RoleID configured in the App Role authentication backend when setting
  21060. up the authentication backend in Vault.
  21061. type: string
  21062. roleRef:
  21063. description: |-
  21064. Reference to a key in a Secret that contains the App Role ID used
  21065. to authenticate with Vault.
  21066. The `key` field must be specified and denotes which entry within the Secret
  21067. resource is used as the app role id.
  21068. properties:
  21069. key:
  21070. description: |-
  21071. A key in the referenced Secret.
  21072. Some instances of this field may be defaulted, in others it may be required.
  21073. maxLength: 253
  21074. minLength: 1
  21075. pattern: ^[-._a-zA-Z0-9]+$
  21076. type: string
  21077. name:
  21078. description: The name of the Secret resource being referred to.
  21079. maxLength: 253
  21080. minLength: 1
  21081. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21082. type: string
  21083. namespace:
  21084. description: |-
  21085. The namespace of the Secret resource being referred to.
  21086. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21087. maxLength: 63
  21088. minLength: 1
  21089. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21090. type: string
  21091. type: object
  21092. secretRef:
  21093. description: |-
  21094. Reference to a key in a Secret that contains the App Role secret used
  21095. to authenticate with Vault.
  21096. The `key` field must be specified and denotes which entry within the Secret
  21097. resource is used as the app role secret.
  21098. properties:
  21099. key:
  21100. description: |-
  21101. A key in the referenced Secret.
  21102. Some instances of this field may be defaulted, in others it may be required.
  21103. maxLength: 253
  21104. minLength: 1
  21105. pattern: ^[-._a-zA-Z0-9]+$
  21106. type: string
  21107. name:
  21108. description: The name of the Secret resource being referred to.
  21109. maxLength: 253
  21110. minLength: 1
  21111. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21112. type: string
  21113. namespace:
  21114. description: |-
  21115. The namespace of the Secret resource being referred to.
  21116. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21117. maxLength: 63
  21118. minLength: 1
  21119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21120. type: string
  21121. type: object
  21122. required:
  21123. - path
  21124. - secretRef
  21125. type: object
  21126. cert:
  21127. description: |-
  21128. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  21129. Cert authentication method
  21130. properties:
  21131. clientCert:
  21132. description: |-
  21133. ClientCert is a certificate to authenticate using the Cert Vault
  21134. authentication method
  21135. properties:
  21136. key:
  21137. description: |-
  21138. A key in the referenced Secret.
  21139. Some instances of this field may be defaulted, in others it may be required.
  21140. maxLength: 253
  21141. minLength: 1
  21142. pattern: ^[-._a-zA-Z0-9]+$
  21143. type: string
  21144. name:
  21145. description: The name of the Secret resource being referred to.
  21146. maxLength: 253
  21147. minLength: 1
  21148. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21149. type: string
  21150. namespace:
  21151. description: |-
  21152. The namespace of the Secret resource being referred to.
  21153. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21154. maxLength: 63
  21155. minLength: 1
  21156. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21157. type: string
  21158. type: object
  21159. path:
  21160. default: cert
  21161. description: |-
  21162. Path where the Certificate authentication backend is mounted
  21163. in Vault, e.g: "cert"
  21164. type: string
  21165. secretRef:
  21166. description: |-
  21167. SecretRef to a key in a Secret resource containing client private key to
  21168. authenticate with Vault using the Cert authentication method
  21169. properties:
  21170. key:
  21171. description: |-
  21172. A key in the referenced Secret.
  21173. Some instances of this field may be defaulted, in others it may be required.
  21174. maxLength: 253
  21175. minLength: 1
  21176. pattern: ^[-._a-zA-Z0-9]+$
  21177. type: string
  21178. name:
  21179. description: The name of the Secret resource being referred to.
  21180. maxLength: 253
  21181. minLength: 1
  21182. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21183. type: string
  21184. namespace:
  21185. description: |-
  21186. The namespace of the Secret resource being referred to.
  21187. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21188. maxLength: 63
  21189. minLength: 1
  21190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21191. type: string
  21192. type: object
  21193. vaultRole:
  21194. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  21195. type: string
  21196. type: object
  21197. gcp:
  21198. description: |-
  21199. Gcp authenticates with Vault using Google Cloud Platform authentication method
  21200. GCP authentication method
  21201. properties:
  21202. location:
  21203. description: Location optionally defines a location/region for the secret
  21204. type: string
  21205. path:
  21206. default: gcp
  21207. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  21208. type: string
  21209. projectID:
  21210. description: Project ID of the Google Cloud Platform project
  21211. type: string
  21212. role:
  21213. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  21214. type: string
  21215. secretRef:
  21216. description: Specify credentials in a Secret object
  21217. properties:
  21218. secretAccessKeySecretRef:
  21219. description: The SecretAccessKey is used for authentication
  21220. properties:
  21221. key:
  21222. description: |-
  21223. A key in the referenced Secret.
  21224. Some instances of this field may be defaulted, in others it may be required.
  21225. maxLength: 253
  21226. minLength: 1
  21227. pattern: ^[-._a-zA-Z0-9]+$
  21228. type: string
  21229. name:
  21230. description: The name of the Secret resource being referred to.
  21231. maxLength: 253
  21232. minLength: 1
  21233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21234. type: string
  21235. namespace:
  21236. description: |-
  21237. The namespace of the Secret resource being referred to.
  21238. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21239. maxLength: 63
  21240. minLength: 1
  21241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21242. type: string
  21243. type: object
  21244. type: object
  21245. serviceAccountRef:
  21246. description: ServiceAccountRef to a service account for impersonation
  21247. properties:
  21248. audiences:
  21249. description: |-
  21250. Audience specifies the `aud` claim for the service account token
  21251. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21252. then this audiences will be appended to the list
  21253. items:
  21254. type: string
  21255. type: array
  21256. name:
  21257. description: The name of the ServiceAccount resource being referred to.
  21258. maxLength: 253
  21259. minLength: 1
  21260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21261. type: string
  21262. namespace:
  21263. description: |-
  21264. Namespace of the resource being referred to.
  21265. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21266. maxLength: 63
  21267. minLength: 1
  21268. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21269. type: string
  21270. required:
  21271. - name
  21272. type: object
  21273. workloadIdentity:
  21274. description: Specify a service account with Workload Identity
  21275. properties:
  21276. clusterLocation:
  21277. description: |-
  21278. ClusterLocation is the location of the cluster
  21279. If not specified, it fetches information from the metadata server
  21280. type: string
  21281. clusterName:
  21282. description: |-
  21283. ClusterName is the name of the cluster
  21284. If not specified, it fetches information from the metadata server
  21285. type: string
  21286. clusterProjectID:
  21287. description: |-
  21288. ClusterProjectID is the project ID of the cluster
  21289. If not specified, it fetches information from the metadata server
  21290. type: string
  21291. serviceAccountRef:
  21292. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  21293. properties:
  21294. audiences:
  21295. description: |-
  21296. Audience specifies the `aud` claim for the service account token
  21297. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21298. then this audiences will be appended to the list
  21299. items:
  21300. type: string
  21301. type: array
  21302. name:
  21303. description: The name of the ServiceAccount resource being referred to.
  21304. maxLength: 253
  21305. minLength: 1
  21306. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21307. type: string
  21308. namespace:
  21309. description: |-
  21310. Namespace of the resource being referred to.
  21311. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21312. maxLength: 63
  21313. minLength: 1
  21314. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21315. type: string
  21316. required:
  21317. - name
  21318. type: object
  21319. required:
  21320. - serviceAccountRef
  21321. type: object
  21322. required:
  21323. - role
  21324. type: object
  21325. iam:
  21326. description: |-
  21327. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  21328. AWS IAM authentication method
  21329. properties:
  21330. externalID:
  21331. description: AWS External ID set on assumed IAM roles
  21332. type: string
  21333. jwt:
  21334. description: Specify a service account with IRSA enabled
  21335. properties:
  21336. serviceAccountRef:
  21337. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  21338. properties:
  21339. audiences:
  21340. description: |-
  21341. Audience specifies the `aud` claim for the service account token
  21342. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21343. then this audiences will be appended to the list
  21344. items:
  21345. type: string
  21346. type: array
  21347. name:
  21348. description: The name of the ServiceAccount resource being referred to.
  21349. maxLength: 253
  21350. minLength: 1
  21351. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21352. type: string
  21353. namespace:
  21354. description: |-
  21355. Namespace of the resource being referred to.
  21356. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21357. maxLength: 63
  21358. minLength: 1
  21359. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21360. type: string
  21361. required:
  21362. - name
  21363. type: object
  21364. type: object
  21365. path:
  21366. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  21367. type: string
  21368. region:
  21369. description: AWS region
  21370. type: string
  21371. role:
  21372. description: This is the AWS role to be assumed before talking to vault
  21373. type: string
  21374. secretRef:
  21375. description: Specify credentials in a Secret object
  21376. properties:
  21377. accessKeyIDSecretRef:
  21378. description: The AccessKeyID is used for authentication
  21379. properties:
  21380. key:
  21381. description: |-
  21382. A key in the referenced Secret.
  21383. Some instances of this field may be defaulted, in others it may be required.
  21384. maxLength: 253
  21385. minLength: 1
  21386. pattern: ^[-._a-zA-Z0-9]+$
  21387. type: string
  21388. name:
  21389. description: The name of the Secret resource being referred to.
  21390. maxLength: 253
  21391. minLength: 1
  21392. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21393. type: string
  21394. namespace:
  21395. description: |-
  21396. The namespace of the Secret resource being referred to.
  21397. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21398. maxLength: 63
  21399. minLength: 1
  21400. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21401. type: string
  21402. type: object
  21403. secretAccessKeySecretRef:
  21404. description: The SecretAccessKey is used for authentication
  21405. properties:
  21406. key:
  21407. description: |-
  21408. A key in the referenced Secret.
  21409. Some instances of this field may be defaulted, in others it may be required.
  21410. maxLength: 253
  21411. minLength: 1
  21412. pattern: ^[-._a-zA-Z0-9]+$
  21413. type: string
  21414. name:
  21415. description: The name of the Secret resource being referred to.
  21416. maxLength: 253
  21417. minLength: 1
  21418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21419. type: string
  21420. namespace:
  21421. description: |-
  21422. The namespace of the Secret resource being referred to.
  21423. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21424. maxLength: 63
  21425. minLength: 1
  21426. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21427. type: string
  21428. type: object
  21429. sessionTokenSecretRef:
  21430. description: |-
  21431. The SessionToken used for authentication
  21432. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  21433. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  21434. properties:
  21435. key:
  21436. description: |-
  21437. A key in the referenced Secret.
  21438. Some instances of this field may be defaulted, in others it may be required.
  21439. maxLength: 253
  21440. minLength: 1
  21441. pattern: ^[-._a-zA-Z0-9]+$
  21442. type: string
  21443. name:
  21444. description: The name of the Secret resource being referred to.
  21445. maxLength: 253
  21446. minLength: 1
  21447. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21448. type: string
  21449. namespace:
  21450. description: |-
  21451. The namespace of the Secret resource being referred to.
  21452. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21453. maxLength: 63
  21454. minLength: 1
  21455. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21456. type: string
  21457. type: object
  21458. type: object
  21459. vaultAwsIamServerID:
  21460. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  21461. type: string
  21462. vaultRole:
  21463. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  21464. type: string
  21465. required:
  21466. - vaultRole
  21467. type: object
  21468. jwt:
  21469. description: |-
  21470. Jwt authenticates with Vault by passing role and JWT token using the
  21471. JWT/OIDC authentication method
  21472. properties:
  21473. kubernetesServiceAccountToken:
  21474. description: |-
  21475. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  21476. a token for with the `TokenRequest` API.
  21477. properties:
  21478. audiences:
  21479. description: |-
  21480. Optional audiences field that will be used to request a temporary Kubernetes service
  21481. account token for the service account referenced by `serviceAccountRef`.
  21482. Defaults to a single audience `vault` it not specified.
  21483. Deprecated: use serviceAccountRef.Audiences instead
  21484. items:
  21485. type: string
  21486. type: array
  21487. expirationSeconds:
  21488. description: |-
  21489. Optional expiration time in seconds that will be used to request a temporary
  21490. Kubernetes service account token for the service account referenced by
  21491. `serviceAccountRef`.
  21492. Deprecated: this will be removed in the future.
  21493. Defaults to 10 minutes.
  21494. format: int64
  21495. type: integer
  21496. serviceAccountRef:
  21497. description: Service account field containing the name of a kubernetes ServiceAccount.
  21498. properties:
  21499. audiences:
  21500. description: |-
  21501. Audience specifies the `aud` claim for the service account token
  21502. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21503. then this audiences will be appended to the list
  21504. items:
  21505. type: string
  21506. type: array
  21507. name:
  21508. description: The name of the ServiceAccount resource being referred to.
  21509. maxLength: 253
  21510. minLength: 1
  21511. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21512. type: string
  21513. namespace:
  21514. description: |-
  21515. Namespace of the resource being referred to.
  21516. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21517. maxLength: 63
  21518. minLength: 1
  21519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21520. type: string
  21521. required:
  21522. - name
  21523. type: object
  21524. required:
  21525. - serviceAccountRef
  21526. type: object
  21527. path:
  21528. default: jwt
  21529. description: |-
  21530. Path where the JWT authentication backend is mounted
  21531. in Vault, e.g: "jwt"
  21532. type: string
  21533. role:
  21534. description: |-
  21535. Role is a JWT role to authenticate using the JWT/OIDC Vault
  21536. authentication method
  21537. type: string
  21538. secretRef:
  21539. description: |-
  21540. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  21541. authenticate with Vault using the JWT/OIDC authentication method.
  21542. properties:
  21543. key:
  21544. description: |-
  21545. A key in the referenced Secret.
  21546. Some instances of this field may be defaulted, in others it may be required.
  21547. maxLength: 253
  21548. minLength: 1
  21549. pattern: ^[-._a-zA-Z0-9]+$
  21550. type: string
  21551. name:
  21552. description: The name of the Secret resource being referred to.
  21553. maxLength: 253
  21554. minLength: 1
  21555. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21556. type: string
  21557. namespace:
  21558. description: |-
  21559. The namespace of the Secret resource being referred to.
  21560. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21561. maxLength: 63
  21562. minLength: 1
  21563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21564. type: string
  21565. type: object
  21566. required:
  21567. - path
  21568. type: object
  21569. kubernetes:
  21570. description: |-
  21571. Kubernetes authenticates with Vault by passing the ServiceAccount
  21572. token stored in the named Secret resource to the Vault server.
  21573. properties:
  21574. mountPath:
  21575. default: kubernetes
  21576. description: |-
  21577. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  21578. "kubernetes"
  21579. type: string
  21580. role:
  21581. description: |-
  21582. A required field containing the Vault Role to assume. A Role binds a
  21583. Kubernetes ServiceAccount with a set of Vault policies.
  21584. type: string
  21585. secretRef:
  21586. description: |-
  21587. Optional secret field containing a Kubernetes ServiceAccount JWT used
  21588. for authenticating with Vault. If a name is specified without a key,
  21589. `token` is the default. If one is not specified, the one bound to
  21590. the controller will be used.
  21591. properties:
  21592. key:
  21593. description: |-
  21594. A key in the referenced Secret.
  21595. Some instances of this field may be defaulted, in others it may be required.
  21596. maxLength: 253
  21597. minLength: 1
  21598. pattern: ^[-._a-zA-Z0-9]+$
  21599. type: string
  21600. name:
  21601. description: The name of the Secret resource being referred to.
  21602. maxLength: 253
  21603. minLength: 1
  21604. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21605. type: string
  21606. namespace:
  21607. description: |-
  21608. The namespace of the Secret resource being referred to.
  21609. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21610. maxLength: 63
  21611. minLength: 1
  21612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21613. type: string
  21614. type: object
  21615. serviceAccountRef:
  21616. description: |-
  21617. Optional service account field containing the name of a kubernetes ServiceAccount.
  21618. If the service account is specified, the service account secret token JWT will be used
  21619. for authenticating with Vault. If the service account selector is not supplied,
  21620. the secretRef will be used instead.
  21621. properties:
  21622. audiences:
  21623. description: |-
  21624. Audience specifies the `aud` claim for the service account token
  21625. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21626. then this audiences will be appended to the list
  21627. items:
  21628. type: string
  21629. type: array
  21630. name:
  21631. description: The name of the ServiceAccount resource being referred to.
  21632. maxLength: 253
  21633. minLength: 1
  21634. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21635. type: string
  21636. namespace:
  21637. description: |-
  21638. Namespace of the resource being referred to.
  21639. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21640. maxLength: 63
  21641. minLength: 1
  21642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21643. type: string
  21644. required:
  21645. - name
  21646. type: object
  21647. required:
  21648. - mountPath
  21649. - role
  21650. type: object
  21651. ldap:
  21652. description: |-
  21653. Ldap authenticates with Vault by passing username/password pair using
  21654. the LDAP authentication method
  21655. properties:
  21656. path:
  21657. default: ldap
  21658. description: |-
  21659. Path where the LDAP authentication backend is mounted
  21660. in Vault, e.g: "ldap"
  21661. type: string
  21662. secretRef:
  21663. description: |-
  21664. SecretRef to a key in a Secret resource containing password for the LDAP
  21665. user used to authenticate with Vault using the LDAP authentication
  21666. method
  21667. properties:
  21668. key:
  21669. description: |-
  21670. A key in the referenced Secret.
  21671. Some instances of this field may be defaulted, in others it may be required.
  21672. maxLength: 253
  21673. minLength: 1
  21674. pattern: ^[-._a-zA-Z0-9]+$
  21675. type: string
  21676. name:
  21677. description: The name of the Secret resource being referred to.
  21678. maxLength: 253
  21679. minLength: 1
  21680. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21681. type: string
  21682. namespace:
  21683. description: |-
  21684. The namespace of the Secret resource being referred to.
  21685. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21686. maxLength: 63
  21687. minLength: 1
  21688. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21689. type: string
  21690. type: object
  21691. username:
  21692. description: |-
  21693. Username is an LDAP username used to authenticate using the LDAP Vault
  21694. authentication method
  21695. type: string
  21696. required:
  21697. - path
  21698. - username
  21699. type: object
  21700. namespace:
  21701. description: |-
  21702. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  21703. Namespaces is a set of features within Vault Enterprise that allows
  21704. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  21705. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  21706. This will default to Vault.Namespace field if set, or empty otherwise
  21707. type: string
  21708. tokenSecretRef:
  21709. description: TokenSecretRef authenticates with Vault by presenting a token.
  21710. properties:
  21711. key:
  21712. description: |-
  21713. A key in the referenced Secret.
  21714. Some instances of this field may be defaulted, in others it may be required.
  21715. maxLength: 253
  21716. minLength: 1
  21717. pattern: ^[-._a-zA-Z0-9]+$
  21718. type: string
  21719. name:
  21720. description: The name of the Secret resource being referred to.
  21721. maxLength: 253
  21722. minLength: 1
  21723. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21724. type: string
  21725. namespace:
  21726. description: |-
  21727. The namespace of the Secret resource being referred to.
  21728. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21729. maxLength: 63
  21730. minLength: 1
  21731. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21732. type: string
  21733. type: object
  21734. userPass:
  21735. description: UserPass authenticates with Vault by passing username/password pair
  21736. properties:
  21737. path:
  21738. default: userpass
  21739. description: |-
  21740. Path where the UserPassword authentication backend is mounted
  21741. in Vault, e.g: "userpass"
  21742. type: string
  21743. secretRef:
  21744. description: |-
  21745. SecretRef to a key in a Secret resource containing password for the
  21746. user used to authenticate with Vault using the UserPass authentication
  21747. method
  21748. properties:
  21749. key:
  21750. description: |-
  21751. A key in the referenced Secret.
  21752. Some instances of this field may be defaulted, in others it may be required.
  21753. maxLength: 253
  21754. minLength: 1
  21755. pattern: ^[-._a-zA-Z0-9]+$
  21756. type: string
  21757. name:
  21758. description: The name of the Secret resource being referred to.
  21759. maxLength: 253
  21760. minLength: 1
  21761. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21762. type: string
  21763. namespace:
  21764. description: |-
  21765. The namespace of the Secret resource being referred to.
  21766. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21767. maxLength: 63
  21768. minLength: 1
  21769. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21770. type: string
  21771. type: object
  21772. username:
  21773. description: |-
  21774. Username is a username used to authenticate using the UserPass Vault
  21775. authentication method
  21776. type: string
  21777. required:
  21778. - path
  21779. - username
  21780. type: object
  21781. type: object
  21782. caBundle:
  21783. description: |-
  21784. PEM encoded CA bundle used to validate Vault server certificate. Only used
  21785. if the Server URL is using HTTPS protocol. This parameter is ignored for
  21786. plain HTTP protocol connection. If not set the system root certificates
  21787. are used to validate the TLS connection.
  21788. format: byte
  21789. type: string
  21790. caProvider:
  21791. description: The provider for the CA bundle to use to validate Vault server certificate.
  21792. properties:
  21793. key:
  21794. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  21795. maxLength: 253
  21796. minLength: 1
  21797. pattern: ^[-._a-zA-Z0-9]+$
  21798. type: string
  21799. name:
  21800. description: The name of the object located at the provider type.
  21801. maxLength: 253
  21802. minLength: 1
  21803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21804. type: string
  21805. namespace:
  21806. description: |-
  21807. The namespace the Provider type is in.
  21808. Can only be defined when used in a ClusterSecretStore.
  21809. maxLength: 63
  21810. minLength: 1
  21811. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21812. type: string
  21813. type:
  21814. description: The type of provider to use such as "Secret", or "ConfigMap".
  21815. enum:
  21816. - Secret
  21817. - ConfigMap
  21818. type: string
  21819. required:
  21820. - name
  21821. - type
  21822. type: object
  21823. checkAndSet:
  21824. description: |-
  21825. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  21826. Only applies to Vault KV v2 stores. When enabled, write operations must include
  21827. the current version of the secret to prevent unintentional overwrites.
  21828. properties:
  21829. required:
  21830. description: |-
  21831. Required when true, all write operations must include a check-and-set parameter.
  21832. This helps prevent unintentional overwrites of secrets.
  21833. type: boolean
  21834. type: object
  21835. forwardInconsistent:
  21836. description: |-
  21837. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  21838. leader instead of simply retrying within a loop. This can increase performance if
  21839. the option is enabled serverside.
  21840. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  21841. type: boolean
  21842. headers:
  21843. additionalProperties:
  21844. type: string
  21845. description: Headers to be added in Vault request
  21846. type: object
  21847. namespace:
  21848. description: |-
  21849. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  21850. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  21851. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  21852. type: string
  21853. path:
  21854. description: |-
  21855. Path is the mount path of the Vault KV backend endpoint, e.g:
  21856. "secret". The v2 KV secret engine version specific "/data" path suffix
  21857. for fetching secrets from Vault is optional and will be appended
  21858. if not present in specified path.
  21859. type: string
  21860. readYourWrites:
  21861. description: |-
  21862. ReadYourWrites ensures isolated read-after-write semantics by
  21863. providing discovered cluster replication states in each request.
  21864. More information about eventual consistency in Vault can be found here
  21865. https://www.vaultproject.io/docs/enterprise/consistency
  21866. type: boolean
  21867. server:
  21868. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  21869. type: string
  21870. tls:
  21871. description: |-
  21872. The configuration used for client side related TLS communication, when the Vault server
  21873. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  21874. This parameter is ignored for plain HTTP protocol connection.
  21875. It's worth noting this configuration is different from the "TLS certificates auth method",
  21876. which is available under the `auth.cert` section.
  21877. properties:
  21878. certSecretRef:
  21879. description: |-
  21880. CertSecretRef is a certificate added to the transport layer
  21881. when communicating with the Vault server.
  21882. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  21883. properties:
  21884. key:
  21885. description: |-
  21886. A key in the referenced Secret.
  21887. Some instances of this field may be defaulted, in others it may be required.
  21888. maxLength: 253
  21889. minLength: 1
  21890. pattern: ^[-._a-zA-Z0-9]+$
  21891. type: string
  21892. name:
  21893. description: The name of the Secret resource being referred to.
  21894. maxLength: 253
  21895. minLength: 1
  21896. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21897. type: string
  21898. namespace:
  21899. description: |-
  21900. The namespace of the Secret resource being referred to.
  21901. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21902. maxLength: 63
  21903. minLength: 1
  21904. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21905. type: string
  21906. type: object
  21907. keySecretRef:
  21908. description: |-
  21909. KeySecretRef to a key in a Secret resource containing client private key
  21910. added to the transport layer when communicating with the Vault server.
  21911. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  21912. properties:
  21913. key:
  21914. description: |-
  21915. A key in the referenced Secret.
  21916. Some instances of this field may be defaulted, in others it may be required.
  21917. maxLength: 253
  21918. minLength: 1
  21919. pattern: ^[-._a-zA-Z0-9]+$
  21920. type: string
  21921. name:
  21922. description: The name of the Secret resource being referred to.
  21923. maxLength: 253
  21924. minLength: 1
  21925. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21926. type: string
  21927. namespace:
  21928. description: |-
  21929. The namespace of the Secret resource being referred to.
  21930. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21931. maxLength: 63
  21932. minLength: 1
  21933. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21934. type: string
  21935. type: object
  21936. type: object
  21937. version:
  21938. default: v2
  21939. description: |-
  21940. Version is the Vault KV secret engine version. This can be either "v1" or
  21941. "v2". Version defaults to "v2".
  21942. enum:
  21943. - v1
  21944. - v2
  21945. type: string
  21946. required:
  21947. - server
  21948. type: object
  21949. volcengine:
  21950. description: Volcengine configures this store to sync secrets using the Volcengine provider
  21951. properties:
  21952. auth:
  21953. description: |-
  21954. Auth defines the authentication method to use.
  21955. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  21956. properties:
  21957. secretRef:
  21958. description: |-
  21959. SecretRef defines the static credentials to use for authentication.
  21960. If not set, IRSA is used.
  21961. properties:
  21962. accessKeyID:
  21963. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  21964. properties:
  21965. key:
  21966. description: |-
  21967. A key in the referenced Secret.
  21968. Some instances of this field may be defaulted, in others it may be required.
  21969. maxLength: 253
  21970. minLength: 1
  21971. pattern: ^[-._a-zA-Z0-9]+$
  21972. type: string
  21973. name:
  21974. description: The name of the Secret resource being referred to.
  21975. maxLength: 253
  21976. minLength: 1
  21977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21978. type: string
  21979. namespace:
  21980. description: |-
  21981. The namespace of the Secret resource being referred to.
  21982. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21983. maxLength: 63
  21984. minLength: 1
  21985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21986. type: string
  21987. type: object
  21988. secretAccessKey:
  21989. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  21990. properties:
  21991. key:
  21992. description: |-
  21993. A key in the referenced Secret.
  21994. Some instances of this field may be defaulted, in others it may be required.
  21995. maxLength: 253
  21996. minLength: 1
  21997. pattern: ^[-._a-zA-Z0-9]+$
  21998. type: string
  21999. name:
  22000. description: The name of the Secret resource being referred to.
  22001. maxLength: 253
  22002. minLength: 1
  22003. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22004. type: string
  22005. namespace:
  22006. description: |-
  22007. The namespace of the Secret resource being referred to.
  22008. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22009. maxLength: 63
  22010. minLength: 1
  22011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22012. type: string
  22013. type: object
  22014. token:
  22015. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  22016. properties:
  22017. key:
  22018. description: |-
  22019. A key in the referenced Secret.
  22020. Some instances of this field may be defaulted, in others it may be required.
  22021. maxLength: 253
  22022. minLength: 1
  22023. pattern: ^[-._a-zA-Z0-9]+$
  22024. type: string
  22025. name:
  22026. description: The name of the Secret resource being referred to.
  22027. maxLength: 253
  22028. minLength: 1
  22029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22030. type: string
  22031. namespace:
  22032. description: |-
  22033. The namespace of the Secret resource being referred to.
  22034. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22035. maxLength: 63
  22036. minLength: 1
  22037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22038. type: string
  22039. type: object
  22040. required:
  22041. - accessKeyID
  22042. - secretAccessKey
  22043. type: object
  22044. type: object
  22045. region:
  22046. description: Region specifies the Volcengine region to connect to.
  22047. type: string
  22048. required:
  22049. - region
  22050. type: object
  22051. webhook:
  22052. description: Webhook configures this store to sync secrets using a generic templated webhook
  22053. properties:
  22054. auth:
  22055. description: Auth specifies a authorization protocol. Only one protocol may be set.
  22056. maxProperties: 1
  22057. minProperties: 1
  22058. properties:
  22059. ntlm:
  22060. description: NTLMProtocol configures the store to use NTLM for auth
  22061. properties:
  22062. passwordSecret:
  22063. description: |-
  22064. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22065. In some instances, `key` is a required field.
  22066. properties:
  22067. key:
  22068. description: |-
  22069. A key in the referenced Secret.
  22070. Some instances of this field may be defaulted, in others it may be required.
  22071. maxLength: 253
  22072. minLength: 1
  22073. pattern: ^[-._a-zA-Z0-9]+$
  22074. type: string
  22075. name:
  22076. description: The name of the Secret resource being referred to.
  22077. maxLength: 253
  22078. minLength: 1
  22079. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22080. type: string
  22081. namespace:
  22082. description: |-
  22083. The namespace of the Secret resource being referred to.
  22084. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22085. maxLength: 63
  22086. minLength: 1
  22087. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22088. type: string
  22089. type: object
  22090. usernameSecret:
  22091. description: |-
  22092. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22093. In some instances, `key` is a required field.
  22094. properties:
  22095. key:
  22096. description: |-
  22097. A key in the referenced Secret.
  22098. Some instances of this field may be defaulted, in others it may be required.
  22099. maxLength: 253
  22100. minLength: 1
  22101. pattern: ^[-._a-zA-Z0-9]+$
  22102. type: string
  22103. name:
  22104. description: The name of the Secret resource being referred to.
  22105. maxLength: 253
  22106. minLength: 1
  22107. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22108. type: string
  22109. namespace:
  22110. description: |-
  22111. The namespace of the Secret resource being referred to.
  22112. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22113. maxLength: 63
  22114. minLength: 1
  22115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22116. type: string
  22117. type: object
  22118. required:
  22119. - passwordSecret
  22120. - usernameSecret
  22121. type: object
  22122. type: object
  22123. body:
  22124. description: Body
  22125. type: string
  22126. caBundle:
  22127. description: |-
  22128. PEM encoded CA bundle used to validate webhook server certificate. Only used
  22129. if the Server URL is using HTTPS protocol. This parameter is ignored for
  22130. plain HTTP protocol connection. If not set the system root certificates
  22131. are used to validate the TLS connection.
  22132. format: byte
  22133. type: string
  22134. caProvider:
  22135. description: The provider for the CA bundle to use to validate webhook server certificate.
  22136. properties:
  22137. key:
  22138. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22139. maxLength: 253
  22140. minLength: 1
  22141. pattern: ^[-._a-zA-Z0-9]+$
  22142. type: string
  22143. name:
  22144. description: The name of the object located at the provider type.
  22145. maxLength: 253
  22146. minLength: 1
  22147. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22148. type: string
  22149. namespace:
  22150. description: The namespace the Provider type is in.
  22151. maxLength: 63
  22152. minLength: 1
  22153. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22154. type: string
  22155. type:
  22156. description: The type of provider to use such as "Secret", or "ConfigMap".
  22157. enum:
  22158. - Secret
  22159. - ConfigMap
  22160. type: string
  22161. required:
  22162. - name
  22163. - type
  22164. type: object
  22165. headers:
  22166. additionalProperties:
  22167. type: string
  22168. description: Headers
  22169. type: object
  22170. method:
  22171. description: Webhook Method
  22172. type: string
  22173. result:
  22174. description: Result formatting
  22175. properties:
  22176. jsonPath:
  22177. description: Json path of return value
  22178. type: string
  22179. type: object
  22180. secrets:
  22181. description: |-
  22182. Secrets to fill in templates
  22183. These secrets will be passed to the templating function as key value pairs under the given name
  22184. items:
  22185. description: WebhookSecret defines a secret that will be passed to the webhook request.
  22186. properties:
  22187. name:
  22188. description: Name of this secret in templates
  22189. type: string
  22190. secretRef:
  22191. description: Secret ref to fill in credentials
  22192. properties:
  22193. key:
  22194. description: |-
  22195. A key in the referenced Secret.
  22196. Some instances of this field may be defaulted, in others it may be required.
  22197. maxLength: 253
  22198. minLength: 1
  22199. pattern: ^[-._a-zA-Z0-9]+$
  22200. type: string
  22201. name:
  22202. description: The name of the Secret resource being referred to.
  22203. maxLength: 253
  22204. minLength: 1
  22205. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22206. type: string
  22207. namespace:
  22208. description: |-
  22209. The namespace of the Secret resource being referred to.
  22210. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22211. maxLength: 63
  22212. minLength: 1
  22213. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22214. type: string
  22215. type: object
  22216. required:
  22217. - name
  22218. - secretRef
  22219. type: object
  22220. type: array
  22221. timeout:
  22222. description: Timeout
  22223. type: string
  22224. url:
  22225. description: Webhook url to call
  22226. type: string
  22227. required:
  22228. - url
  22229. type: object
  22230. yandexcertificatemanager:
  22231. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  22232. properties:
  22233. apiEndpoint:
  22234. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  22235. type: string
  22236. auth:
  22237. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  22238. properties:
  22239. authorizedKeySecretRef:
  22240. description: The authorized key used for authentication
  22241. properties:
  22242. key:
  22243. description: |-
  22244. A key in the referenced Secret.
  22245. Some instances of this field may be defaulted, in others it may be required.
  22246. maxLength: 253
  22247. minLength: 1
  22248. pattern: ^[-._a-zA-Z0-9]+$
  22249. type: string
  22250. name:
  22251. description: The name of the Secret resource being referred to.
  22252. maxLength: 253
  22253. minLength: 1
  22254. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22255. type: string
  22256. namespace:
  22257. description: |-
  22258. The namespace of the Secret resource being referred to.
  22259. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22260. maxLength: 63
  22261. minLength: 1
  22262. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22263. type: string
  22264. type: object
  22265. type: object
  22266. caProvider:
  22267. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  22268. properties:
  22269. certSecretRef:
  22270. description: |-
  22271. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22272. In some instances, `key` is a required field.
  22273. properties:
  22274. key:
  22275. description: |-
  22276. A key in the referenced Secret.
  22277. Some instances of this field may be defaulted, in others it may be required.
  22278. maxLength: 253
  22279. minLength: 1
  22280. pattern: ^[-._a-zA-Z0-9]+$
  22281. type: string
  22282. name:
  22283. description: The name of the Secret resource being referred to.
  22284. maxLength: 253
  22285. minLength: 1
  22286. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22287. type: string
  22288. namespace:
  22289. description: |-
  22290. The namespace of the Secret resource being referred to.
  22291. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22292. maxLength: 63
  22293. minLength: 1
  22294. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22295. type: string
  22296. type: object
  22297. type: object
  22298. fetching:
  22299. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  22300. maxProperties: 1
  22301. minProperties: 1
  22302. properties:
  22303. byID:
  22304. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  22305. type: object
  22306. byName:
  22307. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  22308. properties:
  22309. folderID:
  22310. description: The folder to fetch secrets from
  22311. type: string
  22312. required:
  22313. - folderID
  22314. type: object
  22315. type: object
  22316. required:
  22317. - auth
  22318. type: object
  22319. yandexlockbox:
  22320. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  22321. properties:
  22322. apiEndpoint:
  22323. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  22324. type: string
  22325. auth:
  22326. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  22327. properties:
  22328. authorizedKeySecretRef:
  22329. description: The authorized key used for authentication
  22330. properties:
  22331. key:
  22332. description: |-
  22333. A key in the referenced Secret.
  22334. Some instances of this field may be defaulted, in others it may be required.
  22335. maxLength: 253
  22336. minLength: 1
  22337. pattern: ^[-._a-zA-Z0-9]+$
  22338. type: string
  22339. name:
  22340. description: The name of the Secret resource being referred to.
  22341. maxLength: 253
  22342. minLength: 1
  22343. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22344. type: string
  22345. namespace:
  22346. description: |-
  22347. The namespace of the Secret resource being referred to.
  22348. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22349. maxLength: 63
  22350. minLength: 1
  22351. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22352. type: string
  22353. type: object
  22354. type: object
  22355. caProvider:
  22356. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  22357. properties:
  22358. certSecretRef:
  22359. description: |-
  22360. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22361. In some instances, `key` is a required field.
  22362. properties:
  22363. key:
  22364. description: |-
  22365. A key in the referenced Secret.
  22366. Some instances of this field may be defaulted, in others it may be required.
  22367. maxLength: 253
  22368. minLength: 1
  22369. pattern: ^[-._a-zA-Z0-9]+$
  22370. type: string
  22371. name:
  22372. description: The name of the Secret resource being referred to.
  22373. maxLength: 253
  22374. minLength: 1
  22375. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22376. type: string
  22377. namespace:
  22378. description: |-
  22379. The namespace of the Secret resource being referred to.
  22380. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22381. maxLength: 63
  22382. minLength: 1
  22383. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22384. type: string
  22385. type: object
  22386. type: object
  22387. fetching:
  22388. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  22389. maxProperties: 1
  22390. minProperties: 1
  22391. properties:
  22392. byID:
  22393. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  22394. type: object
  22395. byName:
  22396. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  22397. properties:
  22398. folderID:
  22399. description: The folder to fetch secrets from
  22400. type: string
  22401. required:
  22402. - folderID
  22403. type: object
  22404. type: object
  22405. required:
  22406. - auth
  22407. type: object
  22408. type: object
  22409. refreshInterval:
  22410. anyOf:
  22411. - type: integer
  22412. - type: string
  22413. description: |-
  22414. Used to configure store refresh interval. Accepts either an integer number
  22415. of seconds (legacy) or a Go duration string such as "1h" or "5m". Empty or
  22416. 0 will default to the controller config.
  22417. x-kubernetes-int-or-string: true
  22418. retrySettings:
  22419. description: Used to configure HTTP retries on failures.
  22420. properties:
  22421. maxRetries:
  22422. format: int32
  22423. type: integer
  22424. retryInterval:
  22425. type: string
  22426. type: object
  22427. required:
  22428. - provider
  22429. type: object
  22430. status:
  22431. description: SecretStoreStatus defines the observed state of the SecretStore.
  22432. properties:
  22433. capabilities:
  22434. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  22435. type: string
  22436. conditions:
  22437. items:
  22438. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  22439. properties:
  22440. lastTransitionTime:
  22441. format: date-time
  22442. type: string
  22443. message:
  22444. type: string
  22445. reason:
  22446. type: string
  22447. status:
  22448. type: string
  22449. type:
  22450. description: SecretStoreConditionType represents the condition of the SecretStore.
  22451. type: string
  22452. required:
  22453. - status
  22454. - type
  22455. type: object
  22456. type: array
  22457. type: object
  22458. type: object
  22459. served: true
  22460. storage: true
  22461. subresources:
  22462. status: {}
  22463. - additionalPrinterColumns:
  22464. - jsonPath: .metadata.creationTimestamp
  22465. name: AGE
  22466. type: date
  22467. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  22468. name: Status
  22469. type: string
  22470. - jsonPath: .status.capabilities
  22471. name: Capabilities
  22472. type: string
  22473. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  22474. name: Ready
  22475. type: string
  22476. deprecated: true
  22477. name: v1beta1
  22478. schema:
  22479. openAPIV3Schema:
  22480. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  22481. properties:
  22482. apiVersion:
  22483. description: |-
  22484. APIVersion defines the versioned schema of this representation of an object.
  22485. Servers should convert recognized schemas to the latest internal value, and
  22486. may reject unrecognized values.
  22487. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  22488. type: string
  22489. kind:
  22490. description: |-
  22491. Kind is a string value representing the REST resource this object represents.
  22492. Servers may infer this from the endpoint the client submits requests to.
  22493. Cannot be updated.
  22494. In CamelCase.
  22495. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  22496. type: string
  22497. metadata:
  22498. type: object
  22499. spec:
  22500. description: SecretStoreSpec defines the desired state of SecretStore.
  22501. properties:
  22502. conditions:
  22503. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  22504. items:
  22505. description: |-
  22506. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  22507. for a ClusterSecretStore instance.
  22508. properties:
  22509. namespaceRegexes:
  22510. description: Choose namespaces by using regex matching
  22511. items:
  22512. type: string
  22513. type: array
  22514. namespaceSelector:
  22515. description: Choose namespace using a labelSelector
  22516. properties:
  22517. matchExpressions:
  22518. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  22519. items:
  22520. description: |-
  22521. A label selector requirement is a selector that contains values, a key, and an operator that
  22522. relates the key and values.
  22523. properties:
  22524. key:
  22525. description: key is the label key that the selector applies to.
  22526. type: string
  22527. operator:
  22528. description: |-
  22529. operator represents a key's relationship to a set of values.
  22530. Valid operators are In, NotIn, Exists and DoesNotExist.
  22531. type: string
  22532. values:
  22533. description: |-
  22534. values is an array of string values. If the operator is In or NotIn,
  22535. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  22536. the values array must be empty. This array is replaced during a strategic
  22537. merge patch.
  22538. items:
  22539. type: string
  22540. type: array
  22541. x-kubernetes-list-type: atomic
  22542. required:
  22543. - key
  22544. - operator
  22545. type: object
  22546. type: array
  22547. x-kubernetes-list-type: atomic
  22548. matchLabels:
  22549. additionalProperties:
  22550. type: string
  22551. description: |-
  22552. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  22553. map is equivalent to an element of matchExpressions, whose key field is "key", the
  22554. operator is "In", and the values array contains only "value". The requirements are ANDed.
  22555. type: object
  22556. type: object
  22557. x-kubernetes-map-type: atomic
  22558. namespaces:
  22559. description: Choose namespaces by name
  22560. items:
  22561. maxLength: 63
  22562. minLength: 1
  22563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22564. type: string
  22565. type: array
  22566. type: object
  22567. type: array
  22568. controller:
  22569. description: |-
  22570. Used to select the correct ESO controller (think: ingress.ingressClassName)
  22571. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  22572. type: string
  22573. provider:
  22574. description: Used to configure the provider. Only one provider may be set
  22575. maxProperties: 1
  22576. minProperties: 1
  22577. properties:
  22578. akeyless:
  22579. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  22580. properties:
  22581. akeylessGWApiURL:
  22582. description: Akeyless GW API Url from which the secrets to be fetched from.
  22583. type: string
  22584. authSecretRef:
  22585. description: Auth configures how the operator authenticates with Akeyless.
  22586. properties:
  22587. kubernetesAuth:
  22588. description: |-
  22589. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  22590. token stored in the named Secret resource.
  22591. properties:
  22592. accessID:
  22593. description: the Akeyless Kubernetes auth-method access-id
  22594. type: string
  22595. k8sConfName:
  22596. description: Kubernetes-auth configuration name in Akeyless-Gateway
  22597. type: string
  22598. secretRef:
  22599. description: |-
  22600. Optional secret field containing a Kubernetes ServiceAccount JWT used
  22601. for authenticating with Akeyless. If a name is specified without a key,
  22602. `token` is the default. If one is not specified, the one bound to
  22603. the controller will be used.
  22604. properties:
  22605. key:
  22606. description: |-
  22607. A key in the referenced Secret.
  22608. Some instances of this field may be defaulted, in others it may be required.
  22609. maxLength: 253
  22610. minLength: 1
  22611. pattern: ^[-._a-zA-Z0-9]+$
  22612. type: string
  22613. name:
  22614. description: The name of the Secret resource being referred to.
  22615. maxLength: 253
  22616. minLength: 1
  22617. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22618. type: string
  22619. namespace:
  22620. description: |-
  22621. The namespace of the Secret resource being referred to.
  22622. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22623. maxLength: 63
  22624. minLength: 1
  22625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22626. type: string
  22627. type: object
  22628. serviceAccountRef:
  22629. description: |-
  22630. Optional service account field containing the name of a kubernetes ServiceAccount.
  22631. If the service account is specified, the service account secret token JWT will be used
  22632. for authenticating with Akeyless. If the service account selector is not supplied,
  22633. the secretRef will be used instead.
  22634. properties:
  22635. audiences:
  22636. description: |-
  22637. Audience specifies the `aud` claim for the service account token
  22638. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  22639. then this audiences will be appended to the list
  22640. items:
  22641. type: string
  22642. type: array
  22643. name:
  22644. description: The name of the ServiceAccount resource being referred to.
  22645. maxLength: 253
  22646. minLength: 1
  22647. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22648. type: string
  22649. namespace:
  22650. description: |-
  22651. Namespace of the resource being referred to.
  22652. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22653. maxLength: 63
  22654. minLength: 1
  22655. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22656. type: string
  22657. required:
  22658. - name
  22659. type: object
  22660. required:
  22661. - accessID
  22662. - k8sConfName
  22663. type: object
  22664. secretRef:
  22665. description: |-
  22666. Reference to a Secret that contains the details
  22667. to authenticate with Akeyless.
  22668. properties:
  22669. accessID:
  22670. description: The SecretAccessID is used for authentication
  22671. properties:
  22672. key:
  22673. description: |-
  22674. A key in the referenced Secret.
  22675. Some instances of this field may be defaulted, in others it may be required.
  22676. maxLength: 253
  22677. minLength: 1
  22678. pattern: ^[-._a-zA-Z0-9]+$
  22679. type: string
  22680. name:
  22681. description: The name of the Secret resource being referred to.
  22682. maxLength: 253
  22683. minLength: 1
  22684. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22685. type: string
  22686. namespace:
  22687. description: |-
  22688. The namespace of the Secret resource being referred to.
  22689. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22690. maxLength: 63
  22691. minLength: 1
  22692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22693. type: string
  22694. type: object
  22695. accessType:
  22696. description: |-
  22697. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22698. In some instances, `key` is a required field.
  22699. properties:
  22700. key:
  22701. description: |-
  22702. A key in the referenced Secret.
  22703. Some instances of this field may be defaulted, in others it may be required.
  22704. maxLength: 253
  22705. minLength: 1
  22706. pattern: ^[-._a-zA-Z0-9]+$
  22707. type: string
  22708. name:
  22709. description: The name of the Secret resource being referred to.
  22710. maxLength: 253
  22711. minLength: 1
  22712. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22713. type: string
  22714. namespace:
  22715. description: |-
  22716. The namespace of the Secret resource being referred to.
  22717. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22718. maxLength: 63
  22719. minLength: 1
  22720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22721. type: string
  22722. type: object
  22723. accessTypeParam:
  22724. description: |-
  22725. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22726. In some instances, `key` is a required field.
  22727. properties:
  22728. key:
  22729. description: |-
  22730. A key in the referenced Secret.
  22731. Some instances of this field may be defaulted, in others it may be required.
  22732. maxLength: 253
  22733. minLength: 1
  22734. pattern: ^[-._a-zA-Z0-9]+$
  22735. type: string
  22736. name:
  22737. description: The name of the Secret resource being referred to.
  22738. maxLength: 253
  22739. minLength: 1
  22740. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22741. type: string
  22742. namespace:
  22743. description: |-
  22744. The namespace of the Secret resource being referred to.
  22745. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22746. maxLength: 63
  22747. minLength: 1
  22748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22749. type: string
  22750. type: object
  22751. type: object
  22752. type: object
  22753. caBundle:
  22754. description: |-
  22755. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  22756. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  22757. are used to validate the TLS connection.
  22758. format: byte
  22759. type: string
  22760. caProvider:
  22761. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  22762. properties:
  22763. key:
  22764. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22765. maxLength: 253
  22766. minLength: 1
  22767. pattern: ^[-._a-zA-Z0-9]+$
  22768. type: string
  22769. name:
  22770. description: The name of the object located at the provider type.
  22771. maxLength: 253
  22772. minLength: 1
  22773. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22774. type: string
  22775. namespace:
  22776. description: |-
  22777. The namespace the Provider type is in.
  22778. Can only be defined when used in a ClusterSecretStore.
  22779. maxLength: 63
  22780. minLength: 1
  22781. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22782. type: string
  22783. type:
  22784. description: The type of provider to use such as "Secret", or "ConfigMap".
  22785. enum:
  22786. - Secret
  22787. - ConfigMap
  22788. type: string
  22789. required:
  22790. - name
  22791. - type
  22792. type: object
  22793. required:
  22794. - akeylessGWApiURL
  22795. - authSecretRef
  22796. type: object
  22797. alibaba:
  22798. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  22799. properties:
  22800. auth:
  22801. description: AlibabaAuth contains a secretRef for credentials.
  22802. properties:
  22803. rrsa:
  22804. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  22805. properties:
  22806. oidcProviderArn:
  22807. type: string
  22808. oidcTokenFilePath:
  22809. type: string
  22810. roleArn:
  22811. type: string
  22812. sessionName:
  22813. type: string
  22814. required:
  22815. - oidcProviderArn
  22816. - oidcTokenFilePath
  22817. - roleArn
  22818. - sessionName
  22819. type: object
  22820. secretRef:
  22821. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  22822. properties:
  22823. accessKeyIDSecretRef:
  22824. description: The AccessKeyID is used for authentication
  22825. properties:
  22826. key:
  22827. description: |-
  22828. A key in the referenced Secret.
  22829. Some instances of this field may be defaulted, in others it may be required.
  22830. maxLength: 253
  22831. minLength: 1
  22832. pattern: ^[-._a-zA-Z0-9]+$
  22833. type: string
  22834. name:
  22835. description: The name of the Secret resource being referred to.
  22836. maxLength: 253
  22837. minLength: 1
  22838. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22839. type: string
  22840. namespace:
  22841. description: |-
  22842. The namespace of the Secret resource being referred to.
  22843. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22844. maxLength: 63
  22845. minLength: 1
  22846. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22847. type: string
  22848. type: object
  22849. accessKeySecretSecretRef:
  22850. description: The AccessKeySecret is used for authentication
  22851. properties:
  22852. key:
  22853. description: |-
  22854. A key in the referenced Secret.
  22855. Some instances of this field may be defaulted, in others it may be required.
  22856. maxLength: 253
  22857. minLength: 1
  22858. pattern: ^[-._a-zA-Z0-9]+$
  22859. type: string
  22860. name:
  22861. description: The name of the Secret resource being referred to.
  22862. maxLength: 253
  22863. minLength: 1
  22864. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22865. type: string
  22866. namespace:
  22867. description: |-
  22868. The namespace of the Secret resource being referred to.
  22869. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22870. maxLength: 63
  22871. minLength: 1
  22872. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22873. type: string
  22874. type: object
  22875. required:
  22876. - accessKeyIDSecretRef
  22877. - accessKeySecretSecretRef
  22878. type: object
  22879. type: object
  22880. regionID:
  22881. description: Alibaba Region to be used for the provider
  22882. type: string
  22883. required:
  22884. - auth
  22885. - regionID
  22886. type: object
  22887. aws:
  22888. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  22889. properties:
  22890. additionalRoles:
  22891. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  22892. items:
  22893. type: string
  22894. type: array
  22895. auth:
  22896. description: |-
  22897. Auth defines the information necessary to authenticate against AWS
  22898. if not set aws sdk will infer credentials from your environment
  22899. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  22900. properties:
  22901. jwt:
  22902. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  22903. properties:
  22904. serviceAccountRef:
  22905. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  22906. properties:
  22907. audiences:
  22908. description: |-
  22909. Audience specifies the `aud` claim for the service account token
  22910. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  22911. then this audiences will be appended to the list
  22912. items:
  22913. type: string
  22914. type: array
  22915. name:
  22916. description: The name of the ServiceAccount resource being referred to.
  22917. maxLength: 253
  22918. minLength: 1
  22919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22920. type: string
  22921. namespace:
  22922. description: |-
  22923. Namespace of the resource being referred to.
  22924. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22925. maxLength: 63
  22926. minLength: 1
  22927. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22928. type: string
  22929. required:
  22930. - name
  22931. type: object
  22932. type: object
  22933. secretRef:
  22934. description: |-
  22935. AWSAuthSecretRef holds secret references for AWS credentials
  22936. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  22937. properties:
  22938. accessKeyIDSecretRef:
  22939. description: The AccessKeyID is used for authentication
  22940. properties:
  22941. key:
  22942. description: |-
  22943. A key in the referenced Secret.
  22944. Some instances of this field may be defaulted, in others it may be required.
  22945. maxLength: 253
  22946. minLength: 1
  22947. pattern: ^[-._a-zA-Z0-9]+$
  22948. type: string
  22949. name:
  22950. description: The name of the Secret resource being referred to.
  22951. maxLength: 253
  22952. minLength: 1
  22953. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22954. type: string
  22955. namespace:
  22956. description: |-
  22957. The namespace of the Secret resource being referred to.
  22958. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22959. maxLength: 63
  22960. minLength: 1
  22961. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22962. type: string
  22963. type: object
  22964. secretAccessKeySecretRef:
  22965. description: The SecretAccessKey is used for authentication
  22966. properties:
  22967. key:
  22968. description: |-
  22969. A key in the referenced Secret.
  22970. Some instances of this field may be defaulted, in others it may be required.
  22971. maxLength: 253
  22972. minLength: 1
  22973. pattern: ^[-._a-zA-Z0-9]+$
  22974. type: string
  22975. name:
  22976. description: The name of the Secret resource being referred to.
  22977. maxLength: 253
  22978. minLength: 1
  22979. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22980. type: string
  22981. namespace:
  22982. description: |-
  22983. The namespace of the Secret resource being referred to.
  22984. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22985. maxLength: 63
  22986. minLength: 1
  22987. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22988. type: string
  22989. type: object
  22990. sessionTokenSecretRef:
  22991. description: |-
  22992. The SessionToken used for authentication
  22993. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  22994. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  22995. properties:
  22996. key:
  22997. description: |-
  22998. A key in the referenced Secret.
  22999. Some instances of this field may be defaulted, in others it may be required.
  23000. maxLength: 253
  23001. minLength: 1
  23002. pattern: ^[-._a-zA-Z0-9]+$
  23003. type: string
  23004. name:
  23005. description: The name of the Secret resource being referred to.
  23006. maxLength: 253
  23007. minLength: 1
  23008. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23009. type: string
  23010. namespace:
  23011. description: |-
  23012. The namespace of the Secret resource being referred to.
  23013. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23014. maxLength: 63
  23015. minLength: 1
  23016. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23017. type: string
  23018. type: object
  23019. type: object
  23020. type: object
  23021. externalID:
  23022. description: AWS External ID set on assumed IAM roles
  23023. type: string
  23024. prefix:
  23025. description: Prefix adds a prefix to all retrieved values.
  23026. type: string
  23027. region:
  23028. description: AWS Region to be used for the provider
  23029. type: string
  23030. role:
  23031. description: Role is a Role ARN which the provider will assume
  23032. type: string
  23033. secretsManager:
  23034. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  23035. properties:
  23036. forceDeleteWithoutRecovery:
  23037. description: |-
  23038. Specifies whether to delete the secret without any recovery window. You
  23039. can't use both this parameter and RecoveryWindowInDays in the same call.
  23040. If you don't use either, then by default Secrets Manager uses a 30 day
  23041. recovery window.
  23042. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  23043. type: boolean
  23044. recoveryWindowInDays:
  23045. description: |-
  23046. The number of days from 7 to 30 that Secrets Manager waits before
  23047. permanently deleting the secret. You can't use both this parameter and
  23048. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  23049. then by default Secrets Manager uses a 30 day recovery window.
  23050. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  23051. format: int64
  23052. type: integer
  23053. type: object
  23054. service:
  23055. description: Service defines which service should be used to fetch the secrets
  23056. enum:
  23057. - SecretsManager
  23058. - ParameterStore
  23059. type: string
  23060. sessionTags:
  23061. description: AWS STS assume role session tags
  23062. items:
  23063. description: Tag defines a tag key and value for AWS resources.
  23064. properties:
  23065. key:
  23066. type: string
  23067. value:
  23068. type: string
  23069. required:
  23070. - key
  23071. - value
  23072. type: object
  23073. type: array
  23074. transitiveTagKeys:
  23075. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  23076. items:
  23077. type: string
  23078. type: array
  23079. required:
  23080. - region
  23081. - service
  23082. type: object
  23083. azurekv:
  23084. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  23085. properties:
  23086. authSecretRef:
  23087. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  23088. properties:
  23089. clientCertificate:
  23090. description: The Azure ClientCertificate of the service principle used for authentication.
  23091. properties:
  23092. key:
  23093. description: |-
  23094. A key in the referenced Secret.
  23095. Some instances of this field may be defaulted, in others it may be required.
  23096. maxLength: 253
  23097. minLength: 1
  23098. pattern: ^[-._a-zA-Z0-9]+$
  23099. type: string
  23100. name:
  23101. description: The name of the Secret resource being referred to.
  23102. maxLength: 253
  23103. minLength: 1
  23104. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23105. type: string
  23106. namespace:
  23107. description: |-
  23108. The namespace of the Secret resource being referred to.
  23109. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23110. maxLength: 63
  23111. minLength: 1
  23112. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23113. type: string
  23114. type: object
  23115. clientId:
  23116. description: The Azure clientId of the service principle or managed identity used for authentication.
  23117. properties:
  23118. key:
  23119. description: |-
  23120. A key in the referenced Secret.
  23121. Some instances of this field may be defaulted, in others it may be required.
  23122. maxLength: 253
  23123. minLength: 1
  23124. pattern: ^[-._a-zA-Z0-9]+$
  23125. type: string
  23126. name:
  23127. description: The name of the Secret resource being referred to.
  23128. maxLength: 253
  23129. minLength: 1
  23130. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23131. type: string
  23132. namespace:
  23133. description: |-
  23134. The namespace of the Secret resource being referred to.
  23135. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23136. maxLength: 63
  23137. minLength: 1
  23138. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23139. type: string
  23140. type: object
  23141. clientSecret:
  23142. description: The Azure ClientSecret of the service principle used for authentication.
  23143. properties:
  23144. key:
  23145. description: |-
  23146. A key in the referenced Secret.
  23147. Some instances of this field may be defaulted, in others it may be required.
  23148. maxLength: 253
  23149. minLength: 1
  23150. pattern: ^[-._a-zA-Z0-9]+$
  23151. type: string
  23152. name:
  23153. description: The name of the Secret resource being referred to.
  23154. maxLength: 253
  23155. minLength: 1
  23156. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23157. type: string
  23158. namespace:
  23159. description: |-
  23160. The namespace of the Secret resource being referred to.
  23161. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23162. maxLength: 63
  23163. minLength: 1
  23164. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23165. type: string
  23166. type: object
  23167. tenantId:
  23168. description: The Azure tenantId of the managed identity used for authentication.
  23169. properties:
  23170. key:
  23171. description: |-
  23172. A key in the referenced Secret.
  23173. Some instances of this field may be defaulted, in others it may be required.
  23174. maxLength: 253
  23175. minLength: 1
  23176. pattern: ^[-._a-zA-Z0-9]+$
  23177. type: string
  23178. name:
  23179. description: The name of the Secret resource being referred to.
  23180. maxLength: 253
  23181. minLength: 1
  23182. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23183. type: string
  23184. namespace:
  23185. description: |-
  23186. The namespace of the Secret resource being referred to.
  23187. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23188. maxLength: 63
  23189. minLength: 1
  23190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23191. type: string
  23192. type: object
  23193. type: object
  23194. authType:
  23195. default: ServicePrincipal
  23196. description: |-
  23197. Auth type defines how to authenticate to the keyvault service.
  23198. Valid values are:
  23199. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  23200. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  23201. enum:
  23202. - ServicePrincipal
  23203. - ManagedIdentity
  23204. - WorkloadIdentity
  23205. type: string
  23206. environmentType:
  23207. default: PublicCloud
  23208. description: |-
  23209. EnvironmentType specifies the Azure cloud environment endpoints to use for
  23210. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  23211. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  23212. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  23213. enum:
  23214. - PublicCloud
  23215. - USGovernmentCloud
  23216. - ChinaCloud
  23217. - GermanCloud
  23218. type: string
  23219. identityId:
  23220. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  23221. type: string
  23222. serviceAccountRef:
  23223. description: |-
  23224. ServiceAccountRef specified the service account
  23225. that should be used when authenticating with WorkloadIdentity.
  23226. properties:
  23227. audiences:
  23228. description: |-
  23229. Audience specifies the `aud` claim for the service account token
  23230. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  23231. then this audiences will be appended to the list
  23232. items:
  23233. type: string
  23234. type: array
  23235. name:
  23236. description: The name of the ServiceAccount resource being referred to.
  23237. maxLength: 253
  23238. minLength: 1
  23239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23240. type: string
  23241. namespace:
  23242. description: |-
  23243. Namespace of the resource being referred to.
  23244. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23245. maxLength: 63
  23246. minLength: 1
  23247. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23248. type: string
  23249. required:
  23250. - name
  23251. type: object
  23252. tenantId:
  23253. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  23254. type: string
  23255. vaultUrl:
  23256. description: Vault Url from which the secrets to be fetched from.
  23257. type: string
  23258. required:
  23259. - vaultUrl
  23260. type: object
  23261. beyondtrust:
  23262. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  23263. properties:
  23264. auth:
  23265. description: Auth configures how the operator authenticates with Beyondtrust.
  23266. properties:
  23267. apiKey:
  23268. description: APIKey If not provided then ClientID/ClientSecret become required.
  23269. properties:
  23270. secretRef:
  23271. description: SecretRef references a key in a secret that will be used as value.
  23272. properties:
  23273. key:
  23274. description: |-
  23275. A key in the referenced Secret.
  23276. Some instances of this field may be defaulted, in others it may be required.
  23277. maxLength: 253
  23278. minLength: 1
  23279. pattern: ^[-._a-zA-Z0-9]+$
  23280. type: string
  23281. name:
  23282. description: The name of the Secret resource being referred to.
  23283. maxLength: 253
  23284. minLength: 1
  23285. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23286. type: string
  23287. namespace:
  23288. description: |-
  23289. The namespace of the Secret resource being referred to.
  23290. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23291. maxLength: 63
  23292. minLength: 1
  23293. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23294. type: string
  23295. type: object
  23296. value:
  23297. description: Value can be specified directly to set a value without using a secret.
  23298. type: string
  23299. type: object
  23300. certificate:
  23301. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  23302. properties:
  23303. secretRef:
  23304. description: SecretRef references a key in a secret that will be used as value.
  23305. properties:
  23306. key:
  23307. description: |-
  23308. A key in the referenced Secret.
  23309. Some instances of this field may be defaulted, in others it may be required.
  23310. maxLength: 253
  23311. minLength: 1
  23312. pattern: ^[-._a-zA-Z0-9]+$
  23313. type: string
  23314. name:
  23315. description: The name of the Secret resource being referred to.
  23316. maxLength: 253
  23317. minLength: 1
  23318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23319. type: string
  23320. namespace:
  23321. description: |-
  23322. The namespace of the Secret resource being referred to.
  23323. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23324. maxLength: 63
  23325. minLength: 1
  23326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23327. type: string
  23328. type: object
  23329. value:
  23330. description: Value can be specified directly to set a value without using a secret.
  23331. type: string
  23332. type: object
  23333. certificateKey:
  23334. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  23335. properties:
  23336. secretRef:
  23337. description: SecretRef references a key in a secret that will be used as value.
  23338. properties:
  23339. key:
  23340. description: |-
  23341. A key in the referenced Secret.
  23342. Some instances of this field may be defaulted, in others it may be required.
  23343. maxLength: 253
  23344. minLength: 1
  23345. pattern: ^[-._a-zA-Z0-9]+$
  23346. type: string
  23347. name:
  23348. description: The name of the Secret resource being referred to.
  23349. maxLength: 253
  23350. minLength: 1
  23351. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23352. type: string
  23353. namespace:
  23354. description: |-
  23355. The namespace of the Secret resource being referred to.
  23356. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23357. maxLength: 63
  23358. minLength: 1
  23359. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23360. type: string
  23361. type: object
  23362. value:
  23363. description: Value can be specified directly to set a value without using a secret.
  23364. type: string
  23365. type: object
  23366. clientId:
  23367. description: ClientID is the API OAuth Client ID.
  23368. properties:
  23369. secretRef:
  23370. description: SecretRef references a key in a secret that will be used as value.
  23371. properties:
  23372. key:
  23373. description: |-
  23374. A key in the referenced Secret.
  23375. Some instances of this field may be defaulted, in others it may be required.
  23376. maxLength: 253
  23377. minLength: 1
  23378. pattern: ^[-._a-zA-Z0-9]+$
  23379. type: string
  23380. name:
  23381. description: The name of the Secret resource being referred to.
  23382. maxLength: 253
  23383. minLength: 1
  23384. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23385. type: string
  23386. namespace:
  23387. description: |-
  23388. The namespace of the Secret resource being referred to.
  23389. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23390. maxLength: 63
  23391. minLength: 1
  23392. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23393. type: string
  23394. type: object
  23395. value:
  23396. description: Value can be specified directly to set a value without using a secret.
  23397. type: string
  23398. type: object
  23399. clientSecret:
  23400. description: ClientSecret is the API OAuth Client Secret.
  23401. properties:
  23402. secretRef:
  23403. description: SecretRef references a key in a secret that will be used as value.
  23404. properties:
  23405. key:
  23406. description: |-
  23407. A key in the referenced Secret.
  23408. Some instances of this field may be defaulted, in others it may be required.
  23409. maxLength: 253
  23410. minLength: 1
  23411. pattern: ^[-._a-zA-Z0-9]+$
  23412. type: string
  23413. name:
  23414. description: The name of the Secret resource being referred to.
  23415. maxLength: 253
  23416. minLength: 1
  23417. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23418. type: string
  23419. namespace:
  23420. description: |-
  23421. The namespace of the Secret resource being referred to.
  23422. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23423. maxLength: 63
  23424. minLength: 1
  23425. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23426. type: string
  23427. type: object
  23428. value:
  23429. description: Value can be specified directly to set a value without using a secret.
  23430. type: string
  23431. type: object
  23432. type: object
  23433. server:
  23434. description: Auth configures how API server works.
  23435. properties:
  23436. apiUrl:
  23437. type: string
  23438. apiVersion:
  23439. type: string
  23440. clientTimeOutSeconds:
  23441. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  23442. type: integer
  23443. decrypt:
  23444. default: true
  23445. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  23446. type: boolean
  23447. retrievalType:
  23448. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  23449. type: string
  23450. separator:
  23451. description: A character that separates the folder names.
  23452. type: string
  23453. verifyCA:
  23454. type: boolean
  23455. required:
  23456. - apiUrl
  23457. - verifyCA
  23458. type: object
  23459. required:
  23460. - auth
  23461. - server
  23462. type: object
  23463. bitwardensecretsmanager:
  23464. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  23465. properties:
  23466. apiURL:
  23467. type: string
  23468. auth:
  23469. description: |-
  23470. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  23471. Make sure that the token being used has permissions on the given secret.
  23472. properties:
  23473. secretRef:
  23474. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  23475. properties:
  23476. credentials:
  23477. description: AccessToken used for the bitwarden instance.
  23478. properties:
  23479. key:
  23480. description: |-
  23481. A key in the referenced Secret.
  23482. Some instances of this field may be defaulted, in others it may be required.
  23483. maxLength: 253
  23484. minLength: 1
  23485. pattern: ^[-._a-zA-Z0-9]+$
  23486. type: string
  23487. name:
  23488. description: The name of the Secret resource being referred to.
  23489. maxLength: 253
  23490. minLength: 1
  23491. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23492. type: string
  23493. namespace:
  23494. description: |-
  23495. The namespace of the Secret resource being referred to.
  23496. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23497. maxLength: 63
  23498. minLength: 1
  23499. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23500. type: string
  23501. type: object
  23502. required:
  23503. - credentials
  23504. type: object
  23505. required:
  23506. - secretRef
  23507. type: object
  23508. bitwardenServerSDKURL:
  23509. type: string
  23510. caBundle:
  23511. description: |-
  23512. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  23513. can be performed.
  23514. type: string
  23515. caProvider:
  23516. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  23517. properties:
  23518. key:
  23519. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23520. maxLength: 253
  23521. minLength: 1
  23522. pattern: ^[-._a-zA-Z0-9]+$
  23523. type: string
  23524. name:
  23525. description: The name of the object located at the provider type.
  23526. maxLength: 253
  23527. minLength: 1
  23528. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23529. type: string
  23530. namespace:
  23531. description: |-
  23532. The namespace the Provider type is in.
  23533. Can only be defined when used in a ClusterSecretStore.
  23534. maxLength: 63
  23535. minLength: 1
  23536. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23537. type: string
  23538. type:
  23539. description: The type of provider to use such as "Secret", or "ConfigMap".
  23540. enum:
  23541. - Secret
  23542. - ConfigMap
  23543. type: string
  23544. required:
  23545. - name
  23546. - type
  23547. type: object
  23548. identityURL:
  23549. type: string
  23550. organizationID:
  23551. description: OrganizationID determines which organization this secret store manages.
  23552. type: string
  23553. projectID:
  23554. description: ProjectID determines which project this secret store manages.
  23555. type: string
  23556. required:
  23557. - auth
  23558. - organizationID
  23559. - projectID
  23560. type: object
  23561. chef:
  23562. description: Chef configures this store to sync secrets with chef server
  23563. properties:
  23564. auth:
  23565. description: Auth defines the information necessary to authenticate against chef Server
  23566. properties:
  23567. secretRef:
  23568. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  23569. properties:
  23570. privateKeySecretRef:
  23571. description: SecretKey is the Signing Key in PEM format, used for authentication.
  23572. properties:
  23573. key:
  23574. description: |-
  23575. A key in the referenced Secret.
  23576. Some instances of this field may be defaulted, in others it may be required.
  23577. maxLength: 253
  23578. minLength: 1
  23579. pattern: ^[-._a-zA-Z0-9]+$
  23580. type: string
  23581. name:
  23582. description: The name of the Secret resource being referred to.
  23583. maxLength: 253
  23584. minLength: 1
  23585. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23586. type: string
  23587. namespace:
  23588. description: |-
  23589. The namespace of the Secret resource being referred to.
  23590. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23591. maxLength: 63
  23592. minLength: 1
  23593. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23594. type: string
  23595. type: object
  23596. required:
  23597. - privateKeySecretRef
  23598. type: object
  23599. required:
  23600. - secretRef
  23601. type: object
  23602. serverUrl:
  23603. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  23604. type: string
  23605. username:
  23606. description: UserName should be the user ID on the chef server
  23607. type: string
  23608. required:
  23609. - auth
  23610. - serverUrl
  23611. - username
  23612. type: object
  23613. cloudrusm:
  23614. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  23615. properties:
  23616. auth:
  23617. description: CSMAuth contains a secretRef for credentials.
  23618. properties:
  23619. secretRef:
  23620. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  23621. properties:
  23622. accessKeyIDSecretRef:
  23623. description: The AccessKeyID is used for authentication
  23624. properties:
  23625. key:
  23626. description: |-
  23627. A key in the referenced Secret.
  23628. Some instances of this field may be defaulted, in others it may be required.
  23629. maxLength: 253
  23630. minLength: 1
  23631. pattern: ^[-._a-zA-Z0-9]+$
  23632. type: string
  23633. name:
  23634. description: The name of the Secret resource being referred to.
  23635. maxLength: 253
  23636. minLength: 1
  23637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23638. type: string
  23639. namespace:
  23640. description: |-
  23641. The namespace of the Secret resource being referred to.
  23642. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23643. maxLength: 63
  23644. minLength: 1
  23645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23646. type: string
  23647. type: object
  23648. accessKeySecretSecretRef:
  23649. description: The AccessKeySecret is used for authentication
  23650. properties:
  23651. key:
  23652. description: |-
  23653. A key in the referenced Secret.
  23654. Some instances of this field may be defaulted, in others it may be required.
  23655. maxLength: 253
  23656. minLength: 1
  23657. pattern: ^[-._a-zA-Z0-9]+$
  23658. type: string
  23659. name:
  23660. description: The name of the Secret resource being referred to.
  23661. maxLength: 253
  23662. minLength: 1
  23663. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23664. type: string
  23665. namespace:
  23666. description: |-
  23667. The namespace of the Secret resource being referred to.
  23668. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23669. maxLength: 63
  23670. minLength: 1
  23671. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23672. type: string
  23673. type: object
  23674. required:
  23675. - accessKeyIDSecretRef
  23676. - accessKeySecretSecretRef
  23677. type: object
  23678. type: object
  23679. projectID:
  23680. description: ProjectID is the project, which the secrets are stored in.
  23681. type: string
  23682. required:
  23683. - auth
  23684. type: object
  23685. conjur:
  23686. description: Conjur configures this store to sync secrets using conjur provider
  23687. properties:
  23688. auth:
  23689. description: Defines authentication settings for connecting to Conjur.
  23690. properties:
  23691. apikey:
  23692. description: Authenticates with Conjur using an API key.
  23693. properties:
  23694. account:
  23695. description: Account is the Conjur organization account name.
  23696. type: string
  23697. apiKeyRef:
  23698. description: |-
  23699. A reference to a specific 'key' containing the Conjur API key
  23700. within a Secret resource. In some instances, `key` is a required field.
  23701. properties:
  23702. key:
  23703. description: |-
  23704. A key in the referenced Secret.
  23705. Some instances of this field may be defaulted, in others it may be required.
  23706. maxLength: 253
  23707. minLength: 1
  23708. pattern: ^[-._a-zA-Z0-9]+$
  23709. type: string
  23710. name:
  23711. description: The name of the Secret resource being referred to.
  23712. maxLength: 253
  23713. minLength: 1
  23714. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23715. type: string
  23716. namespace:
  23717. description: |-
  23718. The namespace of the Secret resource being referred to.
  23719. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23720. maxLength: 63
  23721. minLength: 1
  23722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23723. type: string
  23724. type: object
  23725. userRef:
  23726. description: |-
  23727. A reference to a specific 'key' containing the Conjur username
  23728. within a Secret resource. In some instances, `key` is a required field.
  23729. properties:
  23730. key:
  23731. description: |-
  23732. A key in the referenced Secret.
  23733. Some instances of this field may be defaulted, in others it may be required.
  23734. maxLength: 253
  23735. minLength: 1
  23736. pattern: ^[-._a-zA-Z0-9]+$
  23737. type: string
  23738. name:
  23739. description: The name of the Secret resource being referred to.
  23740. maxLength: 253
  23741. minLength: 1
  23742. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23743. type: string
  23744. namespace:
  23745. description: |-
  23746. The namespace of the Secret resource being referred to.
  23747. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23748. maxLength: 63
  23749. minLength: 1
  23750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23751. type: string
  23752. type: object
  23753. required:
  23754. - account
  23755. - apiKeyRef
  23756. - userRef
  23757. type: object
  23758. jwt:
  23759. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  23760. properties:
  23761. account:
  23762. description: Account is the Conjur organization account name.
  23763. type: string
  23764. hostId:
  23765. description: |-
  23766. Optional HostID for JWT authentication. This may be used depending
  23767. on how the Conjur JWT authenticator policy is configured.
  23768. type: string
  23769. secretRef:
  23770. description: |-
  23771. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  23772. authenticate with Conjur using the JWT authentication method.
  23773. properties:
  23774. key:
  23775. description: |-
  23776. A key in the referenced Secret.
  23777. Some instances of this field may be defaulted, in others it may be required.
  23778. maxLength: 253
  23779. minLength: 1
  23780. pattern: ^[-._a-zA-Z0-9]+$
  23781. type: string
  23782. name:
  23783. description: The name of the Secret resource being referred to.
  23784. maxLength: 253
  23785. minLength: 1
  23786. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23787. type: string
  23788. namespace:
  23789. description: |-
  23790. The namespace of the Secret resource being referred to.
  23791. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23792. maxLength: 63
  23793. minLength: 1
  23794. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23795. type: string
  23796. type: object
  23797. serviceAccountRef:
  23798. description: |-
  23799. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  23800. a token for with the `TokenRequest` API.
  23801. properties:
  23802. audiences:
  23803. description: |-
  23804. Audience specifies the `aud` claim for the service account token
  23805. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  23806. then this audiences will be appended to the list
  23807. items:
  23808. type: string
  23809. type: array
  23810. name:
  23811. description: The name of the ServiceAccount resource being referred to.
  23812. maxLength: 253
  23813. minLength: 1
  23814. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23815. type: string
  23816. namespace:
  23817. description: |-
  23818. Namespace of the resource being referred to.
  23819. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23820. maxLength: 63
  23821. minLength: 1
  23822. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23823. type: string
  23824. required:
  23825. - name
  23826. type: object
  23827. serviceID:
  23828. description: The conjur authn jwt webservice id
  23829. type: string
  23830. required:
  23831. - account
  23832. - serviceID
  23833. type: object
  23834. type: object
  23835. caBundle:
  23836. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  23837. type: string
  23838. caProvider:
  23839. description: |-
  23840. Used to provide custom certificate authority (CA) certificates
  23841. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  23842. that contains a PEM-encoded certificate.
  23843. properties:
  23844. key:
  23845. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23846. maxLength: 253
  23847. minLength: 1
  23848. pattern: ^[-._a-zA-Z0-9]+$
  23849. type: string
  23850. name:
  23851. description: The name of the object located at the provider type.
  23852. maxLength: 253
  23853. minLength: 1
  23854. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23855. type: string
  23856. namespace:
  23857. description: |-
  23858. The namespace the Provider type is in.
  23859. Can only be defined when used in a ClusterSecretStore.
  23860. maxLength: 63
  23861. minLength: 1
  23862. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23863. type: string
  23864. type:
  23865. description: The type of provider to use such as "Secret", or "ConfigMap".
  23866. enum:
  23867. - Secret
  23868. - ConfigMap
  23869. type: string
  23870. required:
  23871. - name
  23872. - type
  23873. type: object
  23874. url:
  23875. description: URL is the endpoint of the Conjur instance.
  23876. type: string
  23877. required:
  23878. - auth
  23879. - url
  23880. type: object
  23881. delinea:
  23882. description: |-
  23883. Delinea DevOps Secrets Vault
  23884. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  23885. properties:
  23886. clientId:
  23887. description: ClientID is the non-secret part of the credential.
  23888. properties:
  23889. secretRef:
  23890. description: SecretRef references a key in a secret that will be used as value.
  23891. properties:
  23892. key:
  23893. description: |-
  23894. A key in the referenced Secret.
  23895. Some instances of this field may be defaulted, in others it may be required.
  23896. maxLength: 253
  23897. minLength: 1
  23898. pattern: ^[-._a-zA-Z0-9]+$
  23899. type: string
  23900. name:
  23901. description: The name of the Secret resource being referred to.
  23902. maxLength: 253
  23903. minLength: 1
  23904. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23905. type: string
  23906. namespace:
  23907. description: |-
  23908. The namespace of the Secret resource being referred to.
  23909. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23910. maxLength: 63
  23911. minLength: 1
  23912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23913. type: string
  23914. type: object
  23915. value:
  23916. description: Value can be specified directly to set a value without using a secret.
  23917. type: string
  23918. type: object
  23919. clientSecret:
  23920. description: ClientSecret is the secret part of the credential.
  23921. properties:
  23922. secretRef:
  23923. description: SecretRef references a key in a secret that will be used as value.
  23924. properties:
  23925. key:
  23926. description: |-
  23927. A key in the referenced Secret.
  23928. Some instances of this field may be defaulted, in others it may be required.
  23929. maxLength: 253
  23930. minLength: 1
  23931. pattern: ^[-._a-zA-Z0-9]+$
  23932. type: string
  23933. name:
  23934. description: The name of the Secret resource being referred to.
  23935. maxLength: 253
  23936. minLength: 1
  23937. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23938. type: string
  23939. namespace:
  23940. description: |-
  23941. The namespace of the Secret resource being referred to.
  23942. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23943. maxLength: 63
  23944. minLength: 1
  23945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23946. type: string
  23947. type: object
  23948. value:
  23949. description: Value can be specified directly to set a value without using a secret.
  23950. type: string
  23951. type: object
  23952. tenant:
  23953. description: Tenant is the chosen hostname / site name.
  23954. type: string
  23955. tld:
  23956. description: |-
  23957. TLD is based on the server location that was chosen during provisioning.
  23958. If unset, defaults to "com".
  23959. type: string
  23960. urlTemplate:
  23961. description: |-
  23962. URLTemplate
  23963. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  23964. type: string
  23965. required:
  23966. - clientId
  23967. - clientSecret
  23968. - tenant
  23969. type: object
  23970. device42:
  23971. description: Device42 configures this store to sync secrets using the Device42 provider
  23972. properties:
  23973. auth:
  23974. description: Auth configures how secret-manager authenticates with a Device42 instance.
  23975. properties:
  23976. secretRef:
  23977. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  23978. properties:
  23979. credentials:
  23980. description: Username / Password is used for authentication.
  23981. properties:
  23982. key:
  23983. description: |-
  23984. A key in the referenced Secret.
  23985. Some instances of this field may be defaulted, in others it may be required.
  23986. maxLength: 253
  23987. minLength: 1
  23988. pattern: ^[-._a-zA-Z0-9]+$
  23989. type: string
  23990. name:
  23991. description: The name of the Secret resource being referred to.
  23992. maxLength: 253
  23993. minLength: 1
  23994. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23995. type: string
  23996. namespace:
  23997. description: |-
  23998. The namespace of the Secret resource being referred to.
  23999. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24000. maxLength: 63
  24001. minLength: 1
  24002. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24003. type: string
  24004. type: object
  24005. type: object
  24006. required:
  24007. - secretRef
  24008. type: object
  24009. host:
  24010. description: URL configures the Device42 instance URL.
  24011. type: string
  24012. required:
  24013. - auth
  24014. - host
  24015. type: object
  24016. doppler:
  24017. description: Doppler configures this store to sync secrets using the Doppler provider
  24018. properties:
  24019. auth:
  24020. description: Auth configures how the Operator authenticates with the Doppler API
  24021. properties:
  24022. secretRef:
  24023. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  24024. properties:
  24025. dopplerToken:
  24026. description: |-
  24027. The DopplerToken is used for authentication.
  24028. See https://docs.doppler.com/reference/api#authentication for auth token types.
  24029. The Key attribute defaults to dopplerToken if not specified.
  24030. properties:
  24031. key:
  24032. description: |-
  24033. A key in the referenced Secret.
  24034. Some instances of this field may be defaulted, in others it may be required.
  24035. maxLength: 253
  24036. minLength: 1
  24037. pattern: ^[-._a-zA-Z0-9]+$
  24038. type: string
  24039. name:
  24040. description: The name of the Secret resource being referred to.
  24041. maxLength: 253
  24042. minLength: 1
  24043. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24044. type: string
  24045. namespace:
  24046. description: |-
  24047. The namespace of the Secret resource being referred to.
  24048. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24049. maxLength: 63
  24050. minLength: 1
  24051. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24052. type: string
  24053. type: object
  24054. required:
  24055. - dopplerToken
  24056. type: object
  24057. required:
  24058. - secretRef
  24059. type: object
  24060. config:
  24061. description: Doppler config (required if not using a Service Token)
  24062. type: string
  24063. format:
  24064. description: Format enables the downloading of secrets as a file (string)
  24065. enum:
  24066. - json
  24067. - dotnet-json
  24068. - env
  24069. - yaml
  24070. - docker
  24071. type: string
  24072. nameTransformer:
  24073. description: Environment variable compatible name transforms that change secret names to a different format
  24074. enum:
  24075. - upper-camel
  24076. - camel
  24077. - lower-snake
  24078. - tf-var
  24079. - dotnet-env
  24080. - lower-kebab
  24081. type: string
  24082. project:
  24083. description: Doppler project (required if not using a Service Token)
  24084. type: string
  24085. required:
  24086. - auth
  24087. type: object
  24088. fake:
  24089. description: Fake configures a store with static key/value pairs
  24090. properties:
  24091. data:
  24092. items:
  24093. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  24094. properties:
  24095. key:
  24096. type: string
  24097. value:
  24098. type: string
  24099. version:
  24100. type: string
  24101. required:
  24102. - key
  24103. - value
  24104. type: object
  24105. type: array
  24106. required:
  24107. - data
  24108. type: object
  24109. fortanix:
  24110. description: Fortanix configures this store to sync secrets using the Fortanix provider
  24111. properties:
  24112. apiKey:
  24113. description: APIKey is the API token to access SDKMS Applications.
  24114. properties:
  24115. secretRef:
  24116. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  24117. properties:
  24118. key:
  24119. description: |-
  24120. A key in the referenced Secret.
  24121. Some instances of this field may be defaulted, in others it may be required.
  24122. maxLength: 253
  24123. minLength: 1
  24124. pattern: ^[-._a-zA-Z0-9]+$
  24125. type: string
  24126. name:
  24127. description: The name of the Secret resource being referred to.
  24128. maxLength: 253
  24129. minLength: 1
  24130. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24131. type: string
  24132. namespace:
  24133. description: |-
  24134. The namespace of the Secret resource being referred to.
  24135. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24136. maxLength: 63
  24137. minLength: 1
  24138. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24139. type: string
  24140. type: object
  24141. type: object
  24142. apiUrl:
  24143. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  24144. type: string
  24145. type: object
  24146. gcpsm:
  24147. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  24148. properties:
  24149. auth:
  24150. description: Auth defines the information necessary to authenticate against GCP
  24151. properties:
  24152. secretRef:
  24153. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  24154. properties:
  24155. secretAccessKeySecretRef:
  24156. description: The SecretAccessKey is used for authentication
  24157. properties:
  24158. key:
  24159. description: |-
  24160. A key in the referenced Secret.
  24161. Some instances of this field may be defaulted, in others it may be required.
  24162. maxLength: 253
  24163. minLength: 1
  24164. pattern: ^[-._a-zA-Z0-9]+$
  24165. type: string
  24166. name:
  24167. description: The name of the Secret resource being referred to.
  24168. maxLength: 253
  24169. minLength: 1
  24170. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24171. type: string
  24172. namespace:
  24173. description: |-
  24174. The namespace of the Secret resource being referred to.
  24175. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24176. maxLength: 63
  24177. minLength: 1
  24178. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24179. type: string
  24180. type: object
  24181. type: object
  24182. workloadIdentity:
  24183. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  24184. properties:
  24185. clusterLocation:
  24186. description: |-
  24187. ClusterLocation is the location of the cluster
  24188. If not specified, it fetches information from the metadata server
  24189. type: string
  24190. clusterName:
  24191. description: |-
  24192. ClusterName is the name of the cluster
  24193. If not specified, it fetches information from the metadata server
  24194. type: string
  24195. clusterProjectID:
  24196. description: |-
  24197. ClusterProjectID is the project ID of the cluster
  24198. If not specified, it fetches information from the metadata server
  24199. type: string
  24200. serviceAccountRef:
  24201. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  24202. properties:
  24203. audiences:
  24204. description: |-
  24205. Audience specifies the `aud` claim for the service account token
  24206. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  24207. then this audiences will be appended to the list
  24208. items:
  24209. type: string
  24210. type: array
  24211. name:
  24212. description: The name of the ServiceAccount resource being referred to.
  24213. maxLength: 253
  24214. minLength: 1
  24215. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24216. type: string
  24217. namespace:
  24218. description: |-
  24219. Namespace of the resource being referred to.
  24220. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24221. maxLength: 63
  24222. minLength: 1
  24223. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24224. type: string
  24225. required:
  24226. - name
  24227. type: object
  24228. required:
  24229. - serviceAccountRef
  24230. type: object
  24231. type: object
  24232. location:
  24233. description: Location optionally defines a location for a secret
  24234. type: string
  24235. projectID:
  24236. description: ProjectID project where secret is located
  24237. type: string
  24238. type: object
  24239. github:
  24240. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  24241. properties:
  24242. appID:
  24243. description: appID specifies the Github APP that will be used to authenticate the client
  24244. format: int64
  24245. type: integer
  24246. auth:
  24247. description: auth configures how secret-manager authenticates with a Github instance.
  24248. properties:
  24249. privateKey:
  24250. description: |-
  24251. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24252. In some instances, `key` is a required field.
  24253. properties:
  24254. key:
  24255. description: |-
  24256. A key in the referenced Secret.
  24257. Some instances of this field may be defaulted, in others it may be required.
  24258. maxLength: 253
  24259. minLength: 1
  24260. pattern: ^[-._a-zA-Z0-9]+$
  24261. type: string
  24262. name:
  24263. description: The name of the Secret resource being referred to.
  24264. maxLength: 253
  24265. minLength: 1
  24266. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24267. type: string
  24268. namespace:
  24269. description: |-
  24270. The namespace of the Secret resource being referred to.
  24271. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24272. maxLength: 63
  24273. minLength: 1
  24274. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24275. type: string
  24276. type: object
  24277. required:
  24278. - privateKey
  24279. type: object
  24280. environment:
  24281. description: environment will be used to fetch secrets from a particular environment within a github repository
  24282. type: string
  24283. installationID:
  24284. description: installationID specifies the Github APP installation that will be used to authenticate the client
  24285. format: int64
  24286. type: integer
  24287. organization:
  24288. description: organization will be used to fetch secrets from the Github organization
  24289. type: string
  24290. repository:
  24291. description: repository will be used to fetch secrets from the Github repository within an organization
  24292. type: string
  24293. uploadURL:
  24294. description: Upload URL for enterprise instances. Default to URL.
  24295. type: string
  24296. url:
  24297. default: https://github.com/
  24298. description: URL configures the Github instance URL. Defaults to https://github.com/.
  24299. type: string
  24300. required:
  24301. - appID
  24302. - auth
  24303. - installationID
  24304. - organization
  24305. type: object
  24306. gitlab:
  24307. description: GitLab configures this store to sync secrets using GitLab Variables provider
  24308. properties:
  24309. auth:
  24310. description: Auth configures how secret-manager authenticates with a GitLab instance.
  24311. properties:
  24312. SecretRef:
  24313. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  24314. properties:
  24315. accessToken:
  24316. description: AccessToken is used for authentication.
  24317. properties:
  24318. key:
  24319. description: |-
  24320. A key in the referenced Secret.
  24321. Some instances of this field may be defaulted, in others it may be required.
  24322. maxLength: 253
  24323. minLength: 1
  24324. pattern: ^[-._a-zA-Z0-9]+$
  24325. type: string
  24326. name:
  24327. description: The name of the Secret resource being referred to.
  24328. maxLength: 253
  24329. minLength: 1
  24330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24331. type: string
  24332. namespace:
  24333. description: |-
  24334. The namespace of the Secret resource being referred to.
  24335. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24336. maxLength: 63
  24337. minLength: 1
  24338. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24339. type: string
  24340. type: object
  24341. type: object
  24342. required:
  24343. - SecretRef
  24344. type: object
  24345. caBundle:
  24346. description: |-
  24347. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  24348. can be performed.
  24349. format: byte
  24350. type: string
  24351. caProvider:
  24352. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  24353. properties:
  24354. key:
  24355. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24356. maxLength: 253
  24357. minLength: 1
  24358. pattern: ^[-._a-zA-Z0-9]+$
  24359. type: string
  24360. name:
  24361. description: The name of the object located at the provider type.
  24362. maxLength: 253
  24363. minLength: 1
  24364. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24365. type: string
  24366. namespace:
  24367. description: |-
  24368. The namespace the Provider type is in.
  24369. Can only be defined when used in a ClusterSecretStore.
  24370. maxLength: 63
  24371. minLength: 1
  24372. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24373. type: string
  24374. type:
  24375. description: The type of provider to use such as "Secret", or "ConfigMap".
  24376. enum:
  24377. - Secret
  24378. - ConfigMap
  24379. type: string
  24380. required:
  24381. - name
  24382. - type
  24383. type: object
  24384. environment:
  24385. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  24386. type: string
  24387. groupIDs:
  24388. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  24389. items:
  24390. type: string
  24391. type: array
  24392. inheritFromGroups:
  24393. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  24394. type: boolean
  24395. projectID:
  24396. description: ProjectID specifies a project where secrets are located.
  24397. type: string
  24398. url:
  24399. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  24400. type: string
  24401. required:
  24402. - auth
  24403. type: object
  24404. ibm:
  24405. description: IBM configures this store to sync secrets using IBM Cloud provider
  24406. properties:
  24407. auth:
  24408. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  24409. maxProperties: 1
  24410. minProperties: 1
  24411. properties:
  24412. containerAuth:
  24413. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  24414. properties:
  24415. iamEndpoint:
  24416. type: string
  24417. profile:
  24418. description: the IBM Trusted Profile
  24419. type: string
  24420. tokenLocation:
  24421. description: Location the token is mounted on the pod
  24422. type: string
  24423. required:
  24424. - profile
  24425. type: object
  24426. secretRef:
  24427. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  24428. properties:
  24429. secretApiKeySecretRef:
  24430. description: The SecretAccessKey is used for authentication
  24431. properties:
  24432. key:
  24433. description: |-
  24434. A key in the referenced Secret.
  24435. Some instances of this field may be defaulted, in others it may be required.
  24436. maxLength: 253
  24437. minLength: 1
  24438. pattern: ^[-._a-zA-Z0-9]+$
  24439. type: string
  24440. name:
  24441. description: The name of the Secret resource being referred to.
  24442. maxLength: 253
  24443. minLength: 1
  24444. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24445. type: string
  24446. namespace:
  24447. description: |-
  24448. The namespace of the Secret resource being referred to.
  24449. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24450. maxLength: 63
  24451. minLength: 1
  24452. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24453. type: string
  24454. type: object
  24455. type: object
  24456. type: object
  24457. serviceUrl:
  24458. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  24459. type: string
  24460. required:
  24461. - auth
  24462. type: object
  24463. infisical:
  24464. description: Infisical configures this store to sync secrets using the Infisical provider
  24465. properties:
  24466. auth:
  24467. description: Auth configures how the Operator authenticates with the Infisical API
  24468. properties:
  24469. universalAuthCredentials:
  24470. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  24471. properties:
  24472. clientId:
  24473. description: |-
  24474. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24475. In some instances, `key` is a required field.
  24476. properties:
  24477. key:
  24478. description: |-
  24479. A key in the referenced Secret.
  24480. Some instances of this field may be defaulted, in others it may be required.
  24481. maxLength: 253
  24482. minLength: 1
  24483. pattern: ^[-._a-zA-Z0-9]+$
  24484. type: string
  24485. name:
  24486. description: The name of the Secret resource being referred to.
  24487. maxLength: 253
  24488. minLength: 1
  24489. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24490. type: string
  24491. namespace:
  24492. description: |-
  24493. The namespace of the Secret resource being referred to.
  24494. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24495. maxLength: 63
  24496. minLength: 1
  24497. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24498. type: string
  24499. type: object
  24500. clientSecret:
  24501. description: |-
  24502. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24503. In some instances, `key` is a required field.
  24504. properties:
  24505. key:
  24506. description: |-
  24507. A key in the referenced Secret.
  24508. Some instances of this field may be defaulted, in others it may be required.
  24509. maxLength: 253
  24510. minLength: 1
  24511. pattern: ^[-._a-zA-Z0-9]+$
  24512. type: string
  24513. name:
  24514. description: The name of the Secret resource being referred to.
  24515. maxLength: 253
  24516. minLength: 1
  24517. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24518. type: string
  24519. namespace:
  24520. description: |-
  24521. The namespace of the Secret resource being referred to.
  24522. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24523. maxLength: 63
  24524. minLength: 1
  24525. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24526. type: string
  24527. type: object
  24528. required:
  24529. - clientId
  24530. - clientSecret
  24531. type: object
  24532. type: object
  24533. hostAPI:
  24534. default: https://app.infisical.com/api
  24535. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  24536. type: string
  24537. secretsScope:
  24538. description: SecretsScope defines the scope of the secrets within the workspace
  24539. properties:
  24540. environmentSlug:
  24541. description: EnvironmentSlug is the required slug identifier for the environment.
  24542. type: string
  24543. expandSecretReferences:
  24544. default: true
  24545. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  24546. type: boolean
  24547. projectSlug:
  24548. description: ProjectSlug is the required slug identifier for the project.
  24549. type: string
  24550. recursive:
  24551. default: false
  24552. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  24553. type: boolean
  24554. secretsPath:
  24555. default: /
  24556. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  24557. type: string
  24558. required:
  24559. - environmentSlug
  24560. - projectSlug
  24561. type: object
  24562. required:
  24563. - auth
  24564. - secretsScope
  24565. type: object
  24566. keepersecurity:
  24567. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  24568. properties:
  24569. authRef:
  24570. description: |-
  24571. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24572. In some instances, `key` is a required field.
  24573. properties:
  24574. key:
  24575. description: |-
  24576. A key in the referenced Secret.
  24577. Some instances of this field may be defaulted, in others it may be required.
  24578. maxLength: 253
  24579. minLength: 1
  24580. pattern: ^[-._a-zA-Z0-9]+$
  24581. type: string
  24582. name:
  24583. description: The name of the Secret resource being referred to.
  24584. maxLength: 253
  24585. minLength: 1
  24586. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24587. type: string
  24588. namespace:
  24589. description: |-
  24590. The namespace of the Secret resource being referred to.
  24591. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24592. maxLength: 63
  24593. minLength: 1
  24594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24595. type: string
  24596. type: object
  24597. folderID:
  24598. type: string
  24599. required:
  24600. - authRef
  24601. - folderID
  24602. type: object
  24603. kubernetes:
  24604. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  24605. properties:
  24606. auth:
  24607. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  24608. maxProperties: 1
  24609. minProperties: 1
  24610. properties:
  24611. cert:
  24612. description: has both clientCert and clientKey as secretKeySelector
  24613. properties:
  24614. clientCert:
  24615. description: |-
  24616. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24617. In some instances, `key` is a required field.
  24618. properties:
  24619. key:
  24620. description: |-
  24621. A key in the referenced Secret.
  24622. Some instances of this field may be defaulted, in others it may be required.
  24623. maxLength: 253
  24624. minLength: 1
  24625. pattern: ^[-._a-zA-Z0-9]+$
  24626. type: string
  24627. name:
  24628. description: The name of the Secret resource being referred to.
  24629. maxLength: 253
  24630. minLength: 1
  24631. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24632. type: string
  24633. namespace:
  24634. description: |-
  24635. The namespace of the Secret resource being referred to.
  24636. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24637. maxLength: 63
  24638. minLength: 1
  24639. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24640. type: string
  24641. type: object
  24642. clientKey:
  24643. description: |-
  24644. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24645. In some instances, `key` is a required field.
  24646. properties:
  24647. key:
  24648. description: |-
  24649. A key in the referenced Secret.
  24650. Some instances of this field may be defaulted, in others it may be required.
  24651. maxLength: 253
  24652. minLength: 1
  24653. pattern: ^[-._a-zA-Z0-9]+$
  24654. type: string
  24655. name:
  24656. description: The name of the Secret resource being referred to.
  24657. maxLength: 253
  24658. minLength: 1
  24659. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24660. type: string
  24661. namespace:
  24662. description: |-
  24663. The namespace of the Secret resource being referred to.
  24664. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24665. maxLength: 63
  24666. minLength: 1
  24667. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24668. type: string
  24669. type: object
  24670. type: object
  24671. serviceAccount:
  24672. description: points to a service account that should be used for authentication
  24673. properties:
  24674. audiences:
  24675. description: |-
  24676. Audience specifies the `aud` claim for the service account token
  24677. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  24678. then this audiences will be appended to the list
  24679. items:
  24680. type: string
  24681. type: array
  24682. name:
  24683. description: The name of the ServiceAccount resource being referred to.
  24684. maxLength: 253
  24685. minLength: 1
  24686. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24687. type: string
  24688. namespace:
  24689. description: |-
  24690. Namespace of the resource being referred to.
  24691. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24692. maxLength: 63
  24693. minLength: 1
  24694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24695. type: string
  24696. required:
  24697. - name
  24698. type: object
  24699. token:
  24700. description: use static token to authenticate with
  24701. properties:
  24702. bearerToken:
  24703. description: |-
  24704. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24705. In some instances, `key` is a required field.
  24706. properties:
  24707. key:
  24708. description: |-
  24709. A key in the referenced Secret.
  24710. Some instances of this field may be defaulted, in others it may be required.
  24711. maxLength: 253
  24712. minLength: 1
  24713. pattern: ^[-._a-zA-Z0-9]+$
  24714. type: string
  24715. name:
  24716. description: The name of the Secret resource being referred to.
  24717. maxLength: 253
  24718. minLength: 1
  24719. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24720. type: string
  24721. namespace:
  24722. description: |-
  24723. The namespace of the Secret resource being referred to.
  24724. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24725. maxLength: 63
  24726. minLength: 1
  24727. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24728. type: string
  24729. type: object
  24730. type: object
  24731. type: object
  24732. authRef:
  24733. description: A reference to a secret that contains the auth information.
  24734. properties:
  24735. key:
  24736. description: |-
  24737. A key in the referenced Secret.
  24738. Some instances of this field may be defaulted, in others it may be required.
  24739. maxLength: 253
  24740. minLength: 1
  24741. pattern: ^[-._a-zA-Z0-9]+$
  24742. type: string
  24743. name:
  24744. description: The name of the Secret resource being referred to.
  24745. maxLength: 253
  24746. minLength: 1
  24747. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24748. type: string
  24749. namespace:
  24750. description: |-
  24751. The namespace of the Secret resource being referred to.
  24752. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24753. maxLength: 63
  24754. minLength: 1
  24755. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24756. type: string
  24757. type: object
  24758. remoteNamespace:
  24759. default: default
  24760. description: Remote namespace to fetch the secrets from
  24761. maxLength: 63
  24762. minLength: 1
  24763. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24764. type: string
  24765. server:
  24766. description: configures the Kubernetes server Address.
  24767. properties:
  24768. caBundle:
  24769. description: CABundle is a base64-encoded CA certificate
  24770. format: byte
  24771. type: string
  24772. caProvider:
  24773. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  24774. properties:
  24775. key:
  24776. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24777. maxLength: 253
  24778. minLength: 1
  24779. pattern: ^[-._a-zA-Z0-9]+$
  24780. type: string
  24781. name:
  24782. description: The name of the object located at the provider type.
  24783. maxLength: 253
  24784. minLength: 1
  24785. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24786. type: string
  24787. namespace:
  24788. description: |-
  24789. The namespace the Provider type is in.
  24790. Can only be defined when used in a ClusterSecretStore.
  24791. maxLength: 63
  24792. minLength: 1
  24793. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24794. type: string
  24795. type:
  24796. description: The type of provider to use such as "Secret", or "ConfigMap".
  24797. enum:
  24798. - Secret
  24799. - ConfigMap
  24800. type: string
  24801. required:
  24802. - name
  24803. - type
  24804. type: object
  24805. url:
  24806. default: kubernetes.default
  24807. description: configures the Kubernetes server Address.
  24808. type: string
  24809. type: object
  24810. type: object
  24811. onboardbase:
  24812. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  24813. properties:
  24814. apiHost:
  24815. default: https://public.onboardbase.com/api/v1/
  24816. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  24817. type: string
  24818. auth:
  24819. description: Auth configures how the Operator authenticates with the Onboardbase API
  24820. properties:
  24821. apiKeyRef:
  24822. description: |-
  24823. OnboardbaseAPIKey is the APIKey generated by an admin account.
  24824. It is used to recognize and authorize access to a project and environment within onboardbase
  24825. properties:
  24826. key:
  24827. description: |-
  24828. A key in the referenced Secret.
  24829. Some instances of this field may be defaulted, in others it may be required.
  24830. maxLength: 253
  24831. minLength: 1
  24832. pattern: ^[-._a-zA-Z0-9]+$
  24833. type: string
  24834. name:
  24835. description: The name of the Secret resource being referred to.
  24836. maxLength: 253
  24837. minLength: 1
  24838. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24839. type: string
  24840. namespace:
  24841. description: |-
  24842. The namespace of the Secret resource being referred to.
  24843. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24844. maxLength: 63
  24845. minLength: 1
  24846. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24847. type: string
  24848. type: object
  24849. passcodeRef:
  24850. description: OnboardbasePasscode is the passcode attached to the API Key
  24851. properties:
  24852. key:
  24853. description: |-
  24854. A key in the referenced Secret.
  24855. Some instances of this field may be defaulted, in others it may be required.
  24856. maxLength: 253
  24857. minLength: 1
  24858. pattern: ^[-._a-zA-Z0-9]+$
  24859. type: string
  24860. name:
  24861. description: The name of the Secret resource being referred to.
  24862. maxLength: 253
  24863. minLength: 1
  24864. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24865. type: string
  24866. namespace:
  24867. description: |-
  24868. The namespace of the Secret resource being referred to.
  24869. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24870. maxLength: 63
  24871. minLength: 1
  24872. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24873. type: string
  24874. type: object
  24875. required:
  24876. - apiKeyRef
  24877. - passcodeRef
  24878. type: object
  24879. environment:
  24880. default: development
  24881. description: Environment is the name of an environmnent within a project to pull the secrets from
  24882. type: string
  24883. project:
  24884. default: development
  24885. description: Project is an onboardbase project that the secrets should be pulled from
  24886. type: string
  24887. required:
  24888. - apiHost
  24889. - auth
  24890. - environment
  24891. - project
  24892. type: object
  24893. onepassword:
  24894. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  24895. properties:
  24896. auth:
  24897. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  24898. properties:
  24899. secretRef:
  24900. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  24901. properties:
  24902. connectTokenSecretRef:
  24903. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  24904. properties:
  24905. key:
  24906. description: |-
  24907. A key in the referenced Secret.
  24908. Some instances of this field may be defaulted, in others it may be required.
  24909. maxLength: 253
  24910. minLength: 1
  24911. pattern: ^[-._a-zA-Z0-9]+$
  24912. type: string
  24913. name:
  24914. description: The name of the Secret resource being referred to.
  24915. maxLength: 253
  24916. minLength: 1
  24917. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24918. type: string
  24919. namespace:
  24920. description: |-
  24921. The namespace of the Secret resource being referred to.
  24922. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24923. maxLength: 63
  24924. minLength: 1
  24925. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24926. type: string
  24927. type: object
  24928. required:
  24929. - connectTokenSecretRef
  24930. type: object
  24931. required:
  24932. - secretRef
  24933. type: object
  24934. connectHost:
  24935. description: ConnectHost defines the OnePassword Connect Server to connect to
  24936. type: string
  24937. vaults:
  24938. additionalProperties:
  24939. type: integer
  24940. description: Vaults defines which OnePassword vaults to search in which order
  24941. type: object
  24942. required:
  24943. - auth
  24944. - connectHost
  24945. - vaults
  24946. type: object
  24947. oracle:
  24948. description: Oracle configures this store to sync secrets using Oracle Vault provider
  24949. properties:
  24950. auth:
  24951. description: |-
  24952. Auth configures how secret-manager authenticates with the Oracle Vault.
  24953. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  24954. properties:
  24955. secretRef:
  24956. description: SecretRef to pass through sensitive information.
  24957. properties:
  24958. fingerprint:
  24959. description: Fingerprint is the fingerprint of the API private key.
  24960. properties:
  24961. key:
  24962. description: |-
  24963. A key in the referenced Secret.
  24964. Some instances of this field may be defaulted, in others it may be required.
  24965. maxLength: 253
  24966. minLength: 1
  24967. pattern: ^[-._a-zA-Z0-9]+$
  24968. type: string
  24969. name:
  24970. description: The name of the Secret resource being referred to.
  24971. maxLength: 253
  24972. minLength: 1
  24973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24974. type: string
  24975. namespace:
  24976. description: |-
  24977. The namespace of the Secret resource being referred to.
  24978. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24979. maxLength: 63
  24980. minLength: 1
  24981. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24982. type: string
  24983. type: object
  24984. privatekey:
  24985. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  24986. properties:
  24987. key:
  24988. description: |-
  24989. A key in the referenced Secret.
  24990. Some instances of this field may be defaulted, in others it may be required.
  24991. maxLength: 253
  24992. minLength: 1
  24993. pattern: ^[-._a-zA-Z0-9]+$
  24994. type: string
  24995. name:
  24996. description: The name of the Secret resource being referred to.
  24997. maxLength: 253
  24998. minLength: 1
  24999. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25000. type: string
  25001. namespace:
  25002. description: |-
  25003. The namespace of the Secret resource being referred to.
  25004. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25005. maxLength: 63
  25006. minLength: 1
  25007. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25008. type: string
  25009. type: object
  25010. required:
  25011. - fingerprint
  25012. - privatekey
  25013. type: object
  25014. tenancy:
  25015. description: Tenancy is the tenancy OCID where user is located.
  25016. type: string
  25017. user:
  25018. description: User is an access OCID specific to the account.
  25019. type: string
  25020. required:
  25021. - secretRef
  25022. - tenancy
  25023. - user
  25024. type: object
  25025. compartment:
  25026. description: |-
  25027. Compartment is the vault compartment OCID.
  25028. Required for PushSecret
  25029. type: string
  25030. encryptionKey:
  25031. description: |-
  25032. EncryptionKey is the OCID of the encryption key within the vault.
  25033. Required for PushSecret
  25034. type: string
  25035. principalType:
  25036. description: |-
  25037. The type of principal to use for authentication. If left blank, the Auth struct will
  25038. determine the principal type. This optional field must be specified if using
  25039. workload identity.
  25040. enum:
  25041. - ""
  25042. - UserPrincipal
  25043. - InstancePrincipal
  25044. - Workload
  25045. type: string
  25046. region:
  25047. description: Region is the region where vault is located.
  25048. type: string
  25049. serviceAccountRef:
  25050. description: |-
  25051. ServiceAccountRef specified the service account
  25052. that should be used when authenticating with WorkloadIdentity.
  25053. properties:
  25054. audiences:
  25055. description: |-
  25056. Audience specifies the `aud` claim for the service account token
  25057. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25058. then this audiences will be appended to the list
  25059. items:
  25060. type: string
  25061. type: array
  25062. name:
  25063. description: The name of the ServiceAccount resource being referred to.
  25064. maxLength: 253
  25065. minLength: 1
  25066. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25067. type: string
  25068. namespace:
  25069. description: |-
  25070. Namespace of the resource being referred to.
  25071. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25072. maxLength: 63
  25073. minLength: 1
  25074. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25075. type: string
  25076. required:
  25077. - name
  25078. type: object
  25079. vault:
  25080. description: Vault is the vault's OCID of the specific vault where secret is located.
  25081. type: string
  25082. required:
  25083. - region
  25084. - vault
  25085. type: object
  25086. passbolt:
  25087. description: PassboltProvider defines configuration for the Passbolt provider.
  25088. properties:
  25089. auth:
  25090. description: Auth defines the information necessary to authenticate against Passbolt Server
  25091. properties:
  25092. passwordSecretRef:
  25093. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  25094. properties:
  25095. key:
  25096. description: |-
  25097. A key in the referenced Secret.
  25098. Some instances of this field may be defaulted, in others it may be required.
  25099. maxLength: 253
  25100. minLength: 1
  25101. pattern: ^[-._a-zA-Z0-9]+$
  25102. type: string
  25103. name:
  25104. description: The name of the Secret resource being referred to.
  25105. maxLength: 253
  25106. minLength: 1
  25107. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25108. type: string
  25109. namespace:
  25110. description: |-
  25111. The namespace of the Secret resource being referred to.
  25112. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25113. maxLength: 63
  25114. minLength: 1
  25115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25116. type: string
  25117. type: object
  25118. privateKeySecretRef:
  25119. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  25120. properties:
  25121. key:
  25122. description: |-
  25123. A key in the referenced Secret.
  25124. Some instances of this field may be defaulted, in others it may be required.
  25125. maxLength: 253
  25126. minLength: 1
  25127. pattern: ^[-._a-zA-Z0-9]+$
  25128. type: string
  25129. name:
  25130. description: The name of the Secret resource being referred to.
  25131. maxLength: 253
  25132. minLength: 1
  25133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25134. type: string
  25135. namespace:
  25136. description: |-
  25137. The namespace of the Secret resource being referred to.
  25138. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25139. maxLength: 63
  25140. minLength: 1
  25141. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25142. type: string
  25143. type: object
  25144. required:
  25145. - passwordSecretRef
  25146. - privateKeySecretRef
  25147. type: object
  25148. host:
  25149. description: Host defines the Passbolt Server to connect to
  25150. type: string
  25151. required:
  25152. - auth
  25153. - host
  25154. type: object
  25155. passworddepot:
  25156. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  25157. properties:
  25158. auth:
  25159. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  25160. properties:
  25161. secretRef:
  25162. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  25163. properties:
  25164. credentials:
  25165. description: Username / Password is used for authentication.
  25166. properties:
  25167. key:
  25168. description: |-
  25169. A key in the referenced Secret.
  25170. Some instances of this field may be defaulted, in others it may be required.
  25171. maxLength: 253
  25172. minLength: 1
  25173. pattern: ^[-._a-zA-Z0-9]+$
  25174. type: string
  25175. name:
  25176. description: The name of the Secret resource being referred to.
  25177. maxLength: 253
  25178. minLength: 1
  25179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25180. type: string
  25181. namespace:
  25182. description: |-
  25183. The namespace of the Secret resource being referred to.
  25184. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25185. maxLength: 63
  25186. minLength: 1
  25187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25188. type: string
  25189. type: object
  25190. type: object
  25191. required:
  25192. - secretRef
  25193. type: object
  25194. database:
  25195. description: Database to use as source
  25196. type: string
  25197. host:
  25198. description: URL configures the Password Depot instance URL.
  25199. type: string
  25200. required:
  25201. - auth
  25202. - database
  25203. - host
  25204. type: object
  25205. previder:
  25206. description: Previder configures this store to sync secrets using the Previder provider
  25207. properties:
  25208. auth:
  25209. description: PreviderAuth contains a secretRef for credentials.
  25210. properties:
  25211. secretRef:
  25212. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  25213. properties:
  25214. accessToken:
  25215. description: The AccessToken is used for authentication
  25216. properties:
  25217. key:
  25218. description: |-
  25219. A key in the referenced Secret.
  25220. Some instances of this field may be defaulted, in others it may be required.
  25221. maxLength: 253
  25222. minLength: 1
  25223. pattern: ^[-._a-zA-Z0-9]+$
  25224. type: string
  25225. name:
  25226. description: The name of the Secret resource being referred to.
  25227. maxLength: 253
  25228. minLength: 1
  25229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25230. type: string
  25231. namespace:
  25232. description: |-
  25233. The namespace of the Secret resource being referred to.
  25234. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25235. maxLength: 63
  25236. minLength: 1
  25237. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25238. type: string
  25239. type: object
  25240. required:
  25241. - accessToken
  25242. type: object
  25243. type: object
  25244. baseUri:
  25245. type: string
  25246. required:
  25247. - auth
  25248. type: object
  25249. pulumi:
  25250. description: Pulumi configures this store to sync secrets using the Pulumi provider
  25251. properties:
  25252. accessToken:
  25253. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  25254. properties:
  25255. secretRef:
  25256. description: SecretRef is a reference to a secret containing the Pulumi API token.
  25257. properties:
  25258. key:
  25259. description: |-
  25260. A key in the referenced Secret.
  25261. Some instances of this field may be defaulted, in others it may be required.
  25262. maxLength: 253
  25263. minLength: 1
  25264. pattern: ^[-._a-zA-Z0-9]+$
  25265. type: string
  25266. name:
  25267. description: The name of the Secret resource being referred to.
  25268. maxLength: 253
  25269. minLength: 1
  25270. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25271. type: string
  25272. namespace:
  25273. description: |-
  25274. The namespace of the Secret resource being referred to.
  25275. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25276. maxLength: 63
  25277. minLength: 1
  25278. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25279. type: string
  25280. type: object
  25281. type: object
  25282. apiUrl:
  25283. default: https://api.pulumi.com/api/esc
  25284. description: APIURL is the URL of the Pulumi API.
  25285. type: string
  25286. environment:
  25287. description: |-
  25288. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  25289. dynamically retrieved values from supported providers including all major clouds,
  25290. and other Pulumi ESC environments.
  25291. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  25292. type: string
  25293. organization:
  25294. description: |-
  25295. Organization are a space to collaborate on shared projects and stacks.
  25296. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  25297. type: string
  25298. project:
  25299. description: Project is the name of the Pulumi ESC project the environment belongs to.
  25300. type: string
  25301. required:
  25302. - accessToken
  25303. - environment
  25304. - organization
  25305. - project
  25306. type: object
  25307. scaleway:
  25308. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  25309. properties:
  25310. accessKey:
  25311. description: AccessKey is the non-secret part of the api key.
  25312. properties:
  25313. secretRef:
  25314. description: SecretRef references a key in a secret that will be used as value.
  25315. properties:
  25316. key:
  25317. description: |-
  25318. A key in the referenced Secret.
  25319. Some instances of this field may be defaulted, in others it may be required.
  25320. maxLength: 253
  25321. minLength: 1
  25322. pattern: ^[-._a-zA-Z0-9]+$
  25323. type: string
  25324. name:
  25325. description: The name of the Secret resource being referred to.
  25326. maxLength: 253
  25327. minLength: 1
  25328. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25329. type: string
  25330. namespace:
  25331. description: |-
  25332. The namespace of the Secret resource being referred to.
  25333. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25334. maxLength: 63
  25335. minLength: 1
  25336. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25337. type: string
  25338. type: object
  25339. value:
  25340. description: Value can be specified directly to set a value without using a secret.
  25341. type: string
  25342. type: object
  25343. apiUrl:
  25344. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  25345. type: string
  25346. projectId:
  25347. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  25348. type: string
  25349. region:
  25350. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  25351. type: string
  25352. secretKey:
  25353. description: SecretKey is the non-secret part of the api key.
  25354. properties:
  25355. secretRef:
  25356. description: SecretRef references a key in a secret that will be used as value.
  25357. properties:
  25358. key:
  25359. description: |-
  25360. A key in the referenced Secret.
  25361. Some instances of this field may be defaulted, in others it may be required.
  25362. maxLength: 253
  25363. minLength: 1
  25364. pattern: ^[-._a-zA-Z0-9]+$
  25365. type: string
  25366. name:
  25367. description: The name of the Secret resource being referred to.
  25368. maxLength: 253
  25369. minLength: 1
  25370. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25371. type: string
  25372. namespace:
  25373. description: |-
  25374. The namespace of the Secret resource being referred to.
  25375. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25376. maxLength: 63
  25377. minLength: 1
  25378. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25379. type: string
  25380. type: object
  25381. value:
  25382. description: Value can be specified directly to set a value without using a secret.
  25383. type: string
  25384. type: object
  25385. required:
  25386. - accessKey
  25387. - projectId
  25388. - region
  25389. - secretKey
  25390. type: object
  25391. secretserver:
  25392. description: |-
  25393. SecretServer configures this store to sync secrets using SecretServer provider
  25394. https://docs.delinea.com/online-help/secret-server/start.htm
  25395. properties:
  25396. password:
  25397. description: Password is the secret server account password.
  25398. properties:
  25399. secretRef:
  25400. description: SecretRef references a key in a secret that will be used as value.
  25401. properties:
  25402. key:
  25403. description: |-
  25404. A key in the referenced Secret.
  25405. Some instances of this field may be defaulted, in others it may be required.
  25406. maxLength: 253
  25407. minLength: 1
  25408. pattern: ^[-._a-zA-Z0-9]+$
  25409. type: string
  25410. name:
  25411. description: The name of the Secret resource being referred to.
  25412. maxLength: 253
  25413. minLength: 1
  25414. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25415. type: string
  25416. namespace:
  25417. description: |-
  25418. The namespace of the Secret resource being referred to.
  25419. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25420. maxLength: 63
  25421. minLength: 1
  25422. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25423. type: string
  25424. type: object
  25425. value:
  25426. description: Value can be specified directly to set a value without using a secret.
  25427. type: string
  25428. type: object
  25429. serverURL:
  25430. description: |-
  25431. ServerURL
  25432. URL to your secret server installation
  25433. type: string
  25434. username:
  25435. description: Username is the secret server account username.
  25436. properties:
  25437. secretRef:
  25438. description: SecretRef references a key in a secret that will be used as value.
  25439. properties:
  25440. key:
  25441. description: |-
  25442. A key in the referenced Secret.
  25443. Some instances of this field may be defaulted, in others it may be required.
  25444. maxLength: 253
  25445. minLength: 1
  25446. pattern: ^[-._a-zA-Z0-9]+$
  25447. type: string
  25448. name:
  25449. description: The name of the Secret resource being referred to.
  25450. maxLength: 253
  25451. minLength: 1
  25452. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25453. type: string
  25454. namespace:
  25455. description: |-
  25456. The namespace of the Secret resource being referred to.
  25457. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25458. maxLength: 63
  25459. minLength: 1
  25460. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25461. type: string
  25462. type: object
  25463. value:
  25464. description: Value can be specified directly to set a value without using a secret.
  25465. type: string
  25466. type: object
  25467. required:
  25468. - password
  25469. - serverURL
  25470. - username
  25471. type: object
  25472. senhasegura:
  25473. description: Senhasegura configures this store to sync secrets using senhasegura provider
  25474. properties:
  25475. auth:
  25476. description: Auth defines parameters to authenticate in senhasegura
  25477. properties:
  25478. clientId:
  25479. type: string
  25480. clientSecretSecretRef:
  25481. description: |-
  25482. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25483. In some instances, `key` is a required field.
  25484. properties:
  25485. key:
  25486. description: |-
  25487. A key in the referenced Secret.
  25488. Some instances of this field may be defaulted, in others it may be required.
  25489. maxLength: 253
  25490. minLength: 1
  25491. pattern: ^[-._a-zA-Z0-9]+$
  25492. type: string
  25493. name:
  25494. description: The name of the Secret resource being referred to.
  25495. maxLength: 253
  25496. minLength: 1
  25497. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25498. type: string
  25499. namespace:
  25500. description: |-
  25501. The namespace of the Secret resource being referred to.
  25502. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25503. maxLength: 63
  25504. minLength: 1
  25505. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25506. type: string
  25507. type: object
  25508. required:
  25509. - clientId
  25510. - clientSecretSecretRef
  25511. type: object
  25512. ignoreSslCertificate:
  25513. default: false
  25514. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  25515. type: boolean
  25516. module:
  25517. description: Module defines which senhasegura module should be used to get secrets
  25518. type: string
  25519. url:
  25520. description: URL of senhasegura
  25521. type: string
  25522. required:
  25523. - auth
  25524. - module
  25525. - url
  25526. type: object
  25527. vault:
  25528. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  25529. properties:
  25530. auth:
  25531. description: Auth configures how secret-manager authenticates with the Vault server.
  25532. properties:
  25533. appRole:
  25534. description: |-
  25535. AppRole authenticates with Vault using the App Role auth mechanism,
  25536. with the role and secret stored in a Kubernetes Secret resource.
  25537. properties:
  25538. path:
  25539. default: approle
  25540. description: |-
  25541. Path where the App Role authentication backend is mounted
  25542. in Vault, e.g: "approle"
  25543. type: string
  25544. roleId:
  25545. description: |-
  25546. RoleID configured in the App Role authentication backend when setting
  25547. up the authentication backend in Vault.
  25548. type: string
  25549. roleRef:
  25550. description: |-
  25551. Reference to a key in a Secret that contains the App Role ID used
  25552. to authenticate with Vault.
  25553. The `key` field must be specified and denotes which entry within the Secret
  25554. resource is used as the app role id.
  25555. properties:
  25556. key:
  25557. description: |-
  25558. A key in the referenced Secret.
  25559. Some instances of this field may be defaulted, in others it may be required.
  25560. maxLength: 253
  25561. minLength: 1
  25562. pattern: ^[-._a-zA-Z0-9]+$
  25563. type: string
  25564. name:
  25565. description: The name of the Secret resource being referred to.
  25566. maxLength: 253
  25567. minLength: 1
  25568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25569. type: string
  25570. namespace:
  25571. description: |-
  25572. The namespace of the Secret resource being referred to.
  25573. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25574. maxLength: 63
  25575. minLength: 1
  25576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25577. type: string
  25578. type: object
  25579. secretRef:
  25580. description: |-
  25581. Reference to a key in a Secret that contains the App Role secret used
  25582. to authenticate with Vault.
  25583. The `key` field must be specified and denotes which entry within the Secret
  25584. resource is used as the app role secret.
  25585. properties:
  25586. key:
  25587. description: |-
  25588. A key in the referenced Secret.
  25589. Some instances of this field may be defaulted, in others it may be required.
  25590. maxLength: 253
  25591. minLength: 1
  25592. pattern: ^[-._a-zA-Z0-9]+$
  25593. type: string
  25594. name:
  25595. description: The name of the Secret resource being referred to.
  25596. maxLength: 253
  25597. minLength: 1
  25598. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25599. type: string
  25600. namespace:
  25601. description: |-
  25602. The namespace of the Secret resource being referred to.
  25603. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25604. maxLength: 63
  25605. minLength: 1
  25606. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25607. type: string
  25608. type: object
  25609. required:
  25610. - path
  25611. - secretRef
  25612. type: object
  25613. cert:
  25614. description: |-
  25615. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  25616. Cert authentication method
  25617. properties:
  25618. clientCert:
  25619. description: |-
  25620. ClientCert is a certificate to authenticate using the Cert Vault
  25621. authentication method
  25622. properties:
  25623. key:
  25624. description: |-
  25625. A key in the referenced Secret.
  25626. Some instances of this field may be defaulted, in others it may be required.
  25627. maxLength: 253
  25628. minLength: 1
  25629. pattern: ^[-._a-zA-Z0-9]+$
  25630. type: string
  25631. name:
  25632. description: The name of the Secret resource being referred to.
  25633. maxLength: 253
  25634. minLength: 1
  25635. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25636. type: string
  25637. namespace:
  25638. description: |-
  25639. The namespace of the Secret resource being referred to.
  25640. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25641. maxLength: 63
  25642. minLength: 1
  25643. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25644. type: string
  25645. type: object
  25646. secretRef:
  25647. description: |-
  25648. SecretRef to a key in a Secret resource containing client private key to
  25649. authenticate with Vault using the Cert authentication method
  25650. properties:
  25651. key:
  25652. description: |-
  25653. A key in the referenced Secret.
  25654. Some instances of this field may be defaulted, in others it may be required.
  25655. maxLength: 253
  25656. minLength: 1
  25657. pattern: ^[-._a-zA-Z0-9]+$
  25658. type: string
  25659. name:
  25660. description: The name of the Secret resource being referred to.
  25661. maxLength: 253
  25662. minLength: 1
  25663. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25664. type: string
  25665. namespace:
  25666. description: |-
  25667. The namespace of the Secret resource being referred to.
  25668. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25669. maxLength: 63
  25670. minLength: 1
  25671. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25672. type: string
  25673. type: object
  25674. type: object
  25675. iam:
  25676. description: |-
  25677. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  25678. AWS IAM authentication method
  25679. properties:
  25680. externalID:
  25681. description: AWS External ID set on assumed IAM roles
  25682. type: string
  25683. jwt:
  25684. description: Specify a service account with IRSA enabled
  25685. properties:
  25686. serviceAccountRef:
  25687. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  25688. properties:
  25689. audiences:
  25690. description: |-
  25691. Audience specifies the `aud` claim for the service account token
  25692. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25693. then this audiences will be appended to the list
  25694. items:
  25695. type: string
  25696. type: array
  25697. name:
  25698. description: The name of the ServiceAccount resource being referred to.
  25699. maxLength: 253
  25700. minLength: 1
  25701. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25702. type: string
  25703. namespace:
  25704. description: |-
  25705. Namespace of the resource being referred to.
  25706. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25707. maxLength: 63
  25708. minLength: 1
  25709. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25710. type: string
  25711. required:
  25712. - name
  25713. type: object
  25714. type: object
  25715. path:
  25716. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  25717. type: string
  25718. region:
  25719. description: AWS region
  25720. type: string
  25721. role:
  25722. description: This is the AWS role to be assumed before talking to vault
  25723. type: string
  25724. secretRef:
  25725. description: Specify credentials in a Secret object
  25726. properties:
  25727. accessKeyIDSecretRef:
  25728. description: The AccessKeyID is used for authentication
  25729. properties:
  25730. key:
  25731. description: |-
  25732. A key in the referenced Secret.
  25733. Some instances of this field may be defaulted, in others it may be required.
  25734. maxLength: 253
  25735. minLength: 1
  25736. pattern: ^[-._a-zA-Z0-9]+$
  25737. type: string
  25738. name:
  25739. description: The name of the Secret resource being referred to.
  25740. maxLength: 253
  25741. minLength: 1
  25742. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25743. type: string
  25744. namespace:
  25745. description: |-
  25746. The namespace of the Secret resource being referred to.
  25747. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25748. maxLength: 63
  25749. minLength: 1
  25750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25751. type: string
  25752. type: object
  25753. secretAccessKeySecretRef:
  25754. description: The SecretAccessKey is used for authentication
  25755. properties:
  25756. key:
  25757. description: |-
  25758. A key in the referenced Secret.
  25759. Some instances of this field may be defaulted, in others it may be required.
  25760. maxLength: 253
  25761. minLength: 1
  25762. pattern: ^[-._a-zA-Z0-9]+$
  25763. type: string
  25764. name:
  25765. description: The name of the Secret resource being referred to.
  25766. maxLength: 253
  25767. minLength: 1
  25768. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25769. type: string
  25770. namespace:
  25771. description: |-
  25772. The namespace of the Secret resource being referred to.
  25773. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25774. maxLength: 63
  25775. minLength: 1
  25776. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25777. type: string
  25778. type: object
  25779. sessionTokenSecretRef:
  25780. description: |-
  25781. The SessionToken used for authentication
  25782. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  25783. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  25784. properties:
  25785. key:
  25786. description: |-
  25787. A key in the referenced Secret.
  25788. Some instances of this field may be defaulted, in others it may be required.
  25789. maxLength: 253
  25790. minLength: 1
  25791. pattern: ^[-._a-zA-Z0-9]+$
  25792. type: string
  25793. name:
  25794. description: The name of the Secret resource being referred to.
  25795. maxLength: 253
  25796. minLength: 1
  25797. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25798. type: string
  25799. namespace:
  25800. description: |-
  25801. The namespace of the Secret resource being referred to.
  25802. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25803. maxLength: 63
  25804. minLength: 1
  25805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25806. type: string
  25807. type: object
  25808. type: object
  25809. vaultAwsIamServerID:
  25810. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  25811. type: string
  25812. vaultRole:
  25813. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  25814. type: string
  25815. required:
  25816. - vaultRole
  25817. type: object
  25818. jwt:
  25819. description: |-
  25820. Jwt authenticates with Vault by passing role and JWT token using the
  25821. JWT/OIDC authentication method
  25822. properties:
  25823. kubernetesServiceAccountToken:
  25824. description: |-
  25825. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  25826. a token for with the `TokenRequest` API.
  25827. properties:
  25828. audiences:
  25829. description: |-
  25830. Optional audiences field that will be used to request a temporary Kubernetes service
  25831. account token for the service account referenced by `serviceAccountRef`.
  25832. Defaults to a single audience `vault` it not specified.
  25833. Deprecated: use serviceAccountRef.Audiences instead
  25834. items:
  25835. type: string
  25836. type: array
  25837. expirationSeconds:
  25838. description: |-
  25839. Optional expiration time in seconds that will be used to request a temporary
  25840. Kubernetes service account token for the service account referenced by
  25841. `serviceAccountRef`.
  25842. Deprecated: this will be removed in the future.
  25843. Defaults to 10 minutes.
  25844. format: int64
  25845. type: integer
  25846. serviceAccountRef:
  25847. description: Service account field containing the name of a kubernetes ServiceAccount.
  25848. properties:
  25849. audiences:
  25850. description: |-
  25851. Audience specifies the `aud` claim for the service account token
  25852. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25853. then this audiences will be appended to the list
  25854. items:
  25855. type: string
  25856. type: array
  25857. name:
  25858. description: The name of the ServiceAccount resource being referred to.
  25859. maxLength: 253
  25860. minLength: 1
  25861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25862. type: string
  25863. namespace:
  25864. description: |-
  25865. Namespace of the resource being referred to.
  25866. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25867. maxLength: 63
  25868. minLength: 1
  25869. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25870. type: string
  25871. required:
  25872. - name
  25873. type: object
  25874. required:
  25875. - serviceAccountRef
  25876. type: object
  25877. path:
  25878. default: jwt
  25879. description: |-
  25880. Path where the JWT authentication backend is mounted
  25881. in Vault, e.g: "jwt"
  25882. type: string
  25883. role:
  25884. description: |-
  25885. Role is a JWT role to authenticate using the JWT/OIDC Vault
  25886. authentication method
  25887. type: string
  25888. secretRef:
  25889. description: |-
  25890. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  25891. authenticate with Vault using the JWT/OIDC authentication method.
  25892. properties:
  25893. key:
  25894. description: |-
  25895. A key in the referenced Secret.
  25896. Some instances of this field may be defaulted, in others it may be required.
  25897. maxLength: 253
  25898. minLength: 1
  25899. pattern: ^[-._a-zA-Z0-9]+$
  25900. type: string
  25901. name:
  25902. description: The name of the Secret resource being referred to.
  25903. maxLength: 253
  25904. minLength: 1
  25905. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25906. type: string
  25907. namespace:
  25908. description: |-
  25909. The namespace of the Secret resource being referred to.
  25910. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25911. maxLength: 63
  25912. minLength: 1
  25913. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25914. type: string
  25915. type: object
  25916. required:
  25917. - path
  25918. type: object
  25919. kubernetes:
  25920. description: |-
  25921. Kubernetes authenticates with Vault by passing the ServiceAccount
  25922. token stored in the named Secret resource to the Vault server.
  25923. properties:
  25924. mountPath:
  25925. default: kubernetes
  25926. description: |-
  25927. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  25928. "kubernetes"
  25929. type: string
  25930. role:
  25931. description: |-
  25932. A required field containing the Vault Role to assume. A Role binds a
  25933. Kubernetes ServiceAccount with a set of Vault policies.
  25934. type: string
  25935. secretRef:
  25936. description: |-
  25937. Optional secret field containing a Kubernetes ServiceAccount JWT used
  25938. for authenticating with Vault. If a name is specified without a key,
  25939. `token` is the default. If one is not specified, the one bound to
  25940. the controller will be used.
  25941. properties:
  25942. key:
  25943. description: |-
  25944. A key in the referenced Secret.
  25945. Some instances of this field may be defaulted, in others it may be required.
  25946. maxLength: 253
  25947. minLength: 1
  25948. pattern: ^[-._a-zA-Z0-9]+$
  25949. type: string
  25950. name:
  25951. description: The name of the Secret resource being referred to.
  25952. maxLength: 253
  25953. minLength: 1
  25954. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25955. type: string
  25956. namespace:
  25957. description: |-
  25958. The namespace of the Secret resource being referred to.
  25959. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25960. maxLength: 63
  25961. minLength: 1
  25962. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25963. type: string
  25964. type: object
  25965. serviceAccountRef:
  25966. description: |-
  25967. Optional service account field containing the name of a kubernetes ServiceAccount.
  25968. If the service account is specified, the service account secret token JWT will be used
  25969. for authenticating with Vault. If the service account selector is not supplied,
  25970. the secretRef will be used instead.
  25971. properties:
  25972. audiences:
  25973. description: |-
  25974. Audience specifies the `aud` claim for the service account token
  25975. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25976. then this audiences will be appended to the list
  25977. items:
  25978. type: string
  25979. type: array
  25980. name:
  25981. description: The name of the ServiceAccount resource being referred to.
  25982. maxLength: 253
  25983. minLength: 1
  25984. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25985. type: string
  25986. namespace:
  25987. description: |-
  25988. Namespace of the resource being referred to.
  25989. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25990. maxLength: 63
  25991. minLength: 1
  25992. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25993. type: string
  25994. required:
  25995. - name
  25996. type: object
  25997. required:
  25998. - mountPath
  25999. - role
  26000. type: object
  26001. ldap:
  26002. description: |-
  26003. Ldap authenticates with Vault by passing username/password pair using
  26004. the LDAP authentication method
  26005. properties:
  26006. path:
  26007. default: ldap
  26008. description: |-
  26009. Path where the LDAP authentication backend is mounted
  26010. in Vault, e.g: "ldap"
  26011. type: string
  26012. secretRef:
  26013. description: |-
  26014. SecretRef to a key in a Secret resource containing password for the LDAP
  26015. user used to authenticate with Vault using the LDAP authentication
  26016. method
  26017. properties:
  26018. key:
  26019. description: |-
  26020. A key in the referenced Secret.
  26021. Some instances of this field may be defaulted, in others it may be required.
  26022. maxLength: 253
  26023. minLength: 1
  26024. pattern: ^[-._a-zA-Z0-9]+$
  26025. type: string
  26026. name:
  26027. description: The name of the Secret resource being referred to.
  26028. maxLength: 253
  26029. minLength: 1
  26030. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26031. type: string
  26032. namespace:
  26033. description: |-
  26034. The namespace of the Secret resource being referred to.
  26035. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26036. maxLength: 63
  26037. minLength: 1
  26038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26039. type: string
  26040. type: object
  26041. username:
  26042. description: |-
  26043. Username is an LDAP username used to authenticate using the LDAP Vault
  26044. authentication method
  26045. type: string
  26046. required:
  26047. - path
  26048. - username
  26049. type: object
  26050. namespace:
  26051. description: |-
  26052. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  26053. Namespaces is a set of features within Vault Enterprise that allows
  26054. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  26055. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  26056. This will default to Vault.Namespace field if set, or empty otherwise
  26057. type: string
  26058. tokenSecretRef:
  26059. description: TokenSecretRef authenticates with Vault by presenting a token.
  26060. properties:
  26061. key:
  26062. description: |-
  26063. A key in the referenced Secret.
  26064. Some instances of this field may be defaulted, in others it may be required.
  26065. maxLength: 253
  26066. minLength: 1
  26067. pattern: ^[-._a-zA-Z0-9]+$
  26068. type: string
  26069. name:
  26070. description: The name of the Secret resource being referred to.
  26071. maxLength: 253
  26072. minLength: 1
  26073. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26074. type: string
  26075. namespace:
  26076. description: |-
  26077. The namespace of the Secret resource being referred to.
  26078. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26079. maxLength: 63
  26080. minLength: 1
  26081. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26082. type: string
  26083. type: object
  26084. userPass:
  26085. description: UserPass authenticates with Vault by passing username/password pair
  26086. properties:
  26087. path:
  26088. default: userpass
  26089. description: |-
  26090. Path where the UserPassword authentication backend is mounted
  26091. in Vault, e.g: "userpass"
  26092. type: string
  26093. secretRef:
  26094. description: |-
  26095. SecretRef to a key in a Secret resource containing password for the
  26096. user used to authenticate with Vault using the UserPass authentication
  26097. method
  26098. properties:
  26099. key:
  26100. description: |-
  26101. A key in the referenced Secret.
  26102. Some instances of this field may be defaulted, in others it may be required.
  26103. maxLength: 253
  26104. minLength: 1
  26105. pattern: ^[-._a-zA-Z0-9]+$
  26106. type: string
  26107. name:
  26108. description: The name of the Secret resource being referred to.
  26109. maxLength: 253
  26110. minLength: 1
  26111. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26112. type: string
  26113. namespace:
  26114. description: |-
  26115. The namespace of the Secret resource being referred to.
  26116. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26117. maxLength: 63
  26118. minLength: 1
  26119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26120. type: string
  26121. type: object
  26122. username:
  26123. description: |-
  26124. Username is a username used to authenticate using the UserPass Vault
  26125. authentication method
  26126. type: string
  26127. required:
  26128. - path
  26129. - username
  26130. type: object
  26131. type: object
  26132. caBundle:
  26133. description: |-
  26134. PEM encoded CA bundle used to validate Vault server certificate. Only used
  26135. if the Server URL is using HTTPS protocol. This parameter is ignored for
  26136. plain HTTP protocol connection. If not set the system root certificates
  26137. are used to validate the TLS connection.
  26138. format: byte
  26139. type: string
  26140. caProvider:
  26141. description: The provider for the CA bundle to use to validate Vault server certificate.
  26142. properties:
  26143. key:
  26144. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26145. maxLength: 253
  26146. minLength: 1
  26147. pattern: ^[-._a-zA-Z0-9]+$
  26148. type: string
  26149. name:
  26150. description: The name of the object located at the provider type.
  26151. maxLength: 253
  26152. minLength: 1
  26153. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26154. type: string
  26155. namespace:
  26156. description: |-
  26157. The namespace the Provider type is in.
  26158. Can only be defined when used in a ClusterSecretStore.
  26159. maxLength: 63
  26160. minLength: 1
  26161. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26162. type: string
  26163. type:
  26164. description: The type of provider to use such as "Secret", or "ConfigMap".
  26165. enum:
  26166. - Secret
  26167. - ConfigMap
  26168. type: string
  26169. required:
  26170. - name
  26171. - type
  26172. type: object
  26173. forwardInconsistent:
  26174. description: |-
  26175. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  26176. leader instead of simply retrying within a loop. This can increase performance if
  26177. the option is enabled serverside.
  26178. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  26179. type: boolean
  26180. headers:
  26181. additionalProperties:
  26182. type: string
  26183. description: Headers to be added in Vault request
  26184. type: object
  26185. namespace:
  26186. description: |-
  26187. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  26188. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  26189. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  26190. type: string
  26191. path:
  26192. description: |-
  26193. Path is the mount path of the Vault KV backend endpoint, e.g:
  26194. "secret". The v2 KV secret engine version specific "/data" path suffix
  26195. for fetching secrets from Vault is optional and will be appended
  26196. if not present in specified path.
  26197. type: string
  26198. readYourWrites:
  26199. description: |-
  26200. ReadYourWrites ensures isolated read-after-write semantics by
  26201. providing discovered cluster replication states in each request.
  26202. More information about eventual consistency in Vault can be found here
  26203. https://www.vaultproject.io/docs/enterprise/consistency
  26204. type: boolean
  26205. server:
  26206. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  26207. type: string
  26208. tls:
  26209. description: |-
  26210. The configuration used for client side related TLS communication, when the Vault server
  26211. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  26212. This parameter is ignored for plain HTTP protocol connection.
  26213. It's worth noting this configuration is different from the "TLS certificates auth method",
  26214. which is available under the `auth.cert` section.
  26215. properties:
  26216. certSecretRef:
  26217. description: |-
  26218. CertSecretRef is a certificate added to the transport layer
  26219. when communicating with the Vault server.
  26220. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  26221. properties:
  26222. key:
  26223. description: |-
  26224. A key in the referenced Secret.
  26225. Some instances of this field may be defaulted, in others it may be required.
  26226. maxLength: 253
  26227. minLength: 1
  26228. pattern: ^[-._a-zA-Z0-9]+$
  26229. type: string
  26230. name:
  26231. description: The name of the Secret resource being referred to.
  26232. maxLength: 253
  26233. minLength: 1
  26234. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26235. type: string
  26236. namespace:
  26237. description: |-
  26238. The namespace of the Secret resource being referred to.
  26239. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26240. maxLength: 63
  26241. minLength: 1
  26242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26243. type: string
  26244. type: object
  26245. keySecretRef:
  26246. description: |-
  26247. KeySecretRef to a key in a Secret resource containing client private key
  26248. added to the transport layer when communicating with the Vault server.
  26249. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  26250. properties:
  26251. key:
  26252. description: |-
  26253. A key in the referenced Secret.
  26254. Some instances of this field may be defaulted, in others it may be required.
  26255. maxLength: 253
  26256. minLength: 1
  26257. pattern: ^[-._a-zA-Z0-9]+$
  26258. type: string
  26259. name:
  26260. description: The name of the Secret resource being referred to.
  26261. maxLength: 253
  26262. minLength: 1
  26263. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26264. type: string
  26265. namespace:
  26266. description: |-
  26267. The namespace of the Secret resource being referred to.
  26268. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26269. maxLength: 63
  26270. minLength: 1
  26271. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26272. type: string
  26273. type: object
  26274. type: object
  26275. version:
  26276. default: v2
  26277. description: |-
  26278. Version is the Vault KV secret engine version. This can be either "v1" or
  26279. "v2". Version defaults to "v2".
  26280. enum:
  26281. - v1
  26282. - v2
  26283. type: string
  26284. required:
  26285. - server
  26286. type: object
  26287. webhook:
  26288. description: Webhook configures this store to sync secrets using a generic templated webhook
  26289. properties:
  26290. auth:
  26291. description: Auth specifies a authorization protocol. Only one protocol may be set.
  26292. maxProperties: 1
  26293. minProperties: 1
  26294. properties:
  26295. ntlm:
  26296. description: NTLMProtocol configures the store to use NTLM for auth
  26297. properties:
  26298. passwordSecret:
  26299. description: |-
  26300. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26301. In some instances, `key` is a required field.
  26302. properties:
  26303. key:
  26304. description: |-
  26305. A key in the referenced Secret.
  26306. Some instances of this field may be defaulted, in others it may be required.
  26307. maxLength: 253
  26308. minLength: 1
  26309. pattern: ^[-._a-zA-Z0-9]+$
  26310. type: string
  26311. name:
  26312. description: The name of the Secret resource being referred to.
  26313. maxLength: 253
  26314. minLength: 1
  26315. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26316. type: string
  26317. namespace:
  26318. description: |-
  26319. The namespace of the Secret resource being referred to.
  26320. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26321. maxLength: 63
  26322. minLength: 1
  26323. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26324. type: string
  26325. type: object
  26326. usernameSecret:
  26327. description: |-
  26328. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26329. In some instances, `key` is a required field.
  26330. properties:
  26331. key:
  26332. description: |-
  26333. A key in the referenced Secret.
  26334. Some instances of this field may be defaulted, in others it may be required.
  26335. maxLength: 253
  26336. minLength: 1
  26337. pattern: ^[-._a-zA-Z0-9]+$
  26338. type: string
  26339. name:
  26340. description: The name of the Secret resource being referred to.
  26341. maxLength: 253
  26342. minLength: 1
  26343. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26344. type: string
  26345. namespace:
  26346. description: |-
  26347. The namespace of the Secret resource being referred to.
  26348. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26349. maxLength: 63
  26350. minLength: 1
  26351. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26352. type: string
  26353. type: object
  26354. required:
  26355. - passwordSecret
  26356. - usernameSecret
  26357. type: object
  26358. type: object
  26359. body:
  26360. description: Body
  26361. type: string
  26362. caBundle:
  26363. description: |-
  26364. PEM encoded CA bundle used to validate webhook server certificate. Only used
  26365. if the Server URL is using HTTPS protocol. This parameter is ignored for
  26366. plain HTTP protocol connection. If not set the system root certificates
  26367. are used to validate the TLS connection.
  26368. format: byte
  26369. type: string
  26370. caProvider:
  26371. description: The provider for the CA bundle to use to validate webhook server certificate.
  26372. properties:
  26373. key:
  26374. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26375. maxLength: 253
  26376. minLength: 1
  26377. pattern: ^[-._a-zA-Z0-9]+$
  26378. type: string
  26379. name:
  26380. description: The name of the object located at the provider type.
  26381. maxLength: 253
  26382. minLength: 1
  26383. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26384. type: string
  26385. namespace:
  26386. description: The namespace the Provider type is in.
  26387. maxLength: 63
  26388. minLength: 1
  26389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26390. type: string
  26391. type:
  26392. description: The type of provider to use such as "Secret", or "ConfigMap".
  26393. enum:
  26394. - Secret
  26395. - ConfigMap
  26396. type: string
  26397. required:
  26398. - name
  26399. - type
  26400. type: object
  26401. headers:
  26402. additionalProperties:
  26403. type: string
  26404. description: Headers
  26405. type: object
  26406. method:
  26407. description: Webhook Method
  26408. type: string
  26409. result:
  26410. description: Result formatting
  26411. properties:
  26412. jsonPath:
  26413. description: Json path of return value
  26414. type: string
  26415. type: object
  26416. secrets:
  26417. description: |-
  26418. Secrets to fill in templates
  26419. These secrets will be passed to the templating function as key value pairs under the given name
  26420. items:
  26421. description: WebhookSecret defines a secret to be used in webhook templates.
  26422. properties:
  26423. name:
  26424. description: Name of this secret in templates
  26425. type: string
  26426. secretRef:
  26427. description: Secret ref to fill in credentials
  26428. properties:
  26429. key:
  26430. description: |-
  26431. A key in the referenced Secret.
  26432. Some instances of this field may be defaulted, in others it may be required.
  26433. maxLength: 253
  26434. minLength: 1
  26435. pattern: ^[-._a-zA-Z0-9]+$
  26436. type: string
  26437. name:
  26438. description: The name of the Secret resource being referred to.
  26439. maxLength: 253
  26440. minLength: 1
  26441. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26442. type: string
  26443. namespace:
  26444. description: |-
  26445. The namespace of the Secret resource being referred to.
  26446. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26447. maxLength: 63
  26448. minLength: 1
  26449. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26450. type: string
  26451. type: object
  26452. required:
  26453. - name
  26454. - secretRef
  26455. type: object
  26456. type: array
  26457. timeout:
  26458. description: Timeout
  26459. type: string
  26460. url:
  26461. description: Webhook url to call
  26462. type: string
  26463. required:
  26464. - result
  26465. - url
  26466. type: object
  26467. yandexcertificatemanager:
  26468. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  26469. properties:
  26470. apiEndpoint:
  26471. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  26472. type: string
  26473. auth:
  26474. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  26475. properties:
  26476. authorizedKeySecretRef:
  26477. description: The authorized key used for authentication
  26478. properties:
  26479. key:
  26480. description: |-
  26481. A key in the referenced Secret.
  26482. Some instances of this field may be defaulted, in others it may be required.
  26483. maxLength: 253
  26484. minLength: 1
  26485. pattern: ^[-._a-zA-Z0-9]+$
  26486. type: string
  26487. name:
  26488. description: The name of the Secret resource being referred to.
  26489. maxLength: 253
  26490. minLength: 1
  26491. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26492. type: string
  26493. namespace:
  26494. description: |-
  26495. The namespace of the Secret resource being referred to.
  26496. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26497. maxLength: 63
  26498. minLength: 1
  26499. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26500. type: string
  26501. type: object
  26502. type: object
  26503. caProvider:
  26504. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  26505. properties:
  26506. certSecretRef:
  26507. description: |-
  26508. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26509. In some instances, `key` is a required field.
  26510. properties:
  26511. key:
  26512. description: |-
  26513. A key in the referenced Secret.
  26514. Some instances of this field may be defaulted, in others it may be required.
  26515. maxLength: 253
  26516. minLength: 1
  26517. pattern: ^[-._a-zA-Z0-9]+$
  26518. type: string
  26519. name:
  26520. description: The name of the Secret resource being referred to.
  26521. maxLength: 253
  26522. minLength: 1
  26523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26524. type: string
  26525. namespace:
  26526. description: |-
  26527. The namespace of the Secret resource being referred to.
  26528. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26529. maxLength: 63
  26530. minLength: 1
  26531. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26532. type: string
  26533. type: object
  26534. type: object
  26535. required:
  26536. - auth
  26537. type: object
  26538. yandexlockbox:
  26539. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  26540. properties:
  26541. apiEndpoint:
  26542. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  26543. type: string
  26544. auth:
  26545. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  26546. properties:
  26547. authorizedKeySecretRef:
  26548. description: The authorized key used for authentication
  26549. properties:
  26550. key:
  26551. description: |-
  26552. A key in the referenced Secret.
  26553. Some instances of this field may be defaulted, in others it may be required.
  26554. maxLength: 253
  26555. minLength: 1
  26556. pattern: ^[-._a-zA-Z0-9]+$
  26557. type: string
  26558. name:
  26559. description: The name of the Secret resource being referred to.
  26560. maxLength: 253
  26561. minLength: 1
  26562. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26563. type: string
  26564. namespace:
  26565. description: |-
  26566. The namespace of the Secret resource being referred to.
  26567. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26568. maxLength: 63
  26569. minLength: 1
  26570. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26571. type: string
  26572. type: object
  26573. type: object
  26574. caProvider:
  26575. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  26576. properties:
  26577. certSecretRef:
  26578. description: |-
  26579. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26580. In some instances, `key` is a required field.
  26581. properties:
  26582. key:
  26583. description: |-
  26584. A key in the referenced Secret.
  26585. Some instances of this field may be defaulted, in others it may be required.
  26586. maxLength: 253
  26587. minLength: 1
  26588. pattern: ^[-._a-zA-Z0-9]+$
  26589. type: string
  26590. name:
  26591. description: The name of the Secret resource being referred to.
  26592. maxLength: 253
  26593. minLength: 1
  26594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26595. type: string
  26596. namespace:
  26597. description: |-
  26598. The namespace of the Secret resource being referred to.
  26599. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26600. maxLength: 63
  26601. minLength: 1
  26602. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26603. type: string
  26604. type: object
  26605. type: object
  26606. required:
  26607. - auth
  26608. type: object
  26609. type: object
  26610. refreshInterval:
  26611. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  26612. type: integer
  26613. retrySettings:
  26614. description: Used to configure HTTP retries on failures.
  26615. properties:
  26616. maxRetries:
  26617. description: MaxRetries is the maximum number of retry attempts.
  26618. format: int32
  26619. type: integer
  26620. retryInterval:
  26621. description: RetryInterval is the interval between retry attempts.
  26622. type: string
  26623. type: object
  26624. required:
  26625. - provider
  26626. type: object
  26627. status:
  26628. description: SecretStoreStatus defines the observed state of the SecretStore.
  26629. properties:
  26630. capabilities:
  26631. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  26632. type: string
  26633. conditions:
  26634. items:
  26635. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  26636. properties:
  26637. lastTransitionTime:
  26638. format: date-time
  26639. type: string
  26640. message:
  26641. type: string
  26642. reason:
  26643. type: string
  26644. status:
  26645. type: string
  26646. type:
  26647. description: SecretStoreConditionType represents the condition type of the SecretStore.
  26648. type: string
  26649. required:
  26650. - status
  26651. - type
  26652. type: object
  26653. type: array
  26654. type: object
  26655. type: object
  26656. served: false
  26657. storage: false
  26658. subresources:
  26659. status: {}
  26660. ---
  26661. apiVersion: apiextensions.k8s.io/v1
  26662. kind: CustomResourceDefinition
  26663. metadata:
  26664. annotations:
  26665. controller-gen.kubebuilder.io/version: v0.19.0
  26666. labels:
  26667. external-secrets.io/component: controller
  26668. name: acraccesstokens.generators.external-secrets.io
  26669. spec:
  26670. group: generators.external-secrets.io
  26671. names:
  26672. categories:
  26673. - external-secrets
  26674. - external-secrets-generators
  26675. kind: ACRAccessToken
  26676. listKind: ACRAccessTokenList
  26677. plural: acraccesstokens
  26678. singular: acraccesstoken
  26679. scope: Namespaced
  26680. versions:
  26681. - name: v1alpha1
  26682. schema:
  26683. openAPIV3Schema:
  26684. description: |-
  26685. ACRAccessToken returns an Azure Container Registry token
  26686. that can be used for pushing/pulling images.
  26687. Note: by default it will return an ACR Refresh Token with full access
  26688. (depending on the identity).
  26689. This can be scoped down to the repository level using .spec.scope.
  26690. In case scope is defined it will return an ACR Access Token.
  26691. See docs: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md
  26692. properties:
  26693. apiVersion:
  26694. description: |-
  26695. APIVersion defines the versioned schema of this representation of an object.
  26696. Servers should convert recognized schemas to the latest internal value, and
  26697. may reject unrecognized values.
  26698. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  26699. type: string
  26700. kind:
  26701. description: |-
  26702. Kind is a string value representing the REST resource this object represents.
  26703. Servers may infer this from the endpoint the client submits requests to.
  26704. Cannot be updated.
  26705. In CamelCase.
  26706. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  26707. type: string
  26708. metadata:
  26709. type: object
  26710. spec:
  26711. description: |-
  26712. ACRAccessTokenSpec defines how to generate the access token
  26713. e.g. how to authenticate and which registry to use.
  26714. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  26715. properties:
  26716. auth:
  26717. description: ACRAuth defines the authentication methods for Azure Container Registry.
  26718. properties:
  26719. managedIdentity:
  26720. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  26721. properties:
  26722. identityId:
  26723. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  26724. type: string
  26725. type: object
  26726. servicePrincipal:
  26727. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  26728. properties:
  26729. secretRef:
  26730. description: |-
  26731. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  26732. It uses static credentials stored in a Kind=Secret.
  26733. properties:
  26734. clientId:
  26735. description: The Azure clientId of the service principle used for authentication.
  26736. properties:
  26737. key:
  26738. description: |-
  26739. A key in the referenced Secret.
  26740. Some instances of this field may be defaulted, in others it may be required.
  26741. maxLength: 253
  26742. minLength: 1
  26743. pattern: ^[-._a-zA-Z0-9]+$
  26744. type: string
  26745. name:
  26746. description: The name of the Secret resource being referred to.
  26747. maxLength: 253
  26748. minLength: 1
  26749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26750. type: string
  26751. namespace:
  26752. description: |-
  26753. The namespace of the Secret resource being referred to.
  26754. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26755. maxLength: 63
  26756. minLength: 1
  26757. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26758. type: string
  26759. type: object
  26760. clientSecret:
  26761. description: The Azure ClientSecret of the service principle used for authentication.
  26762. properties:
  26763. key:
  26764. description: |-
  26765. A key in the referenced Secret.
  26766. Some instances of this field may be defaulted, in others it may be required.
  26767. maxLength: 253
  26768. minLength: 1
  26769. pattern: ^[-._a-zA-Z0-9]+$
  26770. type: string
  26771. name:
  26772. description: The name of the Secret resource being referred to.
  26773. maxLength: 253
  26774. minLength: 1
  26775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26776. type: string
  26777. namespace:
  26778. description: |-
  26779. The namespace of the Secret resource being referred to.
  26780. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26781. maxLength: 63
  26782. minLength: 1
  26783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26784. type: string
  26785. type: object
  26786. type: object
  26787. required:
  26788. - secretRef
  26789. type: object
  26790. workloadIdentity:
  26791. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  26792. properties:
  26793. serviceAccountRef:
  26794. description: |-
  26795. ServiceAccountRef specified the service account
  26796. that should be used when authenticating with WorkloadIdentity.
  26797. properties:
  26798. audiences:
  26799. description: |-
  26800. Audience specifies the `aud` claim for the service account token
  26801. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  26802. then this audiences will be appended to the list
  26803. items:
  26804. type: string
  26805. type: array
  26806. name:
  26807. description: The name of the ServiceAccount resource being referred to.
  26808. maxLength: 253
  26809. minLength: 1
  26810. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26811. type: string
  26812. namespace:
  26813. description: |-
  26814. Namespace of the resource being referred to.
  26815. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26816. maxLength: 63
  26817. minLength: 1
  26818. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26819. type: string
  26820. required:
  26821. - name
  26822. type: object
  26823. type: object
  26824. type: object
  26825. environmentType:
  26826. default: PublicCloud
  26827. description: |-
  26828. EnvironmentType specifies the Azure cloud environment endpoints to use for
  26829. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  26830. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  26831. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  26832. enum:
  26833. - PublicCloud
  26834. - USGovernmentCloud
  26835. - ChinaCloud
  26836. - GermanCloud
  26837. - AzureStackCloud
  26838. type: string
  26839. registry:
  26840. description: |-
  26841. the domain name of the ACR registry
  26842. e.g. foobarexample.azurecr.io
  26843. type: string
  26844. scope:
  26845. description: |-
  26846. Define the scope for the access token, e.g. pull/push access for a repository.
  26847. if not provided it will return a refresh token that has full scope.
  26848. Note: you need to pin it down to the repository level, there is no wildcard available.
  26849. examples:
  26850. repository:my-repository:pull,push
  26851. repository:my-repository:pull
  26852. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  26853. type: string
  26854. tenantId:
  26855. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  26856. type: string
  26857. required:
  26858. - auth
  26859. - registry
  26860. type: object
  26861. type: object
  26862. served: true
  26863. storage: true
  26864. subresources:
  26865. status: {}
  26866. ---
  26867. apiVersion: apiextensions.k8s.io/v1
  26868. kind: CustomResourceDefinition
  26869. metadata:
  26870. annotations:
  26871. controller-gen.kubebuilder.io/version: v0.19.0
  26872. labels:
  26873. external-secrets.io/component: controller
  26874. name: beyondtrustworkloadcredentialsdynamicsecrets.generators.external-secrets.io
  26875. spec:
  26876. group: generators.external-secrets.io
  26877. names:
  26878. categories:
  26879. - external-secrets
  26880. - external-secrets-generators
  26881. kind: BeyondtrustWorkloadCredentialsDynamicSecret
  26882. listKind: BeyondtrustWorkloadCredentialsDynamicSecretList
  26883. plural: beyondtrustworkloadcredentialsdynamicsecrets
  26884. singular: beyondtrustworkloadcredentialsdynamicsecret
  26885. scope: Namespaced
  26886. versions:
  26887. - name: v1alpha1
  26888. schema:
  26889. openAPIV3Schema:
  26890. description: |-
  26891. BeyondtrustWorkloadCredentialsDynamicSecret represents a generator that requests dynamic credentials from BeyondTrust Workload Credentials.
  26892. This generator calls the BeyondTrust Workload Credentials API to generate fresh, temporary credentials
  26893. (such as AWS STS credentials) each time an ExternalSecret is refreshed.
  26894. Dynamic secret definitions must be created in BeyondTrust Workload Credentials before they can be referenced.
  26895. For complete documentation, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26896. properties:
  26897. apiVersion:
  26898. description: |-
  26899. APIVersion defines the versioned schema of this representation of an object.
  26900. Servers should convert recognized schemas to the latest internal value, and
  26901. may reject unrecognized values.
  26902. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  26903. type: string
  26904. kind:
  26905. description: |-
  26906. Kind is a string value representing the REST resource this object represents.
  26907. Servers may infer this from the endpoint the client submits requests to.
  26908. Cannot be updated.
  26909. In CamelCase.
  26910. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  26911. type: string
  26912. metadata:
  26913. type: object
  26914. spec:
  26915. description: |-
  26916. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  26917. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  26918. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26919. properties:
  26920. controller:
  26921. description: |-
  26922. Controller selects the controller that should handle this generator.
  26923. Leave empty to use the default controller.
  26924. type: string
  26925. provider:
  26926. description: |-
  26927. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  26928. server connection details, and the folder path to the dynamic secret definition.
  26929. The folderPath should point to a dynamic secret definition that has been created in
  26930. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  26931. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26932. properties:
  26933. auth:
  26934. description: |-
  26935. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  26936. Currently supports API key authentication via Kubernetes secret reference.
  26937. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  26938. properties:
  26939. apikey:
  26940. description: |-
  26941. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  26942. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  26943. properties:
  26944. token:
  26945. description: |-
  26946. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  26947. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  26948. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  26949. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  26950. properties:
  26951. key:
  26952. description: |-
  26953. A key in the referenced Secret.
  26954. Some instances of this field may be defaulted, in others it may be required.
  26955. maxLength: 253
  26956. minLength: 1
  26957. pattern: ^[-._a-zA-Z0-9]+$
  26958. type: string
  26959. name:
  26960. description: The name of the Secret resource being referred to.
  26961. maxLength: 253
  26962. minLength: 1
  26963. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26964. type: string
  26965. namespace:
  26966. description: |-
  26967. The namespace of the Secret resource being referred to.
  26968. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26969. maxLength: 63
  26970. minLength: 1
  26971. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26972. type: string
  26973. type: object
  26974. required:
  26975. - token
  26976. type: object
  26977. required:
  26978. - apikey
  26979. type: object
  26980. caBundle:
  26981. description: |-
  26982. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  26983. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  26984. If not set, the system's trusted root certificates are used.
  26985. format: byte
  26986. type: string
  26987. caProvider:
  26988. description: |-
  26989. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  26990. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  26991. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  26992. properties:
  26993. key:
  26994. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26995. maxLength: 253
  26996. minLength: 1
  26997. pattern: ^[-._a-zA-Z0-9]+$
  26998. type: string
  26999. name:
  27000. description: The name of the object located at the provider type.
  27001. maxLength: 253
  27002. minLength: 1
  27003. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27004. type: string
  27005. namespace:
  27006. description: |-
  27007. The namespace the Provider type is in.
  27008. Can only be defined when used in a ClusterSecretStore.
  27009. maxLength: 63
  27010. minLength: 1
  27011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27012. type: string
  27013. type:
  27014. description: The type of provider to use such as "Secret", or "ConfigMap".
  27015. enum:
  27016. - Secret
  27017. - ConfigMap
  27018. type: string
  27019. required:
  27020. - name
  27021. - type
  27022. type: object
  27023. folderPath:
  27024. description: |-
  27025. FolderPath specifies the default folder path for secret retrieval.
  27026. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  27027. Example: "production/database" or "dev/api-keys"
  27028. Leave empty to retrieve secrets from the root folder.
  27029. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  27030. type: string
  27031. server:
  27032. description: |-
  27033. Server configures the BeyondTrust Workload Credentials server connection details.
  27034. Includes the API URL and Site ID for your BeyondTrust instance.
  27035. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27036. properties:
  27037. apiUrl:
  27038. description: |-
  27039. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  27040. This should be the full URL to your BeyondTrust instance.
  27041. Example: https://api.beyondtrust.io/siie
  27042. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  27043. type: string
  27044. siteId:
  27045. description: |-
  27046. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  27047. This identifier is unique to your BeyondTrust Workload Credentials instance.
  27048. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  27049. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  27050. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27051. type: string
  27052. required:
  27053. - apiUrl
  27054. - siteId
  27055. type: object
  27056. required:
  27057. - auth
  27058. - server
  27059. type: object
  27060. retrySettings:
  27061. description: |-
  27062. RetrySettings configures exponential backoff for failed API requests.
  27063. If not specified, uses the default retry settings.
  27064. properties:
  27065. maxRetries:
  27066. format: int32
  27067. type: integer
  27068. retryInterval:
  27069. type: string
  27070. type: object
  27071. required:
  27072. - provider
  27073. type: object
  27074. type: object
  27075. served: true
  27076. storage: true
  27077. subresources:
  27078. status: {}
  27079. ---
  27080. apiVersion: apiextensions.k8s.io/v1
  27081. kind: CustomResourceDefinition
  27082. metadata:
  27083. annotations:
  27084. controller-gen.kubebuilder.io/version: v0.19.0
  27085. labels:
  27086. external-secrets.io/component: controller
  27087. name: cloudsmithaccesstokens.generators.external-secrets.io
  27088. spec:
  27089. group: generators.external-secrets.io
  27090. names:
  27091. categories:
  27092. - external-secrets
  27093. - external-secrets-generators
  27094. kind: CloudsmithAccessToken
  27095. listKind: CloudsmithAccessTokenList
  27096. plural: cloudsmithaccesstokens
  27097. singular: cloudsmithaccesstoken
  27098. scope: Namespaced
  27099. versions:
  27100. - name: v1alpha1
  27101. schema:
  27102. openAPIV3Schema:
  27103. description: CloudsmithAccessToken generates Cloudsmith access token using OIDC authentication
  27104. properties:
  27105. apiVersion:
  27106. description: |-
  27107. APIVersion defines the versioned schema of this representation of an object.
  27108. Servers should convert recognized schemas to the latest internal value, and
  27109. may reject unrecognized values.
  27110. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27111. type: string
  27112. kind:
  27113. description: |-
  27114. Kind is a string value representing the REST resource this object represents.
  27115. Servers may infer this from the endpoint the client submits requests to.
  27116. Cannot be updated.
  27117. In CamelCase.
  27118. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27119. type: string
  27120. metadata:
  27121. type: object
  27122. spec:
  27123. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  27124. properties:
  27125. apiUrl:
  27126. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  27127. type: string
  27128. orgSlug:
  27129. description: OrgSlug is the organization slug in Cloudsmith
  27130. type: string
  27131. serviceAccountRef:
  27132. description: Name of the service account you are federating with
  27133. properties:
  27134. audiences:
  27135. description: |-
  27136. Audience specifies the `aud` claim for the service account token
  27137. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27138. then this audiences will be appended to the list
  27139. items:
  27140. type: string
  27141. type: array
  27142. name:
  27143. description: The name of the ServiceAccount resource being referred to.
  27144. maxLength: 253
  27145. minLength: 1
  27146. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27147. type: string
  27148. namespace:
  27149. description: |-
  27150. Namespace of the resource being referred to.
  27151. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27152. maxLength: 63
  27153. minLength: 1
  27154. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27155. type: string
  27156. required:
  27157. - name
  27158. type: object
  27159. serviceSlug:
  27160. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  27161. type: string
  27162. required:
  27163. - orgSlug
  27164. - serviceAccountRef
  27165. - serviceSlug
  27166. type: object
  27167. type: object
  27168. served: true
  27169. storage: true
  27170. subresources:
  27171. status: {}
  27172. ---
  27173. apiVersion: apiextensions.k8s.io/v1
  27174. kind: CustomResourceDefinition
  27175. metadata:
  27176. annotations:
  27177. controller-gen.kubebuilder.io/version: v0.19.0
  27178. labels:
  27179. external-secrets.io/component: controller
  27180. name: clustergenerators.generators.external-secrets.io
  27181. spec:
  27182. group: generators.external-secrets.io
  27183. names:
  27184. categories:
  27185. - external-secrets
  27186. - external-secrets-generators
  27187. kind: ClusterGenerator
  27188. listKind: ClusterGeneratorList
  27189. plural: clustergenerators
  27190. singular: clustergenerator
  27191. scope: Cluster
  27192. versions:
  27193. - name: v1alpha1
  27194. schema:
  27195. openAPIV3Schema:
  27196. description: ClusterGenerator represents a cluster-wide generator which can be referenced as part of `generatorRef` fields.
  27197. properties:
  27198. apiVersion:
  27199. description: |-
  27200. APIVersion defines the versioned schema of this representation of an object.
  27201. Servers should convert recognized schemas to the latest internal value, and
  27202. may reject unrecognized values.
  27203. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27204. type: string
  27205. kind:
  27206. description: |-
  27207. Kind is a string value representing the REST resource this object represents.
  27208. Servers may infer this from the endpoint the client submits requests to.
  27209. Cannot be updated.
  27210. In CamelCase.
  27211. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27212. type: string
  27213. metadata:
  27214. type: object
  27215. spec:
  27216. description: ClusterGeneratorSpec defines the desired state of a ClusterGenerator.
  27217. properties:
  27218. generator:
  27219. description: Generator the spec for this generator, must match the kind.
  27220. maxProperties: 1
  27221. minProperties: 1
  27222. properties:
  27223. acrAccessTokenSpec:
  27224. description: |-
  27225. ACRAccessTokenSpec defines how to generate the access token
  27226. e.g. how to authenticate and which registry to use.
  27227. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  27228. properties:
  27229. auth:
  27230. description: ACRAuth defines the authentication methods for Azure Container Registry.
  27231. properties:
  27232. managedIdentity:
  27233. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  27234. properties:
  27235. identityId:
  27236. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  27237. type: string
  27238. type: object
  27239. servicePrincipal:
  27240. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  27241. properties:
  27242. secretRef:
  27243. description: |-
  27244. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  27245. It uses static credentials stored in a Kind=Secret.
  27246. properties:
  27247. clientId:
  27248. description: The Azure clientId of the service principle used for authentication.
  27249. properties:
  27250. key:
  27251. description: |-
  27252. A key in the referenced Secret.
  27253. Some instances of this field may be defaulted, in others it may be required.
  27254. maxLength: 253
  27255. minLength: 1
  27256. pattern: ^[-._a-zA-Z0-9]+$
  27257. type: string
  27258. name:
  27259. description: The name of the Secret resource being referred to.
  27260. maxLength: 253
  27261. minLength: 1
  27262. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27263. type: string
  27264. namespace:
  27265. description: |-
  27266. The namespace of the Secret resource being referred to.
  27267. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27268. maxLength: 63
  27269. minLength: 1
  27270. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27271. type: string
  27272. type: object
  27273. clientSecret:
  27274. description: The Azure ClientSecret of the service principle used for authentication.
  27275. properties:
  27276. key:
  27277. description: |-
  27278. A key in the referenced Secret.
  27279. Some instances of this field may be defaulted, in others it may be required.
  27280. maxLength: 253
  27281. minLength: 1
  27282. pattern: ^[-._a-zA-Z0-9]+$
  27283. type: string
  27284. name:
  27285. description: The name of the Secret resource being referred to.
  27286. maxLength: 253
  27287. minLength: 1
  27288. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27289. type: string
  27290. namespace:
  27291. description: |-
  27292. The namespace of the Secret resource being referred to.
  27293. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27294. maxLength: 63
  27295. minLength: 1
  27296. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27297. type: string
  27298. type: object
  27299. type: object
  27300. required:
  27301. - secretRef
  27302. type: object
  27303. workloadIdentity:
  27304. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  27305. properties:
  27306. serviceAccountRef:
  27307. description: |-
  27308. ServiceAccountRef specified the service account
  27309. that should be used when authenticating with WorkloadIdentity.
  27310. properties:
  27311. audiences:
  27312. description: |-
  27313. Audience specifies the `aud` claim for the service account token
  27314. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27315. then this audiences will be appended to the list
  27316. items:
  27317. type: string
  27318. type: array
  27319. name:
  27320. description: The name of the ServiceAccount resource being referred to.
  27321. maxLength: 253
  27322. minLength: 1
  27323. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27324. type: string
  27325. namespace:
  27326. description: |-
  27327. Namespace of the resource being referred to.
  27328. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27329. maxLength: 63
  27330. minLength: 1
  27331. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27332. type: string
  27333. required:
  27334. - name
  27335. type: object
  27336. type: object
  27337. type: object
  27338. environmentType:
  27339. default: PublicCloud
  27340. description: |-
  27341. EnvironmentType specifies the Azure cloud environment endpoints to use for
  27342. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  27343. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  27344. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  27345. enum:
  27346. - PublicCloud
  27347. - USGovernmentCloud
  27348. - ChinaCloud
  27349. - GermanCloud
  27350. - AzureStackCloud
  27351. type: string
  27352. registry:
  27353. description: |-
  27354. the domain name of the ACR registry
  27355. e.g. foobarexample.azurecr.io
  27356. type: string
  27357. scope:
  27358. description: |-
  27359. Define the scope for the access token, e.g. pull/push access for a repository.
  27360. if not provided it will return a refresh token that has full scope.
  27361. Note: you need to pin it down to the repository level, there is no wildcard available.
  27362. examples:
  27363. repository:my-repository:pull,push
  27364. repository:my-repository:pull
  27365. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  27366. type: string
  27367. tenantId:
  27368. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  27369. type: string
  27370. required:
  27371. - auth
  27372. - registry
  27373. type: object
  27374. beyondtrustWorkloadCredentialsDynamicSecretSpec:
  27375. description: |-
  27376. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  27377. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  27378. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27379. properties:
  27380. controller:
  27381. description: |-
  27382. Controller selects the controller that should handle this generator.
  27383. Leave empty to use the default controller.
  27384. type: string
  27385. provider:
  27386. description: |-
  27387. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  27388. server connection details, and the folder path to the dynamic secret definition.
  27389. The folderPath should point to a dynamic secret definition that has been created in
  27390. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  27391. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27392. properties:
  27393. auth:
  27394. description: |-
  27395. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  27396. Currently supports API key authentication via Kubernetes secret reference.
  27397. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27398. properties:
  27399. apikey:
  27400. description: |-
  27401. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  27402. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  27403. properties:
  27404. token:
  27405. description: |-
  27406. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  27407. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  27408. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  27409. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27410. properties:
  27411. key:
  27412. description: |-
  27413. A key in the referenced Secret.
  27414. Some instances of this field may be defaulted, in others it may be required.
  27415. maxLength: 253
  27416. minLength: 1
  27417. pattern: ^[-._a-zA-Z0-9]+$
  27418. type: string
  27419. name:
  27420. description: The name of the Secret resource being referred to.
  27421. maxLength: 253
  27422. minLength: 1
  27423. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27424. type: string
  27425. namespace:
  27426. description: |-
  27427. The namespace of the Secret resource being referred to.
  27428. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27429. maxLength: 63
  27430. minLength: 1
  27431. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27432. type: string
  27433. type: object
  27434. required:
  27435. - token
  27436. type: object
  27437. required:
  27438. - apikey
  27439. type: object
  27440. caBundle:
  27441. description: |-
  27442. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27443. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  27444. If not set, the system's trusted root certificates are used.
  27445. format: byte
  27446. type: string
  27447. caProvider:
  27448. description: |-
  27449. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  27450. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27451. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  27452. properties:
  27453. key:
  27454. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  27455. maxLength: 253
  27456. minLength: 1
  27457. pattern: ^[-._a-zA-Z0-9]+$
  27458. type: string
  27459. name:
  27460. description: The name of the object located at the provider type.
  27461. maxLength: 253
  27462. minLength: 1
  27463. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27464. type: string
  27465. namespace:
  27466. description: |-
  27467. The namespace the Provider type is in.
  27468. Can only be defined when used in a ClusterSecretStore.
  27469. maxLength: 63
  27470. minLength: 1
  27471. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27472. type: string
  27473. type:
  27474. description: The type of provider to use such as "Secret", or "ConfigMap".
  27475. enum:
  27476. - Secret
  27477. - ConfigMap
  27478. type: string
  27479. required:
  27480. - name
  27481. - type
  27482. type: object
  27483. folderPath:
  27484. description: |-
  27485. FolderPath specifies the default folder path for secret retrieval.
  27486. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  27487. Example: "production/database" or "dev/api-keys"
  27488. Leave empty to retrieve secrets from the root folder.
  27489. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  27490. type: string
  27491. server:
  27492. description: |-
  27493. Server configures the BeyondTrust Workload Credentials server connection details.
  27494. Includes the API URL and Site ID for your BeyondTrust instance.
  27495. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27496. properties:
  27497. apiUrl:
  27498. description: |-
  27499. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  27500. This should be the full URL to your BeyondTrust instance.
  27501. Example: https://api.beyondtrust.io/siie
  27502. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  27503. type: string
  27504. siteId:
  27505. description: |-
  27506. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  27507. This identifier is unique to your BeyondTrust Workload Credentials instance.
  27508. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  27509. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  27510. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27511. type: string
  27512. required:
  27513. - apiUrl
  27514. - siteId
  27515. type: object
  27516. required:
  27517. - auth
  27518. - server
  27519. type: object
  27520. retrySettings:
  27521. description: |-
  27522. RetrySettings configures exponential backoff for failed API requests.
  27523. If not specified, uses the default retry settings.
  27524. properties:
  27525. maxRetries:
  27526. format: int32
  27527. type: integer
  27528. retryInterval:
  27529. type: string
  27530. type: object
  27531. required:
  27532. - provider
  27533. type: object
  27534. cloudsmithAccessTokenSpec:
  27535. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  27536. properties:
  27537. apiUrl:
  27538. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  27539. type: string
  27540. orgSlug:
  27541. description: OrgSlug is the organization slug in Cloudsmith
  27542. type: string
  27543. serviceAccountRef:
  27544. description: Name of the service account you are federating with
  27545. properties:
  27546. audiences:
  27547. description: |-
  27548. Audience specifies the `aud` claim for the service account token
  27549. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27550. then this audiences will be appended to the list
  27551. items:
  27552. type: string
  27553. type: array
  27554. name:
  27555. description: The name of the ServiceAccount resource being referred to.
  27556. maxLength: 253
  27557. minLength: 1
  27558. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27559. type: string
  27560. namespace:
  27561. description: |-
  27562. Namespace of the resource being referred to.
  27563. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27564. maxLength: 63
  27565. minLength: 1
  27566. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27567. type: string
  27568. required:
  27569. - name
  27570. type: object
  27571. serviceSlug:
  27572. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  27573. type: string
  27574. required:
  27575. - orgSlug
  27576. - serviceAccountRef
  27577. - serviceSlug
  27578. type: object
  27579. ecrAuthorizationTokenSpec:
  27580. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  27581. properties:
  27582. auth:
  27583. description: Auth defines how to authenticate with AWS
  27584. properties:
  27585. jwt:
  27586. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  27587. properties:
  27588. serviceAccountRef:
  27589. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  27590. properties:
  27591. audiences:
  27592. description: |-
  27593. Audience specifies the `aud` claim for the service account token
  27594. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27595. then this audiences will be appended to the list
  27596. items:
  27597. type: string
  27598. type: array
  27599. name:
  27600. description: The name of the ServiceAccount resource being referred to.
  27601. maxLength: 253
  27602. minLength: 1
  27603. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27604. type: string
  27605. namespace:
  27606. description: |-
  27607. Namespace of the resource being referred to.
  27608. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27609. maxLength: 63
  27610. minLength: 1
  27611. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27612. type: string
  27613. required:
  27614. - name
  27615. type: object
  27616. type: object
  27617. secretRef:
  27618. description: |-
  27619. AWSAuthSecretRef holds secret references for AWS credentials
  27620. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  27621. properties:
  27622. accessKeyIDSecretRef:
  27623. description: The AccessKeyID is used for authentication
  27624. properties:
  27625. key:
  27626. description: |-
  27627. A key in the referenced Secret.
  27628. Some instances of this field may be defaulted, in others it may be required.
  27629. maxLength: 253
  27630. minLength: 1
  27631. pattern: ^[-._a-zA-Z0-9]+$
  27632. type: string
  27633. name:
  27634. description: The name of the Secret resource being referred to.
  27635. maxLength: 253
  27636. minLength: 1
  27637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27638. type: string
  27639. namespace:
  27640. description: |-
  27641. The namespace of the Secret resource being referred to.
  27642. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27643. maxLength: 63
  27644. minLength: 1
  27645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27646. type: string
  27647. type: object
  27648. secretAccessKeySecretRef:
  27649. description: The SecretAccessKey is used for authentication
  27650. properties:
  27651. key:
  27652. description: |-
  27653. A key in the referenced Secret.
  27654. Some instances of this field may be defaulted, in others it may be required.
  27655. maxLength: 253
  27656. minLength: 1
  27657. pattern: ^[-._a-zA-Z0-9]+$
  27658. type: string
  27659. name:
  27660. description: The name of the Secret resource being referred to.
  27661. maxLength: 253
  27662. minLength: 1
  27663. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27664. type: string
  27665. namespace:
  27666. description: |-
  27667. The namespace of the Secret resource being referred to.
  27668. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27669. maxLength: 63
  27670. minLength: 1
  27671. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27672. type: string
  27673. type: object
  27674. sessionTokenSecretRef:
  27675. description: |-
  27676. The SessionToken used for authentication
  27677. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  27678. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  27679. properties:
  27680. key:
  27681. description: |-
  27682. A key in the referenced Secret.
  27683. Some instances of this field may be defaulted, in others it may be required.
  27684. maxLength: 253
  27685. minLength: 1
  27686. pattern: ^[-._a-zA-Z0-9]+$
  27687. type: string
  27688. name:
  27689. description: The name of the Secret resource being referred to.
  27690. maxLength: 253
  27691. minLength: 1
  27692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27693. type: string
  27694. namespace:
  27695. description: |-
  27696. The namespace of the Secret resource being referred to.
  27697. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27698. maxLength: 63
  27699. minLength: 1
  27700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27701. type: string
  27702. type: object
  27703. type: object
  27704. type: object
  27705. region:
  27706. description: Region specifies the region to operate in.
  27707. type: string
  27708. role:
  27709. description: |-
  27710. You can assume a role before making calls to the
  27711. desired AWS service.
  27712. type: string
  27713. scope:
  27714. description: |-
  27715. Scope specifies the ECR service scope.
  27716. Valid options are private and public.
  27717. type: string
  27718. required:
  27719. - region
  27720. type: object
  27721. fakeSpec:
  27722. description: FakeSpec contains the static data.
  27723. properties:
  27724. controller:
  27725. description: |-
  27726. Used to select the correct ESO controller (think: ingress.ingressClassName)
  27727. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  27728. type: string
  27729. data:
  27730. additionalProperties:
  27731. type: string
  27732. description: |-
  27733. Data defines the static data returned
  27734. by this generator.
  27735. type: object
  27736. type: object
  27737. gcrAccessTokenSpec:
  27738. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  27739. properties:
  27740. auth:
  27741. description: Auth defines the means for authenticating with GCP
  27742. properties:
  27743. secretRef:
  27744. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  27745. properties:
  27746. secretAccessKeySecretRef:
  27747. description: The SecretAccessKey is used for authentication
  27748. properties:
  27749. key:
  27750. description: |-
  27751. A key in the referenced Secret.
  27752. Some instances of this field may be defaulted, in others it may be required.
  27753. maxLength: 253
  27754. minLength: 1
  27755. pattern: ^[-._a-zA-Z0-9]+$
  27756. type: string
  27757. name:
  27758. description: The name of the Secret resource being referred to.
  27759. maxLength: 253
  27760. minLength: 1
  27761. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27762. type: string
  27763. namespace:
  27764. description: |-
  27765. The namespace of the Secret resource being referred to.
  27766. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27767. maxLength: 63
  27768. minLength: 1
  27769. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27770. type: string
  27771. type: object
  27772. type: object
  27773. workloadIdentity:
  27774. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  27775. properties:
  27776. clusterLocation:
  27777. type: string
  27778. clusterName:
  27779. type: string
  27780. clusterProjectID:
  27781. type: string
  27782. serviceAccountRef:
  27783. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  27784. properties:
  27785. audiences:
  27786. description: |-
  27787. Audience specifies the `aud` claim for the service account token
  27788. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27789. then this audiences will be appended to the list
  27790. items:
  27791. type: string
  27792. type: array
  27793. name:
  27794. description: The name of the ServiceAccount resource being referred to.
  27795. maxLength: 253
  27796. minLength: 1
  27797. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27798. type: string
  27799. namespace:
  27800. description: |-
  27801. Namespace of the resource being referred to.
  27802. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27803. maxLength: 63
  27804. minLength: 1
  27805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27806. type: string
  27807. required:
  27808. - name
  27809. type: object
  27810. required:
  27811. - clusterLocation
  27812. - clusterName
  27813. - serviceAccountRef
  27814. type: object
  27815. workloadIdentityFederation:
  27816. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  27817. properties:
  27818. audience:
  27819. description: |-
  27820. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  27821. If specified, Audience found in the external account credential config will be overridden with the configured value.
  27822. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  27823. type: string
  27824. awsSecurityCredentials:
  27825. description: |-
  27826. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  27827. when using the AWS metadata server is not an option.
  27828. properties:
  27829. awsCredentialsSecretRef:
  27830. description: |-
  27831. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  27832. Secret should be created with below names for keys
  27833. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  27834. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  27835. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  27836. properties:
  27837. name:
  27838. description: name of the secret.
  27839. maxLength: 253
  27840. minLength: 1
  27841. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27842. type: string
  27843. namespace:
  27844. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  27845. maxLength: 63
  27846. minLength: 1
  27847. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27848. type: string
  27849. required:
  27850. - name
  27851. type: object
  27852. region:
  27853. description: region is for configuring the AWS region to be used.
  27854. example: ap-south-1
  27855. maxLength: 50
  27856. minLength: 1
  27857. pattern: ^[a-z0-9-]+$
  27858. type: string
  27859. required:
  27860. - awsCredentialsSecretRef
  27861. - region
  27862. type: object
  27863. credConfig:
  27864. description: |-
  27865. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  27866. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  27867. serviceAccountRef must be used by providing operators service account details.
  27868. properties:
  27869. key:
  27870. description: key name holding the external account credential config.
  27871. maxLength: 253
  27872. minLength: 1
  27873. pattern: ^[-._a-zA-Z0-9]+$
  27874. type: string
  27875. name:
  27876. description: name of the configmap.
  27877. maxLength: 253
  27878. minLength: 1
  27879. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27880. type: string
  27881. namespace:
  27882. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  27883. maxLength: 63
  27884. minLength: 1
  27885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27886. type: string
  27887. required:
  27888. - key
  27889. - name
  27890. type: object
  27891. externalTokenEndpoint:
  27892. description: |-
  27893. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  27894. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  27895. URL is having the expected value.
  27896. type: string
  27897. gcpServiceAccountEmail:
  27898. description: |-
  27899. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  27900. after Workload Identity Federation. Use this to grant access through the service account's
  27901. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  27902. service_account_impersonation_url in the external account JSON from credConfig;
  27903. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  27904. on that ServiceAccount.
  27905. example: my-gsa@my-project.iam.gserviceaccount.com
  27906. minLength: 1
  27907. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  27908. type: string
  27909. serviceAccountRef:
  27910. description: |-
  27911. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  27912. when Kubernetes is configured as provider in workload identity pool.
  27913. properties:
  27914. audiences:
  27915. description: |-
  27916. Audience specifies the `aud` claim for the service account token
  27917. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27918. then this audiences will be appended to the list
  27919. items:
  27920. type: string
  27921. type: array
  27922. name:
  27923. description: The name of the ServiceAccount resource being referred to.
  27924. maxLength: 253
  27925. minLength: 1
  27926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27927. type: string
  27928. namespace:
  27929. description: |-
  27930. Namespace of the resource being referred to.
  27931. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27932. maxLength: 63
  27933. minLength: 1
  27934. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27935. type: string
  27936. required:
  27937. - name
  27938. type: object
  27939. type: object
  27940. type: object
  27941. projectID:
  27942. description: ProjectID defines which project to use to authenticate with
  27943. type: string
  27944. required:
  27945. - auth
  27946. - projectID
  27947. type: object
  27948. githubAccessTokenSpec:
  27949. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  27950. properties:
  27951. appID:
  27952. type: string
  27953. auth:
  27954. description: Auth configures how ESO authenticates with a Github instance.
  27955. properties:
  27956. privateKey:
  27957. description: GithubSecretRef references a secret containing GitHub credentials.
  27958. properties:
  27959. secretRef:
  27960. description: |-
  27961. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  27962. In some instances, `key` is a required field.
  27963. properties:
  27964. key:
  27965. description: |-
  27966. A key in the referenced Secret.
  27967. Some instances of this field may be defaulted, in others it may be required.
  27968. maxLength: 253
  27969. minLength: 1
  27970. pattern: ^[-._a-zA-Z0-9]+$
  27971. type: string
  27972. name:
  27973. description: The name of the Secret resource being referred to.
  27974. maxLength: 253
  27975. minLength: 1
  27976. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27977. type: string
  27978. namespace:
  27979. description: |-
  27980. The namespace of the Secret resource being referred to.
  27981. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27982. maxLength: 63
  27983. minLength: 1
  27984. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27985. type: string
  27986. type: object
  27987. required:
  27988. - secretRef
  27989. type: object
  27990. required:
  27991. - privateKey
  27992. type: object
  27993. installID:
  27994. type: string
  27995. permissions:
  27996. additionalProperties:
  27997. type: string
  27998. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  27999. type: object
  28000. repositories:
  28001. description: |-
  28002. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  28003. is installed to.
  28004. items:
  28005. type: string
  28006. type: array
  28007. url:
  28008. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  28009. type: string
  28010. required:
  28011. - appID
  28012. - auth
  28013. - installID
  28014. type: object
  28015. gitlabDeployTokenSpec:
  28016. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  28017. properties:
  28018. auth:
  28019. description: Auth configures how ESO authenticates with the GitLab API.
  28020. properties:
  28021. token:
  28022. description: |-
  28023. Token references a secret containing a GitLab access token (personal, group, or
  28024. project) with the api scope and at least the Maintainer role on the target.
  28025. properties:
  28026. secretRef:
  28027. description: |-
  28028. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28029. In some instances, `key` is a required field.
  28030. properties:
  28031. key:
  28032. description: |-
  28033. A key in the referenced Secret.
  28034. Some instances of this field may be defaulted, in others it may be required.
  28035. maxLength: 253
  28036. minLength: 1
  28037. pattern: ^[-._a-zA-Z0-9]+$
  28038. type: string
  28039. name:
  28040. description: The name of the Secret resource being referred to.
  28041. maxLength: 253
  28042. minLength: 1
  28043. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28044. type: string
  28045. namespace:
  28046. description: |-
  28047. The namespace of the Secret resource being referred to.
  28048. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28049. maxLength: 63
  28050. minLength: 1
  28051. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28052. type: string
  28053. type: object
  28054. required:
  28055. - secretRef
  28056. type: object
  28057. required:
  28058. - token
  28059. type: object
  28060. expiresAt:
  28061. description: |-
  28062. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  28063. not expire on the GitLab side and is revoked only when the generator state is
  28064. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  28065. format: date-time
  28066. type: string
  28067. groupID:
  28068. description: |-
  28069. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  28070. create the deploy token in. The generator URL-escapes paths before calling the
  28071. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  28072. minLength: 1
  28073. type: string
  28074. name:
  28075. description: Name of the deploy token.
  28076. minLength: 1
  28077. type: string
  28078. projectID:
  28079. description: |-
  28080. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  28081. project to create the deploy token in. The generator URL-escapes paths before
  28082. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  28083. minLength: 1
  28084. type: string
  28085. scopes:
  28086. description: Scopes granted to the deploy token. At least one scope is required.
  28087. items:
  28088. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  28089. enum:
  28090. - read_repository
  28091. - read_registry
  28092. - write_registry
  28093. - read_package_registry
  28094. - write_package_registry
  28095. - read_virtual_registry
  28096. - write_virtual_registry
  28097. type: string
  28098. minItems: 1
  28099. type: array
  28100. url:
  28101. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  28102. type: string
  28103. username:
  28104. description: |-
  28105. Username is an optional username for the deploy token. GitLab defaults it to
  28106. gitlab+deploy-token-{n} when omitted.
  28107. type: string
  28108. required:
  28109. - auth
  28110. - name
  28111. - scopes
  28112. type: object
  28113. x-kubernetes-validations:
  28114. - message: exactly one of projectID or groupID must be set
  28115. rule: has(self.projectID) != has(self.groupID)
  28116. grafanaSpec:
  28117. description: GrafanaSpec controls the behavior of the grafana generator.
  28118. properties:
  28119. auth:
  28120. description: |-
  28121. Auth is the authentication configuration to authenticate
  28122. against the Grafana instance.
  28123. properties:
  28124. basic:
  28125. description: |-
  28126. Basic auth credentials used to authenticate against the Grafana instance.
  28127. Note: you need a token which has elevated permissions to create service accounts.
  28128. See here for the documentation on basic roles offered by Grafana:
  28129. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28130. properties:
  28131. password:
  28132. description: A basic auth password used to authenticate against the Grafana instance.
  28133. properties:
  28134. key:
  28135. description: The key where the token is found.
  28136. maxLength: 253
  28137. minLength: 1
  28138. pattern: ^[-._a-zA-Z0-9]+$
  28139. type: string
  28140. name:
  28141. description: The name of the Secret resource being referred to.
  28142. maxLength: 253
  28143. minLength: 1
  28144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28145. type: string
  28146. type: object
  28147. username:
  28148. description: A basic auth username used to authenticate against the Grafana instance.
  28149. type: string
  28150. required:
  28151. - password
  28152. - username
  28153. type: object
  28154. token:
  28155. description: |-
  28156. A service account token used to authenticate against the Grafana instance.
  28157. Note: you need a token which has elevated permissions to create service accounts.
  28158. See here for the documentation on basic roles offered by Grafana:
  28159. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28160. properties:
  28161. key:
  28162. description: The key where the token is found.
  28163. maxLength: 253
  28164. minLength: 1
  28165. pattern: ^[-._a-zA-Z0-9]+$
  28166. type: string
  28167. name:
  28168. description: The name of the Secret resource being referred to.
  28169. maxLength: 253
  28170. minLength: 1
  28171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28172. type: string
  28173. type: object
  28174. type: object
  28175. serviceAccount:
  28176. description: |-
  28177. ServiceAccount is the configuration for the service account that
  28178. is supposed to be generated by the generator.
  28179. properties:
  28180. name:
  28181. description: Name is the name of the service account that will be created by ESO.
  28182. type: string
  28183. role:
  28184. description: |-
  28185. Role is the role of the service account.
  28186. See here for the documentation on basic roles offered by Grafana:
  28187. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28188. type: string
  28189. secondsToLive:
  28190. description: |-
  28191. SecondsToLive is the number of seconds before the generated service account token will expire.
  28192. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  28193. format: int64
  28194. minimum: 1
  28195. type: integer
  28196. required:
  28197. - name
  28198. - role
  28199. type: object
  28200. url:
  28201. description: URL is the URL of the Grafana instance.
  28202. type: string
  28203. required:
  28204. - auth
  28205. - serviceAccount
  28206. - url
  28207. type: object
  28208. mfaSpec:
  28209. description: MFASpec controls the behavior of the mfa generator.
  28210. properties:
  28211. algorithm:
  28212. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  28213. type: string
  28214. length:
  28215. description: Length defines the token length. Defaults to 6 characters.
  28216. type: integer
  28217. secret:
  28218. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  28219. properties:
  28220. key:
  28221. description: |-
  28222. A key in the referenced Secret.
  28223. Some instances of this field may be defaulted, in others it may be required.
  28224. maxLength: 253
  28225. minLength: 1
  28226. pattern: ^[-._a-zA-Z0-9]+$
  28227. type: string
  28228. name:
  28229. description: The name of the Secret resource being referred to.
  28230. maxLength: 253
  28231. minLength: 1
  28232. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28233. type: string
  28234. namespace:
  28235. description: |-
  28236. The namespace of the Secret resource being referred to.
  28237. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28238. maxLength: 63
  28239. minLength: 1
  28240. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28241. type: string
  28242. type: object
  28243. timePeriod:
  28244. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  28245. type: integer
  28246. when:
  28247. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  28248. format: date-time
  28249. type: string
  28250. required:
  28251. - secret
  28252. type: object
  28253. passwordSpec:
  28254. description: PasswordSpec controls the behavior of the password generator.
  28255. properties:
  28256. allowRepeat:
  28257. default: false
  28258. description: set AllowRepeat to true to allow repeating characters.
  28259. type: boolean
  28260. digits:
  28261. description: |-
  28262. Digits specifies the number of digits in the generated
  28263. password. If omitted it defaults to 25% of the length of the password
  28264. type: integer
  28265. encoding:
  28266. default: raw
  28267. description: |-
  28268. Encoding specifies the encoding of the generated password.
  28269. Valid values are:
  28270. - "raw" (default): no encoding
  28271. - "base64": standard base64 encoding
  28272. - "base64url": base64url encoding
  28273. - "base32": base32 encoding
  28274. - "hex": hexadecimal encoding
  28275. enum:
  28276. - base64
  28277. - base64url
  28278. - base32
  28279. - hex
  28280. - raw
  28281. type: string
  28282. length:
  28283. default: 24
  28284. description: |-
  28285. Length of the password to be generated.
  28286. Defaults to 24
  28287. type: integer
  28288. noUpper:
  28289. default: false
  28290. description: Set NoUpper to disable uppercase characters
  28291. type: boolean
  28292. secretKeys:
  28293. description: |-
  28294. SecretKeys defines the keys that will be populated with generated passwords.
  28295. Defaults to "password" when not set.
  28296. items:
  28297. type: string
  28298. minItems: 1
  28299. type: array
  28300. symbolCharacters:
  28301. description: |-
  28302. SymbolCharacters specifies the special characters that should be used
  28303. in the generated password.
  28304. type: string
  28305. symbols:
  28306. description: |-
  28307. Symbols specifies the number of symbol characters in the generated
  28308. password. If omitted it defaults to 25% of the length of the password
  28309. type: integer
  28310. required:
  28311. - allowRepeat
  28312. - length
  28313. - noUpper
  28314. type: object
  28315. quayAccessTokenSpec:
  28316. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  28317. properties:
  28318. robotAccount:
  28319. description: Name of the robot account you are federating with
  28320. type: string
  28321. serviceAccountRef:
  28322. description: Name of the service account you are federating with
  28323. properties:
  28324. audiences:
  28325. description: |-
  28326. Audience specifies the `aud` claim for the service account token
  28327. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28328. then this audiences will be appended to the list
  28329. items:
  28330. type: string
  28331. type: array
  28332. name:
  28333. description: The name of the ServiceAccount resource being referred to.
  28334. maxLength: 253
  28335. minLength: 1
  28336. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28337. type: string
  28338. namespace:
  28339. description: |-
  28340. Namespace of the resource being referred to.
  28341. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28342. maxLength: 63
  28343. minLength: 1
  28344. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28345. type: string
  28346. required:
  28347. - name
  28348. type: object
  28349. url:
  28350. description: URL configures the Quay instance URL. Defaults to quay.io.
  28351. type: string
  28352. required:
  28353. - robotAccount
  28354. - serviceAccountRef
  28355. type: object
  28356. sshKeySpec:
  28357. description: SSHKeySpec controls the behavior of the ssh key generator.
  28358. properties:
  28359. comment:
  28360. description: Comment specifies an optional comment for the SSH key
  28361. type: string
  28362. keySize:
  28363. description: |-
  28364. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  28365. For RSA keys: 2048, 3072, 4096
  28366. For ECDSA keys: 256, 384, 521
  28367. Ignored for ed25519 keys
  28368. maximum: 8192
  28369. minimum: 256
  28370. type: integer
  28371. keyType:
  28372. default: rsa
  28373. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  28374. enum:
  28375. - rsa
  28376. - ecdsa
  28377. - ed25519
  28378. type: string
  28379. type: object
  28380. stsSessionTokenSpec:
  28381. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  28382. properties:
  28383. auth:
  28384. description: Auth defines how to authenticate with AWS
  28385. properties:
  28386. jwt:
  28387. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  28388. properties:
  28389. serviceAccountRef:
  28390. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28391. properties:
  28392. audiences:
  28393. description: |-
  28394. Audience specifies the `aud` claim for the service account token
  28395. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28396. then this audiences will be appended to the list
  28397. items:
  28398. type: string
  28399. type: array
  28400. name:
  28401. description: The name of the ServiceAccount resource being referred to.
  28402. maxLength: 253
  28403. minLength: 1
  28404. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28405. type: string
  28406. namespace:
  28407. description: |-
  28408. Namespace of the resource being referred to.
  28409. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28410. maxLength: 63
  28411. minLength: 1
  28412. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28413. type: string
  28414. required:
  28415. - name
  28416. type: object
  28417. type: object
  28418. secretRef:
  28419. description: |-
  28420. AWSAuthSecretRef holds secret references for AWS credentials
  28421. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  28422. properties:
  28423. accessKeyIDSecretRef:
  28424. description: The AccessKeyID is used for authentication
  28425. properties:
  28426. key:
  28427. description: |-
  28428. A key in the referenced Secret.
  28429. Some instances of this field may be defaulted, in others it may be required.
  28430. maxLength: 253
  28431. minLength: 1
  28432. pattern: ^[-._a-zA-Z0-9]+$
  28433. type: string
  28434. name:
  28435. description: The name of the Secret resource being referred to.
  28436. maxLength: 253
  28437. minLength: 1
  28438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28439. type: string
  28440. namespace:
  28441. description: |-
  28442. The namespace of the Secret resource being referred to.
  28443. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28444. maxLength: 63
  28445. minLength: 1
  28446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28447. type: string
  28448. type: object
  28449. secretAccessKeySecretRef:
  28450. description: The SecretAccessKey is used for authentication
  28451. properties:
  28452. key:
  28453. description: |-
  28454. A key in the referenced Secret.
  28455. Some instances of this field may be defaulted, in others it may be required.
  28456. maxLength: 253
  28457. minLength: 1
  28458. pattern: ^[-._a-zA-Z0-9]+$
  28459. type: string
  28460. name:
  28461. description: The name of the Secret resource being referred to.
  28462. maxLength: 253
  28463. minLength: 1
  28464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28465. type: string
  28466. namespace:
  28467. description: |-
  28468. The namespace of the Secret resource being referred to.
  28469. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28470. maxLength: 63
  28471. minLength: 1
  28472. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28473. type: string
  28474. type: object
  28475. sessionTokenSecretRef:
  28476. description: |-
  28477. The SessionToken used for authentication
  28478. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28479. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28480. properties:
  28481. key:
  28482. description: |-
  28483. A key in the referenced Secret.
  28484. Some instances of this field may be defaulted, in others it may be required.
  28485. maxLength: 253
  28486. minLength: 1
  28487. pattern: ^[-._a-zA-Z0-9]+$
  28488. type: string
  28489. name:
  28490. description: The name of the Secret resource being referred to.
  28491. maxLength: 253
  28492. minLength: 1
  28493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28494. type: string
  28495. namespace:
  28496. description: |-
  28497. The namespace of the Secret resource being referred to.
  28498. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28499. maxLength: 63
  28500. minLength: 1
  28501. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28502. type: string
  28503. type: object
  28504. type: object
  28505. type: object
  28506. region:
  28507. description: Region specifies the region to operate in.
  28508. type: string
  28509. requestParameters:
  28510. description: RequestParameters contains parameters that can be passed to the STS service.
  28511. properties:
  28512. serialNumber:
  28513. description: |-
  28514. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  28515. the GetSessionToken call.
  28516. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  28517. (such as arn:aws:iam::123456789012:mfa/user)
  28518. type: string
  28519. sessionDuration:
  28520. format: int32
  28521. type: integer
  28522. tokenCode:
  28523. description: TokenCode is the value provided by the MFA device, if MFA is required.
  28524. type: string
  28525. type: object
  28526. role:
  28527. description: |-
  28528. You can assume a role before making calls to the
  28529. desired AWS service.
  28530. type: string
  28531. required:
  28532. - region
  28533. type: object
  28534. uuidSpec:
  28535. description: UUIDSpec controls the behavior of the uuid generator.
  28536. type: object
  28537. vaultDynamicSecretSpec:
  28538. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  28539. properties:
  28540. allowEmptyResponse:
  28541. default: false
  28542. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  28543. type: boolean
  28544. controller:
  28545. description: |-
  28546. Used to select the correct ESO controller (think: ingress.ingressClassName)
  28547. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  28548. type: string
  28549. getParameters:
  28550. additionalProperties:
  28551. items:
  28552. type: string
  28553. type: array
  28554. description: |-
  28555. GetParameters are query-string parameters passed to Vault on GET calls.
  28556. Each key may map to multiple values, matching HTTP query-string semantics.
  28557. Ignored for non-GET methods; use Parameters for write bodies.
  28558. type: object
  28559. method:
  28560. description: Vault API method to use (GET/POST/other)
  28561. type: string
  28562. parameters:
  28563. description: Parameters to pass to Vault write (for non-GET methods)
  28564. x-kubernetes-preserve-unknown-fields: true
  28565. path:
  28566. description: Vault path to obtain the dynamic secret from
  28567. type: string
  28568. provider:
  28569. description: Vault provider common spec
  28570. properties:
  28571. auth:
  28572. description: Auth configures how secret-manager authenticates with the Vault server.
  28573. properties:
  28574. appRole:
  28575. description: |-
  28576. AppRole authenticates with Vault using the App Role auth mechanism,
  28577. with the role and secret stored in a Kubernetes Secret resource.
  28578. properties:
  28579. path:
  28580. default: approle
  28581. description: |-
  28582. Path where the App Role authentication backend is mounted
  28583. in Vault, e.g: "approle"
  28584. type: string
  28585. roleId:
  28586. description: |-
  28587. RoleID configured in the App Role authentication backend when setting
  28588. up the authentication backend in Vault.
  28589. type: string
  28590. roleRef:
  28591. description: |-
  28592. Reference to a key in a Secret that contains the App Role ID used
  28593. to authenticate with Vault.
  28594. The `key` field must be specified and denotes which entry within the Secret
  28595. resource is used as the app role id.
  28596. properties:
  28597. key:
  28598. description: |-
  28599. A key in the referenced Secret.
  28600. Some instances of this field may be defaulted, in others it may be required.
  28601. maxLength: 253
  28602. minLength: 1
  28603. pattern: ^[-._a-zA-Z0-9]+$
  28604. type: string
  28605. name:
  28606. description: The name of the Secret resource being referred to.
  28607. maxLength: 253
  28608. minLength: 1
  28609. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28610. type: string
  28611. namespace:
  28612. description: |-
  28613. The namespace of the Secret resource being referred to.
  28614. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28615. maxLength: 63
  28616. minLength: 1
  28617. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28618. type: string
  28619. type: object
  28620. secretRef:
  28621. description: |-
  28622. Reference to a key in a Secret that contains the App Role secret used
  28623. to authenticate with Vault.
  28624. The `key` field must be specified and denotes which entry within the Secret
  28625. resource is used as the app role secret.
  28626. properties:
  28627. key:
  28628. description: |-
  28629. A key in the referenced Secret.
  28630. Some instances of this field may be defaulted, in others it may be required.
  28631. maxLength: 253
  28632. minLength: 1
  28633. pattern: ^[-._a-zA-Z0-9]+$
  28634. type: string
  28635. name:
  28636. description: The name of the Secret resource being referred to.
  28637. maxLength: 253
  28638. minLength: 1
  28639. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28640. type: string
  28641. namespace:
  28642. description: |-
  28643. The namespace of the Secret resource being referred to.
  28644. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28645. maxLength: 63
  28646. minLength: 1
  28647. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28648. type: string
  28649. type: object
  28650. required:
  28651. - path
  28652. - secretRef
  28653. type: object
  28654. cert:
  28655. description: |-
  28656. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  28657. Cert authentication method
  28658. properties:
  28659. clientCert:
  28660. description: |-
  28661. ClientCert is a certificate to authenticate using the Cert Vault
  28662. authentication method
  28663. properties:
  28664. key:
  28665. description: |-
  28666. A key in the referenced Secret.
  28667. Some instances of this field may be defaulted, in others it may be required.
  28668. maxLength: 253
  28669. minLength: 1
  28670. pattern: ^[-._a-zA-Z0-9]+$
  28671. type: string
  28672. name:
  28673. description: The name of the Secret resource being referred to.
  28674. maxLength: 253
  28675. minLength: 1
  28676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28677. type: string
  28678. namespace:
  28679. description: |-
  28680. The namespace of the Secret resource being referred to.
  28681. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28682. maxLength: 63
  28683. minLength: 1
  28684. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28685. type: string
  28686. type: object
  28687. path:
  28688. default: cert
  28689. description: |-
  28690. Path where the Certificate authentication backend is mounted
  28691. in Vault, e.g: "cert"
  28692. type: string
  28693. secretRef:
  28694. description: |-
  28695. SecretRef to a key in a Secret resource containing client private key to
  28696. authenticate with Vault using the Cert authentication method
  28697. properties:
  28698. key:
  28699. description: |-
  28700. A key in the referenced Secret.
  28701. Some instances of this field may be defaulted, in others it may be required.
  28702. maxLength: 253
  28703. minLength: 1
  28704. pattern: ^[-._a-zA-Z0-9]+$
  28705. type: string
  28706. name:
  28707. description: The name of the Secret resource being referred to.
  28708. maxLength: 253
  28709. minLength: 1
  28710. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28711. type: string
  28712. namespace:
  28713. description: |-
  28714. The namespace of the Secret resource being referred to.
  28715. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28716. maxLength: 63
  28717. minLength: 1
  28718. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28719. type: string
  28720. type: object
  28721. vaultRole:
  28722. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  28723. type: string
  28724. type: object
  28725. gcp:
  28726. description: |-
  28727. Gcp authenticates with Vault using Google Cloud Platform authentication method
  28728. GCP authentication method
  28729. properties:
  28730. location:
  28731. description: Location optionally defines a location/region for the secret
  28732. type: string
  28733. path:
  28734. default: gcp
  28735. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  28736. type: string
  28737. projectID:
  28738. description: Project ID of the Google Cloud Platform project
  28739. type: string
  28740. role:
  28741. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  28742. type: string
  28743. secretRef:
  28744. description: Specify credentials in a Secret object
  28745. properties:
  28746. secretAccessKeySecretRef:
  28747. description: The SecretAccessKey is used for authentication
  28748. properties:
  28749. key:
  28750. description: |-
  28751. A key in the referenced Secret.
  28752. Some instances of this field may be defaulted, in others it may be required.
  28753. maxLength: 253
  28754. minLength: 1
  28755. pattern: ^[-._a-zA-Z0-9]+$
  28756. type: string
  28757. name:
  28758. description: The name of the Secret resource being referred to.
  28759. maxLength: 253
  28760. minLength: 1
  28761. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28762. type: string
  28763. namespace:
  28764. description: |-
  28765. The namespace of the Secret resource being referred to.
  28766. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28767. maxLength: 63
  28768. minLength: 1
  28769. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28770. type: string
  28771. type: object
  28772. type: object
  28773. serviceAccountRef:
  28774. description: ServiceAccountRef to a service account for impersonation
  28775. properties:
  28776. audiences:
  28777. description: |-
  28778. Audience specifies the `aud` claim for the service account token
  28779. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28780. then this audiences will be appended to the list
  28781. items:
  28782. type: string
  28783. type: array
  28784. name:
  28785. description: The name of the ServiceAccount resource being referred to.
  28786. maxLength: 253
  28787. minLength: 1
  28788. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28789. type: string
  28790. namespace:
  28791. description: |-
  28792. Namespace of the resource being referred to.
  28793. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28794. maxLength: 63
  28795. minLength: 1
  28796. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28797. type: string
  28798. required:
  28799. - name
  28800. type: object
  28801. workloadIdentity:
  28802. description: Specify a service account with Workload Identity
  28803. properties:
  28804. clusterLocation:
  28805. description: |-
  28806. ClusterLocation is the location of the cluster
  28807. If not specified, it fetches information from the metadata server
  28808. type: string
  28809. clusterName:
  28810. description: |-
  28811. ClusterName is the name of the cluster
  28812. If not specified, it fetches information from the metadata server
  28813. type: string
  28814. clusterProjectID:
  28815. description: |-
  28816. ClusterProjectID is the project ID of the cluster
  28817. If not specified, it fetches information from the metadata server
  28818. type: string
  28819. serviceAccountRef:
  28820. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28821. properties:
  28822. audiences:
  28823. description: |-
  28824. Audience specifies the `aud` claim for the service account token
  28825. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28826. then this audiences will be appended to the list
  28827. items:
  28828. type: string
  28829. type: array
  28830. name:
  28831. description: The name of the ServiceAccount resource being referred to.
  28832. maxLength: 253
  28833. minLength: 1
  28834. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28835. type: string
  28836. namespace:
  28837. description: |-
  28838. Namespace of the resource being referred to.
  28839. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28840. maxLength: 63
  28841. minLength: 1
  28842. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28843. type: string
  28844. required:
  28845. - name
  28846. type: object
  28847. required:
  28848. - serviceAccountRef
  28849. type: object
  28850. required:
  28851. - role
  28852. type: object
  28853. iam:
  28854. description: |-
  28855. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  28856. AWS IAM authentication method
  28857. properties:
  28858. externalID:
  28859. description: AWS External ID set on assumed IAM roles
  28860. type: string
  28861. jwt:
  28862. description: Specify a service account with IRSA enabled
  28863. properties:
  28864. serviceAccountRef:
  28865. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28866. properties:
  28867. audiences:
  28868. description: |-
  28869. Audience specifies the `aud` claim for the service account token
  28870. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28871. then this audiences will be appended to the list
  28872. items:
  28873. type: string
  28874. type: array
  28875. name:
  28876. description: The name of the ServiceAccount resource being referred to.
  28877. maxLength: 253
  28878. minLength: 1
  28879. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28880. type: string
  28881. namespace:
  28882. description: |-
  28883. Namespace of the resource being referred to.
  28884. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28885. maxLength: 63
  28886. minLength: 1
  28887. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28888. type: string
  28889. required:
  28890. - name
  28891. type: object
  28892. type: object
  28893. path:
  28894. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  28895. type: string
  28896. region:
  28897. description: AWS region
  28898. type: string
  28899. role:
  28900. description: This is the AWS role to be assumed before talking to vault
  28901. type: string
  28902. secretRef:
  28903. description: Specify credentials in a Secret object
  28904. properties:
  28905. accessKeyIDSecretRef:
  28906. description: The AccessKeyID is used for authentication
  28907. properties:
  28908. key:
  28909. description: |-
  28910. A key in the referenced Secret.
  28911. Some instances of this field may be defaulted, in others it may be required.
  28912. maxLength: 253
  28913. minLength: 1
  28914. pattern: ^[-._a-zA-Z0-9]+$
  28915. type: string
  28916. name:
  28917. description: The name of the Secret resource being referred to.
  28918. maxLength: 253
  28919. minLength: 1
  28920. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28921. type: string
  28922. namespace:
  28923. description: |-
  28924. The namespace of the Secret resource being referred to.
  28925. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28926. maxLength: 63
  28927. minLength: 1
  28928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28929. type: string
  28930. type: object
  28931. secretAccessKeySecretRef:
  28932. description: The SecretAccessKey is used for authentication
  28933. properties:
  28934. key:
  28935. description: |-
  28936. A key in the referenced Secret.
  28937. Some instances of this field may be defaulted, in others it may be required.
  28938. maxLength: 253
  28939. minLength: 1
  28940. pattern: ^[-._a-zA-Z0-9]+$
  28941. type: string
  28942. name:
  28943. description: The name of the Secret resource being referred to.
  28944. maxLength: 253
  28945. minLength: 1
  28946. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28947. type: string
  28948. namespace:
  28949. description: |-
  28950. The namespace of the Secret resource being referred to.
  28951. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28952. maxLength: 63
  28953. minLength: 1
  28954. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28955. type: string
  28956. type: object
  28957. sessionTokenSecretRef:
  28958. description: |-
  28959. The SessionToken used for authentication
  28960. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28961. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28962. properties:
  28963. key:
  28964. description: |-
  28965. A key in the referenced Secret.
  28966. Some instances of this field may be defaulted, in others it may be required.
  28967. maxLength: 253
  28968. minLength: 1
  28969. pattern: ^[-._a-zA-Z0-9]+$
  28970. type: string
  28971. name:
  28972. description: The name of the Secret resource being referred to.
  28973. maxLength: 253
  28974. minLength: 1
  28975. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28976. type: string
  28977. namespace:
  28978. description: |-
  28979. The namespace of the Secret resource being referred to.
  28980. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28981. maxLength: 63
  28982. minLength: 1
  28983. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28984. type: string
  28985. type: object
  28986. type: object
  28987. vaultAwsIamServerID:
  28988. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  28989. type: string
  28990. vaultRole:
  28991. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  28992. type: string
  28993. required:
  28994. - vaultRole
  28995. type: object
  28996. jwt:
  28997. description: |-
  28998. Jwt authenticates with Vault by passing role and JWT token using the
  28999. JWT/OIDC authentication method
  29000. properties:
  29001. kubernetesServiceAccountToken:
  29002. description: |-
  29003. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  29004. a token for with the `TokenRequest` API.
  29005. properties:
  29006. audiences:
  29007. description: |-
  29008. Optional audiences field that will be used to request a temporary Kubernetes service
  29009. account token for the service account referenced by `serviceAccountRef`.
  29010. Defaults to a single audience `vault` it not specified.
  29011. Deprecated: use serviceAccountRef.Audiences instead
  29012. items:
  29013. type: string
  29014. type: array
  29015. expirationSeconds:
  29016. description: |-
  29017. Optional expiration time in seconds that will be used to request a temporary
  29018. Kubernetes service account token for the service account referenced by
  29019. `serviceAccountRef`.
  29020. Deprecated: this will be removed in the future.
  29021. Defaults to 10 minutes.
  29022. format: int64
  29023. type: integer
  29024. serviceAccountRef:
  29025. description: Service account field containing the name of a kubernetes ServiceAccount.
  29026. properties:
  29027. audiences:
  29028. description: |-
  29029. Audience specifies the `aud` claim for the service account token
  29030. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29031. then this audiences will be appended to the list
  29032. items:
  29033. type: string
  29034. type: array
  29035. name:
  29036. description: The name of the ServiceAccount resource being referred to.
  29037. maxLength: 253
  29038. minLength: 1
  29039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29040. type: string
  29041. namespace:
  29042. description: |-
  29043. Namespace of the resource being referred to.
  29044. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29045. maxLength: 63
  29046. minLength: 1
  29047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29048. type: string
  29049. required:
  29050. - name
  29051. type: object
  29052. required:
  29053. - serviceAccountRef
  29054. type: object
  29055. path:
  29056. default: jwt
  29057. description: |-
  29058. Path where the JWT authentication backend is mounted
  29059. in Vault, e.g: "jwt"
  29060. type: string
  29061. role:
  29062. description: |-
  29063. Role is a JWT role to authenticate using the JWT/OIDC Vault
  29064. authentication method
  29065. type: string
  29066. secretRef:
  29067. description: |-
  29068. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  29069. authenticate with Vault using the JWT/OIDC authentication method.
  29070. properties:
  29071. key:
  29072. description: |-
  29073. A key in the referenced Secret.
  29074. Some instances of this field may be defaulted, in others it may be required.
  29075. maxLength: 253
  29076. minLength: 1
  29077. pattern: ^[-._a-zA-Z0-9]+$
  29078. type: string
  29079. name:
  29080. description: The name of the Secret resource being referred to.
  29081. maxLength: 253
  29082. minLength: 1
  29083. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29084. type: string
  29085. namespace:
  29086. description: |-
  29087. The namespace of the Secret resource being referred to.
  29088. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29089. maxLength: 63
  29090. minLength: 1
  29091. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29092. type: string
  29093. type: object
  29094. required:
  29095. - path
  29096. type: object
  29097. kubernetes:
  29098. description: |-
  29099. Kubernetes authenticates with Vault by passing the ServiceAccount
  29100. token stored in the named Secret resource to the Vault server.
  29101. properties:
  29102. mountPath:
  29103. default: kubernetes
  29104. description: |-
  29105. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  29106. "kubernetes"
  29107. type: string
  29108. role:
  29109. description: |-
  29110. A required field containing the Vault Role to assume. A Role binds a
  29111. Kubernetes ServiceAccount with a set of Vault policies.
  29112. type: string
  29113. secretRef:
  29114. description: |-
  29115. Optional secret field containing a Kubernetes ServiceAccount JWT used
  29116. for authenticating with Vault. If a name is specified without a key,
  29117. `token` is the default. If one is not specified, the one bound to
  29118. the controller will be used.
  29119. properties:
  29120. key:
  29121. description: |-
  29122. A key in the referenced Secret.
  29123. Some instances of this field may be defaulted, in others it may be required.
  29124. maxLength: 253
  29125. minLength: 1
  29126. pattern: ^[-._a-zA-Z0-9]+$
  29127. type: string
  29128. name:
  29129. description: The name of the Secret resource being referred to.
  29130. maxLength: 253
  29131. minLength: 1
  29132. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29133. type: string
  29134. namespace:
  29135. description: |-
  29136. The namespace of the Secret resource being referred to.
  29137. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29138. maxLength: 63
  29139. minLength: 1
  29140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29141. type: string
  29142. type: object
  29143. serviceAccountRef:
  29144. description: |-
  29145. Optional service account field containing the name of a kubernetes ServiceAccount.
  29146. If the service account is specified, the service account secret token JWT will be used
  29147. for authenticating with Vault. If the service account selector is not supplied,
  29148. the secretRef will be used instead.
  29149. properties:
  29150. audiences:
  29151. description: |-
  29152. Audience specifies the `aud` claim for the service account token
  29153. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29154. then this audiences will be appended to the list
  29155. items:
  29156. type: string
  29157. type: array
  29158. name:
  29159. description: The name of the ServiceAccount resource being referred to.
  29160. maxLength: 253
  29161. minLength: 1
  29162. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29163. type: string
  29164. namespace:
  29165. description: |-
  29166. Namespace of the resource being referred to.
  29167. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29168. maxLength: 63
  29169. minLength: 1
  29170. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29171. type: string
  29172. required:
  29173. - name
  29174. type: object
  29175. required:
  29176. - mountPath
  29177. - role
  29178. type: object
  29179. ldap:
  29180. description: |-
  29181. Ldap authenticates with Vault by passing username/password pair using
  29182. the LDAP authentication method
  29183. properties:
  29184. path:
  29185. default: ldap
  29186. description: |-
  29187. Path where the LDAP authentication backend is mounted
  29188. in Vault, e.g: "ldap"
  29189. type: string
  29190. secretRef:
  29191. description: |-
  29192. SecretRef to a key in a Secret resource containing password for the LDAP
  29193. user used to authenticate with Vault using the LDAP authentication
  29194. method
  29195. properties:
  29196. key:
  29197. description: |-
  29198. A key in the referenced Secret.
  29199. Some instances of this field may be defaulted, in others it may be required.
  29200. maxLength: 253
  29201. minLength: 1
  29202. pattern: ^[-._a-zA-Z0-9]+$
  29203. type: string
  29204. name:
  29205. description: The name of the Secret resource being referred to.
  29206. maxLength: 253
  29207. minLength: 1
  29208. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29209. type: string
  29210. namespace:
  29211. description: |-
  29212. The namespace of the Secret resource being referred to.
  29213. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29214. maxLength: 63
  29215. minLength: 1
  29216. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29217. type: string
  29218. type: object
  29219. username:
  29220. description: |-
  29221. Username is an LDAP username used to authenticate using the LDAP Vault
  29222. authentication method
  29223. type: string
  29224. required:
  29225. - path
  29226. - username
  29227. type: object
  29228. namespace:
  29229. description: |-
  29230. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  29231. Namespaces is a set of features within Vault Enterprise that allows
  29232. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  29233. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  29234. This will default to Vault.Namespace field if set, or empty otherwise
  29235. type: string
  29236. tokenSecretRef:
  29237. description: TokenSecretRef authenticates with Vault by presenting a token.
  29238. properties:
  29239. key:
  29240. description: |-
  29241. A key in the referenced Secret.
  29242. Some instances of this field may be defaulted, in others it may be required.
  29243. maxLength: 253
  29244. minLength: 1
  29245. pattern: ^[-._a-zA-Z0-9]+$
  29246. type: string
  29247. name:
  29248. description: The name of the Secret resource being referred to.
  29249. maxLength: 253
  29250. minLength: 1
  29251. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29252. type: string
  29253. namespace:
  29254. description: |-
  29255. The namespace of the Secret resource being referred to.
  29256. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29257. maxLength: 63
  29258. minLength: 1
  29259. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29260. type: string
  29261. type: object
  29262. userPass:
  29263. description: UserPass authenticates with Vault by passing username/password pair
  29264. properties:
  29265. path:
  29266. default: userpass
  29267. description: |-
  29268. Path where the UserPassword authentication backend is mounted
  29269. in Vault, e.g: "userpass"
  29270. type: string
  29271. secretRef:
  29272. description: |-
  29273. SecretRef to a key in a Secret resource containing password for the
  29274. user used to authenticate with Vault using the UserPass authentication
  29275. method
  29276. properties:
  29277. key:
  29278. description: |-
  29279. A key in the referenced Secret.
  29280. Some instances of this field may be defaulted, in others it may be required.
  29281. maxLength: 253
  29282. minLength: 1
  29283. pattern: ^[-._a-zA-Z0-9]+$
  29284. type: string
  29285. name:
  29286. description: The name of the Secret resource being referred to.
  29287. maxLength: 253
  29288. minLength: 1
  29289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29290. type: string
  29291. namespace:
  29292. description: |-
  29293. The namespace of the Secret resource being referred to.
  29294. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29295. maxLength: 63
  29296. minLength: 1
  29297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29298. type: string
  29299. type: object
  29300. username:
  29301. description: |-
  29302. Username is a username used to authenticate using the UserPass Vault
  29303. authentication method
  29304. type: string
  29305. required:
  29306. - path
  29307. - username
  29308. type: object
  29309. type: object
  29310. caBundle:
  29311. description: |-
  29312. PEM encoded CA bundle used to validate Vault server certificate. Only used
  29313. if the Server URL is using HTTPS protocol. This parameter is ignored for
  29314. plain HTTP protocol connection. If not set the system root certificates
  29315. are used to validate the TLS connection.
  29316. format: byte
  29317. type: string
  29318. caProvider:
  29319. description: The provider for the CA bundle to use to validate Vault server certificate.
  29320. properties:
  29321. key:
  29322. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  29323. maxLength: 253
  29324. minLength: 1
  29325. pattern: ^[-._a-zA-Z0-9]+$
  29326. type: string
  29327. name:
  29328. description: The name of the object located at the provider type.
  29329. maxLength: 253
  29330. minLength: 1
  29331. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29332. type: string
  29333. namespace:
  29334. description: |-
  29335. The namespace the Provider type is in.
  29336. Can only be defined when used in a ClusterSecretStore.
  29337. maxLength: 63
  29338. minLength: 1
  29339. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29340. type: string
  29341. type:
  29342. description: The type of provider to use such as "Secret", or "ConfigMap".
  29343. enum:
  29344. - Secret
  29345. - ConfigMap
  29346. type: string
  29347. required:
  29348. - name
  29349. - type
  29350. type: object
  29351. checkAndSet:
  29352. description: |-
  29353. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  29354. Only applies to Vault KV v2 stores. When enabled, write operations must include
  29355. the current version of the secret to prevent unintentional overwrites.
  29356. properties:
  29357. required:
  29358. description: |-
  29359. Required when true, all write operations must include a check-and-set parameter.
  29360. This helps prevent unintentional overwrites of secrets.
  29361. type: boolean
  29362. type: object
  29363. forwardInconsistent:
  29364. description: |-
  29365. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  29366. leader instead of simply retrying within a loop. This can increase performance if
  29367. the option is enabled serverside.
  29368. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  29369. type: boolean
  29370. headers:
  29371. additionalProperties:
  29372. type: string
  29373. description: Headers to be added in Vault request
  29374. type: object
  29375. namespace:
  29376. description: |-
  29377. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  29378. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  29379. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  29380. type: string
  29381. path:
  29382. description: |-
  29383. Path is the mount path of the Vault KV backend endpoint, e.g:
  29384. "secret". The v2 KV secret engine version specific "/data" path suffix
  29385. for fetching secrets from Vault is optional and will be appended
  29386. if not present in specified path.
  29387. type: string
  29388. readYourWrites:
  29389. description: |-
  29390. ReadYourWrites ensures isolated read-after-write semantics by
  29391. providing discovered cluster replication states in each request.
  29392. More information about eventual consistency in Vault can be found here
  29393. https://www.vaultproject.io/docs/enterprise/consistency
  29394. type: boolean
  29395. server:
  29396. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  29397. type: string
  29398. tls:
  29399. description: |-
  29400. The configuration used for client side related TLS communication, when the Vault server
  29401. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  29402. This parameter is ignored for plain HTTP protocol connection.
  29403. It's worth noting this configuration is different from the "TLS certificates auth method",
  29404. which is available under the `auth.cert` section.
  29405. properties:
  29406. certSecretRef:
  29407. description: |-
  29408. CertSecretRef is a certificate added to the transport layer
  29409. when communicating with the Vault server.
  29410. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  29411. properties:
  29412. key:
  29413. description: |-
  29414. A key in the referenced Secret.
  29415. Some instances of this field may be defaulted, in others it may be required.
  29416. maxLength: 253
  29417. minLength: 1
  29418. pattern: ^[-._a-zA-Z0-9]+$
  29419. type: string
  29420. name:
  29421. description: The name of the Secret resource being referred to.
  29422. maxLength: 253
  29423. minLength: 1
  29424. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29425. type: string
  29426. namespace:
  29427. description: |-
  29428. The namespace of the Secret resource being referred to.
  29429. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29430. maxLength: 63
  29431. minLength: 1
  29432. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29433. type: string
  29434. type: object
  29435. keySecretRef:
  29436. description: |-
  29437. KeySecretRef to a key in a Secret resource containing client private key
  29438. added to the transport layer when communicating with the Vault server.
  29439. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  29440. properties:
  29441. key:
  29442. description: |-
  29443. A key in the referenced Secret.
  29444. Some instances of this field may be defaulted, in others it may be required.
  29445. maxLength: 253
  29446. minLength: 1
  29447. pattern: ^[-._a-zA-Z0-9]+$
  29448. type: string
  29449. name:
  29450. description: The name of the Secret resource being referred to.
  29451. maxLength: 253
  29452. minLength: 1
  29453. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29454. type: string
  29455. namespace:
  29456. description: |-
  29457. The namespace of the Secret resource being referred to.
  29458. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29459. maxLength: 63
  29460. minLength: 1
  29461. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29462. type: string
  29463. type: object
  29464. type: object
  29465. version:
  29466. default: v2
  29467. description: |-
  29468. Version is the Vault KV secret engine version. This can be either "v1" or
  29469. "v2". Version defaults to "v2".
  29470. enum:
  29471. - v1
  29472. - v2
  29473. type: string
  29474. required:
  29475. - server
  29476. type: object
  29477. resultType:
  29478. default: Data
  29479. description: |-
  29480. Result type defines which data is returned from the generator.
  29481. By default, it is the "data" section of the Vault API response.
  29482. When using e.g. /auth/token/create the "data" section is empty but
  29483. the "auth" section contains the generated token.
  29484. Please refer to the vault docs regarding the result data structure.
  29485. Additionally, accessing the raw response is possibly by using "Raw" result type.
  29486. enum:
  29487. - Data
  29488. - Auth
  29489. - Raw
  29490. type: string
  29491. retrySettings:
  29492. description: Used to configure http retries if failed
  29493. properties:
  29494. maxRetries:
  29495. format: int32
  29496. type: integer
  29497. retryInterval:
  29498. type: string
  29499. type: object
  29500. required:
  29501. - path
  29502. - provider
  29503. type: object
  29504. webhookSpec:
  29505. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  29506. properties:
  29507. auth:
  29508. description: Auth specifies a authorization protocol. Only one protocol may be set.
  29509. maxProperties: 1
  29510. minProperties: 1
  29511. properties:
  29512. ntlm:
  29513. description: NTLMProtocol configures the store to use NTLM for auth
  29514. properties:
  29515. passwordSecret:
  29516. description: |-
  29517. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  29518. In some instances, `key` is a required field.
  29519. properties:
  29520. key:
  29521. description: |-
  29522. A key in the referenced Secret.
  29523. Some instances of this field may be defaulted, in others it may be required.
  29524. maxLength: 253
  29525. minLength: 1
  29526. pattern: ^[-._a-zA-Z0-9]+$
  29527. type: string
  29528. name:
  29529. description: The name of the Secret resource being referred to.
  29530. maxLength: 253
  29531. minLength: 1
  29532. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29533. type: string
  29534. namespace:
  29535. description: |-
  29536. The namespace of the Secret resource being referred to.
  29537. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29538. maxLength: 63
  29539. minLength: 1
  29540. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29541. type: string
  29542. type: object
  29543. usernameSecret:
  29544. description: |-
  29545. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  29546. In some instances, `key` is a required field.
  29547. properties:
  29548. key:
  29549. description: |-
  29550. A key in the referenced Secret.
  29551. Some instances of this field may be defaulted, in others it may be required.
  29552. maxLength: 253
  29553. minLength: 1
  29554. pattern: ^[-._a-zA-Z0-9]+$
  29555. type: string
  29556. name:
  29557. description: The name of the Secret resource being referred to.
  29558. maxLength: 253
  29559. minLength: 1
  29560. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29561. type: string
  29562. namespace:
  29563. description: |-
  29564. The namespace of the Secret resource being referred to.
  29565. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29566. maxLength: 63
  29567. minLength: 1
  29568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29569. type: string
  29570. type: object
  29571. required:
  29572. - passwordSecret
  29573. - usernameSecret
  29574. type: object
  29575. type: object
  29576. body:
  29577. description: Body
  29578. type: string
  29579. caBundle:
  29580. description: |-
  29581. PEM encoded CA bundle used to validate webhook server certificate. Only used
  29582. if the Server URL is using HTTPS protocol. This parameter is ignored for
  29583. plain HTTP protocol connection. If not set the system root certificates
  29584. are used to validate the TLS connection.
  29585. format: byte
  29586. type: string
  29587. caProvider:
  29588. description: The provider for the CA bundle to use to validate webhook server certificate.
  29589. properties:
  29590. key:
  29591. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  29592. maxLength: 253
  29593. minLength: 1
  29594. pattern: ^[-._a-zA-Z0-9]+$
  29595. type: string
  29596. name:
  29597. description: The name of the object located at the provider type.
  29598. maxLength: 253
  29599. minLength: 1
  29600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29601. type: string
  29602. namespace:
  29603. description: The namespace the Provider type is in.
  29604. maxLength: 63
  29605. minLength: 1
  29606. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29607. type: string
  29608. type:
  29609. description: The type of provider to use such as "Secret", or "ConfigMap".
  29610. enum:
  29611. - Secret
  29612. - ConfigMap
  29613. type: string
  29614. required:
  29615. - name
  29616. - type
  29617. type: object
  29618. headers:
  29619. additionalProperties:
  29620. type: string
  29621. description: Headers
  29622. type: object
  29623. method:
  29624. description: Webhook Method
  29625. type: string
  29626. result:
  29627. description: Result formatting
  29628. properties:
  29629. jsonPath:
  29630. description: Json path of return value
  29631. type: string
  29632. type: object
  29633. secrets:
  29634. description: |-
  29635. Secrets to fill in templates
  29636. These secrets will be passed to the templating function as key value pairs under the given name
  29637. items:
  29638. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  29639. properties:
  29640. name:
  29641. description: Name of this secret in templates
  29642. type: string
  29643. secretRef:
  29644. description: Secret ref to fill in credentials
  29645. properties:
  29646. key:
  29647. description: The key where the token is found.
  29648. maxLength: 253
  29649. minLength: 1
  29650. pattern: ^[-._a-zA-Z0-9]+$
  29651. type: string
  29652. name:
  29653. description: The name of the Secret resource being referred to.
  29654. maxLength: 253
  29655. minLength: 1
  29656. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29657. type: string
  29658. type: object
  29659. required:
  29660. - name
  29661. - secretRef
  29662. type: object
  29663. type: array
  29664. timeout:
  29665. description: Timeout
  29666. type: string
  29667. url:
  29668. description: Webhook url to call
  29669. type: string
  29670. required:
  29671. - result
  29672. - url
  29673. type: object
  29674. type: object
  29675. kind:
  29676. description: Kind the kind of this generator.
  29677. enum:
  29678. - ACRAccessToken
  29679. - BeyondtrustWorkloadCredentialsDynamicSecret
  29680. - CloudsmithAccessToken
  29681. - ECRAuthorizationToken
  29682. - Fake
  29683. - GCRAccessToken
  29684. - GithubAccessToken
  29685. - GitlabDeployToken
  29686. - QuayAccessToken
  29687. - Password
  29688. - SSHKey
  29689. - STSSessionToken
  29690. - UUID
  29691. - VaultDynamicSecret
  29692. - Webhook
  29693. - Grafana
  29694. - MFA
  29695. type: string
  29696. required:
  29697. - generator
  29698. - kind
  29699. type: object
  29700. type: object
  29701. served: true
  29702. storage: true
  29703. subresources:
  29704. status: {}
  29705. ---
  29706. apiVersion: apiextensions.k8s.io/v1
  29707. kind: CustomResourceDefinition
  29708. metadata:
  29709. annotations:
  29710. controller-gen.kubebuilder.io/version: v0.19.0
  29711. labels:
  29712. external-secrets.io/component: controller
  29713. name: ecrauthorizationtokens.generators.external-secrets.io
  29714. spec:
  29715. group: generators.external-secrets.io
  29716. names:
  29717. categories:
  29718. - external-secrets
  29719. - external-secrets-generators
  29720. kind: ECRAuthorizationToken
  29721. listKind: ECRAuthorizationTokenList
  29722. plural: ecrauthorizationtokens
  29723. singular: ecrauthorizationtoken
  29724. scope: Namespaced
  29725. versions:
  29726. - name: v1alpha1
  29727. schema:
  29728. openAPIV3Schema:
  29729. description: |-
  29730. ECRAuthorizationToken uses the GetAuthorizationToken API to retrieve an authorization token.
  29731. The authorization token is valid for 12 hours.
  29732. The authorizationToken returned is a base64 encoded string that can be decoded
  29733. and used in a docker login command to authenticate to a registry.
  29734. For more information, see Registry authentication (https://docs.aws.amazon.com/AmazonECR/latest/userguide/Registries.html#registry_auth) in the Amazon Elastic Container Registry User Guide.
  29735. properties:
  29736. apiVersion:
  29737. description: |-
  29738. APIVersion defines the versioned schema of this representation of an object.
  29739. Servers should convert recognized schemas to the latest internal value, and
  29740. may reject unrecognized values.
  29741. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29742. type: string
  29743. kind:
  29744. description: |-
  29745. Kind is a string value representing the REST resource this object represents.
  29746. Servers may infer this from the endpoint the client submits requests to.
  29747. Cannot be updated.
  29748. In CamelCase.
  29749. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29750. type: string
  29751. metadata:
  29752. type: object
  29753. spec:
  29754. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  29755. properties:
  29756. auth:
  29757. description: Auth defines how to authenticate with AWS
  29758. properties:
  29759. jwt:
  29760. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  29761. properties:
  29762. serviceAccountRef:
  29763. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29764. properties:
  29765. audiences:
  29766. description: |-
  29767. Audience specifies the `aud` claim for the service account token
  29768. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29769. then this audiences will be appended to the list
  29770. items:
  29771. type: string
  29772. type: array
  29773. name:
  29774. description: The name of the ServiceAccount resource being referred to.
  29775. maxLength: 253
  29776. minLength: 1
  29777. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29778. type: string
  29779. namespace:
  29780. description: |-
  29781. Namespace of the resource being referred to.
  29782. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29783. maxLength: 63
  29784. minLength: 1
  29785. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29786. type: string
  29787. required:
  29788. - name
  29789. type: object
  29790. type: object
  29791. secretRef:
  29792. description: |-
  29793. AWSAuthSecretRef holds secret references for AWS credentials
  29794. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  29795. properties:
  29796. accessKeyIDSecretRef:
  29797. description: The AccessKeyID is used for authentication
  29798. properties:
  29799. key:
  29800. description: |-
  29801. A key in the referenced Secret.
  29802. Some instances of this field may be defaulted, in others it may be required.
  29803. maxLength: 253
  29804. minLength: 1
  29805. pattern: ^[-._a-zA-Z0-9]+$
  29806. type: string
  29807. name:
  29808. description: The name of the Secret resource being referred to.
  29809. maxLength: 253
  29810. minLength: 1
  29811. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29812. type: string
  29813. namespace:
  29814. description: |-
  29815. The namespace of the Secret resource being referred to.
  29816. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29817. maxLength: 63
  29818. minLength: 1
  29819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29820. type: string
  29821. type: object
  29822. secretAccessKeySecretRef:
  29823. description: The SecretAccessKey is used for authentication
  29824. properties:
  29825. key:
  29826. description: |-
  29827. A key in the referenced Secret.
  29828. Some instances of this field may be defaulted, in others it may be required.
  29829. maxLength: 253
  29830. minLength: 1
  29831. pattern: ^[-._a-zA-Z0-9]+$
  29832. type: string
  29833. name:
  29834. description: The name of the Secret resource being referred to.
  29835. maxLength: 253
  29836. minLength: 1
  29837. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29838. type: string
  29839. namespace:
  29840. description: |-
  29841. The namespace of the Secret resource being referred to.
  29842. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29843. maxLength: 63
  29844. minLength: 1
  29845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29846. type: string
  29847. type: object
  29848. sessionTokenSecretRef:
  29849. description: |-
  29850. The SessionToken used for authentication
  29851. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  29852. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  29853. properties:
  29854. key:
  29855. description: |-
  29856. A key in the referenced Secret.
  29857. Some instances of this field may be defaulted, in others it may be required.
  29858. maxLength: 253
  29859. minLength: 1
  29860. pattern: ^[-._a-zA-Z0-9]+$
  29861. type: string
  29862. name:
  29863. description: The name of the Secret resource being referred to.
  29864. maxLength: 253
  29865. minLength: 1
  29866. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29867. type: string
  29868. namespace:
  29869. description: |-
  29870. The namespace of the Secret resource being referred to.
  29871. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29872. maxLength: 63
  29873. minLength: 1
  29874. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29875. type: string
  29876. type: object
  29877. type: object
  29878. type: object
  29879. region:
  29880. description: Region specifies the region to operate in.
  29881. type: string
  29882. role:
  29883. description: |-
  29884. You can assume a role before making calls to the
  29885. desired AWS service.
  29886. type: string
  29887. scope:
  29888. description: |-
  29889. Scope specifies the ECR service scope.
  29890. Valid options are private and public.
  29891. type: string
  29892. required:
  29893. - region
  29894. type: object
  29895. type: object
  29896. served: true
  29897. storage: true
  29898. subresources:
  29899. status: {}
  29900. ---
  29901. apiVersion: apiextensions.k8s.io/v1
  29902. kind: CustomResourceDefinition
  29903. metadata:
  29904. annotations:
  29905. controller-gen.kubebuilder.io/version: v0.19.0
  29906. labels:
  29907. external-secrets.io/component: controller
  29908. name: fakes.generators.external-secrets.io
  29909. spec:
  29910. group: generators.external-secrets.io
  29911. names:
  29912. categories:
  29913. - external-secrets
  29914. - external-secrets-generators
  29915. kind: Fake
  29916. listKind: FakeList
  29917. plural: fakes
  29918. singular: fake
  29919. scope: Namespaced
  29920. versions:
  29921. - name: v1alpha1
  29922. schema:
  29923. openAPIV3Schema:
  29924. description: |-
  29925. Fake generator is used for testing. It lets you define
  29926. a static set of credentials that is always returned.
  29927. properties:
  29928. apiVersion:
  29929. description: |-
  29930. APIVersion defines the versioned schema of this representation of an object.
  29931. Servers should convert recognized schemas to the latest internal value, and
  29932. may reject unrecognized values.
  29933. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29934. type: string
  29935. kind:
  29936. description: |-
  29937. Kind is a string value representing the REST resource this object represents.
  29938. Servers may infer this from the endpoint the client submits requests to.
  29939. Cannot be updated.
  29940. In CamelCase.
  29941. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29942. type: string
  29943. metadata:
  29944. type: object
  29945. spec:
  29946. description: FakeSpec contains the static data.
  29947. properties:
  29948. controller:
  29949. description: |-
  29950. Used to select the correct ESO controller (think: ingress.ingressClassName)
  29951. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  29952. type: string
  29953. data:
  29954. additionalProperties:
  29955. type: string
  29956. description: |-
  29957. Data defines the static data returned
  29958. by this generator.
  29959. type: object
  29960. type: object
  29961. type: object
  29962. served: true
  29963. storage: true
  29964. subresources:
  29965. status: {}
  29966. ---
  29967. apiVersion: apiextensions.k8s.io/v1
  29968. kind: CustomResourceDefinition
  29969. metadata:
  29970. annotations:
  29971. controller-gen.kubebuilder.io/version: v0.19.0
  29972. labels:
  29973. external-secrets.io/component: controller
  29974. name: gcraccesstokens.generators.external-secrets.io
  29975. spec:
  29976. group: generators.external-secrets.io
  29977. names:
  29978. categories:
  29979. - external-secrets
  29980. - external-secrets-generators
  29981. kind: GCRAccessToken
  29982. listKind: GCRAccessTokenList
  29983. plural: gcraccesstokens
  29984. singular: gcraccesstoken
  29985. scope: Namespaced
  29986. versions:
  29987. - name: v1alpha1
  29988. schema:
  29989. openAPIV3Schema:
  29990. description: |-
  29991. GCRAccessToken generates an GCP access token
  29992. that can be used to authenticate with GCR.
  29993. properties:
  29994. apiVersion:
  29995. description: |-
  29996. APIVersion defines the versioned schema of this representation of an object.
  29997. Servers should convert recognized schemas to the latest internal value, and
  29998. may reject unrecognized values.
  29999. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30000. type: string
  30001. kind:
  30002. description: |-
  30003. Kind is a string value representing the REST resource this object represents.
  30004. Servers may infer this from the endpoint the client submits requests to.
  30005. Cannot be updated.
  30006. In CamelCase.
  30007. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30008. type: string
  30009. metadata:
  30010. type: object
  30011. spec:
  30012. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  30013. properties:
  30014. auth:
  30015. description: Auth defines the means for authenticating with GCP
  30016. properties:
  30017. secretRef:
  30018. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  30019. properties:
  30020. secretAccessKeySecretRef:
  30021. description: The SecretAccessKey is used for authentication
  30022. properties:
  30023. key:
  30024. description: |-
  30025. A key in the referenced Secret.
  30026. Some instances of this field may be defaulted, in others it may be required.
  30027. maxLength: 253
  30028. minLength: 1
  30029. pattern: ^[-._a-zA-Z0-9]+$
  30030. type: string
  30031. name:
  30032. description: The name of the Secret resource being referred to.
  30033. maxLength: 253
  30034. minLength: 1
  30035. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30036. type: string
  30037. namespace:
  30038. description: |-
  30039. The namespace of the Secret resource being referred to.
  30040. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30041. maxLength: 63
  30042. minLength: 1
  30043. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30044. type: string
  30045. type: object
  30046. type: object
  30047. workloadIdentity:
  30048. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  30049. properties:
  30050. clusterLocation:
  30051. type: string
  30052. clusterName:
  30053. type: string
  30054. clusterProjectID:
  30055. type: string
  30056. serviceAccountRef:
  30057. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  30058. properties:
  30059. audiences:
  30060. description: |-
  30061. Audience specifies the `aud` claim for the service account token
  30062. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30063. then this audiences will be appended to the list
  30064. items:
  30065. type: string
  30066. type: array
  30067. name:
  30068. description: The name of the ServiceAccount resource being referred to.
  30069. maxLength: 253
  30070. minLength: 1
  30071. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30072. type: string
  30073. namespace:
  30074. description: |-
  30075. Namespace of the resource being referred to.
  30076. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30077. maxLength: 63
  30078. minLength: 1
  30079. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30080. type: string
  30081. required:
  30082. - name
  30083. type: object
  30084. required:
  30085. - clusterLocation
  30086. - clusterName
  30087. - serviceAccountRef
  30088. type: object
  30089. workloadIdentityFederation:
  30090. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  30091. properties:
  30092. audience:
  30093. description: |-
  30094. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  30095. If specified, Audience found in the external account credential config will be overridden with the configured value.
  30096. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  30097. type: string
  30098. awsSecurityCredentials:
  30099. description: |-
  30100. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  30101. when using the AWS metadata server is not an option.
  30102. properties:
  30103. awsCredentialsSecretRef:
  30104. description: |-
  30105. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  30106. Secret should be created with below names for keys
  30107. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  30108. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  30109. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  30110. properties:
  30111. name:
  30112. description: name of the secret.
  30113. maxLength: 253
  30114. minLength: 1
  30115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30116. type: string
  30117. namespace:
  30118. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  30119. maxLength: 63
  30120. minLength: 1
  30121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30122. type: string
  30123. required:
  30124. - name
  30125. type: object
  30126. region:
  30127. description: region is for configuring the AWS region to be used.
  30128. example: ap-south-1
  30129. maxLength: 50
  30130. minLength: 1
  30131. pattern: ^[a-z0-9-]+$
  30132. type: string
  30133. required:
  30134. - awsCredentialsSecretRef
  30135. - region
  30136. type: object
  30137. credConfig:
  30138. description: |-
  30139. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  30140. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  30141. serviceAccountRef must be used by providing operators service account details.
  30142. properties:
  30143. key:
  30144. description: key name holding the external account credential config.
  30145. maxLength: 253
  30146. minLength: 1
  30147. pattern: ^[-._a-zA-Z0-9]+$
  30148. type: string
  30149. name:
  30150. description: name of the configmap.
  30151. maxLength: 253
  30152. minLength: 1
  30153. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30154. type: string
  30155. namespace:
  30156. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  30157. maxLength: 63
  30158. minLength: 1
  30159. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30160. type: string
  30161. required:
  30162. - key
  30163. - name
  30164. type: object
  30165. externalTokenEndpoint:
  30166. description: |-
  30167. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  30168. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  30169. URL is having the expected value.
  30170. type: string
  30171. gcpServiceAccountEmail:
  30172. description: |-
  30173. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  30174. after Workload Identity Federation. Use this to grant access through the service account's
  30175. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  30176. service_account_impersonation_url in the external account JSON from credConfig;
  30177. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  30178. on that ServiceAccount.
  30179. example: my-gsa@my-project.iam.gserviceaccount.com
  30180. minLength: 1
  30181. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  30182. type: string
  30183. serviceAccountRef:
  30184. description: |-
  30185. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  30186. when Kubernetes is configured as provider in workload identity pool.
  30187. properties:
  30188. audiences:
  30189. description: |-
  30190. Audience specifies the `aud` claim for the service account token
  30191. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30192. then this audiences will be appended to the list
  30193. items:
  30194. type: string
  30195. type: array
  30196. name:
  30197. description: The name of the ServiceAccount resource being referred to.
  30198. maxLength: 253
  30199. minLength: 1
  30200. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30201. type: string
  30202. namespace:
  30203. description: |-
  30204. Namespace of the resource being referred to.
  30205. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30206. maxLength: 63
  30207. minLength: 1
  30208. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30209. type: string
  30210. required:
  30211. - name
  30212. type: object
  30213. type: object
  30214. type: object
  30215. projectID:
  30216. description: ProjectID defines which project to use to authenticate with
  30217. type: string
  30218. required:
  30219. - auth
  30220. - projectID
  30221. type: object
  30222. type: object
  30223. served: true
  30224. storage: true
  30225. subresources:
  30226. status: {}
  30227. ---
  30228. apiVersion: apiextensions.k8s.io/v1
  30229. kind: CustomResourceDefinition
  30230. metadata:
  30231. annotations:
  30232. controller-gen.kubebuilder.io/version: v0.19.0
  30233. labels:
  30234. external-secrets.io/component: controller
  30235. name: generatorstates.generators.external-secrets.io
  30236. spec:
  30237. group: generators.external-secrets.io
  30238. names:
  30239. categories:
  30240. - external-secrets
  30241. - external-secrets-generators
  30242. kind: GeneratorState
  30243. listKind: GeneratorStateList
  30244. plural: generatorstates
  30245. shortNames:
  30246. - gs
  30247. singular: generatorstate
  30248. scope: Namespaced
  30249. versions:
  30250. - additionalPrinterColumns:
  30251. - jsonPath: .spec.garbageCollectionDeadline
  30252. name: GC Deadline
  30253. type: string
  30254. - jsonPath: .metadata.creationTimestamp
  30255. name: Age
  30256. type: date
  30257. name: v1alpha1
  30258. schema:
  30259. openAPIV3Schema:
  30260. description: GeneratorState represents the state created and managed by a generator resource.
  30261. properties:
  30262. apiVersion:
  30263. description: |-
  30264. APIVersion defines the versioned schema of this representation of an object.
  30265. Servers should convert recognized schemas to the latest internal value, and
  30266. may reject unrecognized values.
  30267. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30268. type: string
  30269. kind:
  30270. description: |-
  30271. Kind is a string value representing the REST resource this object represents.
  30272. Servers may infer this from the endpoint the client submits requests to.
  30273. Cannot be updated.
  30274. In CamelCase.
  30275. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30276. type: string
  30277. metadata:
  30278. type: object
  30279. spec:
  30280. description: GeneratorStateSpec defines the desired state of a generator state resource.
  30281. properties:
  30282. garbageCollectionDeadline:
  30283. description: |-
  30284. GarbageCollectionDeadline is the time after which the generator state
  30285. will be deleted.
  30286. It is set by the controller which creates the generator state and
  30287. can be set configured by the user.
  30288. If the garbage collection deadline is not set the generator state will not be deleted.
  30289. format: date-time
  30290. type: string
  30291. resource:
  30292. description: |-
  30293. Resource is the generator manifest that produced the state.
  30294. It is a snapshot of the generator manifest at the time the state was produced.
  30295. This manifest will be used to delete the resource. Any configuration that is referenced
  30296. in the manifest should be available at the time of garbage collection. If that is not the case deletion will
  30297. be blocked by a finalizer.
  30298. x-kubernetes-preserve-unknown-fields: true
  30299. state:
  30300. description: State is the state that was produced by the generator implementation.
  30301. x-kubernetes-preserve-unknown-fields: true
  30302. required:
  30303. - resource
  30304. - state
  30305. type: object
  30306. status:
  30307. description: GeneratorStateStatus defines the observed state of a generator state resource.
  30308. properties:
  30309. conditions:
  30310. items:
  30311. description: GeneratorStateStatusCondition represents the observed condition of a generator state.
  30312. properties:
  30313. lastTransitionTime:
  30314. format: date-time
  30315. type: string
  30316. message:
  30317. type: string
  30318. reason:
  30319. type: string
  30320. status:
  30321. type: string
  30322. type:
  30323. description: GeneratorStateConditionType represents the type of condition for a generator state.
  30324. type: string
  30325. required:
  30326. - status
  30327. - type
  30328. type: object
  30329. type: array
  30330. type: object
  30331. type: object
  30332. served: true
  30333. storage: true
  30334. subresources: {}
  30335. ---
  30336. apiVersion: apiextensions.k8s.io/v1
  30337. kind: CustomResourceDefinition
  30338. metadata:
  30339. annotations:
  30340. controller-gen.kubebuilder.io/version: v0.19.0
  30341. labels:
  30342. external-secrets.io/component: controller
  30343. name: githubaccesstokens.generators.external-secrets.io
  30344. spec:
  30345. group: generators.external-secrets.io
  30346. names:
  30347. categories:
  30348. - external-secrets
  30349. - external-secrets-generators
  30350. kind: GithubAccessToken
  30351. listKind: GithubAccessTokenList
  30352. plural: githubaccesstokens
  30353. singular: githubaccesstoken
  30354. scope: Namespaced
  30355. versions:
  30356. - name: v1alpha1
  30357. schema:
  30358. openAPIV3Schema:
  30359. description: GithubAccessToken generates ghs_ accessToken
  30360. properties:
  30361. apiVersion:
  30362. description: |-
  30363. APIVersion defines the versioned schema of this representation of an object.
  30364. Servers should convert recognized schemas to the latest internal value, and
  30365. may reject unrecognized values.
  30366. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30367. type: string
  30368. kind:
  30369. description: |-
  30370. Kind is a string value representing the REST resource this object represents.
  30371. Servers may infer this from the endpoint the client submits requests to.
  30372. Cannot be updated.
  30373. In CamelCase.
  30374. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30375. type: string
  30376. metadata:
  30377. type: object
  30378. spec:
  30379. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  30380. properties:
  30381. appID:
  30382. type: string
  30383. auth:
  30384. description: Auth configures how ESO authenticates with a Github instance.
  30385. properties:
  30386. privateKey:
  30387. description: GithubSecretRef references a secret containing GitHub credentials.
  30388. properties:
  30389. secretRef:
  30390. description: |-
  30391. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30392. In some instances, `key` is a required field.
  30393. properties:
  30394. key:
  30395. description: |-
  30396. A key in the referenced Secret.
  30397. Some instances of this field may be defaulted, in others it may be required.
  30398. maxLength: 253
  30399. minLength: 1
  30400. pattern: ^[-._a-zA-Z0-9]+$
  30401. type: string
  30402. name:
  30403. description: The name of the Secret resource being referred to.
  30404. maxLength: 253
  30405. minLength: 1
  30406. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30407. type: string
  30408. namespace:
  30409. description: |-
  30410. The namespace of the Secret resource being referred to.
  30411. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30412. maxLength: 63
  30413. minLength: 1
  30414. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30415. type: string
  30416. type: object
  30417. required:
  30418. - secretRef
  30419. type: object
  30420. required:
  30421. - privateKey
  30422. type: object
  30423. installID:
  30424. type: string
  30425. permissions:
  30426. additionalProperties:
  30427. type: string
  30428. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  30429. type: object
  30430. repositories:
  30431. description: |-
  30432. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  30433. is installed to.
  30434. items:
  30435. type: string
  30436. type: array
  30437. url:
  30438. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  30439. type: string
  30440. required:
  30441. - appID
  30442. - auth
  30443. - installID
  30444. type: object
  30445. type: object
  30446. served: true
  30447. storage: true
  30448. subresources:
  30449. status: {}
  30450. ---
  30451. apiVersion: apiextensions.k8s.io/v1
  30452. kind: CustomResourceDefinition
  30453. metadata:
  30454. annotations:
  30455. controller-gen.kubebuilder.io/version: v0.19.0
  30456. labels:
  30457. external-secrets.io/component: controller
  30458. name: gitlabdeploytokens.generators.external-secrets.io
  30459. spec:
  30460. group: generators.external-secrets.io
  30461. names:
  30462. categories:
  30463. - external-secrets
  30464. - external-secrets-generators
  30465. kind: GitlabDeployToken
  30466. listKind: GitlabDeployTokenList
  30467. plural: gitlabdeploytokens
  30468. singular: gitlabdeploytoken
  30469. scope: Namespaced
  30470. versions:
  30471. - name: v1alpha1
  30472. schema:
  30473. openAPIV3Schema:
  30474. description: GitlabDeployToken generates a GitLab deploy token.
  30475. properties:
  30476. apiVersion:
  30477. description: |-
  30478. APIVersion defines the versioned schema of this representation of an object.
  30479. Servers should convert recognized schemas to the latest internal value, and
  30480. may reject unrecognized values.
  30481. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30482. type: string
  30483. kind:
  30484. description: |-
  30485. Kind is a string value representing the REST resource this object represents.
  30486. Servers may infer this from the endpoint the client submits requests to.
  30487. Cannot be updated.
  30488. In CamelCase.
  30489. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30490. type: string
  30491. metadata:
  30492. type: object
  30493. spec:
  30494. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  30495. properties:
  30496. auth:
  30497. description: Auth configures how ESO authenticates with the GitLab API.
  30498. properties:
  30499. token:
  30500. description: |-
  30501. Token references a secret containing a GitLab access token (personal, group, or
  30502. project) with the api scope and at least the Maintainer role on the target.
  30503. properties:
  30504. secretRef:
  30505. description: |-
  30506. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30507. In some instances, `key` is a required field.
  30508. properties:
  30509. key:
  30510. description: |-
  30511. A key in the referenced Secret.
  30512. Some instances of this field may be defaulted, in others it may be required.
  30513. maxLength: 253
  30514. minLength: 1
  30515. pattern: ^[-._a-zA-Z0-9]+$
  30516. type: string
  30517. name:
  30518. description: The name of the Secret resource being referred to.
  30519. maxLength: 253
  30520. minLength: 1
  30521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30522. type: string
  30523. namespace:
  30524. description: |-
  30525. The namespace of the Secret resource being referred to.
  30526. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30527. maxLength: 63
  30528. minLength: 1
  30529. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30530. type: string
  30531. type: object
  30532. required:
  30533. - secretRef
  30534. type: object
  30535. required:
  30536. - token
  30537. type: object
  30538. expiresAt:
  30539. description: |-
  30540. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  30541. not expire on the GitLab side and is revoked only when the generator state is
  30542. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  30543. format: date-time
  30544. type: string
  30545. groupID:
  30546. description: |-
  30547. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  30548. create the deploy token in. The generator URL-escapes paths before calling the
  30549. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  30550. minLength: 1
  30551. type: string
  30552. name:
  30553. description: Name of the deploy token.
  30554. minLength: 1
  30555. type: string
  30556. projectID:
  30557. description: |-
  30558. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  30559. project to create the deploy token in. The generator URL-escapes paths before
  30560. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  30561. minLength: 1
  30562. type: string
  30563. scopes:
  30564. description: Scopes granted to the deploy token. At least one scope is required.
  30565. items:
  30566. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  30567. enum:
  30568. - read_repository
  30569. - read_registry
  30570. - write_registry
  30571. - read_package_registry
  30572. - write_package_registry
  30573. - read_virtual_registry
  30574. - write_virtual_registry
  30575. type: string
  30576. minItems: 1
  30577. type: array
  30578. url:
  30579. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  30580. type: string
  30581. username:
  30582. description: |-
  30583. Username is an optional username for the deploy token. GitLab defaults it to
  30584. gitlab+deploy-token-{n} when omitted.
  30585. type: string
  30586. required:
  30587. - auth
  30588. - name
  30589. - scopes
  30590. type: object
  30591. x-kubernetes-validations:
  30592. - message: exactly one of projectID or groupID must be set
  30593. rule: has(self.projectID) != has(self.groupID)
  30594. type: object
  30595. served: true
  30596. storage: true
  30597. subresources:
  30598. status: {}
  30599. ---
  30600. apiVersion: apiextensions.k8s.io/v1
  30601. kind: CustomResourceDefinition
  30602. metadata:
  30603. annotations:
  30604. controller-gen.kubebuilder.io/version: v0.19.0
  30605. labels:
  30606. external-secrets.io/component: controller
  30607. name: grafanas.generators.external-secrets.io
  30608. spec:
  30609. group: generators.external-secrets.io
  30610. names:
  30611. categories:
  30612. - external-secrets
  30613. - external-secrets-generators
  30614. kind: Grafana
  30615. listKind: GrafanaList
  30616. plural: grafanas
  30617. singular: grafana
  30618. scope: Namespaced
  30619. versions:
  30620. - name: v1alpha1
  30621. schema:
  30622. openAPIV3Schema:
  30623. description: Grafana represents a generator for Grafana service account tokens.
  30624. properties:
  30625. apiVersion:
  30626. description: |-
  30627. APIVersion defines the versioned schema of this representation of an object.
  30628. Servers should convert recognized schemas to the latest internal value, and
  30629. may reject unrecognized values.
  30630. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30631. type: string
  30632. kind:
  30633. description: |-
  30634. Kind is a string value representing the REST resource this object represents.
  30635. Servers may infer this from the endpoint the client submits requests to.
  30636. Cannot be updated.
  30637. In CamelCase.
  30638. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30639. type: string
  30640. metadata:
  30641. type: object
  30642. spec:
  30643. description: GrafanaSpec controls the behavior of the grafana generator.
  30644. properties:
  30645. auth:
  30646. description: |-
  30647. Auth is the authentication configuration to authenticate
  30648. against the Grafana instance.
  30649. properties:
  30650. basic:
  30651. description: |-
  30652. Basic auth credentials used to authenticate against the Grafana instance.
  30653. Note: you need a token which has elevated permissions to create service accounts.
  30654. See here for the documentation on basic roles offered by Grafana:
  30655. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30656. properties:
  30657. password:
  30658. description: A basic auth password used to authenticate against the Grafana instance.
  30659. properties:
  30660. key:
  30661. description: The key where the token is found.
  30662. maxLength: 253
  30663. minLength: 1
  30664. pattern: ^[-._a-zA-Z0-9]+$
  30665. type: string
  30666. name:
  30667. description: The name of the Secret resource being referred to.
  30668. maxLength: 253
  30669. minLength: 1
  30670. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30671. type: string
  30672. type: object
  30673. username:
  30674. description: A basic auth username used to authenticate against the Grafana instance.
  30675. type: string
  30676. required:
  30677. - password
  30678. - username
  30679. type: object
  30680. token:
  30681. description: |-
  30682. A service account token used to authenticate against the Grafana instance.
  30683. Note: you need a token which has elevated permissions to create service accounts.
  30684. See here for the documentation on basic roles offered by Grafana:
  30685. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30686. properties:
  30687. key:
  30688. description: The key where the token is found.
  30689. maxLength: 253
  30690. minLength: 1
  30691. pattern: ^[-._a-zA-Z0-9]+$
  30692. type: string
  30693. name:
  30694. description: The name of the Secret resource being referred to.
  30695. maxLength: 253
  30696. minLength: 1
  30697. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30698. type: string
  30699. type: object
  30700. type: object
  30701. serviceAccount:
  30702. description: |-
  30703. ServiceAccount is the configuration for the service account that
  30704. is supposed to be generated by the generator.
  30705. properties:
  30706. name:
  30707. description: Name is the name of the service account that will be created by ESO.
  30708. type: string
  30709. role:
  30710. description: |-
  30711. Role is the role of the service account.
  30712. See here for the documentation on basic roles offered by Grafana:
  30713. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30714. type: string
  30715. secondsToLive:
  30716. description: |-
  30717. SecondsToLive is the number of seconds before the generated service account token will expire.
  30718. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  30719. format: int64
  30720. minimum: 1
  30721. type: integer
  30722. required:
  30723. - name
  30724. - role
  30725. type: object
  30726. url:
  30727. description: URL is the URL of the Grafana instance.
  30728. type: string
  30729. required:
  30730. - auth
  30731. - serviceAccount
  30732. - url
  30733. type: object
  30734. type: object
  30735. served: true
  30736. storage: true
  30737. subresources:
  30738. status: {}
  30739. ---
  30740. apiVersion: apiextensions.k8s.io/v1
  30741. kind: CustomResourceDefinition
  30742. metadata:
  30743. annotations:
  30744. controller-gen.kubebuilder.io/version: v0.19.0
  30745. labels:
  30746. external-secrets.io/component: controller
  30747. name: mfas.generators.external-secrets.io
  30748. spec:
  30749. group: generators.external-secrets.io
  30750. names:
  30751. categories:
  30752. - external-secrets
  30753. - external-secrets-generators
  30754. kind: MFA
  30755. listKind: MFAList
  30756. plural: mfas
  30757. singular: mfa
  30758. scope: Namespaced
  30759. versions:
  30760. - name: v1alpha1
  30761. schema:
  30762. openAPIV3Schema:
  30763. description: MFA generates a new TOTP token that is compliant with RFC 6238.
  30764. properties:
  30765. apiVersion:
  30766. description: |-
  30767. APIVersion defines the versioned schema of this representation of an object.
  30768. Servers should convert recognized schemas to the latest internal value, and
  30769. may reject unrecognized values.
  30770. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30771. type: string
  30772. kind:
  30773. description: |-
  30774. Kind is a string value representing the REST resource this object represents.
  30775. Servers may infer this from the endpoint the client submits requests to.
  30776. Cannot be updated.
  30777. In CamelCase.
  30778. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30779. type: string
  30780. metadata:
  30781. type: object
  30782. spec:
  30783. description: MFASpec controls the behavior of the mfa generator.
  30784. properties:
  30785. algorithm:
  30786. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  30787. type: string
  30788. length:
  30789. description: Length defines the token length. Defaults to 6 characters.
  30790. type: integer
  30791. secret:
  30792. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  30793. properties:
  30794. key:
  30795. description: |-
  30796. A key in the referenced Secret.
  30797. Some instances of this field may be defaulted, in others it may be required.
  30798. maxLength: 253
  30799. minLength: 1
  30800. pattern: ^[-._a-zA-Z0-9]+$
  30801. type: string
  30802. name:
  30803. description: The name of the Secret resource being referred to.
  30804. maxLength: 253
  30805. minLength: 1
  30806. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30807. type: string
  30808. namespace:
  30809. description: |-
  30810. The namespace of the Secret resource being referred to.
  30811. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30812. maxLength: 63
  30813. minLength: 1
  30814. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30815. type: string
  30816. type: object
  30817. timePeriod:
  30818. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  30819. type: integer
  30820. when:
  30821. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  30822. format: date-time
  30823. type: string
  30824. required:
  30825. - secret
  30826. type: object
  30827. type: object
  30828. served: true
  30829. storage: true
  30830. subresources:
  30831. status: {}
  30832. ---
  30833. apiVersion: apiextensions.k8s.io/v1
  30834. kind: CustomResourceDefinition
  30835. metadata:
  30836. annotations:
  30837. controller-gen.kubebuilder.io/version: v0.19.0
  30838. labels:
  30839. external-secrets.io/component: controller
  30840. name: passwords.generators.external-secrets.io
  30841. spec:
  30842. group: generators.external-secrets.io
  30843. names:
  30844. categories:
  30845. - external-secrets
  30846. - external-secrets-generators
  30847. kind: Password
  30848. listKind: PasswordList
  30849. plural: passwords
  30850. singular: password
  30851. scope: Namespaced
  30852. versions:
  30853. - name: v1alpha1
  30854. schema:
  30855. openAPIV3Schema:
  30856. description: |-
  30857. Password generates a random password based on the
  30858. configuration parameters in spec.
  30859. You can specify the length, characterset and other attributes.
  30860. properties:
  30861. apiVersion:
  30862. description: |-
  30863. APIVersion defines the versioned schema of this representation of an object.
  30864. Servers should convert recognized schemas to the latest internal value, and
  30865. may reject unrecognized values.
  30866. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30867. type: string
  30868. kind:
  30869. description: |-
  30870. Kind is a string value representing the REST resource this object represents.
  30871. Servers may infer this from the endpoint the client submits requests to.
  30872. Cannot be updated.
  30873. In CamelCase.
  30874. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30875. type: string
  30876. metadata:
  30877. type: object
  30878. spec:
  30879. description: PasswordSpec controls the behavior of the password generator.
  30880. properties:
  30881. allowRepeat:
  30882. default: false
  30883. description: set AllowRepeat to true to allow repeating characters.
  30884. type: boolean
  30885. digits:
  30886. description: |-
  30887. Digits specifies the number of digits in the generated
  30888. password. If omitted it defaults to 25% of the length of the password
  30889. type: integer
  30890. encoding:
  30891. default: raw
  30892. description: |-
  30893. Encoding specifies the encoding of the generated password.
  30894. Valid values are:
  30895. - "raw" (default): no encoding
  30896. - "base64": standard base64 encoding
  30897. - "base64url": base64url encoding
  30898. - "base32": base32 encoding
  30899. - "hex": hexadecimal encoding
  30900. enum:
  30901. - base64
  30902. - base64url
  30903. - base32
  30904. - hex
  30905. - raw
  30906. type: string
  30907. length:
  30908. default: 24
  30909. description: |-
  30910. Length of the password to be generated.
  30911. Defaults to 24
  30912. type: integer
  30913. noUpper:
  30914. default: false
  30915. description: Set NoUpper to disable uppercase characters
  30916. type: boolean
  30917. secretKeys:
  30918. description: |-
  30919. SecretKeys defines the keys that will be populated with generated passwords.
  30920. Defaults to "password" when not set.
  30921. items:
  30922. type: string
  30923. minItems: 1
  30924. type: array
  30925. symbolCharacters:
  30926. description: |-
  30927. SymbolCharacters specifies the special characters that should be used
  30928. in the generated password.
  30929. type: string
  30930. symbols:
  30931. description: |-
  30932. Symbols specifies the number of symbol characters in the generated
  30933. password. If omitted it defaults to 25% of the length of the password
  30934. type: integer
  30935. required:
  30936. - allowRepeat
  30937. - length
  30938. - noUpper
  30939. type: object
  30940. type: object
  30941. served: true
  30942. storage: true
  30943. subresources:
  30944. status: {}
  30945. ---
  30946. apiVersion: apiextensions.k8s.io/v1
  30947. kind: CustomResourceDefinition
  30948. metadata:
  30949. annotations:
  30950. controller-gen.kubebuilder.io/version: v0.19.0
  30951. labels:
  30952. external-secrets.io/component: controller
  30953. name: quayaccesstokens.generators.external-secrets.io
  30954. spec:
  30955. group: generators.external-secrets.io
  30956. names:
  30957. categories:
  30958. - external-secrets
  30959. - external-secrets-generators
  30960. kind: QuayAccessToken
  30961. listKind: QuayAccessTokenList
  30962. plural: quayaccesstokens
  30963. singular: quayaccesstoken
  30964. scope: Namespaced
  30965. versions:
  30966. - name: v1alpha1
  30967. schema:
  30968. openAPIV3Schema:
  30969. description: QuayAccessToken generates Quay oauth token for pulling/pushing images
  30970. properties:
  30971. apiVersion:
  30972. description: |-
  30973. APIVersion defines the versioned schema of this representation of an object.
  30974. Servers should convert recognized schemas to the latest internal value, and
  30975. may reject unrecognized values.
  30976. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30977. type: string
  30978. kind:
  30979. description: |-
  30980. Kind is a string value representing the REST resource this object represents.
  30981. Servers may infer this from the endpoint the client submits requests to.
  30982. Cannot be updated.
  30983. In CamelCase.
  30984. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30985. type: string
  30986. metadata:
  30987. type: object
  30988. spec:
  30989. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  30990. properties:
  30991. robotAccount:
  30992. description: Name of the robot account you are federating with
  30993. type: string
  30994. serviceAccountRef:
  30995. description: Name of the service account you are federating with
  30996. properties:
  30997. audiences:
  30998. description: |-
  30999. Audience specifies the `aud` claim for the service account token
  31000. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31001. then this audiences will be appended to the list
  31002. items:
  31003. type: string
  31004. type: array
  31005. name:
  31006. description: The name of the ServiceAccount resource being referred to.
  31007. maxLength: 253
  31008. minLength: 1
  31009. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31010. type: string
  31011. namespace:
  31012. description: |-
  31013. Namespace of the resource being referred to.
  31014. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31015. maxLength: 63
  31016. minLength: 1
  31017. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31018. type: string
  31019. required:
  31020. - name
  31021. type: object
  31022. url:
  31023. description: URL configures the Quay instance URL. Defaults to quay.io.
  31024. type: string
  31025. required:
  31026. - robotAccount
  31027. - serviceAccountRef
  31028. type: object
  31029. type: object
  31030. served: true
  31031. storage: true
  31032. subresources:
  31033. status: {}
  31034. ---
  31035. apiVersion: apiextensions.k8s.io/v1
  31036. kind: CustomResourceDefinition
  31037. metadata:
  31038. annotations:
  31039. controller-gen.kubebuilder.io/version: v0.19.0
  31040. labels:
  31041. external-secrets.io/component: controller
  31042. name: sshkeys.generators.external-secrets.io
  31043. spec:
  31044. group: generators.external-secrets.io
  31045. names:
  31046. categories:
  31047. - external-secrets
  31048. - external-secrets-generators
  31049. kind: SSHKey
  31050. listKind: SSHKeyList
  31051. plural: sshkeys
  31052. singular: sshkey
  31053. scope: Namespaced
  31054. versions:
  31055. - name: v1alpha1
  31056. schema:
  31057. openAPIV3Schema:
  31058. description: SSHKey generates SSH key pairs.
  31059. properties:
  31060. apiVersion:
  31061. description: |-
  31062. APIVersion defines the versioned schema of this representation of an object.
  31063. Servers should convert recognized schemas to the latest internal value, and
  31064. may reject unrecognized values.
  31065. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31066. type: string
  31067. kind:
  31068. description: |-
  31069. Kind is a string value representing the REST resource this object represents.
  31070. Servers may infer this from the endpoint the client submits requests to.
  31071. Cannot be updated.
  31072. In CamelCase.
  31073. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31074. type: string
  31075. metadata:
  31076. type: object
  31077. spec:
  31078. description: SSHKeySpec controls the behavior of the ssh key generator.
  31079. properties:
  31080. comment:
  31081. description: Comment specifies an optional comment for the SSH key
  31082. type: string
  31083. keySize:
  31084. description: |-
  31085. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  31086. For RSA keys: 2048, 3072, 4096
  31087. For ECDSA keys: 256, 384, 521
  31088. Ignored for ed25519 keys
  31089. maximum: 8192
  31090. minimum: 256
  31091. type: integer
  31092. keyType:
  31093. default: rsa
  31094. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  31095. enum:
  31096. - rsa
  31097. - ecdsa
  31098. - ed25519
  31099. type: string
  31100. type: object
  31101. type: object
  31102. served: true
  31103. storage: true
  31104. subresources:
  31105. status: {}
  31106. ---
  31107. apiVersion: apiextensions.k8s.io/v1
  31108. kind: CustomResourceDefinition
  31109. metadata:
  31110. annotations:
  31111. controller-gen.kubebuilder.io/version: v0.19.0
  31112. labels:
  31113. external-secrets.io/component: controller
  31114. name: stssessiontokens.generators.external-secrets.io
  31115. spec:
  31116. group: generators.external-secrets.io
  31117. names:
  31118. categories:
  31119. - external-secrets
  31120. - external-secrets-generators
  31121. kind: STSSessionToken
  31122. listKind: STSSessionTokenList
  31123. plural: stssessiontokens
  31124. singular: stssessiontoken
  31125. scope: Namespaced
  31126. versions:
  31127. - name: v1alpha1
  31128. schema:
  31129. openAPIV3Schema:
  31130. description: |-
  31131. STSSessionToken uses the GetSessionToken API to retrieve an authorization token.
  31132. The authorization token is valid for 12 hours.
  31133. The authorizationToken returned is a base64 encoded string that can be decoded.
  31134. For more information, see GetSessionToken (https://docs.aws.amazon.com/STS/latest/APIReference/API_GetSessionToken.html).
  31135. properties:
  31136. apiVersion:
  31137. description: |-
  31138. APIVersion defines the versioned schema of this representation of an object.
  31139. Servers should convert recognized schemas to the latest internal value, and
  31140. may reject unrecognized values.
  31141. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31142. type: string
  31143. kind:
  31144. description: |-
  31145. Kind is a string value representing the REST resource this object represents.
  31146. Servers may infer this from the endpoint the client submits requests to.
  31147. Cannot be updated.
  31148. In CamelCase.
  31149. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31150. type: string
  31151. metadata:
  31152. type: object
  31153. spec:
  31154. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  31155. properties:
  31156. auth:
  31157. description: Auth defines how to authenticate with AWS
  31158. properties:
  31159. jwt:
  31160. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  31161. properties:
  31162. serviceAccountRef:
  31163. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31164. properties:
  31165. audiences:
  31166. description: |-
  31167. Audience specifies the `aud` claim for the service account token
  31168. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31169. then this audiences will be appended to the list
  31170. items:
  31171. type: string
  31172. type: array
  31173. name:
  31174. description: The name of the ServiceAccount resource being referred to.
  31175. maxLength: 253
  31176. minLength: 1
  31177. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31178. type: string
  31179. namespace:
  31180. description: |-
  31181. Namespace of the resource being referred to.
  31182. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31183. maxLength: 63
  31184. minLength: 1
  31185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31186. type: string
  31187. required:
  31188. - name
  31189. type: object
  31190. type: object
  31191. secretRef:
  31192. description: |-
  31193. AWSAuthSecretRef holds secret references for AWS credentials
  31194. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  31195. properties:
  31196. accessKeyIDSecretRef:
  31197. description: The AccessKeyID is used for authentication
  31198. properties:
  31199. key:
  31200. description: |-
  31201. A key in the referenced Secret.
  31202. Some instances of this field may be defaulted, in others it may be required.
  31203. maxLength: 253
  31204. minLength: 1
  31205. pattern: ^[-._a-zA-Z0-9]+$
  31206. type: string
  31207. name:
  31208. description: The name of the Secret resource being referred to.
  31209. maxLength: 253
  31210. minLength: 1
  31211. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31212. type: string
  31213. namespace:
  31214. description: |-
  31215. The namespace of the Secret resource being referred to.
  31216. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31217. maxLength: 63
  31218. minLength: 1
  31219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31220. type: string
  31221. type: object
  31222. secretAccessKeySecretRef:
  31223. description: The SecretAccessKey is used for authentication
  31224. properties:
  31225. key:
  31226. description: |-
  31227. A key in the referenced Secret.
  31228. Some instances of this field may be defaulted, in others it may be required.
  31229. maxLength: 253
  31230. minLength: 1
  31231. pattern: ^[-._a-zA-Z0-9]+$
  31232. type: string
  31233. name:
  31234. description: The name of the Secret resource being referred to.
  31235. maxLength: 253
  31236. minLength: 1
  31237. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31238. type: string
  31239. namespace:
  31240. description: |-
  31241. The namespace of the Secret resource being referred to.
  31242. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31243. maxLength: 63
  31244. minLength: 1
  31245. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31246. type: string
  31247. type: object
  31248. sessionTokenSecretRef:
  31249. description: |-
  31250. The SessionToken used for authentication
  31251. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  31252. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  31253. properties:
  31254. key:
  31255. description: |-
  31256. A key in the referenced Secret.
  31257. Some instances of this field may be defaulted, in others it may be required.
  31258. maxLength: 253
  31259. minLength: 1
  31260. pattern: ^[-._a-zA-Z0-9]+$
  31261. type: string
  31262. name:
  31263. description: The name of the Secret resource being referred to.
  31264. maxLength: 253
  31265. minLength: 1
  31266. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31267. type: string
  31268. namespace:
  31269. description: |-
  31270. The namespace of the Secret resource being referred to.
  31271. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31272. maxLength: 63
  31273. minLength: 1
  31274. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31275. type: string
  31276. type: object
  31277. type: object
  31278. type: object
  31279. region:
  31280. description: Region specifies the region to operate in.
  31281. type: string
  31282. requestParameters:
  31283. description: RequestParameters contains parameters that can be passed to the STS service.
  31284. properties:
  31285. serialNumber:
  31286. description: |-
  31287. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  31288. the GetSessionToken call.
  31289. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  31290. (such as arn:aws:iam::123456789012:mfa/user)
  31291. type: string
  31292. sessionDuration:
  31293. format: int32
  31294. type: integer
  31295. tokenCode:
  31296. description: TokenCode is the value provided by the MFA device, if MFA is required.
  31297. type: string
  31298. type: object
  31299. role:
  31300. description: |-
  31301. You can assume a role before making calls to the
  31302. desired AWS service.
  31303. type: string
  31304. required:
  31305. - region
  31306. type: object
  31307. type: object
  31308. served: true
  31309. storage: true
  31310. subresources:
  31311. status: {}
  31312. ---
  31313. apiVersion: apiextensions.k8s.io/v1
  31314. kind: CustomResourceDefinition
  31315. metadata:
  31316. annotations:
  31317. controller-gen.kubebuilder.io/version: v0.19.0
  31318. labels:
  31319. external-secrets.io/component: controller
  31320. name: uuids.generators.external-secrets.io
  31321. spec:
  31322. group: generators.external-secrets.io
  31323. names:
  31324. categories:
  31325. - external-secrets
  31326. - external-secrets-generators
  31327. kind: UUID
  31328. listKind: UUIDList
  31329. plural: uuids
  31330. singular: uuid
  31331. scope: Namespaced
  31332. versions:
  31333. - name: v1alpha1
  31334. schema:
  31335. openAPIV3Schema:
  31336. description: UUID generates a version 1 UUID (e56657e3-764f-11ef-a397-65231a88c216).
  31337. properties:
  31338. apiVersion:
  31339. description: |-
  31340. APIVersion defines the versioned schema of this representation of an object.
  31341. Servers should convert recognized schemas to the latest internal value, and
  31342. may reject unrecognized values.
  31343. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31344. type: string
  31345. kind:
  31346. description: |-
  31347. Kind is a string value representing the REST resource this object represents.
  31348. Servers may infer this from the endpoint the client submits requests to.
  31349. Cannot be updated.
  31350. In CamelCase.
  31351. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31352. type: string
  31353. metadata:
  31354. type: object
  31355. spec:
  31356. description: UUIDSpec controls the behavior of the uuid generator.
  31357. type: object
  31358. type: object
  31359. served: true
  31360. storage: true
  31361. subresources:
  31362. status: {}
  31363. ---
  31364. apiVersion: apiextensions.k8s.io/v1
  31365. kind: CustomResourceDefinition
  31366. metadata:
  31367. annotations:
  31368. controller-gen.kubebuilder.io/version: v0.19.0
  31369. labels:
  31370. external-secrets.io/component: controller
  31371. name: vaultdynamicsecrets.generators.external-secrets.io
  31372. spec:
  31373. group: generators.external-secrets.io
  31374. names:
  31375. categories:
  31376. - external-secrets
  31377. - external-secrets-generators
  31378. kind: VaultDynamicSecret
  31379. listKind: VaultDynamicSecretList
  31380. plural: vaultdynamicsecrets
  31381. singular: vaultdynamicsecret
  31382. scope: Namespaced
  31383. versions:
  31384. - name: v1alpha1
  31385. schema:
  31386. openAPIV3Schema:
  31387. description: VaultDynamicSecret represents a generator that can create dynamic secrets from HashiCorp Vault.
  31388. properties:
  31389. apiVersion:
  31390. description: |-
  31391. APIVersion defines the versioned schema of this representation of an object.
  31392. Servers should convert recognized schemas to the latest internal value, and
  31393. may reject unrecognized values.
  31394. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31395. type: string
  31396. kind:
  31397. description: |-
  31398. Kind is a string value representing the REST resource this object represents.
  31399. Servers may infer this from the endpoint the client submits requests to.
  31400. Cannot be updated.
  31401. In CamelCase.
  31402. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31403. type: string
  31404. metadata:
  31405. type: object
  31406. spec:
  31407. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  31408. properties:
  31409. allowEmptyResponse:
  31410. default: false
  31411. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  31412. type: boolean
  31413. controller:
  31414. description: |-
  31415. Used to select the correct ESO controller (think: ingress.ingressClassName)
  31416. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  31417. type: string
  31418. getParameters:
  31419. additionalProperties:
  31420. items:
  31421. type: string
  31422. type: array
  31423. description: |-
  31424. GetParameters are query-string parameters passed to Vault on GET calls.
  31425. Each key may map to multiple values, matching HTTP query-string semantics.
  31426. Ignored for non-GET methods; use Parameters for write bodies.
  31427. type: object
  31428. method:
  31429. description: Vault API method to use (GET/POST/other)
  31430. type: string
  31431. parameters:
  31432. description: Parameters to pass to Vault write (for non-GET methods)
  31433. x-kubernetes-preserve-unknown-fields: true
  31434. path:
  31435. description: Vault path to obtain the dynamic secret from
  31436. type: string
  31437. provider:
  31438. description: Vault provider common spec
  31439. properties:
  31440. auth:
  31441. description: Auth configures how secret-manager authenticates with the Vault server.
  31442. properties:
  31443. appRole:
  31444. description: |-
  31445. AppRole authenticates with Vault using the App Role auth mechanism,
  31446. with the role and secret stored in a Kubernetes Secret resource.
  31447. properties:
  31448. path:
  31449. default: approle
  31450. description: |-
  31451. Path where the App Role authentication backend is mounted
  31452. in Vault, e.g: "approle"
  31453. type: string
  31454. roleId:
  31455. description: |-
  31456. RoleID configured in the App Role authentication backend when setting
  31457. up the authentication backend in Vault.
  31458. type: string
  31459. roleRef:
  31460. description: |-
  31461. Reference to a key in a Secret that contains the App Role ID used
  31462. to authenticate with Vault.
  31463. The `key` field must be specified and denotes which entry within the Secret
  31464. resource is used as the app role id.
  31465. properties:
  31466. key:
  31467. description: |-
  31468. A key in the referenced Secret.
  31469. Some instances of this field may be defaulted, in others it may be required.
  31470. maxLength: 253
  31471. minLength: 1
  31472. pattern: ^[-._a-zA-Z0-9]+$
  31473. type: string
  31474. name:
  31475. description: The name of the Secret resource being referred to.
  31476. maxLength: 253
  31477. minLength: 1
  31478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31479. type: string
  31480. namespace:
  31481. description: |-
  31482. The namespace of the Secret resource being referred to.
  31483. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31484. maxLength: 63
  31485. minLength: 1
  31486. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31487. type: string
  31488. type: object
  31489. secretRef:
  31490. description: |-
  31491. Reference to a key in a Secret that contains the App Role secret used
  31492. to authenticate with Vault.
  31493. The `key` field must be specified and denotes which entry within the Secret
  31494. resource is used as the app role secret.
  31495. properties:
  31496. key:
  31497. description: |-
  31498. A key in the referenced Secret.
  31499. Some instances of this field may be defaulted, in others it may be required.
  31500. maxLength: 253
  31501. minLength: 1
  31502. pattern: ^[-._a-zA-Z0-9]+$
  31503. type: string
  31504. name:
  31505. description: The name of the Secret resource being referred to.
  31506. maxLength: 253
  31507. minLength: 1
  31508. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31509. type: string
  31510. namespace:
  31511. description: |-
  31512. The namespace of the Secret resource being referred to.
  31513. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31514. maxLength: 63
  31515. minLength: 1
  31516. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31517. type: string
  31518. type: object
  31519. required:
  31520. - path
  31521. - secretRef
  31522. type: object
  31523. cert:
  31524. description: |-
  31525. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  31526. Cert authentication method
  31527. properties:
  31528. clientCert:
  31529. description: |-
  31530. ClientCert is a certificate to authenticate using the Cert Vault
  31531. authentication method
  31532. properties:
  31533. key:
  31534. description: |-
  31535. A key in the referenced Secret.
  31536. Some instances of this field may be defaulted, in others it may be required.
  31537. maxLength: 253
  31538. minLength: 1
  31539. pattern: ^[-._a-zA-Z0-9]+$
  31540. type: string
  31541. name:
  31542. description: The name of the Secret resource being referred to.
  31543. maxLength: 253
  31544. minLength: 1
  31545. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31546. type: string
  31547. namespace:
  31548. description: |-
  31549. The namespace of the Secret resource being referred to.
  31550. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31551. maxLength: 63
  31552. minLength: 1
  31553. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31554. type: string
  31555. type: object
  31556. path:
  31557. default: cert
  31558. description: |-
  31559. Path where the Certificate authentication backend is mounted
  31560. in Vault, e.g: "cert"
  31561. type: string
  31562. secretRef:
  31563. description: |-
  31564. SecretRef to a key in a Secret resource containing client private key to
  31565. authenticate with Vault using the Cert authentication method
  31566. properties:
  31567. key:
  31568. description: |-
  31569. A key in the referenced Secret.
  31570. Some instances of this field may be defaulted, in others it may be required.
  31571. maxLength: 253
  31572. minLength: 1
  31573. pattern: ^[-._a-zA-Z0-9]+$
  31574. type: string
  31575. name:
  31576. description: The name of the Secret resource being referred to.
  31577. maxLength: 253
  31578. minLength: 1
  31579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31580. type: string
  31581. namespace:
  31582. description: |-
  31583. The namespace of the Secret resource being referred to.
  31584. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31585. maxLength: 63
  31586. minLength: 1
  31587. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31588. type: string
  31589. type: object
  31590. vaultRole:
  31591. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  31592. type: string
  31593. type: object
  31594. gcp:
  31595. description: |-
  31596. Gcp authenticates with Vault using Google Cloud Platform authentication method
  31597. GCP authentication method
  31598. properties:
  31599. location:
  31600. description: Location optionally defines a location/region for the secret
  31601. type: string
  31602. path:
  31603. default: gcp
  31604. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  31605. type: string
  31606. projectID:
  31607. description: Project ID of the Google Cloud Platform project
  31608. type: string
  31609. role:
  31610. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  31611. type: string
  31612. secretRef:
  31613. description: Specify credentials in a Secret object
  31614. properties:
  31615. secretAccessKeySecretRef:
  31616. description: The SecretAccessKey is used for authentication
  31617. properties:
  31618. key:
  31619. description: |-
  31620. A key in the referenced Secret.
  31621. Some instances of this field may be defaulted, in others it may be required.
  31622. maxLength: 253
  31623. minLength: 1
  31624. pattern: ^[-._a-zA-Z0-9]+$
  31625. type: string
  31626. name:
  31627. description: The name of the Secret resource being referred to.
  31628. maxLength: 253
  31629. minLength: 1
  31630. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31631. type: string
  31632. namespace:
  31633. description: |-
  31634. The namespace of the Secret resource being referred to.
  31635. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31636. maxLength: 63
  31637. minLength: 1
  31638. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31639. type: string
  31640. type: object
  31641. type: object
  31642. serviceAccountRef:
  31643. description: ServiceAccountRef to a service account for impersonation
  31644. properties:
  31645. audiences:
  31646. description: |-
  31647. Audience specifies the `aud` claim for the service account token
  31648. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31649. then this audiences will be appended to the list
  31650. items:
  31651. type: string
  31652. type: array
  31653. name:
  31654. description: The name of the ServiceAccount resource being referred to.
  31655. maxLength: 253
  31656. minLength: 1
  31657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31658. type: string
  31659. namespace:
  31660. description: |-
  31661. Namespace of the resource being referred to.
  31662. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31663. maxLength: 63
  31664. minLength: 1
  31665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31666. type: string
  31667. required:
  31668. - name
  31669. type: object
  31670. workloadIdentity:
  31671. description: Specify a service account with Workload Identity
  31672. properties:
  31673. clusterLocation:
  31674. description: |-
  31675. ClusterLocation is the location of the cluster
  31676. If not specified, it fetches information from the metadata server
  31677. type: string
  31678. clusterName:
  31679. description: |-
  31680. ClusterName is the name of the cluster
  31681. If not specified, it fetches information from the metadata server
  31682. type: string
  31683. clusterProjectID:
  31684. description: |-
  31685. ClusterProjectID is the project ID of the cluster
  31686. If not specified, it fetches information from the metadata server
  31687. type: string
  31688. serviceAccountRef:
  31689. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31690. properties:
  31691. audiences:
  31692. description: |-
  31693. Audience specifies the `aud` claim for the service account token
  31694. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31695. then this audiences will be appended to the list
  31696. items:
  31697. type: string
  31698. type: array
  31699. name:
  31700. description: The name of the ServiceAccount resource being referred to.
  31701. maxLength: 253
  31702. minLength: 1
  31703. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31704. type: string
  31705. namespace:
  31706. description: |-
  31707. Namespace of the resource being referred to.
  31708. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31709. maxLength: 63
  31710. minLength: 1
  31711. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31712. type: string
  31713. required:
  31714. - name
  31715. type: object
  31716. required:
  31717. - serviceAccountRef
  31718. type: object
  31719. required:
  31720. - role
  31721. type: object
  31722. iam:
  31723. description: |-
  31724. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  31725. AWS IAM authentication method
  31726. properties:
  31727. externalID:
  31728. description: AWS External ID set on assumed IAM roles
  31729. type: string
  31730. jwt:
  31731. description: Specify a service account with IRSA enabled
  31732. properties:
  31733. serviceAccountRef:
  31734. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31735. properties:
  31736. audiences:
  31737. description: |-
  31738. Audience specifies the `aud` claim for the service account token
  31739. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31740. then this audiences will be appended to the list
  31741. items:
  31742. type: string
  31743. type: array
  31744. name:
  31745. description: The name of the ServiceAccount resource being referred to.
  31746. maxLength: 253
  31747. minLength: 1
  31748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31749. type: string
  31750. namespace:
  31751. description: |-
  31752. Namespace of the resource being referred to.
  31753. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31754. maxLength: 63
  31755. minLength: 1
  31756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31757. type: string
  31758. required:
  31759. - name
  31760. type: object
  31761. type: object
  31762. path:
  31763. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  31764. type: string
  31765. region:
  31766. description: AWS region
  31767. type: string
  31768. role:
  31769. description: This is the AWS role to be assumed before talking to vault
  31770. type: string
  31771. secretRef:
  31772. description: Specify credentials in a Secret object
  31773. properties:
  31774. accessKeyIDSecretRef:
  31775. description: The AccessKeyID is used for authentication
  31776. properties:
  31777. key:
  31778. description: |-
  31779. A key in the referenced Secret.
  31780. Some instances of this field may be defaulted, in others it may be required.
  31781. maxLength: 253
  31782. minLength: 1
  31783. pattern: ^[-._a-zA-Z0-9]+$
  31784. type: string
  31785. name:
  31786. description: The name of the Secret resource being referred to.
  31787. maxLength: 253
  31788. minLength: 1
  31789. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31790. type: string
  31791. namespace:
  31792. description: |-
  31793. The namespace of the Secret resource being referred to.
  31794. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31795. maxLength: 63
  31796. minLength: 1
  31797. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31798. type: string
  31799. type: object
  31800. secretAccessKeySecretRef:
  31801. description: The SecretAccessKey is used for authentication
  31802. properties:
  31803. key:
  31804. description: |-
  31805. A key in the referenced Secret.
  31806. Some instances of this field may be defaulted, in others it may be required.
  31807. maxLength: 253
  31808. minLength: 1
  31809. pattern: ^[-._a-zA-Z0-9]+$
  31810. type: string
  31811. name:
  31812. description: The name of the Secret resource being referred to.
  31813. maxLength: 253
  31814. minLength: 1
  31815. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31816. type: string
  31817. namespace:
  31818. description: |-
  31819. The namespace of the Secret resource being referred to.
  31820. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31821. maxLength: 63
  31822. minLength: 1
  31823. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31824. type: string
  31825. type: object
  31826. sessionTokenSecretRef:
  31827. description: |-
  31828. The SessionToken used for authentication
  31829. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  31830. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  31831. properties:
  31832. key:
  31833. description: |-
  31834. A key in the referenced Secret.
  31835. Some instances of this field may be defaulted, in others it may be required.
  31836. maxLength: 253
  31837. minLength: 1
  31838. pattern: ^[-._a-zA-Z0-9]+$
  31839. type: string
  31840. name:
  31841. description: The name of the Secret resource being referred to.
  31842. maxLength: 253
  31843. minLength: 1
  31844. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31845. type: string
  31846. namespace:
  31847. description: |-
  31848. The namespace of the Secret resource being referred to.
  31849. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31850. maxLength: 63
  31851. minLength: 1
  31852. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31853. type: string
  31854. type: object
  31855. type: object
  31856. vaultAwsIamServerID:
  31857. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  31858. type: string
  31859. vaultRole:
  31860. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  31861. type: string
  31862. required:
  31863. - vaultRole
  31864. type: object
  31865. jwt:
  31866. description: |-
  31867. Jwt authenticates with Vault by passing role and JWT token using the
  31868. JWT/OIDC authentication method
  31869. properties:
  31870. kubernetesServiceAccountToken:
  31871. description: |-
  31872. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  31873. a token for with the `TokenRequest` API.
  31874. properties:
  31875. audiences:
  31876. description: |-
  31877. Optional audiences field that will be used to request a temporary Kubernetes service
  31878. account token for the service account referenced by `serviceAccountRef`.
  31879. Defaults to a single audience `vault` it not specified.
  31880. Deprecated: use serviceAccountRef.Audiences instead
  31881. items:
  31882. type: string
  31883. type: array
  31884. expirationSeconds:
  31885. description: |-
  31886. Optional expiration time in seconds that will be used to request a temporary
  31887. Kubernetes service account token for the service account referenced by
  31888. `serviceAccountRef`.
  31889. Deprecated: this will be removed in the future.
  31890. Defaults to 10 minutes.
  31891. format: int64
  31892. type: integer
  31893. serviceAccountRef:
  31894. description: Service account field containing the name of a kubernetes ServiceAccount.
  31895. properties:
  31896. audiences:
  31897. description: |-
  31898. Audience specifies the `aud` claim for the service account token
  31899. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31900. then this audiences will be appended to the list
  31901. items:
  31902. type: string
  31903. type: array
  31904. name:
  31905. description: The name of the ServiceAccount resource being referred to.
  31906. maxLength: 253
  31907. minLength: 1
  31908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31909. type: string
  31910. namespace:
  31911. description: |-
  31912. Namespace of the resource being referred to.
  31913. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31914. maxLength: 63
  31915. minLength: 1
  31916. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31917. type: string
  31918. required:
  31919. - name
  31920. type: object
  31921. required:
  31922. - serviceAccountRef
  31923. type: object
  31924. path:
  31925. default: jwt
  31926. description: |-
  31927. Path where the JWT authentication backend is mounted
  31928. in Vault, e.g: "jwt"
  31929. type: string
  31930. role:
  31931. description: |-
  31932. Role is a JWT role to authenticate using the JWT/OIDC Vault
  31933. authentication method
  31934. type: string
  31935. secretRef:
  31936. description: |-
  31937. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  31938. authenticate with Vault using the JWT/OIDC authentication method.
  31939. properties:
  31940. key:
  31941. description: |-
  31942. A key in the referenced Secret.
  31943. Some instances of this field may be defaulted, in others it may be required.
  31944. maxLength: 253
  31945. minLength: 1
  31946. pattern: ^[-._a-zA-Z0-9]+$
  31947. type: string
  31948. name:
  31949. description: The name of the Secret resource being referred to.
  31950. maxLength: 253
  31951. minLength: 1
  31952. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31953. type: string
  31954. namespace:
  31955. description: |-
  31956. The namespace of the Secret resource being referred to.
  31957. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31958. maxLength: 63
  31959. minLength: 1
  31960. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31961. type: string
  31962. type: object
  31963. required:
  31964. - path
  31965. type: object
  31966. kubernetes:
  31967. description: |-
  31968. Kubernetes authenticates with Vault by passing the ServiceAccount
  31969. token stored in the named Secret resource to the Vault server.
  31970. properties:
  31971. mountPath:
  31972. default: kubernetes
  31973. description: |-
  31974. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  31975. "kubernetes"
  31976. type: string
  31977. role:
  31978. description: |-
  31979. A required field containing the Vault Role to assume. A Role binds a
  31980. Kubernetes ServiceAccount with a set of Vault policies.
  31981. type: string
  31982. secretRef:
  31983. description: |-
  31984. Optional secret field containing a Kubernetes ServiceAccount JWT used
  31985. for authenticating with Vault. If a name is specified without a key,
  31986. `token` is the default. If one is not specified, the one bound to
  31987. the controller will be used.
  31988. properties:
  31989. key:
  31990. description: |-
  31991. A key in the referenced Secret.
  31992. Some instances of this field may be defaulted, in others it may be required.
  31993. maxLength: 253
  31994. minLength: 1
  31995. pattern: ^[-._a-zA-Z0-9]+$
  31996. type: string
  31997. name:
  31998. description: The name of the Secret resource being referred to.
  31999. maxLength: 253
  32000. minLength: 1
  32001. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32002. type: string
  32003. namespace:
  32004. description: |-
  32005. The namespace of the Secret resource being referred to.
  32006. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32007. maxLength: 63
  32008. minLength: 1
  32009. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32010. type: string
  32011. type: object
  32012. serviceAccountRef:
  32013. description: |-
  32014. Optional service account field containing the name of a kubernetes ServiceAccount.
  32015. If the service account is specified, the service account secret token JWT will be used
  32016. for authenticating with Vault. If the service account selector is not supplied,
  32017. the secretRef will be used instead.
  32018. properties:
  32019. audiences:
  32020. description: |-
  32021. Audience specifies the `aud` claim for the service account token
  32022. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  32023. then this audiences will be appended to the list
  32024. items:
  32025. type: string
  32026. type: array
  32027. name:
  32028. description: The name of the ServiceAccount resource being referred to.
  32029. maxLength: 253
  32030. minLength: 1
  32031. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32032. type: string
  32033. namespace:
  32034. description: |-
  32035. Namespace of the resource being referred to.
  32036. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32037. maxLength: 63
  32038. minLength: 1
  32039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32040. type: string
  32041. required:
  32042. - name
  32043. type: object
  32044. required:
  32045. - mountPath
  32046. - role
  32047. type: object
  32048. ldap:
  32049. description: |-
  32050. Ldap authenticates with Vault by passing username/password pair using
  32051. the LDAP authentication method
  32052. properties:
  32053. path:
  32054. default: ldap
  32055. description: |-
  32056. Path where the LDAP authentication backend is mounted
  32057. in Vault, e.g: "ldap"
  32058. type: string
  32059. secretRef:
  32060. description: |-
  32061. SecretRef to a key in a Secret resource containing password for the LDAP
  32062. user used to authenticate with Vault using the LDAP authentication
  32063. method
  32064. properties:
  32065. key:
  32066. description: |-
  32067. A key in the referenced Secret.
  32068. Some instances of this field may be defaulted, in others it may be required.
  32069. maxLength: 253
  32070. minLength: 1
  32071. pattern: ^[-._a-zA-Z0-9]+$
  32072. type: string
  32073. name:
  32074. description: The name of the Secret resource being referred to.
  32075. maxLength: 253
  32076. minLength: 1
  32077. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32078. type: string
  32079. namespace:
  32080. description: |-
  32081. The namespace of the Secret resource being referred to.
  32082. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32083. maxLength: 63
  32084. minLength: 1
  32085. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32086. type: string
  32087. type: object
  32088. username:
  32089. description: |-
  32090. Username is an LDAP username used to authenticate using the LDAP Vault
  32091. authentication method
  32092. type: string
  32093. required:
  32094. - path
  32095. - username
  32096. type: object
  32097. namespace:
  32098. description: |-
  32099. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  32100. Namespaces is a set of features within Vault Enterprise that allows
  32101. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  32102. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  32103. This will default to Vault.Namespace field if set, or empty otherwise
  32104. type: string
  32105. tokenSecretRef:
  32106. description: TokenSecretRef authenticates with Vault by presenting a token.
  32107. properties:
  32108. key:
  32109. description: |-
  32110. A key in the referenced Secret.
  32111. Some instances of this field may be defaulted, in others it may be required.
  32112. maxLength: 253
  32113. minLength: 1
  32114. pattern: ^[-._a-zA-Z0-9]+$
  32115. type: string
  32116. name:
  32117. description: The name of the Secret resource being referred to.
  32118. maxLength: 253
  32119. minLength: 1
  32120. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32121. type: string
  32122. namespace:
  32123. description: |-
  32124. The namespace of the Secret resource being referred to.
  32125. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32126. maxLength: 63
  32127. minLength: 1
  32128. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32129. type: string
  32130. type: object
  32131. userPass:
  32132. description: UserPass authenticates with Vault by passing username/password pair
  32133. properties:
  32134. path:
  32135. default: userpass
  32136. description: |-
  32137. Path where the UserPassword authentication backend is mounted
  32138. in Vault, e.g: "userpass"
  32139. type: string
  32140. secretRef:
  32141. description: |-
  32142. SecretRef to a key in a Secret resource containing password for the
  32143. user used to authenticate with Vault using the UserPass authentication
  32144. method
  32145. properties:
  32146. key:
  32147. description: |-
  32148. A key in the referenced Secret.
  32149. Some instances of this field may be defaulted, in others it may be required.
  32150. maxLength: 253
  32151. minLength: 1
  32152. pattern: ^[-._a-zA-Z0-9]+$
  32153. type: string
  32154. name:
  32155. description: The name of the Secret resource being referred to.
  32156. maxLength: 253
  32157. minLength: 1
  32158. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32159. type: string
  32160. namespace:
  32161. description: |-
  32162. The namespace of the Secret resource being referred to.
  32163. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32164. maxLength: 63
  32165. minLength: 1
  32166. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32167. type: string
  32168. type: object
  32169. username:
  32170. description: |-
  32171. Username is a username used to authenticate using the UserPass Vault
  32172. authentication method
  32173. type: string
  32174. required:
  32175. - path
  32176. - username
  32177. type: object
  32178. type: object
  32179. caBundle:
  32180. description: |-
  32181. PEM encoded CA bundle used to validate Vault server certificate. Only used
  32182. if the Server URL is using HTTPS protocol. This parameter is ignored for
  32183. plain HTTP protocol connection. If not set the system root certificates
  32184. are used to validate the TLS connection.
  32185. format: byte
  32186. type: string
  32187. caProvider:
  32188. description: The provider for the CA bundle to use to validate Vault server certificate.
  32189. properties:
  32190. key:
  32191. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  32192. maxLength: 253
  32193. minLength: 1
  32194. pattern: ^[-._a-zA-Z0-9]+$
  32195. type: string
  32196. name:
  32197. description: The name of the object located at the provider type.
  32198. maxLength: 253
  32199. minLength: 1
  32200. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32201. type: string
  32202. namespace:
  32203. description: |-
  32204. The namespace the Provider type is in.
  32205. Can only be defined when used in a ClusterSecretStore.
  32206. maxLength: 63
  32207. minLength: 1
  32208. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32209. type: string
  32210. type:
  32211. description: The type of provider to use such as "Secret", or "ConfigMap".
  32212. enum:
  32213. - Secret
  32214. - ConfigMap
  32215. type: string
  32216. required:
  32217. - name
  32218. - type
  32219. type: object
  32220. checkAndSet:
  32221. description: |-
  32222. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  32223. Only applies to Vault KV v2 stores. When enabled, write operations must include
  32224. the current version of the secret to prevent unintentional overwrites.
  32225. properties:
  32226. required:
  32227. description: |-
  32228. Required when true, all write operations must include a check-and-set parameter.
  32229. This helps prevent unintentional overwrites of secrets.
  32230. type: boolean
  32231. type: object
  32232. forwardInconsistent:
  32233. description: |-
  32234. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  32235. leader instead of simply retrying within a loop. This can increase performance if
  32236. the option is enabled serverside.
  32237. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  32238. type: boolean
  32239. headers:
  32240. additionalProperties:
  32241. type: string
  32242. description: Headers to be added in Vault request
  32243. type: object
  32244. namespace:
  32245. description: |-
  32246. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  32247. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  32248. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  32249. type: string
  32250. path:
  32251. description: |-
  32252. Path is the mount path of the Vault KV backend endpoint, e.g:
  32253. "secret". The v2 KV secret engine version specific "/data" path suffix
  32254. for fetching secrets from Vault is optional and will be appended
  32255. if not present in specified path.
  32256. type: string
  32257. readYourWrites:
  32258. description: |-
  32259. ReadYourWrites ensures isolated read-after-write semantics by
  32260. providing discovered cluster replication states in each request.
  32261. More information about eventual consistency in Vault can be found here
  32262. https://www.vaultproject.io/docs/enterprise/consistency
  32263. type: boolean
  32264. server:
  32265. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  32266. type: string
  32267. tls:
  32268. description: |-
  32269. The configuration used for client side related TLS communication, when the Vault server
  32270. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  32271. This parameter is ignored for plain HTTP protocol connection.
  32272. It's worth noting this configuration is different from the "TLS certificates auth method",
  32273. which is available under the `auth.cert` section.
  32274. properties:
  32275. certSecretRef:
  32276. description: |-
  32277. CertSecretRef is a certificate added to the transport layer
  32278. when communicating with the Vault server.
  32279. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  32280. properties:
  32281. key:
  32282. description: |-
  32283. A key in the referenced Secret.
  32284. Some instances of this field may be defaulted, in others it may be required.
  32285. maxLength: 253
  32286. minLength: 1
  32287. pattern: ^[-._a-zA-Z0-9]+$
  32288. type: string
  32289. name:
  32290. description: The name of the Secret resource being referred to.
  32291. maxLength: 253
  32292. minLength: 1
  32293. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32294. type: string
  32295. namespace:
  32296. description: |-
  32297. The namespace of the Secret resource being referred to.
  32298. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32299. maxLength: 63
  32300. minLength: 1
  32301. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32302. type: string
  32303. type: object
  32304. keySecretRef:
  32305. description: |-
  32306. KeySecretRef to a key in a Secret resource containing client private key
  32307. added to the transport layer when communicating with the Vault server.
  32308. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  32309. properties:
  32310. key:
  32311. description: |-
  32312. A key in the referenced Secret.
  32313. Some instances of this field may be defaulted, in others it may be required.
  32314. maxLength: 253
  32315. minLength: 1
  32316. pattern: ^[-._a-zA-Z0-9]+$
  32317. type: string
  32318. name:
  32319. description: The name of the Secret resource being referred to.
  32320. maxLength: 253
  32321. minLength: 1
  32322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32323. type: string
  32324. namespace:
  32325. description: |-
  32326. The namespace of the Secret resource being referred to.
  32327. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32328. maxLength: 63
  32329. minLength: 1
  32330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32331. type: string
  32332. type: object
  32333. type: object
  32334. version:
  32335. default: v2
  32336. description: |-
  32337. Version is the Vault KV secret engine version. This can be either "v1" or
  32338. "v2". Version defaults to "v2".
  32339. enum:
  32340. - v1
  32341. - v2
  32342. type: string
  32343. required:
  32344. - server
  32345. type: object
  32346. resultType:
  32347. default: Data
  32348. description: |-
  32349. Result type defines which data is returned from the generator.
  32350. By default, it is the "data" section of the Vault API response.
  32351. When using e.g. /auth/token/create the "data" section is empty but
  32352. the "auth" section contains the generated token.
  32353. Please refer to the vault docs regarding the result data structure.
  32354. Additionally, accessing the raw response is possibly by using "Raw" result type.
  32355. enum:
  32356. - Data
  32357. - Auth
  32358. - Raw
  32359. type: string
  32360. retrySettings:
  32361. description: Used to configure http retries if failed
  32362. properties:
  32363. maxRetries:
  32364. format: int32
  32365. type: integer
  32366. retryInterval:
  32367. type: string
  32368. type: object
  32369. required:
  32370. - path
  32371. - provider
  32372. type: object
  32373. type: object
  32374. served: true
  32375. storage: true
  32376. subresources:
  32377. status: {}
  32378. ---
  32379. apiVersion: apiextensions.k8s.io/v1
  32380. kind: CustomResourceDefinition
  32381. metadata:
  32382. annotations:
  32383. controller-gen.kubebuilder.io/version: v0.19.0
  32384. labels:
  32385. external-secrets.io/component: controller
  32386. name: webhooks.generators.external-secrets.io
  32387. spec:
  32388. group: generators.external-secrets.io
  32389. names:
  32390. categories:
  32391. - external-secrets
  32392. - external-secrets-generators
  32393. kind: Webhook
  32394. listKind: WebhookList
  32395. plural: webhooks
  32396. singular: webhook
  32397. scope: Namespaced
  32398. versions:
  32399. - name: v1alpha1
  32400. schema:
  32401. openAPIV3Schema:
  32402. description: |-
  32403. Webhook connects to a third party API server to handle the secrets generation
  32404. configuration parameters in spec.
  32405. You can specify the server, the token, and additional body parameters.
  32406. See documentation for the full API specification for requests and responses.
  32407. properties:
  32408. apiVersion:
  32409. description: |-
  32410. APIVersion defines the versioned schema of this representation of an object.
  32411. Servers should convert recognized schemas to the latest internal value, and
  32412. may reject unrecognized values.
  32413. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  32414. type: string
  32415. kind:
  32416. description: |-
  32417. Kind is a string value representing the REST resource this object represents.
  32418. Servers may infer this from the endpoint the client submits requests to.
  32419. Cannot be updated.
  32420. In CamelCase.
  32421. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  32422. type: string
  32423. metadata:
  32424. type: object
  32425. spec:
  32426. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  32427. properties:
  32428. auth:
  32429. description: Auth specifies a authorization protocol. Only one protocol may be set.
  32430. maxProperties: 1
  32431. minProperties: 1
  32432. properties:
  32433. ntlm:
  32434. description: NTLMProtocol configures the store to use NTLM for auth
  32435. properties:
  32436. passwordSecret:
  32437. description: |-
  32438. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  32439. In some instances, `key` is a required field.
  32440. properties:
  32441. key:
  32442. description: |-
  32443. A key in the referenced Secret.
  32444. Some instances of this field may be defaulted, in others it may be required.
  32445. maxLength: 253
  32446. minLength: 1
  32447. pattern: ^[-._a-zA-Z0-9]+$
  32448. type: string
  32449. name:
  32450. description: The name of the Secret resource being referred to.
  32451. maxLength: 253
  32452. minLength: 1
  32453. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32454. type: string
  32455. namespace:
  32456. description: |-
  32457. The namespace of the Secret resource being referred to.
  32458. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32459. maxLength: 63
  32460. minLength: 1
  32461. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32462. type: string
  32463. type: object
  32464. usernameSecret:
  32465. description: |-
  32466. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  32467. In some instances, `key` is a required field.
  32468. properties:
  32469. key:
  32470. description: |-
  32471. A key in the referenced Secret.
  32472. Some instances of this field may be defaulted, in others it may be required.
  32473. maxLength: 253
  32474. minLength: 1
  32475. pattern: ^[-._a-zA-Z0-9]+$
  32476. type: string
  32477. name:
  32478. description: The name of the Secret resource being referred to.
  32479. maxLength: 253
  32480. minLength: 1
  32481. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32482. type: string
  32483. namespace:
  32484. description: |-
  32485. The namespace of the Secret resource being referred to.
  32486. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32487. maxLength: 63
  32488. minLength: 1
  32489. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32490. type: string
  32491. type: object
  32492. required:
  32493. - passwordSecret
  32494. - usernameSecret
  32495. type: object
  32496. type: object
  32497. body:
  32498. description: Body
  32499. type: string
  32500. caBundle:
  32501. description: |-
  32502. PEM encoded CA bundle used to validate webhook server certificate. Only used
  32503. if the Server URL is using HTTPS protocol. This parameter is ignored for
  32504. plain HTTP protocol connection. If not set the system root certificates
  32505. are used to validate the TLS connection.
  32506. format: byte
  32507. type: string
  32508. caProvider:
  32509. description: The provider for the CA bundle to use to validate webhook server certificate.
  32510. properties:
  32511. key:
  32512. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  32513. maxLength: 253
  32514. minLength: 1
  32515. pattern: ^[-._a-zA-Z0-9]+$
  32516. type: string
  32517. name:
  32518. description: The name of the object located at the provider type.
  32519. maxLength: 253
  32520. minLength: 1
  32521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32522. type: string
  32523. namespace:
  32524. description: The namespace the Provider type is in.
  32525. maxLength: 63
  32526. minLength: 1
  32527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32528. type: string
  32529. type:
  32530. description: The type of provider to use such as "Secret", or "ConfigMap".
  32531. enum:
  32532. - Secret
  32533. - ConfigMap
  32534. type: string
  32535. required:
  32536. - name
  32537. - type
  32538. type: object
  32539. headers:
  32540. additionalProperties:
  32541. type: string
  32542. description: Headers
  32543. type: object
  32544. method:
  32545. description: Webhook Method
  32546. type: string
  32547. result:
  32548. description: Result formatting
  32549. properties:
  32550. jsonPath:
  32551. description: Json path of return value
  32552. type: string
  32553. type: object
  32554. secrets:
  32555. description: |-
  32556. Secrets to fill in templates
  32557. These secrets will be passed to the templating function as key value pairs under the given name
  32558. items:
  32559. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  32560. properties:
  32561. name:
  32562. description: Name of this secret in templates
  32563. type: string
  32564. secretRef:
  32565. description: Secret ref to fill in credentials
  32566. properties:
  32567. key:
  32568. description: The key where the token is found.
  32569. maxLength: 253
  32570. minLength: 1
  32571. pattern: ^[-._a-zA-Z0-9]+$
  32572. type: string
  32573. name:
  32574. description: The name of the Secret resource being referred to.
  32575. maxLength: 253
  32576. minLength: 1
  32577. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32578. type: string
  32579. type: object
  32580. required:
  32581. - name
  32582. - secretRef
  32583. type: object
  32584. type: array
  32585. timeout:
  32586. description: Timeout
  32587. type: string
  32588. url:
  32589. description: Webhook url to call
  32590. type: string
  32591. required:
  32592. - result
  32593. - url
  32594. type: object
  32595. type: object
  32596. served: true
  32597. storage: true
  32598. subresources:
  32599. status: {}